Re: Anyone here EVER gotten Kerberos authentication working
Posted in 2005
Hi, PAM support first appeared in 9.40.UC2 (rather than 9.40.UC1). That is why it is not in the manuals for 9.4. However, with 9.4 you have in "$INFORMIXDIR/release/en_us/0333" a file named "pam.txt" which documents the support of PAM. It could be, that the documentation in IDS 10 manuals is not as detailed (or with as many examples) as this "pam.txt" file from 9.4. I would send you the file, however, I don't want to send it to the whole list ... If you can't get the file, then let me know and supply an e-mail address to which I can send the file directly to you. The manual actually should have explanation about additional parameters in sqlhosts (pages 5-29 ff): ----------------------------------------------- Configuring a Database Server to Use PAM To configure a server to use PAM, the system administrator must know: - The name of the PAM module. - Whether the PAM module will raise a challenge in addition to accepting a simple username and password combination. The following example shows an sqlhosts entry with illustrative names: Authentication mode: challenge ifxserver2 oltlitcp servermc portnum2 options where options are "s=4, pam_serv=(pam_pass), pamauth=(challenge)" PAM service: pam_password (Needs only a password)\\ Authentication mode: password ifxserver2 oltlitcp servermc portnum2 options where options are "s=4, pam_serv=(pam_pass), pamauth=(password)" ----------------------------------------------- So you would use "s=4, ..., pamauth=(password)" as you don't want to implement challenging. Regarding "local" pam.conf: not that I know of. All the PAM configuration is system wide, as far as I know. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management owner-informix-list@iiug.org wrote on 02.12.2005 05:00:50: > Hi Family. > > I've left the job that sent me into the world of Oracle and I'm back in > the Informix fold. IDS 9.4 on Solaris and Linux boxes. > > My first project assignment is to get Kerboros authentication working > on a Solaris box. It seems that somewhere is the recent past, the > advice (from IBM) was to use a PAM - Plug-in Authentication Module - as > the interface to Kerberos. Note that while the 9.4 IDS is capable of > supporting PAM/Kerberos, it is first documented in release 10.0 > manuals. > > The IDS 10.0 Admin guide (page 5-27) is so sketchy with what seems to > be no real example of the setup: What to put in the options column of > sqlhosts besides s=4? All I want for now is password authentication, > no [other] challenges. Can someone *please* post a definitive example > of such a setup? A complete sqlhosts entry, a complete /etc/pam.conf or > other kerberos/PAM related file in a way that ties all the parts > together. 'Cause trying out different things will be a bad case of > wheel-spinning in pursuit of undomesticated, semi-aquatic avians. (I > stuck that in so that y'all would know it's me again. :-) > > And although this is not an Informix question, is there an environment > variable that would allow a more local file to be the pam.conf file, > instead of /etc/pam.conf? (Sorta like the way I can use > INFORMIXSQLHOSTS to refer to an alternate sqlhosts file instead of the > real on in $INFORMIXDIR/etc.) > > If you respond, please post it and don't reply by e-mail. My new place > won't let me receive Yahoo mail at my desktop. > > Thanks mucho. > > -- Jake S (Nice to be back in the fold) sending to informix-list