Re: A question on Informix JDBC driver
Posted in 1998
Wyan H. Jow wrote: >> >This makes sense to me - I wouldn't want to have my user/password in=20 >> >clear text in my code, or developers needing to know it. Even if it's = in=20 >> >the properties file. >> > >> >Problem is, going oover straight TCP, how do you do all that stuff in= =20 >> >Java, and identify yourself to the remote db host? It seems to fit mor= e=20 >> >in the java model to do it with the way that they're doing it. >> > >>=20 >> 4GL, ESQL/C does this. As I understand the server in this case=20 >> use rcmd authentication. What's the difference between socket=20 >> communications between a JAVA program and a ESQL/C program ? >>=20 >How would Java use rcmd for remote commands/authentication? As far as I= =20 >can guess there are two issues here: The difference between sockets in Ja= va=20 >and ESQL/C =3D nothing and the difference between rcmd in Java and ESQL/C = =3D=20 >there is no rcmd for Java. There are no environment variables in Java. > >I don't know what the protocol would be, but I'm assuming that there's=20 >some lower level stuff going on with ESQL/C on the client side that isn't= =20 >done with Java. > Well, as I know the only real problem for using authentication=20 by JDBC is in unsing the "reserved ports authentication scheme", i.e. opening client sockets in the reserved port numbers area. This could be done anly by superuser. Do you know, do the 4GL or ESQL/C programs run rcmd or any other setuid programs to open reserved ports for authentication? If they not, this become very interesting from the security point of view. Sorry, I don't know very well the authentication protocol used in Informix tools. I just know they use the hosts/user equivalence (/etc/hosts.equiv, $HOME/.rhost based) or $HOME/.netrc for authentication using user/password description in this file. Best Regards, Octav >>=20 >> >Octav Chiriac (com@netinfo-moldova.com) wrote: >> > >> > >> >: Hello, >> > >> >: I have downloaded the Informix JDBC Type 4 driver from Intraware. >> >: I have just started testing.=20 >> > >> >: My question is about specifing connection URL. >> >: Is there any way to connect to database server without >> >: specifying USER and PASSWORD in connection string, so that driver (se= rver) >> >: will use standard UNIX authentication (as in 4GL, ISQL, DBAccess).=20 >> > >> >: Thank You, >> >: Octav >> > >> >: --=20 >> >: Octav Chiriac Phone: (373) 2 21 20 96 >> >: NetInfo S.R.L. Fax: (373) 2 21 20 96 >> >: Chisinau (373) 2 24 00 83 >> >: Moldova, Republic of mailto:com@netinfo-moldova.com >> > >> >-- >> >***************************************************************** >> >* Wyan H. Jow * >> >* "I remember how, in college I got that part-time job as a * >> >* circus clown and the children would laugh and laugh at me. * >> >* I vowed, then and there, that I would get revenge." * >> >* - Jack Handey * >> >***************************************************************** >>=20 >> --=20 >> Octav Chiriac Phone: (373) 2 21 20 96 >> NetInfo S.R.L. Fax: (373) 2 21 20 96 >> Chisinau (373) 2 24 00 83 >> Moldova, Republic of mailto:com@netinfo-moldova.com >>=20 >=01=01=01=01 --=20 Octav Chiriac Phone: (373) 2 21 20 96 NetInfo S.R.L. Fax: (373) 2 21 20 96 Chisinau (373) 2 24 00 83 Moldova, Republic of mailto:com@netinfo-moldova.com