RE: Connectivity: authentication over ssh instead of rsh?
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration
Along these same lines, is there a way to run dbaccess on the Unix command
line from a client machine so it will use a network connection to connect to
the DB?
If Im on the same machine as the instance, its simply
dbaccess dbname sqlfile.sql
Is there a way to run dbaccess and specify it to use a network connection?
> -----Original Message-----
> From: owner-informix-list@iiug.org
> [mailto:owner-informix-list@iiug.org]On Behalf Of Thomas Parsli
> Sent: Friday, February 18, 2000 6:51 AM
> To: informix-list@iiug.org
> Subject: Re: Connectivity: authentication over ssh instead of rsh?
>
>
> Jonathan Leffler <jleffler@earthlink.net> writes:
>
> > Thomas Parsli wrote:
> >
> > > I've got several servers running apache, sshd and qmail. (period)
> > >
> > > I'd like to access a database on another server running _nothing_
> > > but Informix (IDS 2000), sshd and apache.
> > >
> > > (That's no rsh and no rlogin)
> > >
> > > Is it possible?
> >
> > I don't know, and judging from the stunning silence from the rest
> > of the crowd, neither do they.
> >
> > It is going to depend on whether the user authentication processes
> > really depend on rlogin and/or rsh running or not. My expectation
> > would be that the connection stuff does not rely on those services,
> > so you should be OK. I have no proof that this is the case, nor
> > the inclination to set up a machine with such a restricted set of
> > services to try it out.
>
> Looks like normal authentication works fine as long as I use username/
> password.
>
> I'll just pop in PSWDCSM in my tcp-listeners and it should be (relativly)
> safe.
>
> It would be nice to create a secure tunnel between server and client,
> probably something SSL can help me with.
>
> Do you know if there's a way to limit the listeners to certain hosts?
> (Like: "deny from all", "allow from 192.168.1.111")
>
> Maybe I'll just use ip-chains (I'm running on Linux)...
>
> Thomas
>
>
Thomas B Tatum schrieb:
>
> Along these same lines, is there a way to run dbaccess on the Unix command
> line from a client machine so it will use a network connection to connect to
> the DB?
>
> If Im on the same machine as the instance, its simply
>
> dbaccess dbname sqlfile.sql
>
> Is there a way to run dbaccess and specify it to use a network connection?
In fact, it is just as simple as your "local" example.
The secret behind the scenes is correct configuration of your
"sqlhosts" file and the proper setting of your INFORMIXSERVER variable.
All assuming that you are running a version of Informix > 5.
If your INFORMIXSERVER points to a server that is on another machine,
the network connection defined for that INFORMIXSERVER in the file
$INFORMIXDIR/etc/sqlhosts will be used. On the server itself, there
must be a correctly configured listener for this network connection,
of course.
Regards, Richard
--
+--------------------------+------------------------------------------+
| Dr. med Richard Spitz | INTERNET: spitz@ana.med.uni-muenchen.de |
| EDV-Gruppe Anaesthesie | Tel : +49-89-7095-6110 |
| Klinikum Grosshadern | FAX : +49-89-7095-6420 |
| 81366 Munich, Germany | GSM : +49-172-8933578 |
+--------------------------+------------------------------------------+