Re: Protocol
Posted in 1997
Hi Elisa,
Elisa Hoffman wrote:
> Has anyone connected to an Informix UNIX database through a firewall?
>
> How does INFORMIX (on UNIX) using I-NET, via ISQL, validate and confirm
> who the remote client is?
> - Is DNS used? If so, is the lookup based on IP address, where
> server name must be resolved.
>
> - If the client server IP address and name are added to /etc/hosts
> on the database server, would Informix dynamically pick up the
> additional entry if the system is configured so that lookup first
> occurs on the /etc/hosts file before checking DNS?
You haven't mentioned what version of Informix server or client you are
using. That is quite important as things have changed a little in this
area in recent releases. The behaviour I descibe applies to current
product versions (6.x and 7.x clients, 7.x servers). In essence, we
divide
clients into two classes, trusted and non-trusted.
Unix clients can be either trusted or untrusted. DOS, Windows-95 and
Windows-NT
clients are always untrusted.
A trusted client is defined as one where the connection request from the
client does
not specify a password and the client system is Unix. The database
server (Unix or NT)
first checks if the username passed by the client (explicitly or
implicitly)
is defined to the O/S (e.g. /etc/passwd, NIS etc.) If not, the
connection is rejected.
If the user is defined, it checks if access from the particular client
is 'trusted' by
the server system (by checking hosts.equiv and .rhosts [Unix only] as
usual) or if the
client is running on the same system as the server. If either of these
conditions is true,
the connection request succeeds, otherwise it is rejected.
An untrusted client is one which explicitly provides a username and
password in the
connection request. All clients can act as untrusted clients. In this
case, the userid
and password are authenticated against the server OS user database (e.g.
/etc/passwd,
NIS etc.).
In either case, all access to the OS username/passwoord database is via
OS supplied
calls, so NIS etc. is fully supported.
When a client connects to an Informix server, the server attempts to
resolve the
clients IP address into a name using normal OS calls (e.g.
gethostbyaddr). This
means that DNS, NIS etc. is fully supported. If the name resolution
fails, this
does *not* cause the client connection to fail. It simply means that
onstatcommands that normally display the client system name will instead
display its
IP address.
I hope that helps.
Chris
--
Chris Jenkins (chrisj@informix.com)
Advanced Technology Group
>>> All statements and opinions are mine and should in no way <<<
>>> be construed as representing those of Informix Software <<<