Informix Security question...
Posted in 1999
User on IDS 7.3 UC7.2 / Red Hat Linux 6.0 could connect via dbaccess without credentials, but got error -952 (bad password) when supplying an explicit username and Unix password. Respondents (including Art Kagel and Jonathan Leffler) confirmed the cause: the Informix engine couldn't read shadowed (or MD5) passwords, calling it a bug; the workaround was to disable shadow/MD5 passwords. The poster asked how to disable shadowing and was pointed at the PAM documentation, with a comment that Informix should ship a PAM-aware engine rather than requiring OS security to be weakened.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
Hello all, I asked this earlier but did not get any responses - so I am re-phrasing it a bit: I am having trouble logging into an InFormix database when I specify the user name and a password -there is NO problem when I try to connect without a username & password. For reasons that I explained in the previous post -I need to specify a username and password (in short, I need to impersonate another user). Using DBACCESS -thru the CONNECTION menu if I specify a username and its Unix password -it gives error 952 -bad password but if I login without a username it lets me in. I have IDS 7.3 UC7.2 on RedHat Linux 6.0. Linux uses /etc/shadow in addition to /etc/password -could it be because of that? If so -what is the fix? Thanks, Sandeep Sent via Deja.com http://www.deja.com/ Share what you know. Learn what you don't.
You answered your own question. Informix definitely does NOT like shadow passwords. Disable this in your configuration and you should be OK. -CZ <sandeep.singh@usa.net> wrote in message news:7r0q98$sp1$1@nnrp1.deja.com... > Hello all, > > I asked this earlier but did not get any responses - > so I am re-phrasing it a bit: > > I am having trouble logging into an InFormix database > when I specify the user name and a password -there is > NO problem when I try to connect without a username & > password. For reasons that I explained in the previous > post -I need to specify a username and password (in > short, I need to impersonate another user). Using > DBACCESS -thru the CONNECTION menu if I specify a > username and its Unix password -it gives error 952 > -bad password but if I login without a username it > lets me in. > > I have IDS 7.3 UC7.2 on RedHat Linux 6.0. Linux uses > /etc/shadow in addition to /etc/password -could it be > because of that? If so -what is the fix? Thanks, > > Sandeep > > > Sent via Deja.com http://www.deja.com/ > Share what you know. Learn what you don't.
sandeep.singh@usa.net wrote: > > Hello all, > > I asked this earlier but did not get any responses - > so I am re-phrasing it a bit: > > I am having trouble logging into an InFormix database > when I specify the user name and a password -there is > NO problem when I try to connect without a username & > password. For reasons that I explained in the previous > post -I need to specify a username and password (in > short, I need to impersonate another user). Using > DBACCESS -thru the CONNECTION menu if I specify a > username and its Unix password -it gives error 952 > -bad password but if I login without a username it > lets me in. > > I have IDS 7.3 UC7.2 on RedHat Linux 6.0. Linux uses > /etc/shadow in addition to /etc/password -could it be > because of that? If so -what is the fix? Thanks, Yes, there is a problem with the shadow password facility in Linux that prevents explicit logins from Informix if the password file is shadowed. Disable shadow password and all will be well. Art S. Kagel
Thanks for your response -that is what I thought it might be but when I replaced the passwd file with shadow file it started giving me authentication errors -so I abandoned that line of thought. So, how do you disable shadowing? Sandeep In article <rtagoeee8os9@corp.supernews.com>, "CZ" <1@2.3> wrote: > You answered your own question. Informix definitely does NOT like shadow > passwords. Disable this in your configuration and you should be OK. > > -CZ > > <sandeep.singh@usa.net> wrote in message news:7r0q98$sp1$1@nnrp1.deja.com... > > Hello all, > > > > I asked this earlier but did not get any responses - > > so I am re-phrasing it a bit: > > > > I am having trouble logging into an InFormix database > > when I specify the user name and a password -there is > > NO problem when I try to connect without a username & > > password. For reasons that I explained in the previous > > post -I need to specify a username and password (in > > short, I need to impersonate another user). Using > > DBACCESS -thru the CONNECTION menu if I specify a > > username and its Unix password -it gives error 952 > > -bad password but if I login without a username it > > lets me in. > > > > I have IDS 7.3 UC7.2 on RedHat Linux 6.0. Linux uses > > /etc/shadow in addition to /etc/password -could it be > > because of that? If so -what is the fix? Thanks, > > > > Sandeep > > > > > > Sent via Deja.com http://www.deja.com/ > > Share what you know. Learn what you don't. > > Sent via Deja.com http://www.deja.com/ Share what you know. Learn what you don't.
sandeep.singh@usa.net wrote: > I asked this earlier but did not get any responses - > so I am re-phrasing it a bit: > > I am having trouble logging into an InFormix database > when I specify the user name and a password -there is > NO problem when I try to connect without a username & > password. For reasons that I explained in the previous > post -I need to specify a username and password (in > short, I need to impersonate another user). Using > DBACCESS -thru the CONNECTION menu if I specify a > username and its Unix password -it gives error 952 > -bad password but if I login without a username it > lets me in. > > I have IDS 7.3 UC7.2 on RedHat Linux 6.0. Linux uses > /etc/shadow in addition to /etc/password -could it be > because of that? Yes. > If so -what is the fix? Thanks, For the time being, don't use MD5 or shadow passwords. This is a bug. -- Jonathan Leffler (jleffler@informix.com, jleffler@earthlink.net) Guardian of DBD::Informix v0.60 -- see http://www.perl.com/CPAN #include <disclaimer.h>
sandeep.singh@usa.net writes: > Thanks for your response -that is what I thought it > might be but when I replaced the passwd file with > shadow file it started giving me authentication > errors -so I abandoned that line of thought. > > So, how do you disable shadowing? Start reading the supplied documentation for PAM. Next time, I hope Informix releases a PAM-aware version of online. One shouldn't have to cripple the OS security mechanisms to get the database security mechanisms to function. -- Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 President, CEO Fax: (760) 499-9152 My PGP fingerprint: 15 6E C7 91 5F AF 17 C4 24 93 CB 6B EB 38 B5 E5