PAM Authentication with certificates
Posted in 2014
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing, Platform-Specific Issues, Java & JDBC Development
Hi experts,
We need to set up an JAVA environment which accesses an IDS instance via
JDBC/Datasource Pools. (sounds simple, have done that a 100 times ...)
Now comes the challenge:
The requirement is that the client does not have a clear text password stored
in a config file nor hard coded in source code.
I was thinking of a PAM based solution, which would be working based on a
challenge-response
message, which is based on a certificate check (I saw something like this in a
project named X509pam on sourceforge,
which could be modified to be challenge-response instead of referring to a USB
mount).
The user should be setup on the IDS server with an unmatchable password in OS,
without a shell / home dir (unable to login or get access
via the standard connector with password, no .rhosts / hosts.equiv allowed).
The PAM module would be registered and given the location of the servers
certificate/key (which are stored at a secure location).
The client code would respond to the challenge with the public part of the
certificate (or some built-in constant encrypted with the certificate)
and the server PAM code would verify the response against the local
certificates and authenticate the user without password.
(similar to a ssh login with public key authentication).
There is no need to encrypt the data, only authentication should be done
without a password.
The goal is to disallow any user (without programming skills) to get access as
this user e.g. using dbaccess.
Sounds like some programming work, which could be done, but I was wondering if
anybody has a better idea,
which works out-of-the box.
Informix Version would be IDS11.70FC8, Linux 64 bit (probably 12.10FCx when
project gets released).
Programming environment Java 7/JBoss Application server/latest JDBC driver
Any hints are welcome.
Thanks to all in advance.
Marcus Haarmann
While reading your post I got the feeling of beeing a college student in
the middle of an exam... :)
Not that it doesn't make sense, but at some point it could look a bit
academic... Let me express my thoughts:
1- I'm not sure if we provided a way to use certificates for client
authentication... I was under the impression that it was possible, but I
didn't figure out how (it's late here...)
2- You can very easily create a custom PAM module and a call back function
that answers something. It would more or less as you describe, but would
not be "fancy". Point is, it would work for any user... as long as a user
could setup the call back function... but I don't understand the advantage
of this over having the password in the client...?
3- Wouldn't it work if you setup a port with firewall rules that only allow
a connection from a specific origin? Or can't you assure the security of
the client? A user with a sysdbopen() procedure could validate the client
origin (not that this is free of "issues" over versions....)
4- What you describe may well be somewhere on the Internet... if you find
it for PAM, you can use it with Informix
5- 2) and 3) are related... whatever you create with PAM is not associated
with a user, but with a port... however you can add a module that only
allows connections from a user on a specific port.
Regards
On Wed, Aug 20, 2014 at 11:08 PM, Marcus Haarmann <marcus.haarmann@midoco.de
> wrote:
> Hi experts,
>
> We need to set up an JAVA environment which accesses an IDS instance via
> JDBC/Datasource Pools. (sounds simple, have done that a 100 times ...)
>
> Now comes the challenge:
> The requirement is that the client does not have a clear text password
> stored
> in a config file nor hard coded in source code.
> I was thinking of a PAM based solution, which would be working based on a
> challenge-response
> message, which is based on a certificate check (I saw something like this
> in a
> project named X509pam on sourceforge,
> which could be modified to be challenge-response instead of referring to a
> USB
> mount).
>
> The user should be setup on the IDS server with an unmatchable password in
> OS,
> without a shell / home dir (unable to login or get access
> via the standard connector with password, no .rhosts / hosts.equiv
> allowed).
> The PAM module would be registered and given the location of the servers
> certificate/key (which are stored at a secure location).
> The client code would respond to the challenge with the public part of the
> certificate (or some built-in constant encrypted with the certificate)
> and the server PAM code would verify the response against the local
> certificates and authenticate the user without password.
> (similar to a ssh login with public key authentication).
> There is no need to encrypt the data, only authentication should be done
> without a password.
> The goal is to disallow any user (without programming skills) to get
> access as
> this user e.g. using dbaccess.
>
> Sounds like some programming work, which could be done, but I was
> wondering if
> anybody has a better idea,
> which works out-of-the box.
>
> Informix Version would be IDS11.70FC8, Linux 64 bit (probably 12.10FCx when
> project gets released).
> Programming environment Java 7/JBoss Application server/latest JDBC driver
>
> Any hints are welcome.
> Thanks to all in advance.
>
> Marcus Haarmann
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--089e010d8dd60343c9050118fb7d
Hi Fernando,
thank you for your thoughts on this.
referring to 2-
We would have an "application" user, who can select update delete but no ddl.
Then, we would have
additional users which have the ability to select only, and administrative
ones who also can do ddl.
The callback function depends on the accessibilty to the cert file, which is
not reachable for normal users.
Since obviously dbaccess cannot implement this callback functionality, a
normal user would not
be able to become the application user when he gets knowledge of the password
(because the app user does not have
a matchable password).
sysdbopen could be another approach, just to check the IP address of the
client, but the password would be needed.
We could maybe try to make a firewall solution work and restrict the dbaccess
calls to other machines.
Sounds like a possibility we might to think of.
Best regards,
Marcus Haarmann
----- Ursprüngliche Mail -----
Von: "Fernando Nunes" <domusonline@gmail.com>
An: ids@iiug.org
Gesendet: Donnerstag, 21. August 2014 02:41:30
Betreff: Re: PAM Authentication with certificates [33550]
While reading your post I got the feeling of beeing a college student in
the middle of an exam... :)
Not that it doesn't make sense, but at some point it could look a bit
academic... Let me express my thoughts:
1- I'm not sure if we provided a way to use certificates for client
authentication... I was under the impression that it was possible, but I
didn't figure out how (it's late here...)
2- You can very easily create a custom PAM module and a call back function
that answers something. It would more or less as you describe, but would
not be "fancy". Point is, it would work for any user... as long as a user
could setup the call back function... but I don't understand the advantage
of this over having the password in the client...?
3- Wouldn't it work if you setup a port with firewall rules that only allow
a connection from a specific origin? Or can't you assure the security of
the client? A user with a sysdbopen() procedure could validate the client
origin (not that this is free of "issues" over versions....)
4- What you describe may well be somewhere on the Internet... if you find
it for PAM, you can use it with Informix
5- 2) and 3) are related... whatever you create with PAM is not associated
with a user, but with a port... however you can add a module that only
allows connections from a user on a specific port.
Regards
On Wed, Aug 20, 2014 at 11:08 PM, Marcus Haarmann <marcus.haarmann@midoco.de
> wrote:
> Hi experts,
>
> We need to set up an JAVA environment which accesses an IDS instance via
> JDBC/Datasource Pools. (sounds simple, have done that a 100 times ...)
>
> Now comes the challenge:
> The requirement is that the client does not have a clear text password
> stored
> in a config file nor hard coded in source code.
> I was thinking of a PAM based solution, which would be working based on a
> challenge-response
> message, which is based on a certificate check (I saw something like this
> in a
> project named X509pam on sourceforge,
> which could be modified to be challenge-response instead of referring to a
> USB
> mount).
>
> The user should be setup on the IDS server with an unmatchable password in
> OS,
> without a shell / home dir (unable to login or get access
> via the standard connector with password, no .rhosts / hosts.equiv
> allowed).
> The PAM module would be registered and given the location of the servers
> certificate/key (which are stored at a secure location).
> The client code would respond to the challenge with the public part of the
> certificate (or some built-in constant encrypted with the certificate)
> and the server PAM code would verify the response against the local
> certificates and authenticate the user without password.
> (similar to a ssh login with public key authentication).
> There is no need to encrypt the data, only authentication should be done
> without a password.
> The goal is to disallow any user (without programming skills) to get
> access as
> this user e.g. using dbaccess.
>
> Sounds like some programming work, which could be done, but I was
> wondering if
> anybody has a better idea,
> which works out-of-the box.
>
> Informix Version would be IDS11.70FC8, Linux 64 bit (probably 12.10FCx when
> project gets released).
> Programming environment Java 7/JBoss Application server/latest JDBC driver
>
> Any hints are welcome.
> Thanks to all in advance.
>
> Marcus Haarmann
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--089e010d8dd60343c9050118fb7d
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Let me just enforce that it's pretty easy to create a PAM module that
requires a specif answer (which can vary with the user), and implement that
with a callback function.
I'm just not up to the task of doing that with certificates...
A very basic example can be found on one of my blog articles about PAM...
Note I'm not the author of that example. I think it was present in one
developerworks article which I'm not sure if it's still available.
Regards.
On Thu, Aug 21, 2014 at 7:41 AM, Marcus Haarmann <marcus.haarmann@midoco.de>
wrote:
> Hi Fernando,
>
> thank you for your thoughts on this.
>
> referring to 2-
> We would have an "application" user, who can select update delete but no
> ddl.
> Then, we would have
> additional users which have the ability to select only, and administrative
> ones who also can do ddl.
> The callback function depends on the accessibilty to the cert file, which
> is
> not reachable for normal users.
> Since obviously dbaccess cannot implement this callback functionality, a
> normal user would not
> be able to become the application user when he gets knowledge of the
> password
> (because the app user does not have
> a matchable password).
> sysdbopen could be another approach, just to check the IP address of the
> client, but the password would be needed.
>
> We could maybe try to make a firewall solution work and restrict the
> dbaccess> calls to other machines.
> Sounds like a possibility we might to think of.
>
> Best regards,
>
> Marcus Haarmann
>
> ----- Ursprüngliche Mail -----
>
> Von: "Fernando Nunes" <domusonline@gmail.com>
> An: ids@iiug.org
> Gesendet: Donnerstag, 21. August 2014 02:41:30
> Betreff: Re: PAM Authentication with certificates [33550]
>
> While reading your post I got the feeling of beeing a college student in
> the middle of an exam... :)
> Not that it doesn't make sense, but at some point it could look a bit
> academic... Let me express my thoughts:
>
> 1- I'm not sure if we provided a way to use certificates for client
> authentication... I was under the impression that it was possible, but I
> didn't figure out how (it's late here...)
> 2- You can very easily create a custom PAM module and a call back function
> that answers something. It would more or less as you describe, but would
> not be "fancy". Point is, it would work for any user... as long as a user
> could setup the call back function... but I don't understand the advantage
> of this over having the password in the client...?
> 3- Wouldn't it work if you setup a port with firewall rules that only allow
> a connection from a specific origin? Or can't you assure the security of
> the client? A user with a sysdbopen() procedure could validate the client
> origin (not that this is free of "issues" over versions....)
> 4- What you describe may well be somewhere on the Internet... if you find
> it for PAM, you can use it with Informix
> 5- 2) and 3) are related... whatever you create with PAM is not associated
> with a user, but with a port... however you can add a module that only
> allows connections from a user on a specific port.
>
> Regards
>
> On Wed, Aug 20, 2014 at 11:08 PM, Marcus Haarmann <
> marcus.haarmann@midoco.de
> > wrote:
>
> > Hi experts,
> >
> > We need to set up an JAVA environment which accesses an IDS instance via
> > JDBC/Datasource Pools. (sounds simple, have done that a 100 times ...)
> >
> > Now comes the challenge:
> > The requirement is that the client does not have a clear text password
> > stored
> > in a config file nor hard coded in source code.
> > I was thinking of a PAM based solution, which would be working based on a
> > challenge-response
> > message, which is based on a certificate check (I saw something like this
> > in a
> > project named X509pam on sourceforge,
> > which could be modified to be challenge-response instead of referring to
> a
> > USB
> > mount).
> >
> > The user should be setup on the IDS server with an unmatchable password
> in
> > OS,
> > without a shell / home dir (unable to login or get access
> > via the standard connector with password, no .rhosts / hosts.equiv
> > allowed).
> > The PAM module would be registered and given the location of the servers
> > certificate/key (which are stored at a secure location).
> > The client code would respond to the challenge with the public part of
> the
> > certificate (or some built-in constant encrypted with the certificate)
> > and the server PAM code would verify the response against the local
> > certificates and authenticate the user without password.
> > (similar to a ssh login with public key authentication).
> > There is no need to encrypt the data, only authentication should be done
> > without a password.
> > The goal is to disallow any user (without programming skills) to get
> > access as
> > this user e.g. using dbaccess.
> >
> > Sounds like some programming work, which could be done, but I was
> > wondering if
> > anybody has a better idea,
> > which works out-of-the box.
> >
> > Informix Version would be IDS11.70FC8, Linux 64 bit (probably 12.10FCx
> when
> > project gets released).
> > Programming environment Java 7/JBoss Application server/latest JDBC
> driver
> >
> > Any hints are welcome.
> > Thanks to all in advance.
> >
> > Marcus Haarmann
> >
> >
> >
> >
>
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
>
> --089e010d8dd60343c9050118fb7d
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--089e010d8dd6f09c790501204d65