Local vs. LDAP Informix Account
Posted in 2013
Dan asked whether the informix OS account on AIX 6.1 / IDS 11.50 should be a local account or managed via LDAP, worried that an LDAP outage could leave him unable to log in or restart a crashed instance. The consensus from Art Kagel, Carlton Doe (who corrected an earlier misquote), Andrew Ford and Cesar Martins was to keep the informix account local: it avoids an extra authentication layer, guarantees access during maintenance windows or directory outages (Cesar described a similar NIS failure), and offers little administrative benefit otherwise. If LDAP is used, have a plan to add the account locally.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Platform-Specific Issues
AIX 6.1 IDS 11.50.FC7 Hello, I am just wondering if anyone wants to share any thoughts or opinions on the Informix account, local vs. LDAP. I am told that Carlton Doe was at this site earlier this year before I arrived and told them to keep Informix local and that fits my way of thinking but just looking for other opinions and reasoning. Thanx, Dan
I'm a fan of the existing Informix/local OS authentication wherever it fits other corporate standards. Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Thu, Apr 11, 2013 at 11:46 AM, DAN MUELLER <ddmueller@intercall.com>wrote: > AIX 6.1 > IDS 11.50.FC7 > > Hello, > > I am just wondering if anyone wants to share any thoughts or opinions on > the > Informix account, local vs. LDAP. I am told that Carlton Doe was at this > site > earlier this year before I arrived and told them to keep Informix local and > that fits my way of thinking but just looking for other opinions and > reasoning. > > Thanx, > Dan > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --001a11c2b61668691204da187ae6
As I responded to Dan privately, I said no such thing. Carlton Doe dbaresrc@xmission.com Sent from my iPad -- typos and all On Apr 11, 2013, at 11:46 AM, "DAN MUELLER" <ddmueller@intercall.com> wrote: > AIX 6.1 > IDS 11.50.FC7 > > Hello, > > I am just wondering if anyone wants to share any thoughts or opinions on the > Informix account, local vs. LDAP. I am told that Carlton Doe was at this site > earlier this year before I arrived and told them to keep Informix local and > that fits my way of thinking but just looking for other opinions and > reasoning. > > Thanx, > Dan > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
My apologies for the mis-quote. As I said, i wasn't there but was told this by a co-worker.
It seems as though I misquotes Carlton and my apologies for that however... I am still trying to run all the scenarios over through my head and what happens if you lose LDAP for more than the user caching period and your engine crashes? Is there a possibility of not being able to get it back online w/o a restore or advanced support dialing in? I think there is a gotcha out there that could get me into this position and having Informix as a local account would prevent it. Am I wrong? I know we are talking a long shot but when I was in the down systems group, we had to fix those long shots every day. Thanx, Dan
I was wrong in my earlier email. I briefly glanced at the message as a plane door was literally about to close and thought it applied to all Informix access, not just the Informix account in specific. Now that I have a chance to re-read, in context, I must make a correction. For all access, I don't care one way or another. For the actual Informix account, I do prefer local authentication rather than LDAP. Using local removes an entire layer of configuration and set up just to be able to administer an instance. This is particularly important during a maintainence period where some or all elements of remote authentication are disabled to prevent end-users from accessing services. The Informix user ID should ALWAYS be able to connect to the instance at all times. The most reliable way to do this is through local authentication. My apologies for the earlier email. Carlton Doe dbaresrc@xmission.com Sent from my iPad -- typos and all On Apr 11, 2013, at 12:56 PM, "DAN MUELLER" <ddmueller@intercall.com> wrote: > My apologies for the mis-quote. As I said, i wasn't there but was told this by > a co-worker. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > --Apple-Mail-29FAC285-12F5-4BFA-84D1-DF606DDD355F
People actually use LDAP to authenticate the informix user? I've never considered doing this, I don't see the benefit. Reduced user administration by 0.00001%, maybe? Downside outweighs the benefits IMO. Andrew -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Carlton Doe Sent: Thursday, April 11, 2013 2:32 PM To: ids@iiug.org Subject: Re: Local vs. LDAP Informix Account [30037] I was wrong in my earlier email. I briefly glanced at the message as a plane door was literally about to close and thought it applied to all Informix access, not just the Informix account in specific. Now that I have a chance to re-read, in context, I must make a correction. For all access, I don't care one way or another. For the actual Informix account, I do prefer local authentication rather than LDAP. Using local removes an entire layer of configuration and set up just to be able to administer an instance. This is particularly important during a maintainence period where some or all elements of remote authentication are disabled to prevent end-users from accessing services. The Informix user ID should ALWAYS be able to connect to the instance at all times. The most reliable way to do this is through local authentication. My apologies for the earlier email. Carlton Doe dbaresrc@xmission.com Sent from my iPad -- typos and all On Apr 11, 2013, at 12:56 PM, "DAN MUELLER" <ddmueller@intercall.com> wrote: > My apologies for the mis-quote. As I said, i wasn't there but was told > this by > a co-worker. > > > **************************************************************************** *** > Forum Note: Use "Reply" to post a response in the discussion forum. > --Apple-Mail-29FAC285-12F5-4BFA-84D1-DF606DDD355F **************************************************************************** *** Forum Note: Use "Reply" to post a response in the discussion forum.
Hi Dan, I don't have experience with LDAP, but at my work we use NIS to sync our AIX servers. (ifx 11.50 and AIX 6.1) The informix user is local from all machines and I just say "thanks" for that. We already have one or two situations where the NIS service at the mainly produtcion DB (where is a NIS slave) just decide "stop" work... The database just stop to authenticate every new connection. I become to receive a flood of users e-mails, my boss, support team, all them on my desk asking : the database is out??? If my Informix user was synchronized with NIS (* see bellow) I will not able neither to login at the machine to check what happen and not able to answer and them I will need to get help with our AIX admin... and pray to not be the database and to not crash it. When I see the online.log with thousands of authentication error, my first act was start to test if the AIX was recognize them... which wasn't,... then I "forward" all complain to AIX admin without concern with the DB and just go take a horrible coffe on our coffe machine and watch the "unhappy" face of AIX admin trying solve the problem... :) (*) at really , our Informix user is synchronized with NIS too, but we have it local (at passwd file) where take precedence of NIS... So, if you decide use the informix synchronized with LDAP , prepare an plan B with your OS admin to include it fast locally if some problem occur with LDAP to at least able you to login and check if you "baby" is ok. And a note, something to test or concern: if you loose your LDAP , all UIDs will start to be unknown , I don't know if this cold be a problem to instance write the chunks files, logs backups, online log, alarmprogram, sync with any cluster may you have and do anything what depend of Informix user rights. Regards Cesar 2013/4/11 DAN MUELLER <ddmueller@intercall.com> > AIX 6.1 > IDS 11.50.FC7 > > Hello, > > I am just wondering if anyone wants to share any thoughts or opinions on > the > Informix account, local vs. LDAP. I am told that Carlton Doe was at this > site > earlier this year before I arrived and told them to keep Informix local and > that fits my way of thinking but just looking for other opinions and > reasoning. > > Thanx, > Dan > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --14dae9cc9f9695647104da1ef740