Re: Understanding LDAP or MS Active Directory authenticationand Informix
Posted in 2007
Topics: Security, Permissions & Auditing, Platform-Specific Issues
Whoa! First, the LDAP support is through PAM modules. (RTFM) Informix uses the OS to verify its users. If the OS supports PAM (HP-UX, Solaris, LINUX(s), and I believe AIX), then when you make the authentication call to the OS, it goes through the PAM chain that the OS uses. When you want IDS to use LDAP for authentication, then it uses PAM to authenticate against LDAP. You can, in theory, have PAM set up to check any database for authentication. That is to say, you could create a PAM module that authenticates a user against an IDS database of users. In theory, within Cheetah, you could put the authentication table within the sysadmin database. But it is interesting that Fernando said that IDS only supports 32 bit PAM libraries. That would explain a lot if true.... If not true, then you should be able to get the source for PAM modules and compile them for a 64bit environment. In your example, as far as Informix is concerned, that if you set up a user fred, it authenticates that "fred" exists and then goes along its merry way. At least thats the theory behind it. So that Informix then has to check within itself what permissions to gran user "fred". HTH -G > >Fernando, > >Thanks for the response and link. I believe I have a handle on how the >user would be authenticated to the OS. > >I guess my confusion is how do you manage db object permssions in the db if >the user does not exist. Someone mentioned that the user would connect via >public. I'm hoping that the correct way to handle this is through the >sysusers db. Each LDAP user would belong to a groupname in the sysauth >table. Therefore, you would grant perms on the objects to the groupname, >ie, LDAP user djacobs belonging to the groupname 'accounting' could be >granted perms on a specific set of accounting tables. Public would not >have these perms. > >Thanks > > > > > Fernando Nunes > <spam@domus.onlin > e.pt> To > Sent by: informix-list@iiug.org > informix-list-bou cc > nces@iiug.org > Subject > Re: Understanding LDAP or MS Active > 03/07/2007 08:56 Directory authentication and > PM Informix > > > > > > > > > > >Darren_Jacobs@carmax.com wrote: > > PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for >me. > > I'm just trying to understand what type of user id is needed in the > > database to support an LDAP/AD user. > > > > Does that make sense? > > > > >IDS will use OS authentication. If HPUX/64 allows for OS users to be >authenticated in a LDAP server this should work for Informix. >Currently there is no user id inside the database server. > >PAM allows for other ways to authenticate users (only limited by the >availability of PAM itself and the appropriate module(s) ) >I believe that 10.00.FC6 may support PAM on HP-UX (PA-RISC) but the machine >notes are not on the page yet. >For 10.00.FC5 on HP-UX (Itanium) the machine notes ( >http://publib.boulder.ibm.com/epubs/html/22963440.html ) state it supports >PAM. >If you think PAM could help, you can contact support for clarification. > >For OS/LDAP integration maybe this will help: > >http://docs.hp.com/en/internet.html#LDAP-UX%20Integration > > >-- >Fernando Nunes >Portugal > >http://informix-technology.blogspot.com >My email works... but I don't check it frequently... >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list > > >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Win a Zune''make MSN' your homepage for your chance to win! http://homepage.msn.com/zune?icid=hmetagline
Ian Michael Gumby wrote: > > But it is interesting that Fernando said that IDS only supports 32 bit > PAM libraries. That would explain a lot if true.... > Sorry, but I haven't said that... It's true that earlier IDS versions only supported PAM in 32 bit versions. But currently 64bits is supported in most platforms. Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...