Re: NEWERA -- Database Security
Posted in 1997
Mike Ripley wrote: > > I think this question may have been asked before. > > On Windows 3.11 you can force users to enter a password to log on to the > network. If they enter incorrectly they still get the desktop but can't > connect to network drives. > > However this does not stop them connecting to the database through > Informix I-Net unless the server has password protection. > > I do not want the user to have to type in multiple passwords. What is > the recommended method? > Thanks > -- I don't think that it was Microsloths intention to say that allowing a PC to boot without its network drives is a feature. Rather is it a bug. (The PC is still unsecure, and can pose potential security risks.) What is happening is that you have disparaging OSs which have different security models. Informix wants to authenticate the user based on the UNIX id the user is supplying. IMHO, their model works well if we are authenticating server to server, since you then limit your hosts.equiv file to a minimum. Until Informix decides to change their authentication model, your users will have to remember multiple passwords, or you can have them log into the app with one user id and let the app manage security and user authorizations. But if you can wait a bit, and can afford some hardware upgrades, you may want to look at smart card technology. You could place certificates on the card, or even biometrics if you are that security concious. (These readers will become more prevelent when PC makers start to embed them into their products.) HTHs -Mikey -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************