IDS 11.50 (Linux + PAM with MS AD)
Posted in 2010
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing, Platform-Specific Issues
Hey there,
We're considering switching from using local linux (/etc/passwd) accounts to
the Active Directory ones with our Informix. At the moment if a user logs in
to the Linux box (using ssh for instance) and specifies 'user1' then they log
in using local linux user account. If they specify domain\\\\user1 the linux
(winbind, rpc) talks to MS Active Directory and checks user name and password
against AD. To connect (JDBC, ODBC, ServerStudio) to the IDS sitting on this
linux we're currently using the linux local accounts. We'd like to switch to
using AD account when connecting to IDS.
I've managed to connect to IDS -> database using my domain account using
dbacces:
1. [DOMAIN\\\\user@hostname]/home/DOMAIN/user>echo "select first 1 tabname from
systables" | dbaccess sysmaster
...
1 row(s) retrieved.
2. to connect to any user database I have to grant Role/Connect/Resource/DBA
right to this database for user exactly 'DOMAIN/user' with uppercase DOMAIN
3. can't connect using Server Studio, different combination checked, error in
online log:
listener-thread: err = -952: oserr = 0: errstr =
DOMAIN\\\\user@client_hostname.domain: User
(DOMAIN\\\\user@client_hostname.domain)'s password is not correct for the
database server.
I'd expect this to be a matter of telling IDS to use only DOMAIN/user instead
of DOMAIN/user@client_hostname, I might be wrong though.
Does anybody have any experience with such or similar configuration?
Good morning,
Yes, I've done proof-of-concept work with OpenLDAP, eDirectory (Novell),
MS-Active Directory tests as authentication source for CX & Informix. Informix
works fine with LDAP authentication, however, CX runs into problems with
ldap-libs in the PAM authentication stack. Getpw() will fail with LDAP in the
picture from PLIBDATA binary. PLIBDATA simply doesn't like LDAP (prior to SMO
12882). I haven't done any new LDAP auth testing now that SMO 12882 is out.
Now, the good news, is I have everything working very well under NIS
authentication with CX, Informix 10 & 11.50, under SuSE Linux. However, HP-UX
and NIS is a problem with PLIBDATA, DBMAKE on the PA-RICS platform. The reason
why is that NIS is not completely native to HP-UX, you have to introduce NIS
into the PAM authentication stack, where SuSE Linux has NIS authentication
natively without any changes to the PAM modules.
So, long story short, if you're trying to have multiple CX systems, or
separate CX-Application and Informix Database server, NIS is solution to keep
authentication consistent between CX systems on the Linux platform.
If you have any questions, you're welcome to write me directly.
HTH
Sincerely,
---
Jonathan Smaby
Pomona College
(909) 621-8506
jonathan.smaby@pomona.edu
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of WALDEMAR
ZNOINSKI
Sent: Thursday, October 21, 2010 10:23 AM
To: ids@iiug.org
Subject: IDS 11.50 (Linux + PAM with MS AD) [21780]
Hey there,
We're considering switching from using local linux (/etc/passwd) accounts to
the Active Directory ones with our Informix. At the moment if a user logs in
to the Linux box (using ssh for instance) and specifies 'user1' then they log
in using local linux user account. If they specify domain\\\\user1 the linux
(winbind, rpc) talks to MS Active Directory and checks user name and password
against AD. To connect (JDBC, ODBC, ServerStudio) to the IDS sitting on this
linux we're currently using the linux local accounts. We'd like to switch to
using AD account when connecting to IDS.
I've managed to connect to IDS -> database using my domain account using
dbacces:
1. [DOMAIN\\\\user@hostname]/home/DOMAIN/user>echo "select first 1 tabname from
systables" | dbaccess sysmaster
....
1 row(s) retrieved.
2. to connect to any user database I have to grant Role/Connect/Resource/DBA
right to this database for user exactly 'DOMAIN/user' with uppercase DOMAIN
3. can't connect using Server Studio, different combination checked, error in
online log:
listener-thread: err = -952: oserr = 0: errstr =
DOMAIN\\\\user@client_hostname.domain: User
(DOMAIN\\\\user@client_hostname.domain)'s password is not correct for the
database server.
I'd expect this to be a matter of telling IDS to use only DOMAIN/user instead
of DOMAIN/user@client_hostname, I might be wrong though.
Does anybody have any experience with such or similar configuration?
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
-------------------------------------------------------------
This message has been scanned by Postini anti-virus software.
Jonathan thanks for interest in the topic. I've managed to make my Linux (SUSE) a member of Windows 2003 domain (using yast2, suprisingly with few clicks - no use of 'vi' this time). It's using samba-client, winbindd, pam_winbind. Don't use LDAP here at all. Linux (winbindd to be precise) talks to Primary Domain Controller using MSRPC call (yes, the Microsoft one). I think that from Linux point of view there's no much difference is it using winbind or ldap as it's the same PAM style of authentication. The applications using PAM (so let's say sshd and IDS obviously) doesn't (shouldn't) care what's the configuration of the PAM as long as the PAM returns 'SUCCESS' to APP (IDS) for just authenticating user. Did anybody manage to connect client (using i.e. jdbc) to IDS (let's say sitting on Windows even) using DOMAIN/username rather than just only username?