authenticating informix users using winbind
Posted in 2009
Poster set up RHEL5 + IDS 11.50 with winbind/Active Directory authentication; local OS logins worked but Informix connections failed with error 951/952. Fernando Nunes explained that if winbind works at OS level (getpwnam) Informix should authenticate transparently, no PAM needed, and that 952 means the user was found but crypt() password comparison failed. The poster got PAM (pam_winbind in sqlhosts, plus a sysauth entry) working, then dropped PAM so local tools (dbaccess, isql, 4GL) worked, but remote ODBC/.NET clients with AD accounts still failed — PAM isn't supported by the .NET/OleDB providers. No full resolution recorded; the poster was looking at Kerberos/GSSCSM single sign-on as a next step.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Installation, Setup & Upgrades, SQL Development & Query Writing, Server Administration, Security, Permissions & Auditing, Logging & Checkpoints, Platform-Specific Issues, Third-Party Tools & Monitoring, Versions, Editions & End-of-Life
Im setting up a new server with RHEL5 and IDS 11.5.UC1 that will
eventually replace another server running RHEL4 and IDS 10. One of the
goals on the upgrade project is to authenticate users against Active
Directory.
(
http://spiralbound.net/2007/04/11/rhel-winbind-authentication-against-active-directory
http://kbase.redhat.com/faq/docs/DOC-3211
)
The OS was configured to use winbind and can successfully join the
domain and authenticate domain users. Domain users home directory gets
created under /home/DOMAIN/. Once logged in trying to access informix
(ex. dbaccess databse , isql )results in the following error:
951: Incorrect password or user username@devinformix.domain.com is notknown on the database server.
Google found the following on how to configure IDS to authenticate
against AD/LDAP but it requires changes to the AD schema (needs
services for Unix).
http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam-for.html
Im using that as guide and trying to adjust for winbind instead of
pam_ldap but havent been able to get it working. Anyone has a similar
set up using winbind that can give some pointers?
$ uname -a
Linux devinformix.domain.com 2.6.18-120.el5PAE #1 SMP Fri Oct 1718:17:11 EDT 2008 i686 i686 i386 GNU/Linux
$ cat /etc/redhat-releaseRed Hat Enterprise Linux Server release 5.3 Beta (Tikanga)
$ onstat -m
IBM Informix Dynamic Server Version 11.50.UC1 -- On-Line -- Up
15:48:02 -- 1673868 Kbytes
Everything works using local users. So far IDS 11.5 looks very good.
The non-blocking checkpoints and the auto-tune features work great.
The OpenAdminTool is a nice addition too.
brenddie wrote:
> Im setting up a new server with RHEL5 and IDS 11.5.UC1 that will
> eventually replace another server running RHEL4 and IDS 10. One of the
> goals on the upgrade project is to authenticate users against Active
> Directory.
> (
> http://spiralbound.net/2007/04/11/rhel-winbind-authentication-against-active-directory
> http://kbase.redhat.com/faq/docs/DOC-3211
> )
>
> The OS was configured to use winbind and can successfully join the
> domain and authenticate domain users. Domain users home directory gets
> created under /home/DOMAIN/. Once logged in trying to access informix
> (ex. dbaccess databse , isql )results in the following error:
>
> 951: Incorrect password or user username@devinformix.domain.com is not> known on the database server.
>
> Google found the following on how to configure IDS to authenticate
> against AD/LDAP but it requires changes to the AD schema (needs
> services for Unix).
>
> http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam-for.html
>
> Im using that as guide and trying to adjust for winbind instead of
> pam_ldap but havent been able to get it working. Anyone has a similar
> set up using winbind that can give some pointers?
>
>
>
>
> $ uname -a
> Linux devinformix.domain.com 2.6.18-120.el5PAE #1 SMP Fri Oct 17> 18:17:11 EDT 2008 i686 i686 i386 GNU/Linux
>
> $ cat /etc/redhat-release> Red Hat Enterprise Linux Server release 5.3 Beta (Tikanga)
>
> $ onstat -m>
> IBM Informix Dynamic Server Version 11.50.UC1 -- On-Line -- Up
> 15:48:02 -- 1673868 Kbytes>
> Everything works using local users. So far IDS 11.5 looks very good.
> The non-blocking checkpoints and the auto-tune features work great.
> The OpenAdminTool is a nice addition too.
A few thoughts:
- If you configure your OS to authenticate users on AD through winbind
it will be transparent for Informix. This means that if getpwnam() OS
function works, then Informix will work without PAM
- Check the error on the server side (online.log). Client will see 951
most of the times (if not all). Tha error also means you probably have
not configure IDS for PAM (and you shouldn't need to)
The real issue is that getpwnam() must work for your user and return
meaningful data....
Regards,
> A few thoughts:
>
> - If you configure your OS to authenticate users on AD through winbind
> it will be transparent for Informix. This means that if getpwnam() OS
> function works, then Informix will work without PAM
>
> - Check the error on the server side (online.log). Client will see 951
> most of the times (if not all). Tha error also means you probably have
> not configure IDS for PAM (and you shouldn't need to)
>
> The real issue is that getpwnam() must work for your user and return
> meaningful data....
>
> Regards,
I was expecting it to be transparent for informix once the user logged
at least once to the OS but it was giving the error above. I did got
it working now by following your guide and just changing pam_ldap to
pam_winbind and using config=/etc/samba/smb.conf. Been playing for the
last hour with running queries across servers. Just had to add a line
to the sysauth table:
insert into sysauth (username, servers, hosts ) values ( '*','server_engine', 'claims.domain.com' );
I was under the impression that executing and logging as local user
informix to use dbaccess wouldnt work but it does with out any issues.
Havent checked but it seems winbind handles local accounts too so that
was a plus
now that I have it working Im going to go ahead and comment out the
IDS pam settings and try again with out it. maybe informix sees the
winbind authenticated accounts as external and adding a line to
sysauth for the local engine will make it work. Will try testing
getpwnam() and see what it returns
thanks
another thing: in your article you say PAM is not supported yet for .NET clients. Im getting the following error when testing a current asp .net application against the test server using the latest 3.5tc4 csdk .net provider ERROR [08004] [Informix .NET provider][Informix]Server rejected the connection. Is there any workaround for this? This is going to be a deal breaker if I cant get informix to work without PAM with the OS using winbind
Removed the PAM settings from sqlhosts and it works for winbind
authenticated users. Users can Log in to the server using their AD
credentials and run 4gls, dbaccess and isql without problem. The
problem is that informix will reject logins from remote clients if an
AD account is used:
ERROR [28000] [Informix .NET provider][Informix]Incorrect password or
user aduser@pulsar.domain.com is not known on the database server.
online.log:
08/18/09 16:25:40 Password Validation for user [aduser] failed!
08/18/09 16:25:40 Check for password aging/account lock-out.
08/18/09 16:25:40 listener-thread: err = -952: oserr = 0: errstr =
aduser@pulsar.domain.com: User (aduser@pulsar.domain.com)'s password
is not correct for the database server.
tried different combinations of DOMAIN\\username,username@DOMAIN and
ODBC and .net driver but the same error occurs. using the local
informix account credentials works to connect remotely
Any ideas on how to troubleshoot?
brenddie wrote:
> Removed the PAM settings from sqlhosts and it works for winbind
> authenticated users. Users can Log in to the server using their AD
> credentials and run 4gls, dbaccess and isql without problem. The
> problem is that informix will reject logins from remote clients if an
> AD account is used:
>
> ERROR [28000] [Informix .NET provider][Informix]Incorrect password or
> user aduser@pulsar.domain.com is not known on the database server.
>
> online.log:
> 08/18/09 16:25:40 Password Validation for user [aduser] failed!
> 08/18/09 16:25:40 Check for password aging/account lock-out.
> 08/18/09 16:25:40 listener-thread: err = -952: oserr = 0: errstr =
> aduser@pulsar.domain.com: User (aduser@pulsar.domain.com)'s password
> is not correct for the database server.
>
> tried different combinations of DOMAIN\\username,username@DOMAIN and
> ODBC and .net driver but the same error occurs. using the local
> informix account credentials works to connect remotely
>
>
> Any ideas on how to troubleshoot?
I'm not familiar with winbind. Does it make sense to test "aduser"/password?
What password encryption are you using? It should be compatible with
crypt(). Informix will get the user info by calling getpwnam. After
that, it will crypt() the given password and compare it with what it got
from getpwnam(). If the algorithms don't match you'll get that.
Meanwhile, if 952 is the error you get from online log it means it was
able to get the user info, but the passwords didn't match. If it was not
finding the user you'd probably get 951.
As for support for PAM in .NET/OleDB I'm not sure about the status. I
know that there is a feature request for it. In order to be sure you
could contact tech support and manifest your interest... It obviously
makes sense, but I don't know about the planning...
Regards.
brenddie wrote: > The OS was configured to use winbind and can successfully join the > domain and authenticate domain users. Domain users home directory gets > created under /home/DOMAIN/. It certainly sounds like the winbind part of things work. Good. Our IDS 11 on RHEL 5 works well with pam+winbind based logins. If you post your /etc/pam.d/informix and your sqlhosts files, I can try to see if I can spot where the error originates from. By the way (with very little relation to Informix): I wish I had set up Winbind to use IDMAP_RID, instead of the default idmap backend: http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/ idmapper.html#id2606608 (It's somewhat complicated to change after the system has gone into production). The reason why I don't like the default (TDB) local database ID mapping is that I've seen it break a couple of times; and then, with a new, fresh TDB database, users may get new UIDs/GIDs, resulting in chaos. A deterministic user ID mapping like IDMAP_RID, no local state is kept, meaning less risk of confusion. My next project may be to try to use Kerberos based authentication, so that Access/Excel users don't have to (re-)enter passwords when accessing through the ODBC driver. From various reading, I get the impression that it should be possible. -- Troels
>
> Our IDS 11 on RHEL 5 works well with pam+winbind based logins. If you
> post your /etc/pam.d/informix and your sqlhosts files, I can try to see
> if I can spot where the error originates from.
Nice to hear. I got Informix working using PAM settings on sqlhosts
but after some reading it seems that would require modifying any
current 4gls to handle the PAM connection logic. Fernando's idea of
the authentication being transparent to informix once the OS is
working makes sense and thats what Im trying to accomplish now. I
removed the PAM setting from sqlhosts and got it working with only
winbind at the OS. Everything works if exceuted locally on the server.
Trying to connect remotelly (ODBC, .net driver) results in a login
failed error
from onconfig
DBSERVERNAME server_engineDBSERVERALIASES server_engine_tcp
sqlhosts
server_engine onipcshm 192.168.20.1 1530
#members_engine onipcshm 192.168.20.1 1530 s=4,pam_serv=
(ids_pam_service),pamauth=(password)
server_engine_tcp onsoctcp 192.168.20.1 1492
/etc/samba/smb.conf
# Generated by authconfig on 2009/08/17 16:54:09
# DO NOT EDIT THIS SECTION (delimited by --start-line--/--end-line--)
# Any modification may be deleted or altered by authconfig in future
workgroup = domain
password server = dc.domain.com
realm = DOMAIN>COM
security = ads
idmap uid = 16777216-33554431
idmap gid = 16777216-33554431
template shell = /bin/bash
winbind use default domain = true
winbind offline logon = true
#--authconfig--end-line--
>
> By the way (with very little relation to Informix):
> I wish I had set up Winbind to use IDMAP_RID, instead of the default
> idmap backend:http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/
> idmapper.html#id2606608
> (It's somewhat complicated to change after the system has gone into
> production).
> The reason why I don't like the default (TDB) local database ID mapping
> is that I've seen it break a couple of times; and then, with a new, fresh
> TDB database, users may get new UIDs/GIDs, resulting in chaos. A
> deterministic user ID mapping like IDMAP_RID, no local state is kept,
> meaning less risk of confusion.
>
Im still researching and thats something I'll look into. thanks
> My next project may be to try to use Kerberos based authentication, so
> that Access/Excel users don't have to (re-)enter passwords when accessing
> through the ODBC driver. From various reading, I get the impression that
> it should be possible.
having SSH and the ODBC connect without reentering the password would
be an awesome setup. I'm willing to give it a try if you feel like
mentoring me on the process. I have around 2 more weeks to do all the
experimenting and coming up with what would be the next features for
our next prod server.
found this that seems to be what I need: http://www.ibm.com/developerworks/data/library/techarticle/dm-0809govindarajan/index.html still not sure if it will require modifications to any 4gls running locally on the IDS ... server. Remote clients will need to include "s=7, csm = (GSSCSM)" on their connection strings