informix under pam
Posted in 2012
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Internationalization & Character Sets
Sir I have already subscried at iiug but system iiug I dont know i am
unable to find any of your Id or login name my member id is 34190
I have already posted this topic on iiug from facebook but no answers
to face book and mail.
Please help me my server details as under
OS SUSE 10 kernal ver is x86_64 2.6.16.60-0.21
Informix 11.10
we are using have telnet login for users we have made .profile of each
user to restrict user within menu 4gls no prompt for isql
we want to give ODBC this to users as per our boss inst but user can update
data by odbc with out any restrictions we have created read only user with
only select permissions we want only that user have permissions of odbc.
As per my knlowdge pam configured informix can restict for allowed user
to use that port for informix by my informix settings as under
sqlhosts
ofa_eadmin onsoctcp 172.51.100.12 4903
ofa_eadmin onsoctcp 172.51.100.12 4904
onconfig
DBSERVERNAME ofa_eadmin # Name of default database server
DBSERVERALIASES ofa_eadmin1 # List of alternate dbservernames
new setting i have tried as under
new sqlhosts
ofa_eadmin onsoctcp 172.51.100.12 4903
s=4,pam_serv=(odb_pam_
services),pamauth=(password)
ofa_eadmin1 onsoctcp 172.51.100.12 4904
s=4,pam_serv=(odb_pam_service),pamauth=(challenge)
odb_pam_services and odb_pam_service file contents
auth required pam_listfile.so onerr=fail item=group sense=allow
file=/etc/login.group.allowed
#inst by paresM-1.0
#auth sufficient pam_rootok.so
auth include common-auth
account include common-account
password include common-password
session include common-session
session optional pam_xauth.so
login.group.allowed now this file is having all groups but my informix
unable to under stand this files eigher sqlhost or odb_pam_service
after this changes only root and informix are able to connect to database
--e89a8f839d338f2e0f04c6737291
You should be using table and column level privileges to restrict read-only
users. That is the best way.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Sat, Aug 4, 2012 at 12:50 PM, Paresh Thakur <thakur.paresh@gmail.com>wrote:
> Sir I have already subscried at iiug but system iiug I dont know i am
> unable to find any of your Id or login name my member id is 34190
>
> I have already posted this topic on iiug from facebook but no answers
> to face book and mail.
> Please help me my server details as under
> OS SUSE 10 kernal ver is x86_64 2.6.16.60-0.21
> Informix 11.10
>
> we are using have telnet login for users we have made .profile of each
> user to restrict user within menu 4gls no prompt for isql
> we want to give ODBC this to users as per our boss inst but user can update
> data by odbc with out any restrictions we have created read only user with
> only select permissions we want only that user have permissions of odbc.
>
> As per my knlowdge pam configured informix can restict for allowed user
> to use that port for informix by my informix settings as under
>
> sqlhosts
> ofa_eadmin onsoctcp 172.51.100.12 4903
> ofa_eadmin onsoctcp 172.51.100.12 4904>
> onconfig
> DBSERVERNAME ofa_eadmin # Name of default database server
> DBSERVERALIASES ofa_eadmin1 # List of alternate dbservernames>
> new setting i have tried as under
>
> new sqlhosts
> ofa_eadmin onsoctcp 172.51.100.12 4903
> s=4,pam_serv=(odb_pam_
> services),pamauth=(password)
> ofa_eadmin1 onsoctcp 172.51.100.12 4904
> s=4,pam_serv=(odb_pam_service),pamauth=(challenge)>
> odb_pam_services and odb_pam_service file contents
>
> auth required pam_listfile.so onerr=fail item=group sense=allow
> file=/etc/login.group.allowed
> #inst by paresM-1.0
> #auth sufficient pam_rootok.so
> auth include common-auth
> account include common-account
> password include common-password
> session include common-session
> session optional pam_xauth.so
>
> login.group.allowed now this file is having all groups but my informix
> unable to under stand this files eigher sqlhost or odb_pam_service
> after this changes only root and informix are able to connect to database
>
> --e89a8f839d338f2e0f04c6737291
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340f1b6de82504c67ab4f5
Restricting a user when using ODBC is a FAQ, but the answer is still:
Don't/Can't.
If you grant a user write rights (UPDATE/DELETE/INSERT etc.) you can't then
limit if the user is connection through ODBC.
What you can do is to allow certain users to connect only from certain
hosts.
From what I understand from the message below you have a group of users
with write permissions connection through telnet/ssh to a certain host.
So you could prevent thos users from connecting from anywhere else and then
create different users with less rights (tables permissions) and allow them
to connect from anywhere (ODBC etc.)
The problem of doing this is that you'll end up with more users than you
should need.
In order to restrict the users you could effectively use PAM, but that
would add extra complexity that I don't think you need. You could simply
check the hostname of the user in a sysdbopen() procedure and reject (raise
an error) the connection if the "privileged" user was connection from a
different place than you're "telnet/ssh" server.
In theory you could also do this by defining two roles and setting the most
restricted role when the user is connecting from a non trusted host. But
the problem in doing this is that since roles don't have associated
passwords,a user could find out that he has access to a more privileged
role and SET ROLE to that one.
So, in short, I don't believe PAM is the way to solve this.
On Sat, Aug 4, 2012 at 5:50 PM, Paresh Thakur <thakur.paresh@gmail.com>wrote:
> Sir I have already subscried at iiug but system iiug I dont know i am
> unable to find any of your Id or login name my member id is 34190
>
> I have already posted this topic on iiug from facebook but no answers
> to face book and mail.
> Please help me my server details as under
> OS SUSE 10 kernal ver is x86_64 2.6.16.60-0.21
> Informix 11.10
>
> we are using have telnet login for users we have made .profile of each
> user to restrict user within menu 4gls no prompt for isql
> we want to give ODBC this to users as per our boss inst but user can update
> data by odbc with out any restrictions we have created read only user with
> only select permissions we want only that user have permissions of odbc.
>
> As per my knlowdge pam configured informix can restict for allowed user
> to use that port for informix by my informix settings as under
>
> sqlhosts
> ofa_eadmin onsoctcp 172.51.100.12 4903
> ofa_eadmin onsoctcp 172.51.100.12 4904>
> onconfig
> DBSERVERNAME ofa_eadmin # Name of default database server
> DBSERVERALIASES ofa_eadmin1 # List of alternate dbservernames>
> new setting i have tried as under
>
> new sqlhosts
> ofa_eadmin onsoctcp 172.51.100.12 4903
> s=4,pam_serv=(odb_pam_
> services),pamauth=(password)
> ofa_eadmin1 onsoctcp 172.51.100.12 4904
> s=4,pam_serv=(odb_pam_service),pamauth=(challenge)>
> odb_pam_services and odb_pam_service file contents
>
> auth required pam_listfile.so onerr=fail item=group sense=allow
> file=/etc/login.group.allowed
> #inst by paresM-1.0
> #auth sufficient pam_rootok.so
> auth include common-auth
> account include common-account
> password include common-password
> session include common-session
> session optional pam_xauth.so
>
> login.group.allowed now this file is having all groups but my informix
> unable to under stand this files eigher sqlhost or odb_pam_service
> after this changes only root and informix are able to connect to database
>
> --e89a8f839d338f2e0f04c6737291
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--00248c7117c774329c04c6bf512a