LDAP validation
Posted in 2004
Topics: Security, Permissions & Auditing
Sorry for sending this again,
(ESC-key does not work in Outlook as in
vi)
=20
We are starting to implement LDAP and we are having some problems. Now
those users whose accounts were moved to LDAP are having problems
connecting to the database. Their accounts were deleted from
/etc/password and they are getting.
=20
951: Incorrect password or user AUserName is not known on the database
server.
=20
We have not changed anything from the database perspective, Their
permissions still are in place. Does Informix access to /etc/passwd
directly thru their own functions or use standard systems calls?
=20
Thanks
=20
=20
=20
=20
=20
Hi
IDS does not support LDAP directly.
[ IDS uses normal system calls to get authentication information.
These system calls generally do not support LDAP, therefore
IDS does not support LDAP. ]
There are two ways to get IDS to do authentication via LDAP:
a) use PAM which is supported on selected platforms since
IDS 9.40.xC2. Check the file "pam.txt" in
"$INFORMIXDIR/release/en_us/0333" for more information on
PAM support.
With the proper PAM module that does authentication via LDAP,
IDS will thus be able to utilize LDAP via this PAM.
b) get a NIS/NIS+ implementation that transparently supports LDAP.
NIS/NIS+ is transparently supported by the above mentioned
system calls. That way IDS is able to support NIS/NIS+.
Implementations of NIS/NIS+ that transparently support LDAP are
available on various platforms from various sources (though I never
dived into this). As everything is transparent for IDS, it would then
be able to do authentication via LDAP.
This will work even with older versions of IDS (i.e. before 9.40.UC2).
All the above is valid for the various UNIX/LINUX flavours.
If you are on Windows NT - then I don't know. Sorry.
Regards
Martin.
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Data Management Solutions
forum.subscriber@iiug.org wrote on 17.11.2004 17:11:35:
> Sorry for sending this again, (ESC-key does not work in Outlook as in
> vi)
>
> We are starting to implement LDAP and we are having some problems. Now
> those users whose accounts were moved to LDAP are having problems
> connecting to the database. Their accounts were deleted from
> /etc/password and they are getting.
>
> 951: Incorrect password or user AUserName is not known on the database
> server.>
> We have not changed anything from the database perspective, Their
> permissions still are in place. Does Informix access to /etc/passwd
> directly thru their own functions or use standard systems calls?
>
> Thanks
Hi Walter
Not sure if this is going to be relevant in your case
as LDAP is out of my experience; but I know there were
problems in the 7.3x series servers (giving 951
errors) when connecting using the CONNECT statement in
sql where users had passwords that were greater than 8
characters in length.
Malc
--- Walter Milan <Walter_Milan@hilton.com> wrote:
> Sorry for sending this again, (ESC-key does not work
> in Outlook as in
> vi)
>
> =20
>
> We are starting to implement LDAP and we are having
> some problems. Now
> those users whose accounts were moved to LDAP are
> having problems
> connecting to the database. Their accounts were
> deleted from
> /etc/password and they are getting.
>
> =20
>
> 951: Incorrect password or user AUserName is not> known on the database
> server.
>
> =20
>
> We have not changed anything from the database
> perspective, Their
> permissions still are in place. Does Informix access
> to /etc/passwd
> directly thru their own functions or use standard
> systems calls?
>
> =20
>
> Thanks
>
> =20
>
> =20
>
> =20
>
> =20
>
> =20
>
>
>
>
What OS and version? We encountered this same scenario when we initially
went to LDAP validation but only on AIX 5.2, it worked fine on AIX4.3.3.
EFIX 54546_1.040804.epkg.Z fixed the issue.
"Walter Milan"
<Walter_Milan@hil
ton.com> To
Sent by: ids@iiug.org
forum.subscriber@ cc
iiug.org
Subject
LDAP validation [3712]
11/17/2004 08:11
AM
Sorry for sending this again, (ESC-key does not work in Outlook as in
vi)
=20
We are starting to implement LDAP and we are having some problems. Now
those users whose accounts were moved to LDAP are having problems
connecting to the database. Their accounts were deleted from
/etc/password and they are getting.
=20
951: Incorrect password or user AUserName is not known on the database
server.
=20
We have not changed anything from the database perspective, Their
permissions still are in place. Does Informix access to /etc/passwd
directly thru their own functions or use standard systems calls?
=20
Thanks
=20
=20
=20
=20
=20
We are working on Solaris 8 running on 32 bits in this
case. We opened a
case at same time and have received a very good email from IBM pointing
to a Sun website with some troubleshooting
http://docs.sun.com/app/docs/doc/806-5580/6jej518q8?a=view
System Administrators still are working the issue.
Walter
-----Original Message-----
From: Martin_Fischer@agsea.com [mailto:Martin_Fischer@agsea.com]
Sent: Thursday, November 18, 2004 12:29 PM
To: Walter Milan
Cc: forum.subscriber@iiug.org; ids@iiug.org
Subject: Re: LDAP validation [3712]
What OS and version? We encountered this same scenario when we
initially
went to LDAP validation but only on AIX 5.2, it worked fine on AIX4.3.3.
EFIX 54546_1.040804.epkg.Z fixed the issue.
"Walter Milan"
<Walter_Milan@hil
ton.com>
To
Sent by: ids@iiug.org
forum.subscriber@
cc
iiug.org
Subject
LDAP validation [3712]
11/17/2004 08:11
AM
Sorry for sending this again, (ESC-key does not work in Outlook as in
vi)
=20
We are starting to implement LDAP and we are having some problems. Now
those users whose accounts were moved to LDAP are having problems
connecting to the database. Their accounts were deleted from
/etc/password and they are getting.
=20
951: Incorrect password or user AUserName is not known on the database
server.
=20
We have not changed anything from the database perspective, Their
permissions still are in place. Does Informix access to /etc/passwd
directly thru their own functions or use standard systems calls?
=20
Thanks
=20
=20
=20
=20
=20