Anyone here EVER gotten Kerberos authentication working with IDS?
Posted in 2005
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues, Versions, Editions & End-of-Life
Hi Family. I've left the job that sent me into the world of Oracle and I'm back in the Informix fold. IDS 9.4 on Solaris and Linux boxes. My first project assignment is to get Kerboros authentication working on a Solaris box. It seems that somewhere is the recent past, the advice (from IBM) was to use a PAM - Plug-in Authentication Module - as the interface to Kerberos. Note that while the 9.4 IDS is capable of supporting PAM/Kerberos, it is first documented in release 10.0 manuals. The IDS 10.0 Admin guide (page 5-27) is so sketchy with what seems to be no real example of the setup: What to put in the options column of sqlhosts besides s=4? All I want for now is password authentication, no [other] challenges. Can someone *please* post a definitive example of such a setup? A complete sqlhosts entry, a complete /etc/pam.conf or other kerberos/PAM related file in a way that ties all the parts together. 'Cause trying out different things will be a bad case of wheel-spinning in pursuit of undomesticated, semi-aquatic avians. (I stuck that in so that y'all would know it's me again. :-) And although this is not an Informix question, is there an environment variable that would allow a more local file to be the pam.conf file, instead of /etc/pam.conf? (Sorta like the way I can use INFORMIXSQLHOSTS to refer to an alternate sqlhosts file instead of the real on in $INFORMIXDIR/etc.) If you respond, please post it and don't reply by e-mail. My new place won't let me receive Yahoo mail at my desktop. Thanks mucho. -- Jake S (Nice to be back in the fold)
Jacob wrote: > Hi Family. > > I've left the job that sent me into the world of Oracle and I'm back in > the Informix fold. IDS 9.4 on Solaris and Linux boxes. > > My first project assignment is to get Kerboros authentication working > on a Solaris box. It seems that somewhere is the recent past, the > advice (from IBM) was to use a PAM - Plug-in Authentication Module - as > the interface to Kerberos. Note that while the 9.4 IDS is capable of > supporting PAM/Kerberos, it is first documented in release 10.0 > manuals. > > The IDS 10.0 Admin guide (page 5-27) is so sketchy with what seems to > be no real example of the setup: What to put in the options column of > sqlhosts besides s=4? All I want for now is password authentication, > no [other] challenges. Can someone *please* post a definitive example > of such a setup? A complete sqlhosts entry, a complete /etc/pam.conf or > other kerberos/PAM related file in a way that ties all the parts > together. 'Cause trying out different things will be a bad case of > wheel-spinning in pursuit of undomesticated, semi-aquatic avians. (I > stuck that in so that y'all would know it's me again. :-) > > And although this is not an Informix question, is there an environment > variable that would allow a more local file to be the pam.conf file, > instead of /etc/pam.conf? (Sorta like the way I can use > INFORMIXSQLHOSTS to refer to an alternate sqlhosts file instead of the > real on in $INFORMIXDIR/etc.) > > If you respond, please post it and don't reply by e-mail. My new place > won't let me receive Yahoo mail at my desktop. > > Thanks mucho. > > -- Jake S (Nice to be back in the fold) > The best advise I can give you is to look at examples in the PAM docs or PAM conf files on a Linux box. Interesting too, you might want to make sure about which kerberos you're using. Kerberso 4 is supposedly defunct, or not worth using according to the docs, but plenty of systems still use it. Supposedly Kerberos 5 is the 'correct' version, but again only going by the scraps of info out there. The last I read was that Kerberos 4 was too weak and too easy to crack, but then again, you may not have any say in the matter on which version you're supposed to use. Good Luck!
(my does automatic line wrapping, so some configuration lines might look
as two lines in stead of one).
Your sqlhosts file should look something like this
idsname ontlitcp hostname portnum2
s=4,pam_serv=(informix),pamauth=(password)
The text "s=4,pam_serv=(informix),pamauth=(password)" is the option column.
pam_serv=(informix) is the reference into the /etc/pam.conf file or a
file called "informix" in the directory /etc/pam.d (/etc/pam.d is used
on linux, I'm not sure if it's available on Solaris).
In the /etc/pam.conf file add the following 3 lines:
informix auth sufficient /lib/security/pam_krb5.so use_first_pass
forwardable
informix password sufficient /lib/security/pam_krb5.so use_authtok
informix session optional /lib/security/pam_krb5.so
If you're using the /etc/pam.d directory (instead of /etc/pam.conf)
create a file called "/etc/pam.d/informix" with this content:
auth sufficient /lib/security/pam_krb5.so use_first_pass forwardable
password sufficient /lib/security/pam_krb5.so use_authtok
session optional /lib/security/pam_krb5.so
You should also add the PAM_STACKSIZE configuration parameter to your
ONCONFIG file. PAM_STACKSIZE has a default value of 32 Kbytes, but many
pams require much more. So try PAM_STACKSIZE=128 or 64 to see what
memory amount is sufficient. Remember to bounce the IDS instance.
Claus