PAM/LDAP Authentication
Posted in 2007
Topics: Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues, Internationalization & Character Sets
Hi everybody, I'm implanted LDAP on RH AS 4. Authentication on Red Hat is OK. I can do login successfully. May 10 12:32:09 server remote(pam_unix)[18227]: session opened for user user1 by (uid=0) May 10 12:32:09 server login - user1[18227]: LOGIN ON pts/5 BY user1 FROM pc_client By the other hand, I have an 4GL application in the box. My problem is when I run the application and a program connects to the database, IDS send the error... server-user1:/usuarios/user1>FGLSERVER=ip client:5;export FGLSERVER;FGLGUI=1;export FGLGUI; export DATABASE=dbname; menu4js; Program stopped at 'evlogo4js.4gl', line number 132. SQL statement error number -1809. Server rejected the connection. ... and in /var/log/messages and informix.log isn't written any message. Then, I need running the application WITHOUT have to type login and password when I connect to the database. I have validated some configurations, but the latest is the next: Sqlhosts ======= on_oficinas onsoctcp server sqlturbo s=4, pam_serv=(passwd), pamauth=(password) /etc/pam.d/passwd =============== auth required pam_stack.so service=system-auth account required pam_stack.so service=system-auth password required pam_stack.so service=system-auth Nothing message neither in /var/log/messages nor in informix.log. Thanks. P Antes de imprimir este correo, piensa si es necesario ------------------------------------------ Alberto Otero (aotero@bancoetcheverria.es) B|E Banco Etcheverría Departamento de Sistemas CL Real 76, 1º 15003 La Coruña 981 220042 Ext. 122 981 217523 ------------------------------------------
I see that you are using PAM in password mode. When authentication mode is password, applications should supply password and connect explicitly. Implicit connections will be rejected with -1809 error. By the way, 4GL does not directly support PAM authentication. How to get it working ? check following link. http://publib.boulder.ibm.com/infocenter/idshelp/v111/index.jsp?topic=/com.ibm.a dmin.doc/admin225.htm Regards, - Nilesh - ids-bounces@iiug.org wrote on 05/10/2007 06:39:22 AM: > Hi everybody, > > I'm implanted LDAP on RH AS 4. > Authentication on Red Hat is OK. I can do login successfully. > > May 10 12:32:09 server remote(pam_unix)[18227]: session opened for user user1 > by (uid=0) > May 10 12:32:09 server login - user1[18227]: LOGIN ON pts/5 BY user1 FROM > pc_client > > By the other hand, I have an 4GL application in the box. My problem is when I > run the application and a program connects to the database, IDS send the > error... > > server-user1:/usuarios/user1>FGLSERVER=ip client:5;export > FGLSERVER;FGLGUI=1;export FGLGUI; export DATABASE=dbname; menu4js; > Program stopped at 'evlogo4js.4gl', line number 132. > SQL statement error number -1809. > Server rejected the connection. > > .... and in /var/log/messages and informix.log isn't written any message. > > Then, I need running the application WITHOUT have to type login and password > when I connect to the database. > > I have validated some configurations, but the latest is the next: > > Sqlhosts > ======= > on_oficinas onsoctcp server sqlturbo s=4, pam_serv=(passwd), > pamauth=(password) > > /etc/pam.d/passwd > =============== > auth required pam_stack.so service=system-auth > account required pam_stack.so service=system-auth > password required pam_stack.so service=system-auth > > Nothing message neither in /var/log/messages nor in informix.log. > > Thanks. > > P Antes de imprimir este correo, piensa si es necesario > ------------------------------------------ > Alberto Otero (aotero@bancoetcheverria.es) > B|E Banco Etcheverría > Departamento de Sistemas > CL Real 76, 1º > 15003 La Coruña > > 981 220042 Ext. 122 > 981 217523 > ------------------------------------------ > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Hi again Nilesh, Thanks for your continuing assistance. Yes, my applications will supply the password and connect stmt explictily. Regarding your comment on 4gl not directly supporting PAM, mentioned in the reference: "# IBM Informix-4GL does not directly support PAM or LDAP authentication because it has no mechanism for identifying callback functions. However, if IBM Informix-4GL uses the correct version of CSDK, you can write C code that can be called from IBM Informix-4GL to handle the challenge and response protocol. To implement PAM, migrate to the new CSDK version, modify your applications to register a callback that can handle challenges and responses, and recompile your application. # Products such as Informix SQL will not handle the challenge and response protocol." I think that this statement is worded too strongly and not entirely correctly. It should be worded to indicate that 4gl does not support PAM if you are using the Challenge PAM AUTH Mode. If you are using simple password Pam mode and a PAM authentication module, such as krb5 which sends no challenge and expects no response, then 4gl should work just fine. To make the code work in this case: substitue the 4gl statement: DATABASE db_name with the 4gl statement: CONNECT TO db_name USER 'username'variable_with_username USING variable_with_password Let me know if you have questions. Regards, Jim > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On > Behalf Of Nilesh Ozarkar > Sent: Thursday, May 10, 2007 10:52 AM > To: ids@iiug.org > Subject: Re: PAM/LDAP Authentication [9117] > > I see that you are using PAM in password mode. When > authentication mode is password, applications should supply > password and connect explicitly. > Implicit connections will be rejected with -1809 error. > > By the way, 4GL does not directly support PAM authentication. > How to get it working ? check following link. > > > http://publib.boulder.ibm.com/infocenter/idshelp/v111/index.js > p?topic=/com.ibm.admin.doc/admin225.htm > > Regards, > > - Nilesh - > > ids-bounces@iiug.org wrote on 05/10/2007 06:39:22 AM: > > > Hi everybody, > > > > I'm implanted LDAP on RH AS 4. > > Authentication on Red Hat is OK. I can do login successfully. > > > > May 10 12:32:09 server remote(pam_unix)[18227]: session opened for > > user > user1 > > by (uid=0) > > May 10 12:32:09 server login - user1[18227]: LOGIN ON pts/5 BY user1 > FROM > > pc_client > > > > By the other hand, I have an 4GL application in the box. My > problem is > when I > > run the application and a program connects to the database, > IDS send > > the > > > error... > > > > server-user1:/usuarios/user1>FGLSERVER=ip client:5;export > > FGLSERVER;FGLGUI=1;export FGLGUI; export DATABASE=dbname; menu4js; > > Program stopped at 'evlogo4js.4gl', line number 132. > > SQL statement error number -1809. > > Server rejected the connection. > > > > .... and in /var/log/messages and informix.log isn't written any > message. > > > > Then, I need running the application WITHOUT have to type login and > password > > when I connect to the database. > > > > I have validated some configurations, but the latest is the next: > > > > Sqlhosts > > ======= > > on_oficinas onsoctcp server sqlturbo s=4, pam_serv=(passwd), > > pamauth=(password) > > > > /etc/pam.d/passwd > > =============== > > auth required pam_stack.so service=system-auth account required > > pam_stack.so service=system-auth password required pam_stack.so > > service=system-auth > > > > Nothing message neither in /var/log/messages nor in informix.log. > > > > Thanks. > > > > P Antes de imprimir este correo, piensa si es necesario > > ------------------------------------------ > > Alberto Otero (aotero@bancoetcheverria.es) > > B|E Banco Etcheverría > > Departamento de Sistemas > > CL Real 76, 1º > > 15003 La Coruña > > > > 981 220042 Ext. 122 > > 981 217523 > > ------------------------------------------ > > > > > > > > ************************************************************** > ***************** > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > ************************************************************** > ***************** > Forum Note: Use "Reply" to post a response in the discussion forum. > >