Implementing Pluggable Auth Module for dbaccess
Posted in 2011
Topics: Server Administration, Security, Permissions & Auditing
Hello,
I want to implement pluggable authentication module to control access to
dbaccess utility.I mean whenever any user login to the DB server and try to
access any database instance through dbaccess command , the engine first
authenticate that user by password prompt and then allow him to query the
database.
Are there any precise steps available to get this done ?
--
Regards,
Anees Ahmad
Why do you need this? Do you need to have trusted connections to the
database? If not, just disable trusted connections in SQLHOSTS options field
and voila... all your connections will require a password.
Regards
On Wed, Oct 5, 2011 at 10:59 PM, ANEES AHMAD <aanees@i2cinc.com> wrote:
> Hello,
>
> I want to implement pluggable authentication module to control access to
> dbaccess utility.I mean whenever any user login to the DB server and try to
> access any database instance through dbaccess command , the engine first
> authenticate that user by password prompt and then allow him to query the
> database.
>
> Are there any precise steps available to get this done ?
>
> --
> Regards,
> Anees Ahmad
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--0016e6de17b8cc96b604ae952314
It is the requirement that whenever a user logs in to the DB Server and try to
connect to the DB instance by issuing the 'dbaccess' command a password prompt
should be displayed to that user. Without entering correct password the user
should not be able to connect to the db.
I think it could be done through PAM but the question is, how can it be
configured with the dbaccess utility.
Regards
It has nothing to do with PAM, really.
You could write a script that asks for login, put it on the user´s
profile, and call dbaccess like this:
dbaccess - -<<\\\\!
connect to '@instance_name' user 'username';
!
ENTER PASSWORD:
(this is in Information Center website, on the link below:)
http://publib.boulder.ibm.com/infocenter/idshelp/v117/topic/com.ibm.dba.doc/ids_
dba_039.htm?resultof=%22%64%62%61%63%63%65%73%73%22%20
Then, if the password/user is wrong, it won´t be able to run dbaccess.
I think that should solve your issue, right?
Regards.
Em 06/10/2011 13:39, ANEES AHMAD escreveu:
> It is the requirement that whenever a user logs in to the DB Server and try
to
> connect to the DB instance by issuing the 'dbaccess' command a password
prompt
> should be displayed to that user. Without entering correct password the user
> should not be able to connect to the db.
>
> I think it could be done through PAM but the question is, how can it be
> configured with the dbaccess utility.
>
> Regards
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Alexandre Marini
Tecnologia da Informação - DBA
SEFAZ-MS / SGI-UGSR / Sistemas IBM-Informix
<Cert-Info-Mgmt_color.jpg>
IBM Certified System Administrator - Informix Dynamic Server V10 / V11 /
V11.70
IBM Information Management Informix Technical Professional v3