Re: OLEDB connection and AD Windows
Posted in 2008
Richard Spitz wrote: > Fernando Nunes <spam@onlinedomus.net> schrieb: > >> But my whole point is this, and i'm not saying I cannot be wrong: >> >> If you configure the underlying OS to authenticate against an LDAP server, than >> normal IDS connections (not the ones on PAM enable DBSERVERALIAS) should be >> able to work transparently... IDS does not check the files itself. It uses >> normal OS functions (getpwnam is familiar). If these functions return the usual >> result, it should work. > > I wish you were right. My own experience and research on this indicate you are > not, but I'd be more than happy if I were on the wrong track. > Me too :) Sooner or later I'll test it... It's on my personal agenda... > What's the whole point of enabling/configuring IDS for using PAM, when the > normal OS functions suffice for authenticating users? Ahh... the real nice question! Because with PAM you gain a lot more (if some issues are fixed, and if you take the time to learn it). A few examples: * You get rid of .rhosts and hosts.equiv * You can combine modules in anyway you want... Like: * allow connections based on the daytime * let a DBSA inhibit connections from a user without the need for any OS administrator privilege (don't need to block the account or change pwd) * implement complex challenge/response mechanism... for example a user may have all the privileges, but won't be able to connect outside the application that understands the challenges * put the users inside the database in a custom table I could think about more examples... With a few IDS fixes, PAM would push the authentication limits to places we can only imagine... Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...