encryption or ssh
Posted in 2000
Topics: Server Administration, Security, Permissions & Auditing
Does anyone know of a way to encrypt the requests sent to/from the database server ? Since the user name and password are sent pain text it is easily sniffed. I tried to port forward with ssh, but keep getting an error about to many files open I have bumped up the kernal param but still no avail The situation... I have a remote webserver using php4 running queries on an IDS.2000, the queries go thru 2 firewalls nicely, but in the data is readily accessable this way ... any solutions? -- Jo Vaikasas DBA Onflow Corp. 160 Pine St., 3rd Floor San Francisco, CA 94111 Tel: 415-743-9134 Fax: 415-743-9303 www.onflow.com
"Jo Vaikasas" <j.vaikasas@onflow.com> writes: > Does anyone know of a way to encrypt the requests sent to/from the database > server ? > Since the user name and password are sent pain text it is easily sniffed. > I tried to port forward with ssh, but keep getting an error about to many > files open > I have bumped up the kernal param but still no avail > > The situation... > I have a remote webserver using php4 running queries on an IDS.2000, the > queries go thru 2 firewalls nicely, > but in the data is readily accessable this way ... any solutions? Welcome to Informix's conception of database (in)security... You'll need to encrypt at a level that will be transparent to Informix (you already know that). You don't say which ssh you're using or what OS you're on, but perhaps setting up a VPN will get you to where you want to be. -- Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 President, CEO Fax: (760) 499-9152 My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B
Request's encryption depends from your platform and Informix version. If you have DCE shared library ($INFORMIXDIR/lib/csm/libixdce.??) that provides access to DCE security service you can try to encrypt your request. In worse case you can use Informix Password Communication Support Module ($INFORMIXDIR/lib/csm/libixspw.??) for protecting your passwords. Check Communication Support Services(Administrators Guide), and your release notes. Eugene In article <soXr5.1$rR6.691@wdc-read-01.qwest.net>, "Jo Vaikasas" <j.vaikasas@onflow.com> wrote: > Does anyone know of a way to encrypt the requests sent to/from the database > server ? > Since the user name and password are sent pain text it is easily sniffed. > I tried to port forward with ssh, but keep getting an error about to many > files open > I have bumped up the kernal param but still no avail > > The situation... > I have a remote webserver using php4 running queries on an IDS.2000, the > queries go thru 2 firewalls nicely, > but in the data is readily accessable this way ... any solutions? > > -- > Jo Vaikasas > DBA > Onflow Corp. > 160 Pine St., 3rd Floor > San Francisco, CA 94111 > Tel: 415-743-9134 > Fax: 415-743-9303 > www.onflow.com > > Sent via Deja.com http://www.deja.com/ Before you buy.
Eugene Nechayev <4new@my-deja.com> writes: > Request's encryption depends from your platform and Informix > version. If you have DCE shared library > ($INFORMIXDIR/lib/csm/libixdce.??) that provides access to DCE > security service you can try to encrypt your request. In worse case you > can use Informix Password Communication Support Module > ($INFORMIXDIR/lib/csm/libixspw.??) for protecting your passwords. > Check Communication Support Services(Administrators Guide), and your > release notes. > > Eugene > > In article <soXr5.1$rR6.691@wdc-read-01.qwest.net>, > "Jo Vaikasas" <j.vaikasas@onflow.com> wrote: > > Does anyone know of a way to encrypt the requests sent to/from the > database > > server ? > > Since the user name and password are sent pain text it is easily > sniffed. > > I tried to port forward with ssh, but keep getting an error about to > many > > files open > > I have bumped up the kernal param but still no avail > > > > The situation... > > I have a remote webserver using php4 running queries on an IDS.2000, > the > > queries go thru 2 firewalls nicely, > > but in the data is readily accessable this way ... any solutions? > > > > -- > > Jo Vaikasas > > DBA > > Onflow Corp. > > 160 Pine St., 3rd Floor > > San Francisco, CA 94111 > > Tel: 415-743-9134 > > Fax: 415-743-9303 > > www.onflow.com > > > > > > > Sent via Deja.com http://www.deja.com/ > Before you buy. I got the distinct impression that he was looking to protect the queries and data, too (i.e. not just passwords), from sniffing. -- Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 President, CEO Fax: (760) 499-9152 My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B
In article <m38zt6h00c.fsf@yakisoba.forte-intl.com>, Ronald Cole <ronald@forte-intl.com> wrote: > Eugene Nechayev <4new@my-deja.com> writes: > > Request's encryption depends from your platform and Informix > > version. If you have DCE shared library > > ($INFORMIXDIR/lib/csm/libixdce.??) that provides access to DCE > > security service you can try to encrypt your request. In worse case you > > can use Informix Password Communication Support Module > > ($INFORMIXDIR/lib/csm/libixspw.??) for protecting your passwords. > > Check Communication Support Services(Administrators Guide), and your > > release notes. > > > > Eugene > > > > In article <soXr5.1$rR6.691@wdc-read-01.qwest.net>, > > "Jo Vaikasas" <j.vaikasas@onflow.com> wrote: > > > Does anyone know of a way to encrypt the requests sent to/from the > > database > > > server ? > > > Since the user name and password are sent pain text it is easily > > sniffed. > > > I tried to port forward with ssh, but keep getting an error about to > > many > > > files open > > > I have bumped up the kernal param but still no avail > > > > > > The situation... > > > I have a remote webserver using php4 running queries on an IDS.2000, > > the > > > queries go thru 2 firewalls nicely, > > > but in the data is readily accessable this way ... any solutions? > > > > > > -- > > > Jo Vaikasas > > > DBA > > > Onflow Corp. > > > 160 Pine St., 3rd Floor > > > San Francisco, CA 94111 > > > Tel: 415-743-9134 > > > Fax: 415-743-9303 > > > www.onflow.com > > > > > > > > > > > > Sent via Deja.com http://www.deja.com/ > > Before you buy. > > I got the distinct impression that he was looking to protect the > queries and data, too (i.e. not just passwords), from sniffing. Correct. I've got the same idea. However except special written DataBlades(Do you know one ?) encryption from Informix side can be used for passwords only. You have to use third party software in any other case. What's wrong with the ssh configuration and kernel parameters I have no idea it's SysAdmin's problem ;-) Eugene Nechayev Informix DBA Meridex Network Corp. www.meridex.com > > -- > Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 > Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 > President, CEO Fax: (760) 499-9152 > My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B > Sent via Deja.com http://www.deja.com/ Before you buy.