Re: /etc/hosts.equiv
Posted in 1997
In article <33503A4B.3072@segel.NOSPAM-.KING.OF.MYDOMAIN.-NOSPAM.com>, Mike Segel <mikey@segel.NOSPAM-.KING.OF.MYDOMAIN.-NOSPAM.com> wrote: > > Both the use of .rhosts and hosts.equiv are > security holes. > > Informix has yet to answer this issue. > Think about having 200+ clients. > > Informix's Client/Server solutions suck! > The only good thing is that you can create a java based app and > use a thin client. Three tier architecture. Is this relates to any three tier architecture, or just to java based? > This means only > the app server needs to be in the hosts.equiv. In any case, you must manage the access of users to something. If, in this case, three tier architecture ensures, that your users can connect to database engine only via some application, why not to provide this in two tier architecture? Of course, if we are not talking about other advantages of three tier architecture. > > DO NOT USE .rhosts! > > If you want, I could post some notes from some texts on > why not to use .rhosts. I would like to read that notes. > > -Just a tip from your uncle mike ;-) > > Bill Ennis wrote: > > > > This can be done at a more atomic level in each users .rhosts > > file on the server machine. The format of the .rhosts file > > is: > > machine user > > > > } > > } I/Net v7.2 for Windows requires you to setup an hosts.equiv file. Under > > } I/Net v5.01, the hosts.equiv file was not required because the "trusted" > > } login was managed by I/Net. > > } > > } I guess the easy to grant remote access to all clients is to place a "+" > > } in hosts.equiv. To me, it seems like a security whole! With a large > > } end-user population, how do you manage the hosts.equiv file? Do you > > } need the hosts.equiv file? > > } > > } Regards, > > } > > } Steve Romankiw > > } Executive Risk Inc. > > } > > > > -- > > Bill Ennis Voice: 312-474-7516 > > SSA Fax: 312-474-7460 > > 500 W. Madison email: ennis@ssax.com ennis@accesschicago.net > > -- > #include <std_disclaimer.h> /* Mike Segel (MS385) */ > #include <No_Spam.h> > #ifdef OFFENDED_BY_CONTENT > The author takes no responsibility for this post. > Any resemblence to a coherent rational thought is purely coincidence. > -The Management. > #endif Vardan -- vardan@sterling.ru Vardan Aroustamian Sterling Group, Moscow, Russia -------------------==== Posted via Deja News ====----------------------- http://www.dejanews.com/ Search, Read, Post to Usenet