Re: To build better security
Posted in 2004
There are OS (and even Informix) based security mechanisms that you can enable through configuration of INFORMIXSQLHOSTS. In the server security option field (5th field) of SQLHOSTS, you can specify s=1 (/etc/hosts.equiv based) s=2 (~/.rhosts based) s=6 ($INFORMIXDIR/etc/hosts.equiv - applies only for ER-HDR type connections) For non-ER-HDR connections, first 2 options (one at a time) can be used. But, they use OS mechanism for authentication and so may compromise security for other applications running on the server machine that do not want these settings. Another and clean way of doing is through PAM that is supported from 9.40.UC2 onwards. You can write a module parallel to the ones in /usr/lib/security, just like pam_unix.so, and place it in that directory. Then, configure the server for PAM that will use the PAM-module for authentication. -- Ravi "Andrew Hamm" <ahamm@mail.com> wrote in message news:<2l944aFa8h7tU1@uni-berlin.de>... > Mike Smith wrote: > > > > Does any one know of any tool, software or a method that I can use to > > secure my > > > > Informix user connectios only from certain IP addresses, just like in > > MySql database ? > > iptables if using Linux. This is really a networking issue and shouldn't be > addressed in applications. What's better - security controlled in one place > with one code set, or security implemented 50 times, each time in a > different way. > > Although it's a noble thing for MySql to do this, I think it's ultimately > the wrong way to do it.