Informix error -1809 authentication to LDAP-UX
Posted in 2008
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration, Cloud, Docker & Containers, Versions, Editions & End-of-Life
Has anyone successfully have Informix IDS 10.00.HC5 authenticating to
LDAP-UX?
This question has come up before on the list archives, but I wasn=B9t able to
find a resolution/suggestion that would work. I have an HPUX 11.23 64-bit
box running IDS 10.00.HC5. I have LDAP-UX correctly configured to
authenticate users to Netscape/RedHat Directory Server 7.1, and
/etc/pam.conf is setup correctly to call libpam_ldap.so.1. HPUX logins are
working wonderfully. However, I am trying to configure
$INFORMIXDIR/etc/sqlhosts to authentication against LDAP-UX via PAM. I=B9m
getting Informix error =AD1809 =B3Server rejected the connection=B2.
Here is my $INFORMIXDIR/etc/sqlhosts entry:
cxdevco onsoctcp cxdev cxdevco
s=3D4,pam_serv=3D(pam_pass),pamauth=3D(password)
My /etc/pam.conf entry for "pam_pass":
pam_pass auth required libpam_hpsec.so.1
pam_pass auth sufficient libpam_unix.so.1
pam_pass auth required libpam_ldap.so.1 try_first_pass
I have this repeated for account, sessions, and password sections of
/etc/pam.conf.
Any suggestions or recommendations would be very welcome.
TIA.
Jonathan Smaby
Pomona College
--
=B3Laws are like sausages, it is better not to see them being made.=B2
~Otto von Bismarck
-------------------------------------------------------------
This message has been scanned by Postini anti-virus software.
=0D
As a part of my "Alternative Authentication" presentation, I have the source code to a short C program that mimics the IDS use of PAM. The program takes two parameters, userid and service_name. On HPUX, remember to compile with -lpam It may have to be run as root. Here is the source. Let me know if you have any problems. /**************************************************************** * Program to simulate IDS PAM Usage. * Dave Desautels, IBM, 2007 * * Usage: pam_test <username> <PAMservice> * ****************************************************************/ #include <stdio.h> #include <stdlib.h> #include <strings.h> #include <pwd.h> #include <security/pam_appl.h> #define USER (argv[1]) #define SERVICE (argv[2]) int conv_func(int num_msg, struct pam_message *msg[], struct pam_response **resp, void *appdata_ptr) { int i; struct pam_message *msgs = *msg; struct pam_response *aresp = calloc(num_msg, sizeof(*aresp)); char resp_buf[PAM_MAX_RESP_SIZE]; for (i=0; i<num_msg; i++) { aresp[i].resp_retcode = 0; fputs(msgs[i].msg, stderr); fgets(resp_buf, sizeof(resp_buf), stdin); resp_buf[strlen(resp_buf)-1] = '\\\\0'; aresp[i].resp = strdup(resp_buf); } *resp = aresp; return PAM_SUCCESS; } int main(int argc, char *argv[]) { int rc = 0, retval = 0; struct passwd *pw; struct pam_conv conv = {conv_func, NULL}; pam_handle_t *pamh = NULL; pw = getpwnam(USER); if (pw) printf("Name: %s\\ UID: %d\\ GID: %d\\ Home: %s\\ ", pw->pw_name, pw->pw_uid, pw->pw_gid, pw->pw_dir); else { printf("User %s does not exist.\\ ", USER); rc = 1; goto outta_here; } retval = pam_start(SERVICE, USER, &conv, &pamh); if (retval != PAM_SUCCESS) { printf("Error from pam_start\\ %s\\ ", pam_strerror(pamh, retval)); rc = retval; goto pam_cleanup; } printf("Pam Handle: 0x%x\\ ", pamh); retval = pam_authenticate(pamh, 0); if (retval != PAM_SUCCESS) { printf("Error from pam_authenticate: %d\\ %s\\ ", retval, pam_strerror(pamh, retval)); rc = retval; goto pam_cleanup; } retval = pam_acct_mgmt(pamh, 0); if (retval != PAM_SUCCESS) { printf("Error from pam_acct_mgmt: %d\\ %s\\ ", retval, pam_strerror(pamh, retval)); rc = retval; goto pam_cleanup; } if (!rc) printf ("User %s is authorized for service %s!\\ ", USER, SERVICE); pam_cleanup: retval = pam_end(pamh, 0); if (retval != PAM_SUCCESS) { printf("Error from pam_end: %d\\ %s\\ ", retval, pam_strerror(pamh, retval)); rc = retval; } outta_here: return rc; }