IDS - PAM AUTHENTICATION ANYONE WHO HAVE ACTUALLY MANAGED TO USE IT
Posted in 2005
Topics: Error Codes & Troubleshooting, Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Versions, Editions & End-of-Life
Hello People.
We've been trying to use the IDS PAM authentication module for the past 2
weeks, but we seem done only a little progresses.
We followed the release notes under $INFORMIXDIR/release/en_us/0333/pam.txt;
The sqlhosts file is set up as follows.
tadinda_tcp onsoctcp acilia 1525
s=4,pam_serv=(informix),pamauth=(challenge)
The informix file (pam_serv) under /etc/init.d reads as follows:
#%PAM-1.0
#auth optional pam_toledo.so /usr/informix tadinda_tcp
auth required pam_rps.so debug
account required pam_rps.so debug
password required pam_rps.so debug
session required pam_rps.so debug
We have tried many of the available services ( pam_unix_passwd,even our
own!) , but with this configuration (using the pam_rps service) we the
nearest since when running the esqlc pam_demo example prompts back with a
challenge. However it consistently returns the -1809 error!
We're running IDS 10.0.3 and seems pam documentation is rather misleading
and incomplete. We looked throughout the whole net but found nothing
helpful. We need to use PAM with PowerBuilder and so far we've managed to
get PowerBuilder 10 to talk to an esqlc generated DLL (already a big step).
The first person who manages to get the callback function example working,
we can update IIUG with new relevant PAM documentation including
PowerBuilder connectivity.
Many thanks for your help.
The esqlc pam_demo ($INFORMIXDIR/demo/esqlc/pam_demo.ec reads as follows:
#include <stdio.h>
#include <string.h>
#define PAM_PROMPT_ECHO_OFF 1
#define PAM_PROMPT_ECHO_ON 2
#define PAM_ERROR_MSG 3
#define PAM_TEXT_INFO 4
#define PAM_MAX_MSG_SIZE 512
EXEC SQL define FNAME_LEN 40;
EXEC SQL define LNAME_LEN 40;
int callback(char *challenge, char *response, int msg_style);
int main()
{
EXEC SQL BEGIN DECLARE SECTION;
char fname[ FNAME_LEN + 1 ];
char lname[ LNAME_LEN + 1 ];
char dbpass[20];
char dbuser[20];
char dbname[20];
EXEC SQL END DECLARE SECTION;
int retval = 0;
/* First register the callback. This needs to be done before establishing
the
* connection as done here.
*/
printf("Starting PAM demo \\
");
EXEC SQL WHENEVER ERROR STOP;
retval = ifx_pam_callback(callback);
if (retval == -1)
{
printf("Error in registering callback\\
");
return (-1);
}
else
{
printf("Callback Registered. Status=%d\\
",retval);
strcpy(dbpass,"mibobva");
strcpy(dbuser,"acilia");
strcpy(dbname,"cell");
printf( "Callback function registered.\\
");
/* EXEC SQL connect to :dbname user :dbuser using :dbpass; */
EXEC SQL database :dbname ;
printf ("SQLCODE ON CONNECT = %d\\
", SQLCODE);
EXEC SQL declare pamcursor cursor for
select customer,name
into :fname, :lname
from slcustm;
EXEC SQL open pamcursor;
for (;;)
{
EXEC SQL fetch pamcursor;
if (strncmp(SQLSTATE, "00", 2) != 0) {
break; }
printf("%s %s\\
",fname, lname);
}
if (strncmp(SQLSTATE, "02", 2) != 0)
printf("SQLSTATE after fetch is %s\\
", SQLSTATE);
EXEC SQL close pamcursor;
EXEC SQL free pamcursor;
EXEC SQL disconnect current;
printf("\\
PAM DEMO run completed successfully\\
");
}
}
/* The callback function which will provide responses to the challenges. */
int callback(char *challenge, char *response, int msg_style)
{
printf("%s\\
",challenge);
switch (msg_style){
case PAM_PROMPT_ECHO_OFF:
case PAM_PROMPT_ECHO_ON :
printf("%s: %d:\\
",challenge, msg_style);
scanf("%s:",response);
break;
case PAM_ERROR_MSG:
case PAM_TEXT_INFO:
default:
printf("%s: %d\\
",challenge, msg_style);
}
return 0;
}
Stefan Sammut
Software Engineer
Philip Toledo Limited
Computer & Communications Solutions
Notabile Road, Mriehel BKR01, Malta
Tel: (+356) 2144 5566
Fax: (+356) 2148 4316
Website : www.ptl.com.mt
The information contained in this email is confidential and may be
privileged. It is intended for the addressee only, if you are not the
intended recipient please notify the sender and delete the email
immediately. The contents of this e-mail must not be disclosed or copied
without the senders consent. We cannot accept any responsibility for
viruses. Any views expressed in this message are those of the individual
sender, except where the sender specifically states them to be the view of
Philip Toledo Limited
----- Original Message -----
From: "Colin Bull" <Colin.Bull@videonetworks.com>
To: <ids@iiug.org>
Sent: Wednesday, July 27, 2005 3:34 PM
Subject: RE: oninit error .. [5501]
> SANTOSH NIKUMBH wrote
>
> >One more update for this . I get the following in the log :-
> >16:12:29 listener-thread: err = -25572: oserr = 227: errstr = :
> Network driver cannot
> >bind a name to the port.
> > System error = 227.
>
> ------------------------------------------------------------------
> >Does it mean that my entry in the "services" file is NOT proper ?
>
> >I have made an entry in /etc/services file as :-
>
>
> >padbv2 3400/tcp #informix padbv2 instance
>
> What does 'grep padbv2 $INFORMIXDIR/etc/sqlhosts'
>
> output (assuming Unix platform)
>
> Colin Bull
>
> =======================================================================
> This email may contain confidential and privileged information and is
intended for the named or
> authorised recipients only. If you are not the named or authorised
recipient of this email,
> please note that any copying, distribution, disclosure or use of its
contents is strictly
> prohibited. If you have received this email in error please notify the
sender immediately and
> then destroy it. The views expressed in this email are not necessarily
those held by VNL, and VNL
> does not accept any liability for any action taken in reliance on the
contents of this message.
> VNL does not guarantee that the integrity of this email has been
maintained, nor that it is free
> of viruses, interceptions or interference.
>
> _______________________________________________________________________
> This email has been scanned for all known viruses by the MessageLabs Email
Security System.
> _______________________________________________________________________
>
>
>
>
> --
> No virus found in this incoming message.
> Checked by AVG Anti-Virus.
> Version: 7.0.338 / Virus Database: 267.9.5/58 - Release Date: 25/07/05
>
>
This is a multi-part message in MIME format.
------=_NextPart_000_002A_01C59418.03CC3E10
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_002B_01C59418.03CC3E10"
------=_NextPart_001_002B_01C59418.03CC3E10
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Hello,
Thanks for your reply, we have actually seen your documentation.=20
We are using Linux Fedora core 4, and the pam is located under =
/etc/pam.d and keeps it's shared objects within lib security.
When we use the lsof command with |grep pam_rps, we could be see that =
the file is being used. Somehow pam_deny comes also
into the scene, which we think it's one of our problems of why it's not =
being authenticated.
Any further help will be highly appreciated.
Many thanks for help.
Stefan Sammut
Software Engineer
Philip Toledo Limited
Computer & Communications Solutions
Notabile Road, Mriehel BKR01, Malta
Tel: (+356) 2144 5566
Fax: (+356) 2148 4316
Website : www.ptl.com.mt
The information contained in this email is confidential and may be =
privileged. It is intended for the addressee only, if you are not the =
intended recipient please notify the sender and delete the email =
immediately. The contents of this e-mail must not be disclosed or copied =
without the senders consent. We cannot accept any responsibility for =
viruses. Any views expressed in this message are those of the individual =
sender, except where the sender specifically states them to be the view =
of Philip Toledo Limited
----- Original Message -----=20
From: Abhishek Mathur=20
To: Stefan Sammut=20
Cc: forum.subscriber@iiug.org ; ids@iiug.org=20
Sent: Thursday, July 28, 2005 5:04 PM
Subject: Re: IDS - PAM AUTHENTICATION ANYONE WHO HAVE ACTUALLY MANAGED =
TO USE IT PLEASE??? [5503]
Hi,=20
I think the location of the pam_serv file is not correct. I =
believe it should be under /usr/lib/security. Also, the pam_serv file is =
a PAM service module written by the user (typically a shared object ) =
and placed in the /usr/lib/security directory on the machine where the =
server is located.=20
Please also refer to the following article for more details - =
http://www-128.ibm.com/developerworks/db2/zones/informix/library/techarti=
cle/0306mathur/0306mathur.html=20
Thanks and Regards,
Abhishek Mathur
IBM - Information Management
913-599-7109 (T/L - 337-7109)
abhishek@us.ibm.com =20
"Stefan Sammut" <ssammut@ptl.com.mt>=20
Sent by: forum.subscriber@iiug.org=20
07/28/2005 06:14 AM=20
To ids@iiug.org =20
cc =20
Subject IDS - PAM AUTHENTICATION ANYONE WHO HAVE ACTUALLY =
MANAGED TO USE IT PLEASE??? [5503]=20
=20
=20
Hello People.
We've been trying to use the IDS PAM authentication module for the =
past 2
weeks, but we seem done only a little progresses.
We followed the release notes under =
$INFORMIXDIR/release/en_us/0333/pam.txt;
The sqlhosts file is set up as follows.
tadinda_tcp onsoctcp acilia 1525
s=3D4,pam_serv=3D(informix),pamauth=3D(challenge)
The informix file (pam_serv) under /etc/init.d reads as follows:
#%PAM-1.0
#auth optional pam_toledo.so /usr/informix tadinda_tcp
auth required pam_rps.so debug
account required pam_rps.so debug
password required pam_rps.so debug
session required pam_rps.so debug
We have tried many of the available services ( pam_unix_passwd,even =
our
own!) , but with this configuration (using the pam_rps service) we the
nearest since when running the esqlc pam_demo example prompts back =
with a
challenge. However it consistently returns the -1809 error!
We're running IDS 10.0.3 and seems pam documentation is rather =
misleading
and incomplete. We looked throughout the whole net but found nothing
helpful. We need to use PAM with PowerBuilder and so far we've =
managed to
get PowerBuilder 10 to talk to an esqlc generated DLL (already a big =
step).
The first person who manages to get the callback function example =
working,
we can update IIUG with new relevant PAM documentation including
PowerBuilder connectivity.
Many thanks for your help.
The esqlc pam_demo ($INFORMIXDIR/demo/esqlc/pam_demo.ec reads as =
follows:
#include <stdio.h>
#include <string.h>
#define PAM_PROMPT_ECHO_OFF 1
#define PAM_PROMPT_ECHO_ON 2
#define PAM_ERROR_MSG 3
#define PAM_TEXT_INFO 4
#define PAM_MAX_MSG_SIZE 512
EXEC SQL define FNAME_LEN 40;
EXEC SQL define LNAME_LEN 40;
int callback(char *challenge, char *response, int msg_style);
int main()
{
EXEC SQL BEGIN DECLARE SECTION;
char fname[ FNAME_LEN + 1 ];
char lname[ LNAME_LEN + 1 ];
char dbpass[20];
char dbuser[20];
char dbname[20];
EXEC SQL END DECLARE SECTION;
int retval =3D 0;
/* First register the callback. This needs to be done before =
establishing
the
* connection as done here.
*/
printf("Starting PAM demo \\
");
EXEC SQL WHENEVER ERROR STOP;
retval =3D ifx_pam_callback(callback);
if (retval =3D=3D -1)
{
printf("Error in registering callback\\
");
return (-1);
}
else
{
printf("Callback Registered. Status=3D%d\\
",retval);
strcpy(dbpass,"mibobva");
strcpy(dbuser,"acilia");
strcpy(dbname,"cell");
printf( "Callback function registered.\\
");
/* EXEC SQL connect to :dbname user :dbuser using :dbpass; */
EXEC SQL database :dbname ;
printf ("SQLCODE ON CONNECT =3D %d\\
", SQLCODE);
EXEC SQL declare pamcursor cursor for
select customer,name
into :fname, :lname
from slcustm;
EXEC SQL open pamcursor;
for (;;)
{
EXEC SQL fetch pamcursor;
if (strncmp(SQLSTATE, "00", 2) !=3D 0) {
break; }
printf("%s %s\\
",fname, lname);
}
if (strncmp(SQLSTATE, "02", 2) !=3D 0)
printf("SQLSTATE after fetch is %s\\
", SQLSTATE);
EXEC SQL close pamcursor;
EXEC SQL free pamcursor;
EXEC SQL disconnect current;
printf("\\
PAM DEMO run completed successfully\\
");
}
}
/* The callback function which will provide responses to the =
challenges. */
int callback(char *challenge, char *response, int msg_style)
{
printf("%s\\
",challenge);
switch (msg_style){
case PAM_PROMPT_ECHO_OFF:
case PAM_PROMPT_ECHO_ON :
printf("%s: %d:\\
",challenge, msg_style);
scanf("%s:",response);
break;
case PAM_ERROR_MSG:
case PAM_TEXT_INFO:
default:
printf("%s: %d\\
",challenge, msg_style);
}
return 0;
}
Stefan Sammut
Software Engineer
Philip Toledo Limited
Computer & Communications Solutions
Notabile Road, Mriehel BKR01, Malta
Tel: (+356) 2144 5566
Fax: (+356) 2148 4316
Website : www.ptl.com.mt
The information contained in this email is confidential and may be
privileged. It is intended for the addressee only, if you are not t