Re: Authentication with PAM
Posted in 2003
Topics: Performance & Tuning, Installation, Setup & Upgrades, SQL Development & Query Writing, Connectivity: ODBC / JDBC / .NET, Platform-Specific Issues
> we have some questions regarding informix authentication on > linux using the pam-system. > At the moment we have a windows nt domain with a pdc and > some workstations, which authenticate themselves using the > domain. Some of the workstations are informix-Clients > with our software connecting to the db via odbc/informix-net, > one of the workstations is our db-server. Like i said, it > is also in the NT-Domain, so every login (local or via > informix-net) works using user/passwd from the NT-domain > (no local users on the db-server except Administrator and > informix). > Now we evaluate switching the DB-Server to Linux (for stability > and performance reasons). We cant get rid of the other windows- > workstations, because of our windows-software-clients :-) > So we would like to do the db-logins using the NT-Domain. > If we'd have to create every user from the NT-Domain second > time on the db-server, this would be a huge drawback.. > I searched google (web, comp.databases.informix,...) and > found the pam_smb module, which seems to be the right choice > for this purpose and installed it on the db-server > (SuSE Linux 8.1 (Kernel 2.4.19-4, glibc 2.2.5), > Informix 7.31UD5-1, pam_smb 1.1.6). > 2 Problems : > 1.) Trying pam_smb with sshd for instance, i can use my NT-Domain > user/passwd only if the same user exists as a local linux-user > too (even with the pam_smb-Option nolocal) PAM handles authentication, you also need to augment the name space to include the Domain. Name space is handled via NSS, and by default the only module used is local files. If you lookup winbind (comes included in most Samba packages) you can join the domain with the machine and not need any local file entries. Another option if you are using ADS is to load the schema module on your ADS server and use the nss_ldap module on the client. > 2.) It seems that our Informix-version isn't capable of using pam > at all (I found some hints, but no definitive answer to that). > So : Is it possible or not ? Nope. How the *$*(@ *@$()@)_ heck one is supposed to operate a secure Informix server is just beyond me, maintaining /etc/passwd is really an unrealistic option. This feature seems to have been promised for a long time. > (If pam doesn't work with this Informix version at all, there > is no sense in trying to solve problem 1 any longer.) sending to informix-list
>>2.) It seems that our Informix-version isn't capable of using pam >>at all (I found some hints, but no definitive answer to that). >>So : Is it possible or not ? > > > Nope. How the *$*(@ *@$()@)_ heck one is supposed to operate a secure > Informix server is just beyond me, maintaining /etc/passwd is really an > unrealistic option. This feature seems to have been promised for a long > time. > It's been said that thousands of clients have managed to do that for several years. Nevertheless, phear not, because 9.40.UC2 (UC1 had some problems and has it disabled)should be able to use PAM modules to authenticate users. Regards