Re: Is my brain dead or what....
Posted in 1996
In article <55n753$937@nntp.idgonline.no>, Nils Myklebust
<Nils.Myklebust@idg.no> writes
>David Williams <djw@smooth1.demon.co.uk> wrote:
>
>:In article <3277923A.4458@segel.com>, Mike Segel <mikey@segel.com>
>:writes
>
>...snip...
>
>:> The problem occurs in that I now have to manage a database on all the
>:> pc's, their users, and what server applications that they can connect
>:>to.
>:>
>:> Since Informix gets its user authentication from the user_id, and
>:>passwd,
>:> I have two choices:
>:> 1) create a unique user id for all users
>
>: Each user should have a unique user id - basic UNIX security.
>
>Yes David, but do you remember the long threads about how one can (or
>rather can not) change the Unix password from an MS Windows client
>application.
>Do you suggest every user should have a terminal emulator installed
>for this purpose only?
Yes - UNIX requires this and it makes sense. How otherwise you need
another username/password system. Therefore you have two possible
methods of system penetration. Via the UNIX user/password method and
via the other method. Other methods of authenticaton are not likely to
be as widely used as the client/server combination used would decide
the authnetication method used. OS level authenication MUST be used by
everyone since UNIX requires users to be configured. This will be
theautnetication method which is most likely to be secure since it will
be the one which gets the most analysis from security experts.
>An additional problem here is whether you use I-Net alone, I-Net and
>ODBC on top of that, or some sensible ODBC solution without I-Net
>there is no way of knowing whether the Unix password is no longer
>valid or the user simply typed something wrong.
Since the server portion of inet gets the error code from the Online
server (they are separate processes) it must be possible to get the
information from the Online server :-
Part on an Online log I received from someone:
14:39:34 listener-thread: err = -951: User hbad720 is not known on thedatabase server.
14:41:57 listener-thread: err = -952: User's password is not correctfor the database server.
It is even possible to distingush between whether on not the user is
valid (-951) or whether the password is wrong (-952). Therefore it is
a limitaiton of the ODBC solution.
>So in your application you ask your user to retype the password. After
>3 to 5 attempts that user will be locked out of Unix automatically,
>and he can't even try to change his password via a terminal emulator.
>The Unix administrator has to be brought into the picture.
>
Correct otherwise someone who knows a username could write a program
to scan all common passwords.
>We haven't ever heard what Informix's solution to any of this is.
>Isn't Informix out there listening?
>
>:> 2) create a set of authentication routines and maintain a
>:> user_id / passwd table scheme within Informix.
>:> When using /etc/hosts.equiv, I can use the + sign to allow any user
>:> from that PC to connect, however, this too can be considered a security
>:> risk.
>:>
>:>Solutions:
>:> 1) If I am not braindead, then Informix needs to get their act together
>:> so that we can develop large scale client/server applications.
>: Talk to them - I belive they already have their act together.
>
>See above. Do they?
>
>:> 2) switch to web based technologies and use either Web objects or
>:> Netscape to handle security and front end processing.
>: You still have to secure things at the OS level.
>
>Eventually yes. I have not studied the problems this would entail
>enough yet. It seems to me it would still involve regular Unix users
>for access to the database (whether via Java/JDBC or some other means)
>so we probably have exactly the same problems.
>This is even worse, and makes it mandatory for Informix to document
>for us how to do it.
>
>:> 3) Drink until I have to look up to see the curb in front of the
>:> local pub.
>:>
>:>Now #3 does sound appealing. [Right Tom?], but alas, being an old man, I
>:>can't
>:>continue to abuse my body in that way. So, what I am doing wrong?
>:>
>:>-Uncle Mikey.
>
>:--
>:David Williams
>
>I am looking forward to a new whitepaper from Informix on all aspects
>on database access and security as discussed here, as well as the
>previous discussion on security when using I-Net and/or ODBC and
>thereby opening up free access to the database for any user of a
>program that needs such access.
>Is there anybody at Informix who would take it upon themselves to
>either write one, or get someone to write such a whitepaper?
>
I'd like to see one as well.
>
>Nils.Myklebust@idg.no
>NM Data AS, P.O.Box 9090 Gronland, N-0133 Oslo, Norway
>My opinions are those of my company
>The Informix FAQ is at http://www.iiug.org
>
--
David Williams