IDS & Kerberos
Posted in 2004
Topics: Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
Hi there, Is it possible to make Informix & Kerberos work together? The case is as follows. A centralized user DB in MS-Active Directory, so they can log-in in the kerberized linux boxen. after loging in, the user jumps directly to the 4GL appl. so the problem appears at this point: he/she cannot connect to the DB. It looks that Informix checks for user existence in /etc/password. A kerberized account does not existe in /etc/password. BTW: the user login has permissions on connect as well as most of the tables. IDS 9.4 / RH linux 7.3 Any help is really appreciated. Thanks in advance.
Hi, there's no direct support of kerberos by IDS. However, with IDS 9.40.UC2 (or newer) you can utilize PAM (Pluggable Authorization Module) to implement this. The module that will do this specific kerberos authentication that you need will be either 3rd-party provided (i.e. not part of IDS) or you will implement it yourself. There's a file named "pam.txt" documenting the mechanisms of PAM and how IDS supports PAM. The file is in your "$INFORMIXDIR/release/en_us/0333/" directory. Please refer to this documentation for more information. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich Data Management Solutions forum.subscriber@iiug.org wrote on 01.07.2004 19:37:05: > Hi there, > > Is it possible to make Informix & Kerberos work together? > > The case is as follows. A centralized user DB in MS-Active Directory, so they can log-in in the kerberized linux boxen. after loging in, the user jumps directly to the 4GL appl. so the problem appears at this point: he/she cannot connect to the DB. > > It looks that Informix checks for user existence in /etc/password. A kerberized account does not existe in /etc/password. BTW: the user login has permissions on connect as well as most of the tables. > > IDS 9.4 / RH linux 7.3 > > Any help is really appreciated. > Thanks in advance. > >