Re: OLEDB connection and AD Windows
Posted in 2008
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues
Richard Spitz wrote: > Fernando Nunes <spam@onlinedomus.net> schrieb: > >> As I wrote in another article, I could get Linux using PAM and getpwnam worked >> as well as IDS. > > But did you get successful OLEDB connections in your setup? I'd be surprised > if you did! Didn't try, but if I'm right it should not be relevant... see the following comments. > > Did you configure the PAM additions in the sqlhosts file (e.g. the pam_serv > and pamauth parameters) or not? > In this scenario, forget about PAM... >> My test setup included an Openldap server and Fedora (core 5?). >> IIRC I had to change /etc/nsswitch.conf... This can be used to specify that the >> users can be retrived from an LDAP server... > > This is a prerequisite anyway to get the OS itself to authenticate against an > LDAP server using PAM, and has nothing to do with IDS. When IDS is configured > for using PAM, client connections that are not explicitly PAM enabled fail. You can have several "ports"... So assuming this works, PAM enabled ports would be irrelevant. > > The docs are very clear about this: The Informix OLEDB driver does not support > PAM. The problem seems to be that there is really nothing special about PAM > authentication as long as the simple "password" method is used and not the > "challenge" method which requires the client to implement a callback function. > However, IDS refuses to authenticate a client that does not send the > "CLNT_PAM_CAPABLE" flag, even when no special PAM functions are necessary. Ok. If I recall correctly there is a feature request for this. But my whole point is this, and i'm not saying I cannot be wrong: If you configure the underlying OS to authenticate against an LDAP server, than normal IDS connections (not the ones on PAM enable DBSERVERALIAS) should be able to work transparently... IDS does not check the files itself. It uses normal OS functions (getpwnam is familiar). If these functions return the usual result, it should work. I'm really overloaded this next weeks. Unfortunately I don't believe I will be able to check the environment again. But I'll do my best efforts to revive the VM where I played with this. I also exchanged a few emails with another colleague so I can search for them... Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Fernando Nunes <spam@onlinedomus.net> schrieb: >But my whole point is this, and i'm not saying I cannot be wrong: > >If you configure the underlying OS to authenticate against an LDAP server, than >normal IDS connections (not the ones on PAM enable DBSERVERALIAS) should be >able to work transparently... IDS does not check the files itself. It uses >normal OS functions (getpwnam is familiar). If these functions return the usual >result, it should work. I wish you were right. My own experience and research on this indicate you are not, but I'd be more than happy if I were on the wrong track. What's the whole point of enabling/configuring IDS for using PAM, when the normal OS functions suffice for authenticating users? Regards, Richard