Informix SE 7.24.UC5 on RedHat Linux 6.2 and password security
Posted in 1999
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing, Platform-Specific Issues
There would seem to be some issues with password security and this
software/OS combination.
We can establish a connection using dbaccess or ODBC only if we attempt to
connect with the root login and password.
1 - Has anyone experienced the same problems?
2 - Is there a patch or workaround solution that would enable remote
connections under more reasonable security parameters for local hosts on the
network?
3 - Am I simply missing something.
Otis Michaud wrote:
>
> There would seem to be some issues with password security and this
> software/OS combination.
>
> We can establish a connection using dbaccess or ODBC only if we attempt to
> connect with the root login and password.
>
> 1 - Has anyone experienced the same problems?
>
> 2 - Is there a patch or workaround solution that would enable remote
> connections under more reasonable security parameters for local hosts on the
> network?
>
> 3 - Am I simply missing something.
Not enough information about what you have and how it is set up. But here
are some possible issues:
o Informix does not currently work on Linux with shadow password files or
PAM
o Each user that wants to login must have a Linux account on the server
o The client must be a trusted host either through /etc/hosts.equiv, a bad
idea, or through $HOME/.rhosts for each user.
Art S. Kagel
"Art S. Kagel" wrote: > > o Each user that wants to login must have a Linux account on the server > o The client must be a trusted host either through /etc/hosts.equiv, a bad > idea, or through $HOME/.rhosts for each user. > > Art S. Kagel Uhm no using $HOME/.rhosts is also a bad idea. If I were your system administrator, I'd have a little shell script that ran everynight and deleted that little file. Of course, I'm paranoid. I've been a System admin and I do know exactly what sort of troubles this type of thing can cause. Does anyone remember the Morris Worm? (Yeah, and now I'm dating myself. :-P ) Now, the problem with Informix is that you don't want to develop 2 tier applications. You are forced to write 3 tier or n tier applications. That may be an accident. But its a good thing. Oh and any machine you have that is in hosts.equiv, you definately want to lock down too. That means only servers that you can control, not the client PCs. But hey, Anyone who's hacked or played in Unix should know this. Just a tip from your uncle mikey. (6 nephews and one niece, they must have put something in the water....)
I found the same problem, only to find the solution was to simply
run [#setup] goto the password encryption settings and turn off
MD5 passwords.. I also turned off SHADOW passwords and
everything started working.. do a reboot to clear out any remanants,
but it solved the problems for me.
Since MD5 is so new to RedHat 6.X, and IDS was frozen before
it was released (in my case) I would assume a function call some
where has changed and IDS just doesn't know how to handle it.
Fortunately, turning off the new feature restores it to a form/shape
that IDS can handle.
Good luck.
Otis Michaud wrote:
> There would seem to be some issues with password security and this
> software/OS combination.
>
> We can establish a connection using dbaccess or ODBC only if we attempt to
> connect with the root login and password.
>
> 1 - Has anyone experienced the same problems?
>
> 2 - Is there a patch or workaround solution that would enable remote
> connections under more reasonable security parameters for local hosts on the
> network?
>
> 3 - Am I simply missing something.