RE: suppressing username and password prompts in dbaccess
Posted in 2007
First .rhosts is user controlled and you as a system administrator lose control of securing your system.
As to having the same password, you could have a central authentication system like OLAP since the Unix/Linux systems support PAM, you can us a common authentication system.
You don't see the danger cause you're not a sysadmin. But as a DBA you do see the dangers of IDS on raid 5 right?
This is worst because is a potential security hole.
An additional way to authenticate IDS is to use PAM to have the engine authenticate via a look back at IDS. So you can create virtual accounts.
But thats a different story... ;-)
> Date: Wed, 19 Dec 2007 19:43:24 -0500> From: dcruncher4@aim.com> To: im_gumby@hotmail.com> CC: informix-list@iiug.org> Subject: Re: suppressing username and password prompts in dbaccess> > My reply was to how to get dbaccess working without password.> We don't even know whether he is asking about dev or production> machine.> > Also how smart is to keep the same password in the client> and the server machine. I don't see it as any less of a threat> than creating .rhosts file.> > > Ian Michael Gumby wrote:> > Geez!> > > > How many times does it take before the message sinks in.> > > > .rhosts BAD. VERY BAD.> > BAD IDEA FROM THE START.> > > > You should NEVER, EVER LET YOUR USERS use .rhosts since it effectively > > allows them to say that Machine A is a safe and trustworthy machine.> > > > Not a problem if Machine A is sitting next to your server in the machine > > room.> > BIG PROBLEM if Machine A is sitting somewhere well outside your firewall > > and outside of your control.> > > > Since most DBAs are NOT system administrators, talk to your system > > administrators and see what they say.> > > > Hosts.equiv is controlled by your system administrator (root access). > > You should use this only for machines that are truly equivalent.> > (Like machine A load balances for machine B ...)> > > > Think of this as being much worse than running your IDS engine on a RAID > > 5 system.> > > > If I were your system administrator and you did this on one of my > > systems? I'd consider it a terminating offense. One where the use of a > > firing squad is a form of mercy.> > Please be paranoid. We don't want to see another TJX situation on an IDS > > platform now do we? (TJX was running Oracle. ;-)> > > > -G> > PS. Yes, I was at one time a BOFH ;-)> > > > > > > From: dcruncher4@aim.com> > > Subject: Re: suppressing username and password prompts in dbaccess> > > Date: Wed, 19 Dec 2007 10:48:15 -0800> > > To: informix-list@iiug.org> > >> > > In article > > <e89947bf-d9fc-4f33-9ef4-dacf60193a7a@v4g2000hsf.googlegroups.com>,> > > skurlander@yahoo.com says...> > > >> > > >Hi,> > > >> > > >Our site is running Informix Dynamic Server 11 on Linux. Currently,> > > >when connecting to a server using dbaccess the user is prompted for> > > >his user name and password. What options are available so providing a> > > >user name and password is unnecessary, as the username and password is> > > >the same one as they used to log into their machine.> > >> > > One the server machine (where IDS 11 is running), in that user's home> > > directory you have to create a file .rhosts in which you mention the> > > name of the client machine from where the users will connect.> > >> > > Also I am not sure how dbaccess is prompting for user name/password.> > > AFAIK dbaccess does not prompt. You will get error from the database> > > if you don't have appropriate permission.> > >> > > try this> > > create a file test.sql with some dummy statement> > > like> > > database sysmaster;> > > select 1 from systables where tabid = 1 ;> > >> > > run it> > > $ dbaccess - test> > >> > > dbaccess should not prompt for password. It will fail unless you> > > create the trust relationship between the client and the server> > > via that .rhosts file I described above.> > >> > > _______________________________________________> > > Informix-list mailing list> > > Informix-list@iiug.org> > > http://www.iiug.org/mailman/listinfo/informix-list> > > > ------------------------------------------------------------------------> > Get the power of Windows + Web with the new Windows Live. Get it now! > > <http://www.windowslive.com?ocid=TXT_TAGHM_Wave2_powerofwindows_122007>=>
_________________________________________________________________
Don't get caught with egg on your face. Play Chicktionary!
http://club.live.com/chicktionary.aspx?icid=chick_wlhmtextlink1_dec