Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
John Smith asked whether one Informix server can use OS-user authentication on one alias and internal-user authentication on another. Paul Watson said PAM can be on one port only; Andreas Legner said default ports accept both and a port cannot be limited to only one kind. John then said he really wanted a way to hide client passwords, like an Oracle wallet, and mentioned LDAP. Unresolved.
Auto-generated by Claude from the posts below — may be imperfect; read the full thread.
John Smith — source: IBM Community (ConnectedCommunity.org) Informix forum
Hi to All
on onconfig :
i want to use two different authentification methods for the same server : OS USER and INTERNAL USER, is is possible ?
DBSERVERNAME db_serv (OS USER)DBSERVERALIASES db_net (INTERNAL USER)
on sqlhosts
db_serv onsoctcp host_ip host_port_1
db_net onsoctcp host_ip host_port_2
thanks :)
------------------------------John Smith
------------------------------
#Informix
↪ replying to John Smith
Paul Watson — source: IBM Community (ConnectedCommunity.org) Informix forum
You can have PAM on one port and no PAM on the other
Outside of that I'm not aware of any other options but I've never really looked.
But I suspect you do something within sysdbopen to block internal users from db_serv – again never tried
Cheers
Paul
↪ replying to John Smith
Andreas Legner — source: IBM Community (ConnectedCommunity.org) Informix forum
As it stands, any default port would do both, internal and OS user authentication.
Should OS auth be done through PAM, so on an Informix port configured to use PAM, no internal users could connect on that port.
(One could argue why not allowing internal auth on a PAM port, esp. if that's configured to do simple OS auth only, but that's not implemented as of now.)
So, to your question: you'd not even need those two separate ports - but could of course do it this way.
What would not be possible, I think, is restricting such port to either only OS auth or only internal auth.
------------------------------
Andreas Legner
------------------------------
↪ replying to Paul Watson
John Smith — source: IBM Community (ConnectedCommunity.org) Informix forum
Thank you Paul
------------------------------
John Smith
------------------------------
↪ replying to John Smith
John Smith — source: IBM Community (ConnectedCommunity.org) Informix forum
still thinking about auth. methods, i think i was going the wrong way :(
In fact i'm looking for a method where i can hide the user password, on a client server, similar to oracle wallet
i know i can go on LDAP authentifaction (with MS Active directory for example) so no password need , just interacting with LDAP Server
but i m also looking another "informix way :)"
------------------------------
John Smith
------------------------------
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.