Informix Single Sign-On with Active Directory Kerb
Posted in 2010
Topics: Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues
I'm trying to get SSO to work between IDS and AD. My environment is:
IDS host machine: CentOS 5 VM running within XenServer
AD host machine: Windows Server 2008 running within HyperV
IDS version: 11.50.FC5
I'm handling the informix/linux end of things, and am working with someone who
is in charge of the AD/windows portion (so I might screw up some of the AD
terminology). We've set up everything using the instructions from the pdf at
http://www-01.ibm.com/support/docview.wss?rs=0&uid=swg21405613 , although
we're a bit unclear as to what the SPN should be. Presently, we've set it with
the following syntax
setspn -a INFORMIXSERVER/ids.host.machine.com domain\\\\informix
Here, INFORMIXSERVER is the same as the $INFORMIXSERVER variable on the IDS
machine, ids.host.machine.com is its fqdn, "domain" is the AD domain, and
"informix" is the informix user.
When we export the keytab, merge it with /etc/krb5.keytab on the IDS machine,
and configure the informix engine with SSO using the appropriate options in
sqlhosts, we get this error:
$ echo select \\\\* from tablename | dbaccess dbname
5000: CSM error: gss_init_sec_context: Unspecified GSS error. Minor code mayprovide
Logging in as informix works correctly. I currently have an informix user and
group defined in /etc/passwd and /etc/group, but do not have an encrypted
password stored for it in /etc/shadow (so that it authenticates using active
directory). After logging in, the output of klist shows the SPN ticket.
Any ideas where things might be going wrong?
Are there kerberos log files I can check to get more specific info as to why
authentication is failing?
Is what we're trying to do even possible? The release notes at
http://publib.boulder.ibm.com/infocenter/idshelp/v115/index.jsp?topic=/com.ibm.r
elnotes.doc/ifx_1150xc7/ids_defects_11.50.html indicate:
Security
<snip>
IC68364 SSO AUTHENTICATION FAILURE IN
GSS_INIT_SEC_CONTEXT OR GSS_ACQUIRE_CRED ON HP,
AGAINST ACTIVE DIRECTORY KERBEROS SERVER
Does this apply to my version/platform (11.50.FC5 on CentOS 5, as opposed to
11.50.xC7 on HP-UX)?
Found the issue: DES encryption needs to be enabled on the INFORMIXSERVER active directory account. Once that's done, there doesn't even seem to be any need to setspn. If anyone else runs into a similar problem and needs help/clarification, just let me know. One gotcha I can remember is that the sqlhosts file on client machines chokes on the s=7 option that IBM's docs recommend.