Password encryption and Informix
Posted in 2013
Our Info Sec folks have asked that we change our OS passwords to be encrypted using sha256 instead of the md5. When we do this client tools which pass in the user id and password from another server do not work. We are running on AIX 6.1TL7, IDS 11.50.FC9XA, and a variety of different versions of the sdk toolsets. It happens in java, odbc, OAT(php??) and such. We are not using PAM but simple OS authentication.
Any suggestions?
Running dbaccess on the server itself and connecting using user id and password works just fine. So where does the crypt of the password actually happen? Is it on the client box and if it is not setup for sha256 is it encrypting is as md5 and that is why it fails? We are at a loss here.
TIA,
David Link