Three tier, JDBC and authorization
Posted in 2005
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
Hi! At this moment we have terminal-server application. +---------------+ +--------------+ telnet--+ Informix 4GL | | IDS 9.40 | telnet--+ +-----+ | telnet--+ Solaris 2.6 | | Solaris 8 | +---------------+ +--------------+ Users pass authorization on Solaris 2.6. Solaris 8 has all user accounts locked and IDS allows connections due to /etc/hosts.equiv. We now need to realize three-tier model. +----------------+ +--------------+ http--+ jakarta-tomcat | | IDS 9.40 | http--+ JDBC 2.21 +-----+ | http--+ Solaris 2.6 | | Solaris 8 | +----------------+ +--------------+ A middle tier is told to be able to perform user authorization. Can we realize terminal-server-like authorization without having to assign passwords to all users at Solaris 8? Denis
You can configure tomcat to connect as any user you want to use.
Depending on the environment you might want to setup a number of users
so you can easily see who is doing what when running onstat -u. The
minimum I would consider is a discrete account for each app server, if
you wish to go to a finer servlet granularity then I think this is a
good idea.
Denis Melnikov wrote:
> Hi!
>
> At this moment we have terminal-server application.
>
> +---------------+ +--------------+
> telnet--+ Informix 4GL | | IDS 9.40 |
> telnet--+ +-----+ |
> telnet--+ Solaris 2.6 | | Solaris 8 |
> +---------------+ +--------------+
>
> Users pass authorization on Solaris 2.6.
> Solaris 8 has all user accounts locked and
> IDS allows connections due to /etc/hosts.equiv.
>
> We now need to realize three-tier model.
>
> +----------------+ +--------------+
> http--+ jakarta-tomcat | | IDS 9.40 |
> http--+ JDBC 2.21 +-----+ |
> http--+ Solaris 2.6 | | Solaris 8 |
> +----------------+ +--------------+
>
> A middle tier is told to be able to perform user
> authorization.
> Can we realize terminal-server-like authorization
> without having to assign passwords to all users
> at Solaris 8?
>
> Denis
>
>
--
Paul Watson #
Oninit Ltd # Growing old is mandatory
Tel: +44 1436 672201 # Growing up is optional
Fax: +44 1436 678693 #
Mob: +44 7818 003457 #
www.oninit.com #
> You can configure tomcat to connect as any user you want to use.
Do I need to unlock the user's account at Solaris 8?
> Depending on the environment you might want to setup a number of users
> so you can easily see who is doing what when running onstat -u. The
> minimum I would consider is a discrete account for each app server, if
> you wish to go to a finer servlet granularity then I think this is a
> good idea.
The question is: can we use /etc/hosts.equiv authentication
with JDBC?
> Denis Melnikov wrote:
>
> > Hi!
> >
> > At this moment we have terminal-server application.
> >
> > +---------------+ +--------------+
> > telnet--+ Informix 4GL | | IDS 9.40 |
> > telnet--+ +-----+ |
> > telnet--+ Solaris 2.6 | | Solaris 8 |
> > +---------------+ +--------------+
> >
> > Users pass authorization on Solaris 2.6.
> > Solaris 8 has all user accounts locked and
> > IDS allows connections due to /etc/hosts.equiv.
> >
> > We now need to realize three-tier model.
> >
> > +----------------+ +--------------+
> > http--+ jakarta-tomcat | | IDS 9.40 |
> > http--+ JDBC 2.21 +-----+ |
> > http--+ Solaris 2.6 | | Solaris 8 |
> > +----------------+ +--------------+
> >
> > A middle tier is told to be able to perform user
> > authorization.
> > Can we realize terminal-server-like authorization
> > without having to assign passwords to all users
> > at Solaris 8?
> >
> > Denis
> >
> >
>
>
> --
> Paul Watson #
> Oninit Ltd # Growing old is mandatory
> Tel: +44 1436 672201 # Growing up is optional
> Fax: +44 1436 678693 #
> Mob: +44 7818 003457 #
> www.oninit.com #
Denis Melnikov wrote:
>>You can configure tomcat to connect as any user you want to use.
>
>
> Do I need to unlock the user's account at Solaris 8?
Don't know I've never tested, I set the shell to /bin/false for all web
accounts and setup a proper password.
>>Depending on the environment you might want to setup a number of users
>>so you can easily see who is doing what when running onstat -u. The
>>minimum I would consider is a discrete account for each app server, if
>>you wish to go to a finer servlet granularity then I think this is a
>>good idea.
>
>
> The question is: can we use /etc/hosts.equiv authentication
> with JDBC?
We don't, I don't trust any machine trying to access the DB
>
>
>>Denis Melnikov wrote:
>>
>>
>>>Hi!
>>>
>>>At this moment we have terminal-server application.
>>>
>>> +---------------+ +--------------+
>>>telnet--+ Informix 4GL | | IDS 9.40 |
>>>telnet--+ +-----+ |
>>>telnet--+ Solaris 2.6 | | Solaris 8 |
>>> +---------------+ +--------------+
>>>
>>>Users pass authorization on Solaris 2.6.
>>>Solaris 8 has all user accounts locked and
>>>IDS allows connections due to /etc/hosts.equiv.
>>>
>>>We now need to realize three-tier model.
>>>
>>> +----------------+ +--------------+
>>> http--+ jakarta-tomcat | | IDS 9.40 |
>>> http--+ JDBC 2.21 +-----+ |
>>> http--+ Solaris 2.6 | | Solaris 8 |
>>> +----------------+ +--------------+
>>>
>>>A middle tier is told to be able to perform user
>>>authorization.
>>>Can we realize terminal-server-like authorization
>>>without having to assign passwords to all users
>>>at Solaris 8?
>>>
>>>Denis
>>>
>>>
>>
>>
>>--
>>Paul Watson #
>>Oninit Ltd # Growing old is mandatory
>>Tel: +44 1436 672201 # Growing up is optional
>>Fax: +44 1436 678693 #
>>Mob: +44 7818 003457 #
>>www.oninit.com #
>
>
>
--
Paul Watson #
Oninit Ltd # Growing old is mandatory
Tel: +44 1436 672201 # Growing up is optional
Fax: +44 1436 678693 #
Mob: +44 7818 003457 #
www.oninit.com #