Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
A user on IDS 11.50 (Solaris 10) asked how to stop OS users from running dbaccess locally, and whether the database can prompt for a password even for informix/root. Replies: Informix normally trusts OS authentication locally, so there's no built-in local password prompt; suggestions included restricting OS accounts, using connect/database privileges, wrapping dbaccess with a password-checking script, or using sudo. The fullest answer was to set up a PAM-based listener (pam_serv/pamauth) on 127.0.0.1 with s=0 on the external listener to force passwords, blocking the unauthenticated path with firewall rules — while noting root/informix can always bypass any of this. No confirmation from the poster is recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Hi All,
We are using IDS 11.50.FC7 on Solaris 10 Sparc.
How can we re-strict OS users to access database using dbaccess.
Is there any way that database prompt password for any/all users (even
informix or root user) before accessing Database using dbaccess ?
Thanks.
↪ replying to SHAHZAD SALAM KASI
Jack Parker — — source: IIUG Forums & Mailing Lists
Sure, restrict their OS user account, then generate a second OS account =
that does have database access (but no shell), they will have to connect =
to that user account to access the db.
Sounds like a royal pain.
j.
On Sep 14, 2011, at 4:38 PM, SHAHZAD SALAM KASI wrote:
> Hi All,=20
> We are using IDS 11.50.FC7 on Solaris 10 Sparc.=20
>=20
> How can we re-strict OS users to access database using dbaccess.=20
> Is there any way that database prompt password for any/all users (even=20=
> informix or root user) before accessing Database using dbaccess ?=20
>=20
> Thanks.=20
>=20
>=20
> =
**************************************************************************=
*****=20
> Forum Note: Use "Reply" to post a response in the discussion forum.=20=
>=20
Informix normally authenticates users by asking the OS if the user is
authorized. If the user has entered a password to access the OS, what makes
you think that same user couldn't use the same password to access the
database? Informix 11.70 is capable of authenticating users who are not OS
users, and Informix has been able to use PAM, Kerberos, and other 3rd party
authentication for a long time, dbaccess local to the server does not do
that. If you want to lock users out of the data, you can use connect and
access privileges and even LDAP privilege levels to prevent users from
connecting to the server or accessing data to which they do not have
authority.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Wed, Sep 14, 2011 at 4:38 PM, SHAHZAD SALAM KASI <skasi@i2cinc.com>wrote:
> Hi All,
> We are using IDS 11.50.FC7 on Solaris 10 Sparc.
>
> How can we re-strict OS users to access database using dbaccess.
> Is there any way that database prompt password for any/all users (even
> informix or root user) before accessing Database using dbaccess ?
>
> Thanks.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--90e6ba6e90064226ac04aced251a
↪ replying to SHAHZAD SALAM KASI
Madison Pruet — — source: IIUG Forums & Mailing Lists
1) move dbaccess to a different location.
2) write a wrapper program which does password verification
3) If the wrapper program passes verification, then spawn the real
dbaccess
M.P.
From: "SHAHZAD SALAM KASI" <skasi@i2cinc.com>
To: ids@iiug.org
Date: 09/14/2011 03:44 PM
Subject: Dbaccess using password [24930]
Sent by: ids-bounces@iiug.org
Hi All,
We are using IDS 11.50.FC7 on Solaris 10 Sparc.
How can we re-strict OS users to access database using dbaccess.
Is there any way that database prompt password for any/all users (even
informix or root user) before accessing Database using dbaccess ?
Thanks.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
There is no way to force local password usage unless you use PAM. But PAM
can have some implications to existing applications. One solution:
1- Create a listener using PAM on 127.0.0.1:
cheetah_pam onsoctcp 127.0.0.1 1530
k=1,s=4,pam_serv=(pam_informix),pamauth=(password)
2- Configure the pam service (pam_informix) to use the OS password
3- Deny local access to the "external IP/port" for connections using the
local IP (example for LINUX):
iptables -A INPUT --protocol tcp --source 192.168.112.115 --destination
192.168.112.115 --dport 1530 -j REJECT
4- For the external listener (on 192.168.112.115) set "s=0":
cheetah onsoctcp 192.168.112.115 1530 k=1,s=0
This will force password usage since is disables the /etc/hosts.equiv and
~/.rhosts (or their replacements in 11.70.FC2+)
Send root and informix to prison... They can change all this. As I wrote
recently, if you can't control root you can't control nothing. It's a UNIX
issue. Not Informix.
All the other suggestions can also be overcome with root/informix access.
Regards.
On Wed, Sep 14, 2011 at 9:38 PM, SHAHZAD SALAM KASI <skasi@i2cinc.com>wrote:
> Hi All,
> We are using IDS 11.50.FC7 on Solaris 10 Sparc.
>
> How can we re-strict OS users to access database using dbaccess.
> Is there any way that database prompt password for any/all users (even
> informix or root user) before accessing Database using dbaccess ?
>
> Thanks.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--001485394108093f6604acf9a885
↪ replying to Fernando Nunes
KARL OLIVER — — source: IIUG Forums & Mailing Lists
hello
I wonder if sudo could do what you want here.
we use it on our unix systems. Our sysadmins use it to let us access some root
commands.
sudo allows a permitted user to execute a command as the superuser or
another user, as specified in the sudoers file.
This could take some time to set up though.
You could set up a user with sudo so they can run informix onstat only for
example
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.