Re: Understanding LDAP or MS Active Directory authentication and Informix
Posted in 2007
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues, Versions, Editions & End-of-Life
PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for me. I'm just trying to understand what type of user id is needed in the database to support an LDAP/AD user. Does that make sense? "Andrew Ford" <aford@networkip. net> To <informix-list@iiug.org>, 03/07/2007 02:04 <Darren_Jacobs@carmax.com> PM cc Subject Re: Understanding LDAP or MS Active Directory authentication and Informix In Linux I can get the Informix engine to authenticate a user via LDAP through PAM by adding the following options to my server's sqlhosts entry s=4,pam_serv=(system_auth),pamauth=(password) You can find some more info here: http://publib.boulder.ibm.com/infocenter/idshelp/v10/index.jsp?topic=/com.ibm.admin.doc/admin02.htm I'm still testing the functionality myself, not sure how/if it will work under HP/UX and still not sure if I've configured LDAP via PAM correctly but it appears to work. Andrew ----- Original Message ----- From: <Darren_Jacobs@carmax.com> To: <informix-list@iiug.org> Sent: Wednesday, March 07, 2007 11:52 AM Subject: Understanding LDAP or MS Active Directory authentication and Informix > > Greetings, > > I'm hoping someone understands what is necessary to enable LDAP or AD > authentication with Informix. I'm trying to understand if a specific > database ID w/connect needs to be present or if a user is part of a group > in LDAP/AD, connect can be granted to the group name in the DB. I'm > having > a hard time believing that a DB ID does not exist in the DB. > > Or if I'm just not understanding what is required to make LDAP work, could > some explain it to me. > > IDS 9.40 FC2 or FC8 > HPUX 11.11 > > Thanks for any insight you can provide. > > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list
Darren_Jacobs@carmax.com wrote: > PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for me. > I'm just trying to understand what type of user id is needed in the > database to support an LDAP/AD user. > > Does that make sense? > IDS will use OS authentication. If HPUX/64 allows for OS users to be authenticated in a LDAP server this should work for Informix. Currently there is no user id inside the database server. PAM allows for other ways to authenticate users (only limited by the availability of PAM itself and the appropriate module(s) ) I believe that 10.00.FC6 may support PAM on HP-UX (PA-RISC) but the machine notes are not on the page yet. For 10.00.FC5 on HP-UX (Itanium) the machine notes ( http://publib.boulder.ibm.com/epubs/html/22963440.html ) state it supports PAM. If you think PAM could help, you can contact support for clarification. For OS/LDAP integration maybe this will help: http://docs.hp.com/en/internet.html#LDAP-UX%20Integration -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Hi, that is (unfortunately) true. As far as I know, IDS supports PAM on HP-UX, but only HP-UX 32-bit (on PA-Risc that is). One possibility to get this to work anyway is to find some software that does LDAP authentication transparently. In the standard scenario (no PAM) IDS uses normal system library calls to retrieve OS user information (normally from /etc/passwd and /etc/shadow) and do the check. There are some implementations existing that let these normal system library calls do an LDAP look-up very much the way NIS/NIS+ works. This would be transparent to the IDS server and thus would work with IDS. I've never searched for and much less tried any such things for HP-UX. So you will have to do some research yourself. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management Sorry, but the following text is now required by German law: IBM Deutschland GmbH Vorsitzender des Aufsichtsrats: Hans Ulrich Maerki Geschäftsführung: Martin Jetter (Vorsitzender), Rudolf Bauer, Christian Diedrich, Christoph Grandpierre, Matthias Hartmann, Andreas Kerstan Sitz der Gesellschaft: Stuttgart Registergericht: Amtsgericht Stuttgart, HRB 14562 WEEE-Reg.-Nr. DE 99369940 informix-list-bounces@iiug.org wrote on 08.03.2007 02:27:15: > Darren_Jacobs@carmax.com wrote: > > PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for me. > > I'm just trying to understand what type of user id is needed in the > > database to support an LDAP/AD user. > > > > Does that make sense? > > IDS will use OS authentication. If HPUX/64 allows for OS > users to be authenticated in a LDAP server this should work > for Informix. > Currently there is no user id inside the database server. > > PAM allows for other ways to authenticate users (only limited > by the availability of PAM itself and the appropriate module(s) ) > I believe that 10.00.FC6 may support PAM on HP-UX (PA-RISC) > but the machine notes are not on the page yet. > For 10.00.FC5 on HP-UX (Itanium) the machine notes > ( http://publib.boulder.ibm.com/epubs/html/22963440.html ) > state it supports PAM. > If you think PAM could help, you can contact support for clarification. > > For OS/LDAP integration maybe this will help: > > http://docs.hp.com/en/internet.html#LDAP-UX%20Integration > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently... > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list
Fernando, Thanks for the response and link. I believe I have a handle on how the user would be authenticated to the OS. I guess my confusion is how do you manage db object permssions in the db if the user does not exist. Someone mentioned that the user would connect via public. I'm hoping that the correct way to handle this is through the sysusers db. Each LDAP user would belong to a groupname in the sysauth table. Therefore, you would grant perms on the objects to the groupname, ie, LDAP user djacobs belonging to the groupname 'accounting' could be granted perms on a specific set of accounting tables. Public would not have these perms. Thanks Fernando Nunes <spam@domus.onlin e.pt> To Sent by: informix-list@iiug.org informix-list-bou cc nces@iiug.org Subject Re: Understanding LDAP or MS Active 03/07/2007 08:56 Directory authentication and PM Informix Darren_Jacobs@carmax.com wrote: > PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for me. > I'm just trying to understand what type of user id is needed in the > database to support an LDAP/AD user. > > Does that make sense? > IDS will use OS authentication. If HPUX/64 allows for OS users to be authenticated in a LDAP server this should work for Informix. Currently there is no user id inside the database server. PAM allows for other ways to authenticate users (only limited by the availability of PAM itself and the appropriate module(s) ) I believe that 10.00.FC6 may support PAM on HP-UX (PA-RISC) but the machine notes are not on the page yet. For 10.00.FC5 on HP-UX (Itanium) the machine notes ( http://publib.boulder.ibm.com/epubs/html/22963440.html ) state it supports PAM. If you think PAM could help, you can contact support for clarification. For OS/LDAP integration maybe this will help: http://docs.hp.com/en/internet.html#LDAP-UX%20Integration -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list
On 8 Mar, 13:37, Darren_Jac...@carmax.com wrote: > Fernando, > > Thanks for the response and link. I believe I have a handle on how the > user would be authenticated to the OS. > > I guess my confusion is how do you manage db object permssions in the db if > the user does not exist. Someone mentioned that the user would connect via You don't, the user has to exist in the OS otherwise the permissions for public are used. > public. I'm hoping that the correct way to handle this is through the > sysusers db. Each LDAP user would belong to a groupname in the sysauth > table. Therefore, you would grant perms on the objects to the groupname, > ie, LDAP user djacobs belonging to the groupname 'accounting' could be > granted perms on a specific set of accounting tables. Public would not > have these perms. Nope, the username is used.