Re: informix + pam on linux
Posted in 2005
Topics: Backup & Restore, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues, Versions, Editions & End-of-Life
Hi,
sorry for late reply ... :-(
Following is an example about how to
do a basic setup. It's a cut&paste from an
internal www-page that I once created on this
topic. I hope it is readable and understandable
anyway:
--------------------------------------------------------------
OS Setup for PAM
PAMs typically reside as shared libs in /usr/lib/security. The
configuration for each PAM is in /etc/pam.conf. On Linux
however, if directory /etc/pam.d exists, then each module has
its own configuration file in this directory and /etc/pam.conf
is ignored.
The following example illustrates a possible configuration
for a single PAM:
The service name of the PAM is "pam_chal"
and the shared library implementing it is
/usr/lib/security/pam_chal.so. The configuration for this
PAM service consists of the following two lines:
pam_chal <TAB> auth required <TAB> /usr/lib/security/pam_chal.so
pam_chal <TAB> account required <TAB> /usr/lib/security/pam_chal.so
where <TAB> denotes a tab character. This may be necessary,
since it could be possible that the middle parameter in
the line consists of only one token, which might confuse
the parser when reading the configuration. These two lines
are in /etc/pam.conf. On Linux, if the directory /etc/pam.d
exists, they should be placed in file /etc/pam.d/pam_chal.
IDS Setup for PAM
To make a specific IDS server name PAM-enabled, a new set of
additional parameters is used in the sqlhosts file for this
server name. The parameters are:
s=4,pam_serv=(...),pamauth=(...)
Example 1:
mfu1_pam ontlitcp onbarfix s=4,pam_serv=(pam_chal),pamauth=(challenge)
This line in the sqlhosts file will setup the server name
mfu1_pam to use the PAM with the service name pam_chal. The
authentication mode for this server name will be challenge,
so clients connecting to this servername must be prepared
to handle a PAM challenge.
Example 2:
mfu1_pam ontlitcp onbarfix s=4,pam_serv=(other),pamauth=(password)
This line in the sqlhosts file will setup the server name
mfu1_pam to use the PAM with the service name other which
usually is implemented by the system provided PAM module
pam_unix.so. The authentication mode for this server name
will be password, so clients connecting to this servername
must be prepared to provide the password with the connection
request. Implicit connections will be rejected.
--------------------------------------------------------------
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
"Thomas" <tomwic@op.pl>
Sent by: owner-informix-list@iiug.org
16.03.2005 13:07
Please respond to
"Thomas"
To
informix-list@iiug.org
cc
Subject
informix + pam on linux
Hi,
can somebody tell me how to configure pam.d directory/file
on Linux for IDS 9.4/10.0? Which name of file for informix
will be right? ... and how this file and sqlhosts should
look like?
Regards,
Thomas
sending to informix-list
Hi,
thanks a lot for answer! don't worry for late :)
I configured following items:
/etc/services: sqlexec 1540/tcp
Environment
export INFORMIXSERVER=helios
export PATH=$PATH:$INFORMIXDIR/binexport OB2APPNAME=helios
export OB2BARHOSTNAME=helios
export DBSERVERALIASES=helios
export DBSERVERNAME=helios
sqlhosts:
helios ontlitcp helios sqlexec
s=4,pam_serv=(informix),pamauth=(password)
/etc/pam.d/informix auth required pam_unix.so debug
When I use ontlitcp as netype I can not to initialize DB (oninit).
I get: The specified service name or protocol is unknown. Error -25507.
What is the reason? I want to connect to DB via IP protocol.
Regards,
-t
I found that Linux don't support this nettype. I change to onsoctcp. Platform/OS BSTP IPSP IPSM TLTP TLIX MAXC Linux onsoctcp - onipcshm - - onsocimc BSTP - Berkeley sockets using TCP/IP IPSP - IPC using stream pipe IPSM - IPC using shared memory TLTP - TLI using TCP/IP TLIX - TLI using IPX/SPX MAXC - MaxConnect ... but I can not still authorize users via pam... :( Have you any idea? -t