Re: Understanding LDAP or MS Active Directory authenticationand Informix
Posted in 2007
Hi Darren, I know you may not be in the position to upgrade but 10.00.FC6 on PA-RISC 11.11 and greater supports 64 bit PAM ----- Original Message ---- From: "Darren_Jacobs@carmax.com" <Darren_Jacobs@carmax.com> To: Ian Michael Gumby <im_gumby@hotmail.com> Cc: informix-list-bounces@iiug.org; informix-list@iiug.org Sent: Thursday, March 8, 2007 12:15:06 PM Subject: Re: Understanding LDAP or MS Active Directory authenticationand Informix I know the LDAP support is through PAM. Fernando was referring to the following info for HPUX. I interpret this as PAM is not supported running on HPUX 11.11 in 64 bit mode. So, truly, I'm not going to be able to use it. pam.txt: On HP-UX and AIX, PAM is supported in 32 bit mode only. Anyway, Thanks for responding. I do appreciate it. I think I understand that the user still must have an entry in sysusers, correct? And perms are granted as they are with a non LDAP'd user..correct? So users are users and must have a "grant connect to 'username';" performed, correct? I didn't realize my "trying to understand" the db side of the requirements was going to raise a (RTFM). Which I don't mind, because I did. 8-) I guess I should have posted on the forum instead!! 8-) Thanks "Ian Michael Gumby" <im_gumby@hotmail To .com> Darren_Jacobs@carmax.com Sent by: cc informix-list-bou informix-list@iiug.org nces@iiug.org Subject Re: Understanding LDAP or MS Active Directory authenticationand 03/08/2007 12:00 Informix PM Whoa! First, the LDAP support is through PAM modules. (RTFM) Informix uses the OS to verify its users. If the OS supports PAM (HP-UX, Solaris, LINUX(s), and I believe AIX), then when you make the authentication call to the OS, it goes through the PAM chain that the OS uses. When you want IDS to use LDAP for authentication, then it uses PAM to authenticate against LDAP. You can, in theory, have PAM set up to check any database for authentication. That is to say, you could create a PAM module that authenticates a user against an IDS database of users. In theory, within Cheetah, you could put the authentication table within the sysadmin database. But it is interesting that Fernando said that IDS only supports 32 bit PAM libraries. That would explain a lot if true.... If not true, then you should be able to get the source for PAM modules and compile them for a 64bit environment. In your example, as far as Informix is concerned, that if you set up a user fred, it authenticates that "fred" exists and then goes along its merry way. At least thats the theory behind it. So that Informix then has to check within itself what permissions to gran user "fred". HTH -G > >Fernando, > >Thanks for the response and link. I believe I have a handle on how the >user would be authenticated to the OS. > >I guess my confusion is how do you manage db object permssions in the db if >the user does not exist. Someone mentioned that the user would connect via >public. I'm hoping that the correct way to handle this is through the >sysusers db. Each LDAP user would belong to a groupname in the sysauth >table. Therefore, you would grant perms on the objects to the groupname, >ie, LDAP user djacobs belonging to the groupname 'accounting' could be >granted perms on a specific set of accounting tables. Public would not >have these perms. > >Thanks > > > > > Fernando Nunes > <spam@domus.onlin > e.pt> To > Sent by: informix-list@iiug.org > informix-list-bou cc > nces@iiug.org > Subject > Re: Understanding LDAP or MS Active > 03/07/2007 08:56 Directory authentication and > PM Informix > > > > > > > > > > >Darren_Jacobs@carmax.com wrote: > > PAM is not available for 9.40 FCx on HPUX 64 bit which is a problem for >me. > > I'm just trying to understand what type of user id is needed in the > > database to support an LDAP/AD user. > > > > Does that make sense? > > > > >IDS will use OS authentication. If HPUX/64 allows for OS users to be >authenticated in a LDAP server this should work for Informix. >Currently there is no user id inside the database server. > >PAM allows for other ways to authenticate users (only limited by the >availability of PAM itself and the appropriate module(s) ) >I believe that 10.00.FC6 may support PAM on HP-UX (PA-RISC) but the machine >notes are not on the page yet. >For 10.00.FC5 on HP-UX (Itanium) the machine notes ( >http://publib.boulder.ibm.com/epubs/html/22963440.html ) state it supports >PAM. >If you think PAM could help, you can contact support for clarification. > >For OS/LDAP integration maybe this will help: > >http://docs.hp.com/en/internet.html#LDAP-UX%20Integration > > >-- >Fernando Nunes >Portugal > >http://informix-technology.blogspot.com >My email works... but I don't check it frequently... >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list > > >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Win a Zunemake MSN® your homepage for your chance to win! http://homepage.msn.com/zune?icid=hmetagline _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-