/etc/hosts.equiv
Posted in 1999
I have a question relating to the /etc/hosts.equiv file. In my environment, we are running a client/server configuration. The client apps consist of SQL/Windows (16-bit connectivity) and Delphi (32-bit connectivity). Comparing Informix's I/Net 16-bit vs 32-bit product, they do authentication differently. The 16-bit client DOES NOT appear to do "trusted authentication" against the target server. Whereas the 32-bit client DOES do "trusted authentication". So, on our server, we have set /etc/hosts.equiv equal to "+". BAD!!! This is a big security hole that I am trying to fix. I am aware of a couple of options: (1) Leave hosts.equiv alone. (2) specify each client in the hosts.equiv (3) create ~/.rhosts which is specific to a given user. For me, option (1) is not an option; a security hole. With options (2) and (3), these options are <gulp> ok, but I can see this as a huge burden once you begin adding a large number of users. I did an RTFM and noticed that in sqlhosts you can give it the option of s=0 to disable /etc/hosts.equiv authentication, but does not seem to have any effect. Q: If your shop has large number of users, how do you handle this situation? Q: From the perspective of authentication, what is 16-bit doing differently than 32-bit? Thanks. Steve Romankiw Environment **Server** Solaris 2.5.1 / 2.6 IDS 7.23 UC1 **Client** Win/95