How to use PAM authentication on IDS 9.40UC7
Posted in 2007
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration, Versions, Editions & End-of-Life
We are currently stuck with using 9.40UC7 because of our applications and are trying to use PAM to authenticate through Active Directory. I have configured Linux and it works with AD to authenticate users. However, when I try to use an AD account to authenticate in Informix, I get an error telling me that the password is incorrect for the username. My sqlhosts file for this server has the following line: ol_ids onsoctcp 10.1.1.117 ol_ids s=4,pam_serv=(other),pamauth=(password) I have tried a couple of options for the pam_serv and for pamauth have tried both password and challenge. Any ideas? Thanks, Mark
Hi,
you need to find out, which PAM service is the one that is
used on your system for the authentication with AD. I don't
think it is the one named "other". (I think the "other" PAM
service is only for authentication utilizing the normal UNIX
mechanisms with /etc/passwd and /etc/shadow files.)
[ The configuration for each PAM is in /etc/pam.conf. On
Linux however, if directory /etc/pam.d exists, then each
module has its own configuration file in this directory and
/etc/pam.conf is ignored.
]
The service (i.e. PAM) you found out above is the one
you then need to specify in the sqlhosts file for IDS.
The question whether to use "password" or "challenge"
depends more on your application that connects to IDS,
and not so much on the PAM that you use.
[ Authentication Mode
With PAM it is not always necessary to challenge the client for the
password information. Sometimes it is sufficient to get a "normal"
UNIX password from the client, that PAM then uses in whatever way to
do the authentication. With that, since in our SQLI protocol for
client-server communication the password can be passed along with
the initial connect request, in these cases the server can pass this
password information from the connect request right away to PAM.
Therefore, the above method that does not need a challenge is called
password authentication mode. If on the other hand a challenge is
necessary, then this is called challenge authentication mode.
IDS supports PAM with both authentication modes, challenge and
password.
Implicit Connection
Without PAM configuration, IDS and most utilities (like dbaccess)
support implicit connections. This is a connection to the IDS
server, where no passowrd information is supplied in the connection
request. The server authenticates the user by other means (e.g.
.rhosts lookup).
With a PAM configuration in challenge authentication mode, implicit
connections to IDS can work, because the password information will
be retrieved from the user via the challenge.
But for a PAM configuration in password authentication mode, the
password must be supplied always. The password will not be retrieved
via a challenge, therefore it must be provided in the connection
request. Thus implicit connections will always fail with password
authentication mode, because PAM has no way to get the password
information from the client.
]
Hopefully this can clarify the concept.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
IBM Deutschland GmbH
Chairman of the Supervisory Board: Hans Ulrich Märki
Board of Management: Martin Jetter (Chairman), Rudolf Bauer, Christian
Diedrich, Christoph Grandpierre, Matthias Hartmann, Thomas Fell, Michael
Diemer
Corporate Seat: Stuttgart, Germany; Reg.-Gericht: Amtsgericht Stuttgart,
HRB-Nr.: 14 562 WEEE-Reg.-Nr. DE 99369940
ids-bounces@iiug.org wrote on 21.09.2007 15:19:17:
> We are currently stuck with using 9.40UC7 because of our applications
and are
> trying to use PAM to authenticate through Active Directory. I have
configured
> Linux and it works with AD to authenticate users. However, when I try to
use
> an AD account to authenticate in Informix, I get an error telling me
that the
> password is incorrect for the username.
>
> My sqlhosts file for this server has the following line:
>
> ol_ids onsoctcp 10.1.1.117 ol_ids
s=4,pam_serv=(other),pamauth=(password)>
> I have tried a couple of options for the pam_serv and for pamauth have
tried
> both password and challenge.
>
> Any ideas?
>
> Thanks,
> Mark
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Can you please put the relevant contents from /etc/pam.conf (or whateve=
r is
linux equivalent) too?
Also.. I think pam_unix is for normal unix (passwd or shadow files)
authentication.
Manoj.
=
"Martin =
Fuerderer" =
<MARTINFU@de.ibm. =
To
com> ids@iiug.org =
Sent by: =
cc
ids-bounces@iiug. =
org Subj=
ect
Re: How to use PAM authenticatio=
n
on IDS 9.40UC7 [9990] =
09/21/2007 09:27 =
AM =
=
=
Please respond to =
ids@iiug.org =
=
=
Hi,
you need to find out, which PAM service is the one that is
used on your system for the authentication with AD. I don't
think it is the one named "other". (I think the "other" PAM
service is only for authentication utilizing the normal UNIX
mechanisms with /etc/passwd and /etc/shadow files.)
[ The configuration for each PAM is in /etc/pam.conf. On
Linux however, if directory /etc/pam.d exists, then each
module has its own configuration file in this directory and
/etc/pam.conf is ignored.
]
The service (i.e. PAM) you found out above is the one
you then need to specify in the sqlhosts file for IDS.
The question whether to use "password" or "challenge"
depends more on your application that connects to IDS,
and not so much on the PAM that you use.
[ Authentication Mode
With PAM it is not always necessary to challenge the client for the
password information. Sometimes it is sufficient to get a "normal"
UNIX password from the client, that PAM then uses in whatever way to
do the authentication. With that, since in our SQLI protocol for
client-server communication the password can be passed along with
the initial connect request, in these cases the server can pass this
password information from the connect request right away to PAM.
Therefore, the above method that does not need a challenge is called
password authentication mode. If on the other hand a challenge is
necessary, then this is called challenge authentication mode.
IDS supports PAM with both authentication modes, challenge and
password.
Implicit Connection
Without PAM configuration, IDS and most utilities (like dbaccess)
support implicit connections. This is a connection to the IDS
server, where no passowrd information is supplied in the connection
request. The server authenticates the user by other means (e.g.
..rhosts lookup).
With a PAM configuration in challenge authentication mode, implicit
connections to IDS can work, because the password information will
be retrieved from the user via the challenge.
But for a PAM configuration in password authentication mode, the
password must be supplied always. The password will not be retrieved
via a challenge, therefore it must be provided in the connection
request. Thus implicit connections will always fail with password
authentication mode, because PAM has no way to get the password
information from the client.
]
Hopefully this can clarify the concept.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
IBM Deutschland GmbH
Chairman of the Supervisory Board: Hans Ulrich M=E4rki
Board of Management: Martin Jetter (Chairman), Rudolf Bauer, Christian
Diedrich, Christoph Grandpierre, Matthias Hartmann, Thomas Fell, Michae=
l
Diemer
Corporate Seat: Stuttgart, Germany; Reg.-Gericht: Amtsgericht Stuttgart=
,
HRB-Nr.: 14 562 WEEE-Reg.-Nr. DE 99369940
ids-bounces@iiug.org wrote on 21.09.2007 15:19:17:
> We are currently stuck with using 9.40UC7 because of our applications=
and are
> trying to use PAM to authenticate through Active Directory. I have
configured
> Linux and it works with AD to authenticate users. However, when I try=
to
use
> an AD account to authenticate in Informix, I get an error telling me
that the
> password is incorrect for the username.
>
> My sqlhosts file for this server has the following line:
>
> ol_ids onsoctcp 10.1.1.117 ol_ids
s=3D4,pam_serv=3D(other),pamauth=3D(password)>
> I have tried a couple of options for the pam_serv and for pamauth hav=
e
tried
> both password and challenge.
>
> Any ideas?
>
> Thanks,
> Mark
>
>
>
***********************************************************************=
********
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=
Hi,
there's some documentation on PAM available:
http://www.kernel.org/pub/linux/libs/pam/Linux-PAM-html/
And especially in "The System Administrators' Guide" the
chapters on configuration:
http://www.kernel.org/pub/linux/libs/pam/Linux-PAM-html/sag-configuration.html
I don't like so much to provide the content of
my /etc/pam.conf. I used some very simple,
example only PAM, that I compiled myself.
And this is not representative in anyway for
customers or any other systems.
I had my /etc/pam.conf published as an example
somewhere in the past - with the result that people
told me they would not have this PAM library and
asked where they can find it ... :-)
If using PAM seriously, things will need to be
configured rather individually. Therefore I think
it is better to read the documentation and understand
the concept and mechanisms rather than blindly
taking some example without really knowing what's
going on. :)
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
IBM Deutschland GmbH
Chairman of the Supervisory Board: Hans Ulrich Märki
Board of Management: Martin Jetter (Chairman), Rudolf Bauer, Christian
Diedrich, Christoph Grandpierre, Matthias Hartmann, Thomas Fell, Michael
Diemer
Corporate Seat: Stuttgart, Germany; Reg.-Gericht: Amtsgericht Stuttgart,
HRB-Nr.: 14 562 WEEE-Reg.-Nr. DE 99369940
ids-bounces@iiug.org wrote on 21.09.2007 16:56:11:
> Can you please put the relevant contents from /etc/pam.conf
> (or whatever is linux equivalent) too?
>
> Also.. I think pam_unix is for normal unix (passwd or
> shadow files) authentication.
>
> Manoj.
>
> =
>
> "Martin =
>
> Fuerderer" =
>
> <MARTINFU@de.ibm. =
> To
>
> com> ids@iiug.org =
>
> Sent by: =
> cc
>
> ids-bounces@iiug. =
>
> org Subj=
> ect
>
> Re: How to use PAM authenticatio=
> n
>
> on IDS 9.40UC7 [9990] =
>
> 09/21/2007 09:27 =
>
> AM =
>
> =
>
> =
>
> Please respond to =
>
> ids@iiug.org =
>
> =
>
> =
>
> Hi,
>
> you need to find out, which PAM service is the one that is
> used on your system for the authentication with AD. I don't
> think it is the one named "other". (I think the "other" PAM
> service is only for authentication utilizing the normal UNIX
> mechanisms with /etc/passwd and /etc/shadow files.)
>
> [ The configuration for each PAM is in /etc/pam.conf. On
> Linux however, if directory /etc/pam.d exists, then each
> module has its own configuration file in this directory and
> /etc/pam.conf is ignored.
> ]
>
> The service (i.e. PAM) you found out above is the one
> you then need to specify in the sqlhosts file for IDS.
>
> The question whether to use "password" or "challenge"
> depends more on your application that connects to IDS,
> and not so much on the PAM that you use.
>
> [ Authentication Mode
>
> With PAM it is not always necessary to challenge the client for the
> password information. Sometimes it is sufficient to get a "normal"
> UNIX password from the client, that PAM then uses in whatever way to
> do the authentication. With that, since in our SQLI protocol for
> client-server communication the password can be passed along with
> the initial connect request, in these cases the server can pass this
> password information from the connect request right away to PAM.
>
> Therefore, the above method that does not need a challenge is called
> password authentication mode. If on the other hand a challenge is
> necessary, then this is called challenge authentication mode.
>
> IDS supports PAM with both authentication modes, challenge and
> password.
>
> Implicit Connection
>
> Without PAM configuration, IDS and most utilities (like dbaccess)
> support implicit connections. This is a connection to the IDS
> server, where no passowrd information is supplied in the connection
> request. The server authenticates the user by other means (e.g.
> ...rhosts lookup).
>
> With a PAM configuration in challenge authentication mode, implicit
> connections to IDS can work, because the password information will
> be retrieved from the user via the challenge.
>
> But for a PAM configuration in password authentication mode, the
> password must be supplied always. The password will not be retrieved
> via a challenge, therefore it must be provided in the connection
> request. Thus implicit connections will always fail with password
> authentication mode, because PAM has no way to get the password
> information from the client.
> ]
>
> Hopefully this can clarify the concept.
>
> Regards,
> Martin
> --
> Martin Fuerderer
> IBM Informix Development Munich, Germany
> Information Management
>
> IBM Deutschland GmbH
> Chairman of the Supervisory Board: Hans Ulrich M=E4rki
> Board of Management: Martin Jetter (Chairman), Rudolf Bauer, Christian
> Diedrich, Christoph Grandpierre, Matthias Hartmann, Thomas Fell, Michae=
> l
> Diemer
> Corporate Seat: Stuttgart, Germany; Reg.-Gericht: Amtsgericht Stuttgart=
> ,
> HRB-Nr.: 14 562 WEEE-Reg.-Nr. DE 99369940
>
> ids-bounces@iiug.org wrote on 21.09.2007 15:19:17:
>
> > We are currently stuck with using 9.40UC7 because of our applications=
>
> and are
> > trying to use PAM to authenticate through Active Directory. I have
> configured
> > Linux and it works with AD to authenticate users. However, when I try=
> to
> use
> > an AD account to authenticate in Informix, I get an error telling me
> that the
> > password is incorrect for the username.
> >
> > My sqlhosts file for this server has the following line:
> >
> > ol_ids onsoctcp 10.1.1.117 ol_ids
> s=3D4,pam_serv=3D(other),pamauth=3D(password)> >
> > I have tried a couple of options for the pam_serv and for pamauth hav=
> e
> tried
> > both password and challenge.
> >
> > Any ideas?
> >
> > Thanks,
> > Mark
> >
> >
> >
>
> ***********************************************************************=
> ********
>
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
> ***********************************************************************=
> ********
>
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
> =
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>