Trusted context
Posted in 2018
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing
Hi, can anyone tell me if it is possible to establish trusted connection from
application server
to db server without providing user and password and using only Trusted
Context?
I want to achieve same result as with .rhosts but using Trusted Context
feature.
Will Trusted Context work without need of .rhosts or
$INFORMIXDIR/etc/hosts.equiv ??
I'm trying to set up connection using mapped user account (db internal
account) and Trusted Context
but fail getting constant errors telling Client or host user1@laptop1 is not
trusted by the server(956). On client side I get 951 most of the time.
My setup is:
-empty .rhosts, no $INFORMIXDIR/etc/hosts.equiv, no /etc/hosts.equiv, no .netrc
-app server(192.168.1.13, hostname=latop1) with local OS user account user1
-db server with a sample1 database with a mapped user account user1 with
password
-user1 is granted with connect on sample1
-trusted context defined as below:
GRANT DBSECADM TO informix;CREATE TRUSTED CONTEXT tcx1
USER user1
ATTRIBUTES (ADDRESS 192.168.1.13, ADDRESS laptop1) ENABLE
WITH USE FOR user1 WITHOUT AUTHENTICATION;
When I connect using user1 account providing a password all works fine.
When I try to connect using random software with jdbc where connection string
is
jdbc:informix-sqli://192.168.1.13:50005/sample1:INFORMIXSERVER=myinstance;
trusted_context=true;
it fails with 951 error on client side and 956 on the server.
Can anyone tell me what I missed? Is it even possible to make it work using
Trusted Context?
I'd be grateful for any useful hints as there is very little information
regarding this topic.Like
Small correction to above. My db server is 192.168.1.15 so the proper jdbc looks like this: "jdbc:informix-sqli://192.168.1.15:50005/sample1:INFORMIXSERVER=myinstance; trusted_context=true;"
You're missing, or better saying, confusing different concepts.
Informix has a trusted connection and a trusted context. They are very
different things (in spite of the similar names)
A trusted connection is a connection to a database server where no password
is given and for that to happen the user must exist and the trust relation
must have been created.
A trusted context is a concept where an authenticated user can change its
identity to another one previously defined/configured without having to
provide credentials.
The JDBC driver doesn't allow you to specify the USER without the PASSORD
properties. So, in order to make a trusted connection in JDBC you'd have to
connect to the database server with the user running the application.
This is inconvenient, but it's a driver limitation.
The other option is a bit more complex, but should be technically feasible.
You could achieve the same goal by creating a PAM listener and then using
the rhost PAM module to do the "authentication". That way you could
configure it with user and password (dummy one) and let PAM do the magic.
Additionally you could create extra security if you use "challenge" mode
and some module that uses challenge/response mechanism. The application
side would have to implement a Java callback function to answer the
challenge. With custom programming on both sides you could create very
complex authentication mechanisms.
The error 956 means "not trusted" and the online.log will show "why". The
authentication errors on server side (-951, -952, -956 and eventually
others I'm missing) are mapped to -951 on client side. This is a security
feature designed to reduce the information an attacker could collect (if an
attacker received a -956 he would already know the user existed....)
Regards.
On Wed, Feb 21, 2018 at 10:31 AM, MICHAL LUKASZEWICZ <
lukaszewicz.michal@gmail.com> wrote:
> Hi, can anyone tell me if it is possible to establish trusted connection
> from
> application server
> to db server without providing user and password and using only Trusted
> Context?
>
> I want to achieve same result as with .rhosts but using Trusted Context
> feature.
> Will Trusted Context work without need of .rhosts or
> $INFORMIXDIR/etc/hosts.equiv ??
>
> I'm trying to set up connection using mapped user account (db internal
> account) and Trusted Context
> but fail getting constant errors telling âClient or host user1@laptop1 is
> not
> trusted by the serverâ(956). On client side I get 951 most of the time.
>
> My setup is:
> -empty .rhosts, no $INFORMIXDIR/etc/hosts.equiv, no /etc/hosts.equiv, no
> ..netrc
> -app server(192.168.1.13, hostname=latop1) with local OS user account
> âuser1â
> -db server with a âsample1â database with a mapped user account
âuser1â
> with
> password
> -user1 is granted with connect on sample1
> -trusted context defined as below:
> GRANT DBSECADM TO informix;> CREATE TRUSTED CONTEXT tcx1
> USER user1
> ATTRIBUTES (ADDRESS â192.168.1.13â, ADDRESS âlaptop1â) ENABLE
> WITH USE FOR user1 WITHOUT AUTHENTICATION;
>
> When I connect using user1 account providing a password â all works fine.
> When I try to connect using random software with jdbc where connection
> string
> is
>
> âjdbc:informix-sqli://192.168.1.13:50005/sample1:INFORMIXSERVER=myinstance
> ;
> trusted_context=true;â
>
> it fails with 951 error on client side and 956 on the server.
>
> Can anyone tell me what I missed? Is it even possible to make it work using
> Trusted Context?
> I'd be grateful for any useful hints as there is very little information
> regarding this topic.Like
>
>
> ************************************************************
> *******************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...