SSO (Kerberos) on Informix / ODBC
Posted in 2019
Hi all, Using Kerberos 5 authentication on AIX for standard domain user logon is working fine already. Now I am going to implement Kerberos for Informix to use remote ODBC connection. This causes troubles. Some details on the current system and configuration: OS: AIX 7.1 Informix: IDS Version 12.10FC8W Accounts in Active Directory: - Service account for host "host123" (with non-changing password). - Service account for instance "inst123" (with a non-changing password). - Service account for user "informix" (with non-changing-password). - Host resource for the server "host123". keytab files: available for hostname (host123) and instance (inst123), generated on domain controller using ktpass command. Both keytab files have been merged to /etc/krb5/krb5.keytab using ktutil: 1 3 host/host123.euro.domain.net@euro.domain.net 2 6 inst123/host123.euro.domain.net@euro.domain.net /etc/krb5/krb5.conf: [libdefaults] ticket_lifetime = 365d 0h 0m 0s default_keytab_name = FILE:/etc/krb5/krb5.keytab default_realm = EURO.DOMAIN.NET default_tkt_enctypes = aes128-cts-hmac-sha1-96 default_tgs_enctypes = aes128-cts-hmac-sha1-96 [realms] ... is fine! [domain_realm] ... is fine! kinit is okay for any domain user, but seems not for instance/informix user. # root@host123:/usr/krb5/sbin> kinit informix Password for informix@EURO.DOMAIN.NET: <********> com.ibm.security.krb5.KrbException, status code: 14 message: KDC has no support for encryption type # informix@host123:/informix121_02> kinit Unable to obtain initial credentials. Status 0x96c73a0e - KDC has no support for encryption type. # informix@host123:/etc/krb5> kinit inst123 Password for inst123@EURO.DOMAIN.NET: <********> Done! New ticket is stored in cache file /home/infhome/krb5cc_informix I tried to generate keytab file with different enctypes, e.g. AES128 SHA1 as well leave out the crypto parameter: # ktpass -out inst123.keytab -mapUser inst123 -mapOP set -pass XXXXX -crypto aes128-sha1 -pType KRB5_NT_PRINCIPAL # ktpass -out inst123.keytab -mapUser inst123 -mapOP set -pass XXXXX -pType KRB5_NT_PRINCIPAL Kerberos authentification on AIX is working. But using an ODBC client on a remote computer, each attempt to connect ends up in this error in IDS message log (irrespctive of informix user or any other database user): 13:35:33 listener-thread@soc_be.c:3119: err = -14565: oserr = 0: errstr = : CSS: error reading data. 13:35:33 listener-thread@soc_be.c:3400: err = -25582: oserr = 0: errstr = : Network connection is broken. What else can I check or re-configure? I am clueless what may cause this issue. I really appreciate any help... Many thanks in advance!