Connect informix using Active Directory account
Posted in 2017
User attempted to configure Informix to authenticate using Active Directory accounts via PAM instead of local Linux accounts. Initial suggestion was to add CHECKALLDOMAINSFORUSER to ONCONFIG, but this only applies to Windows servers. The core issue identified: PAM authentication doesn't automatically satisfy Informix's requirement that users exist locally (getpwnam() must work). Users need home directories, UIDs, and GIDs.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing, Networking & sqlhosts Configuration
Guys , What I am trying to do is to use Active directory accounts instead of local Linux accounts on server , to have "centrally managed" account. SQLHOSTS: ********* pam_1210 onsoctcp bsqal10ifxin102.dcb.diginsite.net 12741 s=4, pam_serv=(ids_pam_service), pamauth(password) /etc/pam.d/ids_pam_service: **************************** auth required /lib64/security/pam_sss.so account required /lib64/security/pam_permit.so However I am not able to connect. Any help will be appreciated Thanks
Did you alter the ONCONFIG file to pass the authentication out to the domain? I believe you still need to add CHECKALLDOMAINSFORUSER 1 to the ONCONFIG in order to have IDS pass the user authentication out to the Windows domain controllers. Best regards, Martin M. Graney Queues Enforth Development, Inc. -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of J SHA Sent: Monday, May 1, 2017 11:41 AM To: ids@iiug.org Subject: Connect informix using Active Directory account [39064] Guys , What I am trying to do is to use Active directory accounts instead of local Linux accounts on server , to have "centrally managed" account. SQLHOSTS: ********* pam_1210 onsoctcp bsqal10ifxin102.dcb.diginsite.net 12741 s=4, pam_serv=(ids_pam_service), pamauth(password) /etc/pam.d/ids_pam_service: **************************** auth required /lib64/security/pam_sss.so account required /lib64/security/pam_permit.so However I am not able to connect. Any help will be appreciated Thanks ************************************************************************** ***** Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks Martin, Yes i did added this parameter in onconfig file, still i am not able to connect. also i think SSSD is being used in my environment
J - Are you getting any incorrect username or password entries in the IDS message log or is it not getting that far? I had SAMBA set up in my support and development environment for our LINUX and UNIX systems and had the domain pass-through authentication working to my Windows domain controllers some time ago but we have since moved to an all Windows shop. Good luck! Best regards, Martin M. Graney Queues Enforth Development, Inc. 92 Montvale Ave Suite 4350 Stoneham, MA 02180-3647 781-870-1131 This electronic message contains information which may be privileged, confidential, or otherwise protected from disclosure. The information contained herein is intended for the addressee or recipient only. If you are not the addressee, or not the intended recipient, any disclosure, copying, distribution, or use of the contents of this message (including any attachments) is prohibited. If you have received this electronic message in error, please notify the sender immediately and destroy the original message and all copies. (Queues Enforth Development, Inc.) -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of J SHA Sent: Tuesday, May 2, 2017 9:52 AM To: ids@iiug.org Subject: Re: RE: Connect informix using Active Directory ac [39083] Thanks Martin, Yes i did added this parameter in onconfig file, still i am not able to connect. also i think SSSD is being used in my environment ************************************************************************** ***** Forum Note: Use "Reply" to post a response in the discussion forum.
That parameter only applies to Windows database servers, which apparently is not the case here. pam_sss seems to be a pam module to interface with System Security Services daemon. I never used this personally, but I imagine it doesn't transparently make the call to "getpwnan()" to work. If you have the skills to create a small C program that calls this system call with a user of AD, it would be interestingly to see if it returns the required results. I'd bet it doesn't. And if it doesn't, by default, it will not work with Informix. That's because although PAM allows authentication on remote systems, it doesn't by itself remove the requirement that the user ID must be known by the local system. And this "must be known" translates simply into having that call work. As a side, but important note, Informix requires the user to have a home directory, a user and group id.... This is because Informix may need to execute processes with the user identity (SYSTEM SPL call), or create files with the user identity (explain files and/or SPL debug files). This is a simple and annoying fact that is never taken into account when people try to configure external authentication, and that in many cases translates into "it doesn't work... Informix suks!" Now... assuming the system call doesn't work, what you'd need is to setup mapped users. I'd have a bit of trouble trying to explain the configuration of mapped, users, but you could try to search the manuals... and come back with more specific doubts. Basically the "mapped users" feature means that we can create a mapping between one or more AD users with one or more "linux local users". So any activity that requires a local user ID, triggered by an AD user would use the mapped local user. We can map all users to a single user or several users to a single user or a one to one map. Also note that if you're using PAM and you're getting a user does not exist it sounds a bit strange. Any issue with PAM authentication translates into a single error (1809). This is one of the nasty things of using PAM, but that's caused by the PAM API... You'd need to check the PAM module logs (if any) to find out more. I'm not 100% sure if when the PAM part works and the getpwnam() call fails if that changes the error... it's possible. In any case, if you're testing PAM, you NEED to do it remotely. Local connections are treated differently.... Regards. On Mon, May 1, 2017 at 6:51 PM, Martin Graney <mgraney@qed.com> wrote: > Did you alter the ONCONFIG file to pass the authentication out to the > domain? I believe you still need to add CHECKALLDOMAINSFORUSER 1 to > the ONCONFIG in order to have IDS pass the user authentication out to the > Windows domain controllers. > > Best regards, > Martin M. Graney > Queues Enforth Development, Inc. > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of J > SHA > Sent: Monday, May 1, 2017 11:41 AM > To: ids@iiug.org > Subject: Connect informix using Active Directory account [39064] > > Guys , > > What I am trying to do is to use Active directory accounts instead of > local Linux accounts on server , to have "centrally managed" account. > > SQLHOSTS: > ********* > > pam_1210 onsoctcp bsqal10ifxin102.dcb.diginsite.net 12741 s=4, > pam_serv=(ids_pam_service), pamauth(password) > > /etc/pam.d/ids_pam_service: > **************************** > > auth required /lib64/security/pam_sss.so > > account required /lib64/security/pam_permit.so > > However I am not able to connect. > > Any help will be appreciated > > Thanks > > ************************************************************************** > ***** > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --94eb2c05f890a965bf054e8c2860
We are using sssd with ldap here , not sure if my sqlhosts entries are correct.