Restricting Connection to Informixservers
Posted in 2009
Topics: General Discussion
Because of enhanced network security requirments, I have an informixserver for which I've configured a dbserveralias running onsocssl for users of developed applications which require access to the database, but strictly through the developed application. I'd like to restrict the unsecured informixserver so that only a designated group (by IP address or whatever) has access -- perhaps in a manner similar to how inetd (or maybe tcp wrappers?) controls daemons. This cannot be done by simple connection grants at database level since, like all web-related apps that use Informix, a universal connection account is used with object-level privileges effectively controlled from within the application's own security scheme. So, how can I achieve this level of access segregation? Running IDS 11.50 on HPUX 11.23
On 20 Nov, 15:54, "red_val...@yahoo.com" <red_val...@yahoo.com> wrote: > Because of enhanced network security requirments, I have an > informixserver for which I've configured a dbserveralias running > onsocssl for users of developed applications which require access to > the database, but strictly through the developed application. I'd > like to restrict the unsecured informixserver so that only a > designated group (by IP address or whatever) has access -- perhaps in > a manner similar to how inetd (or maybe tcp wrappers?) controls > daemons. This cannot be done by simple connection grants at database > level since, like all web-related apps that use Informix, a universal > connection account is used with object-level privileges effectively > controlled from within the application's own security scheme. > > So, how can I achieve this level of access segregation? > > Running IDS 11.50 on HPUX 11.23
Sorry to top post... If I understand your question... You use a single web app user id to connect all of your web application servers to the database. (Not a good idea, you may want to consider a single id per web app server.) But your problem is that anyone who knows the web app server id(s) and passwords can then connect their web app server so that their applications can then have access. You want to limit connections to a handful of servers. You can do this a couple of ways. 1) Segment your network so that your database listens on a separate network that only have app server machines connecting to it. 2) Implement a solution using PAM, which means you have to wrap your own authentication code (There are a couple of ideas that come to mind.) The simplest thing is to create an unique id for each app server and then control the passwords. Also segment your network so that your communication with the database occurs on a segment of the network that limited access to the outside world. (If you can't do this, can you hard code your routes on that interface so only those machines can talk to it.) Of course what do I know? GO BUCKEYES! SCREW BLUE! YES SPORTS FANS, ITS OSU vs MICHIGAN WEEKEND! -G > From: david@smooth1.co.uk > Subject: Re: Restricting Connection to Informixservers > Date: Fri, 20 Nov 2009 12:38:11 -0800 > To: informix-list@iiug.org > > On 20 Nov, 15:54, "red_val...@yahoo.com" <red_val...@yahoo.com> wrote: > > Because of enhanced network security requirments, I have an > > informixserver for which I've configured a dbserveralias running > > onsocssl for users of developed applications which require access to > > the database, but strictly through the developed application. I'd > > like to restrict the unsecured informixserver so that only a > > designated group (by IP address or whatever) has access -- perhaps in > > a manner similar to how inetd (or maybe tcp wrappers?) controls > > daemons. This cannot be done by simple connection grants at database > > level since, like all web-related apps that use Informix, a universal > > connection account is used with object-level privileges effectively > > controlled from within the application's own security scheme. > > > > So, how can I achieve this level of access segregation? > > > > Running IDS 11.50 on HPUX 11.23 > > >From within the application server. > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Hotmail: Trusted email with powerful SPAM protection. http://clk.atdmt.com/GBL/go/177141665/direct/01/
Related threads
- the longer you surf, the MORE $$$ you earn !!
- Store procedure
- emulation for Vt100
- extent size questions again ...