Re: Is my brain dead or what....
Posted in 1996
In article <3277923A.4458@segel.com>, Mike Segel <mikey@segel.com> writes >OK, > >I have been thinking about this for a couple of days in between my >normal daily >tasks. I need to know if I am missing something or is Informix really >screwed up >when it comes to client/server architecture. > >Assumptions: > 1) I don't have a spell checker, and most normal viewers will skip over > this little detail. > Yes > 2) The scope of my ranting and ravings will be limited to I-NET/ODBC >and > Informix's 7.1x on UNIX > OK >Background: > A large client has 1000+ PCs in its corporate headquarters running > windows 3.11 (Among other things). It is mainly a NOVEL network, read > IPX. Their goal is to have several small VB (Visual Basic) type apps > run against some Informix databases. > >Problem: > 1) To use ODBC connectivity, do we need to IP on each PC ? Informix Online 7.1 on UNIX does support SPX/IPX on some platforms. Depends upon the platform. Which typ of UNIX?. > Putting IP on the PC's is not an easy task. Informix does not > work well with DHCP. and think about trying to manage > 1000 additional nodes in your DNS and network! > > 2) Informix On Unix bases their authentication on UNIX. > Makes sense. Why introduce more authenication scheme. The more code for security the more change of bugs. Security should be handled in one place - the Operating System. > This is a problem in that Informix relies on /etc/hosts and > /etc/hosts.equiv to manage all the PC's connection. [Skip .rhosts > and .netrc files, You don't want to risk the wrath of captain > safety. ;-] > Some users hgave talked about using DNS/MIS - talk to Informix Tech. Support. > The problem occurs in that I now have to manage a database on all the > pc's, their users, and what server applications that they can connect >to. > > Since Informix gets its user authentication from the user_id, and >passwd, > I have two choices: > 1) create a unique user id for all users Each user should have a unique user id - basic UNIX security. > 2) create a set of authentication routines and maintain a > user_id / passwd table scheme within Informix. > When using /etc/hosts.equiv, I can use the + sign to allow any user > from that PC to connect, however, this too can be considered a security > risk. > >Solutions: > 1) If I am not braindead, then Informix needs to get their act together > so that we can develop large scale client/server applications. Talk to them - I belive they already have their act together. > 2) switch to web based technologies and use either Web objects or > Netscape to handle security and front end processing. You still have to secure things at the OS level. > 3) Drink until I have to look up to see the curb in front of the > local pub. > >Now #3 does sound appealing. [Right Tom?], but alas, being an old man, I >can't >continue to abuse my body in that way. So, what I am doing wrong? > >-Uncle Mikey. -- David Williams