Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver.
Posted in 2009
Topics: Connectivity: ODBC / JDBC / .NET, Connectivity: ESQL/C, 4GL & Embedded SQL, Security, Permissions & Auditing, Java & JDBC Development
Ian Michael Gumby wrote: > I've given you a handful of links that were pretty easy to find via > google as to why you don't want to use .rhosts and why you have to be > *VERY* *VERY* *CAREFUL* when using /ect/hosts.equiv. With, or without the "r" services running? > Now, I have't touched 4GL since '96. Really I stopped programming in 4GL > since '93 but I still played with it . 4GL wasn't really designed as a > 'client/server' paradigm. That was an after thought. 4GL was mainly used > on 'green screen' terminals that were connected to the server via a > serial connection. (You do remember those, right?) > > When it went 'client/server', the internet was relatively young and > security wasn't the first thing anyone thought about. After all, you'd > be client server on your own domain and behind a nice set of fire walls > with a DMZ zone and your app wouldn't be out beyond the interior firewall. > > I would have believed that 4GL would have grown up along the way. But > what do I know? I switched to Objective-C / Java work for client server > and laughed at Informix's 'New Error' because those who wrote it didn't > know jack about language theory. 4GL is perfectly able to make the usual user/password connection. I would believe this to be a usual method for client/server. I personally haven't done it (yet), but it should be able to connect to a DBSERVERALIAS configured with PAM, which makes it very flexible. So, I don't really understand what is the problem with 4GL... But hey... ;) > > Yet I digress. > > The point is that if you use a (+) you've now set up your machine to > treat anyone within your subnet as a 'trusted' host. So if I were a > 'disgruntled' employee, or an industrial spy, I'd just bring in a small > USB stick pre-loaded with Linux. I would then log in as root on my > machine and now I can connect as root on to your server. Do I need to > go on, or do you get the drift? You'd only login as root if you put a + on the ~root/.rhosts. On the /etc/hosts.equiv is does not allow root access. You should check the man for ruserok: "The ruserok() and iuserok() functions take a remote host's name or IP address, as returned by gethostbyname(), two user names, and a flag indicating whether the local user's name is that of the super-user. Then, if the user is not the super-user, it checks the ROOTDIR/etc/hosts.equiv file. If that lookup is not done, or is unsuccessful, the .rhosts file in the local user's home directory is checked to see if the request for service is allowed. " And all this of course, and again, only makes sense if you have the "r" services running... And I don't know why someone with security concerns would have these services running... Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
On Apr 15, 6:06 pm, Fernando Nunes <domusonl...@gmail.com> wrote: > 4GL is perfectly able to make the usual user/password connection. > I would believe this to be a usual method for client/server. > I personally haven't done it (yet), but it should be able to connect to a > DBSERVERALIAS configured with PAM, which makes it very flexible. > > So, I don't really understand what is the problem with 4GL... > But hey... ;) > > > There are a lot of problems with 4GL. Its a legacy application that hasn't been really able to make the paradigm shift from the green screen to the multiple windows client. Unfortunately / Fortunately, you have IDEs that you can do a drag and drop and create Swing apps fairly quickly. If you don't like Java or are on a Mac, you can use Interface Builder (Objective-C) that was created by NeXT. There you again have the ability to create drag and drop of visual elements and then using object delegation, tie the screen objects to either controller or business objects. Now I'm dating myself because the java spring framework uses a different term than delegation and my memory is drawing a blank right now... ;-) If you want to look at web based apps, then you can look at Java / JSTL / add your favorite AJAX library like dojo as a way to build apps... But to your point, yes PAM is a bit more interesting. With PAM you can potentially do a lot of things in terms of security and flexibility that didn't exist back in the days of Bill Joy. (.rhosts and /etc/ hosts.equiv) The nice thing about PAM is that it is controlled by the sysadmin and has a lot more controls around it. The bad thing about PAM is the lack of adequate documentation. Especially when it comes to using it with Informix. I think things are better than they were 2 years ago when I started looking at PAM and IDS 10.0 (or was it 3 years ago? ) And yes, this is why I get peeved about people who still feel that they have to use /etc/hosts.equiv or .rhosts. You don't. Don't get me wrong. If you've got a second nic card and a separate subnet connecting your database servers and you want to make it easy to connect two servers for HDR, then by all means use /etc/hosts.equiv to connect those two machines on the private subnet. But that's the limit.
On Thu, Apr 16, 2009 at 2:29 PM, Ian Michael Gumby <im_gumby@hotmail.com>wrote: > On Apr 15, 6:06 pm, Fernando Nunes <domusonl...@gmail.com> wrote: > > > 4GL is perfectly able to make the usual user/password connection. > > I would believe this to be a usual method for client/server. > > I personally haven't done it (yet), but it should be able to connect to a > > DBSERVERALIAS configured with PAM, which makes it very flexible. > > > > So, I don't really understand what is the problem with 4GL... > > But hey... ;) > > > > > > > There are a lot of problems with 4GL. Its a legacy application that > hasn't been really able to make the paradigm shift from the green > screen to the multiple windows client. Unfortunately / Fortunately, > you have IDEs that you can do a drag and drop and create Swing apps > fairly quickly. If you don't like Java or are on a Mac, you can use > Interface Builder (Objective-C) that was created by NeXT. There you > again have the ability to create drag and drop of visual elements and > then using object delegation, tie the screen objects to either > controller or business objects. Now I'm dating myself because the java > spring framework uses a different term than delegation and my memory > is drawing a blank right now... ;-) > > If you want to look at web based apps, then you can look at Java / > JSTL / add your favorite AJAX library like dojo as a way to build > apps... > > But to your point, yes PAM is a bit more interesting. With PAM you can > potentially do a lot of things in terms of security and flexibility > that didn't exist back in the days of Bill Joy. (.rhosts and /etc/ > hosts.equiv) > > The nice thing about PAM is that it is controlled by the sysadmin and > has a lot more controls around it. The bad thing about PAM is the lack > of adequate documentation. Especially when it comes to using it with > Informix. I think things are better than they were 2 years ago when I > started looking at PAM and IDS 10.0 (or was it 3 years ago? ) > > And yes, this is why I get peeved about people who still feel that > they have to use /etc/hosts.equiv or .rhosts. You don't. > Don't get me wrong. If you've got a second nic card and a separate > subnet connecting your database servers and you want to make it easy > to connect two servers for HDR, then by all means use /etc/hosts.equiv > to connect those two machines on the private subnet. But that's the > limit. > _______________________________________________ > Informix-list mailing list > Informix-list@iiug.org > http://www.iiug.org/mailman/listinfo/informix-list > I really enjoy some of your posts as food for thought, but your capacity of dribbling the logic is terrible. The only person as bad as you has not come here for a long time... First, all your rhetoric about 4GL limitations completely ignores the focal point: you can use user and password with 4GL. It's perfectly documented and easy to do. I won't dispute most applications don't do it, but that is not 4GL fault. Obviously 4GL if far from being "modern", but that's not the point. As for the PAM documentation I believe now there is some good stuff, but I admit I'm suspicious to make an opinion on that ;) If you have doubts, feel free to post them here. I'll do my best to help and it would be a good pretext to update the article. And again, you miss completely the point with you example on HDR. The only situation where you can configure Informix trusted relations without using the /etc/hosts.equiv or ~.rhosts is precisely when you're establishing the HDR trusts. Please check the "s=6" option in SQL hosts... You have a lot of experience and we all know a lot about everything. But are you sure you've been keeping up to date with Informix in the last years? Your posts reveal you haven't, which is up to you, but it does look bad on your posts, and worse, can induce some people in error... This is the main reason why I keep answering you... You're too dangerous in spreading wrong technical information about IDS... Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
All:
Back to the origin of this thread and the promise that I would report
back my findings after hours of frustration, I finally found the
solution to "ssh" port forwarding on my Debian development server and
the SQuirreL SQL client connection. Listed below is configuration I
had to use with "onconfig" and "sqlhosts". It seems that Informix
passes a the exact listing for the hostname and translation is not an
option.
SERVER:
$> vi onconfig
#======================================================================
#DBSERVERALIAS PROTOCOL HOSTNAME
SERVICE
#======================================================================
vm_ids_115 onsoctcp vm-debian-5 15260
vm_ids_115_tcp onsoctcp localhost 15260
vm_ids_115 drsoctcp vm-debian-5 15261
vm_ids_115 onipcshm vm-debian-5 dummyvm_ids_115 onipcstr vm-debian-5
dummy
$> vi sqlhosts
DBSERVERALIASES vm_ids_115,vm_ids_115_tcp
CLIENT:
telnet localhost 1526
Thank you again for all the great suggestions.
Christopher
Fernando Nunes wrote:
> On Thu, Apr 16, 2009 at 2:29 PM, Ian Michael Gumby <im_gumby@hotmail.com>wrote:
>
> > On Apr 15, 6:06 pm, Fernando Nunes <domusonl...@gmail.com> wrote:
> >
> > > 4GL is perfectly able to make the usual user/password connection.
> > > I would believe this to be a usual method for client/server.
> > > I personally haven't done it (yet), but it should be able to connect to a
> > > DBSERVERALIAS configured with PAM, which makes it very flexible.
> > >
> > > So, I don't really understand what is the problem with 4GL...
> > > But hey... ;)
> > >
> > >
> > >
> > There are a lot of problems with 4GL. Its a legacy application that
> > hasn't been really able to make the paradigm shift from the green
> > screen to the multiple windows client. Unfortunately / Fortunately,
> > you have IDEs that you can do a drag and drop and create Swing apps
> > fairly quickly. If you don't like Java or are on a Mac, you can use
> > Interface Builder (Objective-C) that was created by NeXT. There you
> > again have the ability to create drag and drop of visual elements and
> > then using object delegation, tie the screen objects to either
> > controller or business objects. Now I'm dating myself because the java
> > spring framework uses a different term than delegation and my memory
> > is drawing a blank right now... ;-)
> >
> > If you want to look at web based apps, then you can look at Java /
> > JSTL / add your favorite AJAX library like dojo as a way to build
> > apps...
> >
> > But to your point, yes PAM is a bit more interesting. With PAM you can
> > potentially do a lot of things in terms of security and flexibility
> > that didn't exist back in the days of Bill Joy. (.rhosts and /etc/
> > hosts.equiv)
> >
> > The nice thing about PAM is that it is controlled by the sysadmin and
> > has a lot more controls around it. The bad thing about PAM is the lack
> > of adequate documentation. Especially when it comes to using it with
> > Informix. I think things are better than they were 2 years ago when I
> > started looking at PAM and IDS 10.0 (or was it 3 years ago? )
> >
> > And yes, this is why I get peeved about people who still feel that
> > they have to use /etc/hosts.equiv or .rhosts. You don't.
> > Don't get me wrong. If you've got a second nic card and a separate
> > subnet connecting your database servers and you want to make it easy
> > to connect two servers for HDR, then by all means use /etc/hosts.equiv
> > to connect those two machines on the private subnet. But that's the
> > limit.
> > _______________________________________________
> > Informix-list mailing list
> > Informix-list@iiug.org
> > http://www.iiug.org/mailman/listinfo/informix-list
> >
>
>
> I really enjoy some of your posts as food for thought, but your capacity of
> dribbling the logic is terrible. The only person as bad as you has not come
> here for a long time...
> First, all your rhetoric about 4GL limitations completely ignores the focal
> point: you can use user and password with 4GL. It's perfectly documented and
> easy to do. I won't dispute most applications don't do it, but that is not
> 4GL fault. Obviously 4GL if far from being "modern", but that's not the
> point.
>
> As for the PAM documentation I believe now there is some good stuff, but I
> admit I'm suspicious to make an opinion on that ;)
> If you have doubts, feel free to post them here. I'll do my best to help and
> it would be a good pretext to update the article.
>
> And again, you miss completely the point with you example on HDR. The only
> situation where you can configure Informix trusted relations without using
> the /etc/hosts.equiv or ~.rhosts is precisely when you're establishing the
> HDR trusts. Please check the "s=6" option in SQL hosts...
> You have a lot of experience and we all know a lot about everything. But are
> you sure you've been keeping up to date with Informix in the last years?
> Your posts reveal you haven't, which is up to you, but it does look bad on
> your posts, and worse, can induce some people in error...
> This is the main reason why I keep answering you... You're too dangerous in
> spreading wrong technical information about IDS...
>
> Regards.
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...