Informix Authentication and ODBC
Posted in 1999
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Third-Party Tools & Monitoring
Greetings, In the ten years I've been using Informix, I've never heard a good solution of how to address the problem of PC-based users, connecting with ODBC, authenticating against UNIX-based Informix. The problem of course is that Informix--grounded in its glory days of Unix/Unix client-server--authenticates against UNIX (and not its own database, like, oh, Oracle, Sybase, etc). In a PC-client environment, chances are very good your users do not have UNIX accounts. Sure, we can create stubbed-out UNIX accounts for them, and then configure the ODBC drivers to prompt for their login and passwords at run-time. But how do those users change their passwords? ODBC doesn't have a "password expired, please change password" message that the driver can respond to. Either you authenticate, or you don't. One hack solution is to provide the user with a desktop procedure and limited shell access that instructs him to telnet to the UNIX system and change his password during aging, compromise, etc. This works, and it stinks, and it's ugly, and I can't believe after all these years, there isn't something better. So educate me, please, anyone who has successfully dealt with this. No solution is too bold. Third-party software, custom ODBC-driver--these are all acceptable, if such things exist or can be done. I understand that some of you might be tempted to say the BOLDEST solution is not to use ODBC. I couldn't agree more. But some decisions are not mine to make, and that's one of them--unless, someone can offer me an ODBC-alternative, that allows rapid development of two-tier clients in VB and other leading GUI RAD environments, that does magically solve this problem. Also, how will this work in Informix 9.2 (or IDS-2000 or whatever the new name)? I've hear rumors that this version will provide its own authentication mechanism (just like, oh, Oracle, Sybase, etc). That's great, but does it solve the problem of giving the user a PC-based mechanism for changing his password? Thanks for any help any of you can provide. Trebor Fenstermaker BTG Inc Fairfax VA
"Trebor C. Fenstermaker" wrote: > > Greetings, > > In the ten years I've been using Informix, I've never heard a good solution > of how to address the problem of PC-based users, connecting with ODBC, > authenticating against UNIX-based Informix. > > The problem of course is that Informix--grounded in its glory days of > Unix/Unix client-server--authenticates against UNIX (and not its own > database, like, oh, Oracle, Sybase, etc). In a PC-client environment, > chances are very good your users do not have UNIX accounts. > > Sure, we can create stubbed-out UNIX accounts for them, and then configure > the ODBC drivers to prompt for their login and passwords at run-time. But > how do those users change their passwords? ODBC doesn't have a "password > expired, please change password" message that the driver can respond to. > Either you authenticate, or you don't. > > One hack solution is to provide the user with a desktop procedure and > limited shell access that instructs him to telnet to the UNIX system and > change his password during aging, compromise, etc. This works, and it > stinks, and it's ugly, and I can't believe after all these years, there > isn't something better. > > So educate me, please, anyone who has successfully dealt with this. No > solution is too bold. Third-party software, custom ODBC-driver--these are > all acceptable, if such things exist or can be done. > > I understand that some of you might be tempted to say the BOLDEST solution > is not to use ODBC. I couldn't agree more. But some decisions are not mine > to make, and that's one of them--unless, someone can offer me an > ODBC-alternative, that allows rapid development of two-tier clients in VB > and other leading GUI RAD environments, that does magically solve this > problem. > > Also, how will this work in Informix 9.2 (or IDS-2000 or whatever the new > name)? I've hear rumors that this version will provide its own > authentication mechanism (just like, oh, Oracle, Sybase, etc). That's > great, but does it solve the problem of giving the user a PC-based mechanism > for changing his password? > > Thanks for any help any of you can provide. > > Trebor Fenstermaker > BTG Inc > Fairfax VA a) Our ODBC driver will cope with password expiry: it's not very neat and you have to do a bit of work to get it going, but that's ODBC & password expiry for you! See: TA # 110002 at www.sco.com/ta How can I make SQL-Retriever respond to UNIX password expiry or run over the rlogin TCP service? We also have additional security on top of the ODBC spec; see: http://www.sco.com/support/ciservices/sqlr/docs/secman.html SCO SQL-Retriever. Take a look at http://www.sco.com/vision/products/sqlretriever/ for more information and a downloadable eval. Allan Gould SCO CID Support, Leeds, UK (allang at sco dot com) (Please remove anti-spam measures if replying)