Encrypting onsoctcp / ODBC traffic
Posted in 2007
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Networking & sqlhosts Configuration
Good morning, Has anyone implemented encryption / secure communication at the SOCs level? I=B9m looking to secure traffic via onsoctcp to Informix 10.00.FC5. I assume that the SDK ODBC client will work with security encryption at the soc level. Any information, experience, or insight with this would be greatly appreciated. Sincerely, Jonathan Smaby ITS Dept Pomona College email: jonathan.smaby@pomona.edu ------------------------------------------------------------- This message has been scanned by Postini anti-virus software. =0D
Good evening to you too :o) You can use ssh tunneling to secure connection from client to server. HTH Hrvoje -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of ITS Sent: Thursday, December 13, 2007 8:41 PM To: ids@iiug.org Subject: Encrypting onsoctcp / ODBC traffic [10750] Good morning, Has anyone implemented encryption / secure communication at the SOCs level? I=B9m looking to secure traffic via onsoctcp to Informix 10.00.FC5. I assume that the SDK ODBC client will work with security encryption at the soc level. Any information, experience, or insight with this would be greatly appreciated. Sincerely, Jonathan Smaby ITS Dept Pomona College email: jonathan.smaby@pomona.edu ------------------------------------------------------------- This message has been scanned by Postini anti-virus software. =0D **************************************************************************** *** Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks Hvroje, Is that something that can be configured in the onconfig or sqlhosts file? If there documentation available, I would be grateful. Jonathan B. Smaby Administrative Information Systems Office Pomona College Email: jonathan.smaby@pomona.edu Tel. (909) 621-8506 -----Original Message----- > From: Hrvoje Zokovic <hzokovic.iiug@gmail.com> > Reply-To: <ids@iiug.org> > Date: Thu, 13 Dec 2007 15:12:21 -0500 (EST) > To: <ids@iiug.org> > Subject: RE: Encrypting onsoctcp / ODBC traffic [10751] > > Good evening to you too :o) > You can use ssh tunneling to secure connection from client to server. > HTH > Hrvoje > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of ITS > Sent: Thursday, December 13, 2007 8:41 PM > To: ids@iiug.org > Subject: Encrypting onsoctcp / ODBC traffic [10750] > > Good morning, > > Has anyone implemented encryption / secure communication at the SOCs level? > I=B9m looking to secure traffic via onsoctcp to Informix 10.00.FC5. I assume > that the SDK ODBC client will work with security encryption at the soc > level. Any information, experience, or insight with this would be greatly > appreciated. > > Sincerely, > > Jonathan Smaby > ITS Dept > Pomona College > email: jonathan.smaby@pomona.edu > > ------------------------------------------------------------- > This message has been scanned by Postini anti-virus software. > =0D > > **************************************************************************** > *** > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ****************************************************************************** > * > Forum Note: Use "Reply" to post a response in the discussion forum. ------------------------------------------------------------- This message has been scanned by Postini anti-virus software.
Hi, Ssh tunneling is independant of IDS. You can tunnel any network communication. IDS can use pam (Pluggable Authentication Module) which can be used to encrypt communication, also. Hrvoje -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Jonathan B. Smaby Sent: Thursday, December 13, 2007 9:20 PM To: ids@iiug.org Subject: Re: Encrypting onsoctcp / ODBC traffic [10752] Thanks Hvroje, Is that something that can be configured in the onconfig or sqlhosts file? If there documentation available, I would be grateful. Jonathan B. Smaby Administrative Information Systems Office Pomona College Email: jonathan.smaby@pomona.edu Tel. (909) 621-8506 -----Original Message----- > From: Hrvoje Zokovic <hzokovic.iiug@gmail.com> > Reply-To: <ids@iiug.org> > Date: Thu, 13 Dec 2007 15:12:21 -0500 (EST) > To: <ids@iiug.org> > Subject: RE: Encrypting onsoctcp / ODBC traffic [10751] > > Good evening to you too :o) > You can use ssh tunneling to secure connection from client to server. > HTH > Hrvoje > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > ITS > Sent: Thursday, December 13, 2007 8:41 PM > To: ids@iiug.org > Subject: Encrypting onsoctcp / ODBC traffic [10750] > > Good morning, > > Has anyone implemented encryption / secure communication at the SOCs level? > I=B9m looking to secure traffic via onsoctcp to Informix 10.00.FC5. I > assume that the SDK ODBC client will work with security encryption at > the soc level. Any information, experience, or insight with this would > be greatly appreciated. > > Sincerely, > > Jonathan Smaby > ITS Dept > Pomona College > email: jonathan.smaby@pomona.edu > > ------------------------------------------------------------- > This message has been scanned by Postini anti-virus software. > =0D > > ********************************************************************** > ****** > *** > Forum Note: Use "Reply" to post a response in the discussion forum. > > > **************************************************************************** ** > * > Forum Note: Use "Reply" to post a response in the discussion forum. ------------------------------------------------------------- This message has been scanned by Postini anti-virus software. **************************************************************************** *** Forum Note: Use "Reply" to post a response in the discussion forum.
On Dec 13, 2007 12:51 PM, Hrvoje Zokovic <hzokovic.iiug@gmail.com> wrote: > Hi, > Ssh tunneling is independant of IDS. You can tunnel any network > communication. That is correct. > IDS can use pam (Pluggable Authentication Module) That is correct, too. > which can be used to encrypt communication, also. That is not correct. PAM is for authentication. You are probably thinking of the ENCCSM module, which is configured in part via the sqlhosts file (and PAM is also configured that way). That does handle encrypted communications between client and server. There is also a SPWDCSM that encrypts just the password as it is sent to the server. As to the original question, I believe ODBC can be encrypted too, but it is configured via the DSN rather than the sqlhosts file per se. This is extracted from a slide I used at the IIUG (IDUG) conference in May 2007: ODBC on Windows * Set option in DSN registry ODBC on Unix * Set option in odbc.ini file JDBC * Set in connection string * Uses Java Cryptography Extension (JCE) See: Informix Information Center at * http://publib.boulder.ibm.com/infocenter/idshelp/v10/index.jsp * Search: "jdbc encryption" or "odbc password". > Hrvoje > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Jonathan B. Smaby > Sent: Thursday, December 13, 2007 9:20 PM > To: ids@iiug.org > Subject: Re: Encrypting onsoctcp / ODBC traffic [10752] > > Thanks Hvroje, > > Is that something that can be configured in the onconfig or sqlhosts file? > If there documentation available, I would be grateful. > > Jonathan B. Smaby > Administrative Information Systems Office Pomona College > Email: jonathan.smaby@pomona.edu > Tel. (909) 621-8506 > > -----Original Message----- > > > From: Hrvoje Zokovic <hzokovic.iiug@gmail.com> > > Reply-To: <ids@iiug.org> > > Date: Thu, 13 Dec 2007 15:12:21 -0500 (EST) > > To: <ids@iiug.org> > > Subject: RE: Encrypting onsoctcp / ODBC traffic [10751] > > > > Good evening to you too :o) > > You can use ssh tunneling to secure connection from client to server. > > HTH > > Hrvoje > > > > -----Original Message----- > > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > > ITS > > Sent: Thursday, December 13, 2007 8:41 PM > > To: ids@iiug.org > > Subject: Encrypting onsoctcp / ODBC traffic [10750] > > > > Good morning, > > > > Has anyone implemented encryption / secure communication at the SOCs > level? > > I=B9m looking to secure traffic via onsoctcp to Informix 10.00.FC5. I > > assume that the SDK ODBC client will work with security encryption at > > the soc level. Any information, experience, or insight with this would > > be greatly appreciated. > > > > Sincerely, > > > > Jonathan Smaby > > ITS Dept > > Pomona College > > email: jonathan.smaby@pomona.edu > > > > ------------------------------------------------------------- > > This message has been scanned by Postini anti-virus software. > > =0D > > > > ********************************************************************** > > ****** > > *** > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > > **************************************************************************** > ** > > * > > Forum Note: Use "Reply" to post a response in the discussion forum. > > ------------------------------------------------------------- > This message has been scanned by Postini anti-virus software. > > **************************************************************************** > *** > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2007.0914 -- http://dbi.perl.org/ NB: Please do not use this email for correspondence. I don't necessarily read it every week, even.