Informix & implicit PAM results in "Server rejecte
Posted in 2016
Topics: Security, Permissions & Auditing
I have PAM auth configured on a new Informix instance; implicit, not
challenge. I see PAM auth **succeed** via /var/log/secure -
oninit: pam_krb5[12289]: TGT verified using key for
'host/argus.XXXXXX.XXX@XXXXXX.XXX'
oninit: pam_krb5[12289]: got result 0 (Success)
oninit: pam_krb5[12366]: no need to create "/tmp"
oninit: pam_krb5[12366]: created ccache "FILE:/tmp/krb5cc_437_1H3gPE"
oninit: pam_krb5[12366]: created ccache 'FILE:/tmp/krb5cc_437_1H3gPE'
for 'adam'
oninit: pam_krb5[12366]: krb5_kuserok() says "true" for ("
adam@XXXXXX.XXX","adam")
oninit: pam_krb5[12366]: destroyed ccache
"FILE:/tmp/krb5cc_437_1H3gPE"
oninit: pam_krb5[12289]: 'adam@XXXXXX.XXX' passes .k5login check for
'adam'
oninit: pam_krb5[12289]: authentication succeeds for 'adam' (
adam@XXXXXX.XXX)
oninit: pam_krb5[12289]: pam_authenticate returning 0 (Success)
- but the connection is still refused by the server.
08004: Server rejected the connection
If I pass an incorrect password, or non-existent username, I see
different [and appropriate] messages in /var/log/secure
Is there anything more I can do to diagnose authentication/connection
to the server?
--
Adam Tauno Williams <mailto:awilliam@whitemice.org> GPG D95ED383
Systems Administrator, Python Developer, LPI / NCLA
I don't have enough information to provide much help.
Thisngs that would help:
1- Your PAM configuration details. You mention "implicit, not challenge,
but the options are "challenge" or "password".
2- Does "adam" exist as an OS user?
3- What is the error? I assume 1809, but please confirm
Even then, and because apparently you're using Kerberos, I may not be able
to help... as I never actually did any real work with kerberos, but let's
start with the above...
Regards.
On Thu, Jul 7, 2016 at 10:02 PM, Adam Tauno Williams <
awilliam@whitemiceconsulting.com> wrote:
> I have PAM auth configured on a new Informix instance; implicit, not
> challenge. I see PAM auth **succeed** via /var/log/secure -
>
> oninit: pam_krb5[12289]: TGT verified using key for
> 'host/argus.XXXXXX.XXX@XXXXXX.XXX'
> oninit: pam_krb5[12289]: got result 0 (Success)
> oninit: pam_krb5[12366]: no need to create "/tmp"
> oninit: pam_krb5[12366]: created ccache "FILE:/tmp/krb5cc_437_1H3gPE"
> oninit: pam_krb5[12366]: created ccache 'FILE:/tmp/krb5cc_437_1H3gPE'
> for 'adam'
> oninit: pam_krb5[12366]: krb5_kuserok() says "true" for ("
> adam@XXXXXX.XXX","adam")
> oninit: pam_krb5[12366]: destroyed ccache
> "FILE:/tmp/krb5cc_437_1H3gPE"
> oninit: pam_krb5[12289]: 'adam@XXXXXX.XXX' passes .k5login check for
> 'adam'
> oninit: pam_krb5[12289]: authentication succeeds for 'adam' (
> adam@XXXXXX.XXX)
> oninit: pam_krb5[12289]: pam_authenticate returning 0 (Success)
>
> - but the connection is still refused by the server.
>
> 08004: Server rejected the connection>
> If I pass an incorrect password, or non-existent username, I see
> different [and appropriate] messages in /var/log/secure
>
> Is there anything more I can do to diagnose authentication/connection
> to the server?
>
> --
> Adam Tauno Williams <mailto:awilliam@whitemice.org> GPG D95ED383
> Systems Administrator, Python Developer, LPI / NCLA
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--001a1145e04078b78805371fb2f6
On Fri, 2016-07-08 at 09:22 -0400, Fernando Nunes wrote:
> I don't have enough information to provide much help.
> Thisngs that would help:
> 1- Your PAM configuration details. You mention "implicit, not
> challenge, but the options are "challenge" or "password".
[root@argus ~]# cat /opt/informix/etc/sqlhosts
BARNET onsoctcp 172.31.5.23 online
s=4,pam_serv=(informix),pamauth=(password)
> 2- Does "adam" exist as an OS user?
[root@argus ~]# id adam
uid=437(adam) gid=230(cis)
groups=230(cis),201(actng),1015(cs),1001(internet),2074(web_dev),1999(D
omain
Admins),221(service),100(users),1237(horde),1499(beta),3000006(wpa_morm
ail),1240(mvp_qc),19(floppy),249(hilo_editors),508(bie_group),260(parts
qc),3000005(Enterprise Admins),1007(Print
Operators),1115(backup),1134(vnc)
> 3- What is the error? I assume 1809, but please confirm
"08004: Server rejected the connection"
> Even then, and because apparently you're using Kerberos, I may not be
> able to help... as I never actually did any real work with kerberos,
> but let's start with the above...
As can be seen in the log - the authentication suceeds. So there is
not an error at the level of Kerberos.
> On Thu, Jul 7, 2016 at 10:02 PM, Adam Tauno Williams <
> awilliam@whitemiceconsulting.com> wrote:
> > I have PAM auth configured on a new Informix instance; implicit,
> > not challenge. I see PAM auth **succeed** via /var/log/secure -
> > oninit: pam_krb5[12289]: TGT verified using key for
> > 'host/argus.XXXXXX.XXX@XXXXXX.XXX'
> > oninit: pam_krb5[12289]: got result 0 (Success)
> > oninit: pam_krb5[12366]: no need to create "/tmp"
> > oninit: pam_krb5[12366]: created ccache
> > "FILE:/tmp/krb5cc_437_1H3gPE"
> > oninit: pam_krb5[12366]: created ccache
> > 'FILE:/tmp/krb5cc_437_1H3gPE'
> > for 'adam'
> > oninit: pam_krb5[12366]: krb5_kuserok() says "true" for ("
> > adam@XXXXXX.XXX","adam")
> > oninit: pam_krb5[12366]: destroyed ccache
> > "FILE:/tmp/krb5cc_437_1H3gPE"
> > oninit: pam_krb5[12289]: 'adam@XXXXXX.XXX' passes .k5login check
> > for 'adam' oninit: pam_krb5[12289]: authentication succeeds for
> > 'adam' ( adam@XXXXXX.XXX) oninit: pam_krb5[12289]: pam_authenticate
> > returning 0 (Success)
> > - but the connection is still refused by the server.
> > 08004: Server rejected the connection
Can you add the PAM file configuration?
And regarding the error.... it looks like the sqlstatus. Can you try a
remote dbaccess to obtain the native error?
I' away from the civilization for a couple of weeks. My ability to help is
limitted...
Regards
On Jul 11, 2016 11:40, "Adam Tauno Williams" <
awilliam@whitemiceconsulting.com> wrote:
On Fri, 2016-07-08 at 09:22 -0400, Fernando Nunes wrote:
> I don't have enough information to provide much help.
> Thisngs that would help:
> 1- Your PAM configuration details. You mention "implicit, not
> challenge, but the options are "challenge" or "password".
[root@argus ~]# cat /opt/informix/etc/sqlhosts
BARNET onsoctcp 172.31.5.23 online
s=4,pam_serv=(informix),pamauth=(password)
> 2- Does "adam" exist as an OS user?
[root@argus ~]# id adam
uid=437(adam) gid=230(cis)
groups=230(cis),201(actng),1015(cs),1001(internet),2074(web_dev),1999(D
omain
Admins),221(service),100(users),1237(horde),1499(beta),3000006(wpa_morm
ail),1240(mvp_qc),19(floppy),249(hilo_editors),508(bie_group),260(parts
qc),3000005(Enterprise Admins),1007(Print
Operators),1115(backup),1134(vnc)
> 3- What is the error? I assume 1809, but please confirm
"08004: Server rejected the connection"
> Even then, and because apparently you're using Kerberos, I may not be
> able to help... as I never actually did any real work with kerberos,
> but let's start with the above...
As can be seen in the log - the authentication suceeds. So there is
not an error at the level of Kerberos.
> On Thu, Jul 7, 2016 at 10:02 PM, Adam Tauno Williams <
> awilliam@whitemiceconsulting.com> wrote:
> > I have PAM auth configured on a new Informix instance; implicit,
> > not challenge. I see PAM auth **succeed** via /var/log/secure -
> > oninit: pam_krb5[12289]: TGT verified using key for
> > 'host/argus.XXXXXX.XXX@XXXXXX.XXX'
> > oninit: pam_krb5[12289]: got result 0 (Success)
> > oninit: pam_krb5[12366]: no need to create "/tmp"
> > oninit: pam_krb5[12366]: created ccache
> > "FILE:/tmp/krb5cc_437_1H3gPE"
> > oninit: pam_krb5[12366]: created ccache
> > 'FILE:/tmp/krb5cc_437_1H3gPE'
> > for 'adam'
> > oninit: pam_krb5[12366]: krb5_kuserok() says "true" for ("
> > adam@XXXXXX.XXX","adam")
> > oninit: pam_krb5[12366]: destroyed ccache
> > "FILE:/tmp/krb5cc_437_1H3gPE"
> > oninit: pam_krb5[12289]: 'adam@XXXXXX.XXX' passes .k5login check
> > for 'adam' oninit: pam_krb5[12289]: authentication succeeds for
> > 'adam' ( adam@XXXXXX.XXX) oninit: pam_krb5[12289]: pam_authenticate
> > returning 0 (Success)
> > - but the connection is still refused by the server.
> > 08004: Server rejected the connection
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
--001a11419f0e7742da05375af324
On Mon, 2016-07-11 at 08:04 -0400, Fernando Nunes wrote:
> Can you add the PAM file configuration?
> And regarding the error.... it looks like the sqlstatus. Can you try
> a remote dbaccess to obtain the native error?
[root@argus ~]# cat /etc/pam.d/informix
# PAM Challenge module
# Module-type Control-flag Module path Options
auth required pam_krb5.so debug
keytab=FILE:/etc/krb5.keytab
And PAM is returning success:
oninit: pam_krb5[26349]: krb5_kuserok() says "true" for ("
adam@MICORE.US","adam")
oninit: pam_krb5[26349]: destroyed ccache "FILE:/tmp/krb5cc_437_g3Aqgu"
oninit: pam_krb5[12289]: 'adam@MICORE.US' passes .k5login check for
'adam'
oninit: pam_krb5[12289]: authentication succeeds for 'adam' (
adam@MICORE.US)
oninit: pam_krb5[12289]: pam_authenticate returning 0 (Success)
--
Adam Tauno Williams <mailto:adam@morrison-ind.com> GPG D95ED383
System & Network Administrator