Centrify single sign on
Posted in 2008
A user piloting Centrify (AD single sign-on) on AIX 5.3 with IDS 9.40.UC3 found Informix only recognised AD users when PAM was enabled, but then dbaccess prompted for username/password on remote connections — unlike the previous NIS setup with implicit/trusted connections. Respondents explained PAM is required, that the OS must know the user, suggested using a 'sufficient' module like pam_unix, and shared working sqlhosts/pam.d examples (noting local connections never prompt, so testing must be remote). The poster concluded PAM was behaving as designed and planned to open an IBM ticket and look into a challenge/response PAM module; no resolution is recorded in the thread.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues
I've been piloting Centrify single sign on software on AIX 5.3 TL7.
The problem I'm having is that Informix 9.4 uc3 doesn't recognize the
users that Centrify is getting from Active Directory unless I use
pam. When I configure IDS for pam then on the client running dbaccess
I'm prompted for the user's login name and password, something that
does not happen when I use NIS.
I read the articles at http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam-for.html
and the ibm developer works articles. It appears that there is no
solution for this unless I modify the many applications we have
written for IDS. Is this true or am I misinterpreting?
Management is already pushing hard to go to MS SQL Server. So if I
can't solve this quickly I will have to transition to SQL Server.
prichard@blm.gov wrote:
> I've been piloting Centrify single sign on software on AIX 5.3 TL7.
> The problem I'm having is that Informix 9.4 uc3 doesn't recognize the
> users that Centrify is getting from Active Directory unless I use
> pam. When I configure IDS for pam then on the client running dbaccess
> I'm prompted for the user's login name and password, something that
> does not happen when I use NIS.
>
> I read the articles at http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam-for.html
> and the ibm developer works articles. It appears that there is no
> solution for this unless I modify the many applications we have
> written for IDS. Is this true or am I misinterpreting?
>
> Management is already pushing hard to go to MS SQL Server. So if I
> can't solve this quickly I will have to transition to SQL Server.
I'm very confused by your post... possible because I'm not familiar with
Centrify...
When you say that dbaccess ask for user and password, with PAM, are you using
centrify or not? What exactly do you do before the request (what menu options
do you choose)? Which Informix ALIAS are you using? The PAM or other?
My article tries to show how to setup Informix with PAM. Not with Centrify...
And currently, even when using PAM, the OS must be aware, or in other words,
must recognize the user identity. The reasons are explained and personally I'd
like to see this change... but with everything going on R&D must set priorities...
What do you mean by "changing the applications"? What change are you thinking
about that might help you?
As you probably know, your management thoughts won't cause great effect on a
newsgroup... It could be different in a PMR... Nevertheless I find it
surprisingly that management is so worried about a technical issue like this.
Hopefully they understand all the impacts of moving a database, a production
environment from Unix to Windows, all the training etc.
If you think it's worth it (given your management point of view) I suggest you
open a case with Centrify (their site references Informix), or possibly with
IBM, since PAM issues sometimes can be tricky to solve (mostly because PAM is a
complex subject and it lies in a cloudy layer... not exactly operating system
and not exactly OS).
If this encourage you, a few months ago I worked with a colleague from tech
support and we successfully got a customer authenticating Informix users in an
LDAP in AIX... It turned out to be a misconfiguration. In fact this was what
triggered me to write the article you mention. And of course, AD is/has an LDAP
server...
One final note... 9.40.UC3 is rather old... In fact if I recall correctly it
was the first version to support PAM...
Regards,
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Do you have pam_unix or some other 'sufficient' module in the list of modules? This should allow multiple sources of authentication. If pam_unix is not the one, there should be a module to somehow automagically recognise a logged-in user on the box.
Perhaps a condition on the pam_permit module will detect a local user.
Either way, I can't believe that PAM can't provide a solution to this problem.
-----Original Message-----
From: informix-list-bounces@iiug.org on behalf of prichard@blm.gov
Sent: Fri 4/4/2008 9:26 AM
To: informix-list@iiug.org
Subject: Centrify single sign on
I've been piloting Centrify single sign on software on AIX 5.3 TL7.
The problem I'm having is that Informix 9.4 uc3 doesn't recognize the
users that Centrify is getting from Active Directory unless I use
pam. When I configure IDS for pam then on the client running dbaccess
I'm prompted for the user's login name and password, something that
does not happen when I use NIS.
I read the articles at http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam-for.html
and the ibm developer works articles. It appears that there is no
solution for this unless I modify the many applications we have
written for IDS. Is this true or am I misinterpreting?
Management is already pushing hard to go to MS SQL Server. So if I
can't solve this quickly I will have to transition to SQL Server.
_______________________________________________
Informix-list mailing list
Informix-list@iiug.org
http://www.iiug.org/mailman/listinfo/informix-list
prichard@blm.gov wrote:
> I've been piloting Centrify single sign on software on AIX 5.3 TL7. The
> problem I'm having is that Informix 9.4 uc3 doesn't recognize the users
> that Centrify is getting from Active Directory unless I use pam.
You _need_ pam for this, as far as I know.
> When I
> configure IDS for pam then on the client running dbaccess I'm prompted
> for the user's login name and password, something that does not happen
> when I use NIS.
Sounds like a configuration issue to me. I've successfully configured
Informix to work with pam, such that local logins don't need to provide a
password. When users log in through TCP, they do have to provide a
password - pretty much as expected, as Informix client software doesn't
support Kerberos, as far as I know.
This was with Linux and Winbind, however; AIX tends to be more cumbersome
regarding just about everything.
Maybe we could help you better if you posted your sqlhosts configuration
file (probably in an "anonymized" form).
This is the sqlhosts file which I use (two lines below the ---- line, in
case newsreader(s) have wrapped lines):
================================================================
# dbserver proto hostname service options
#
--------------------------------------------------------------------------------------
xxxfoo onipcshm the.host.name sqlexec
xxxbar onsoctcp the.host.name sqlexec s=4,pam_serv=(informix),pamauth=(password)
================================================================
In the onconfig file, xxxbar is an alias to xxxfoo.
/etc/pam.d/informix looks like this:
================================================================
auth sufficient pam_unix.so nullok try_first_pass
auth requisite pam_succeed_if.so uid >= 500 quiet
auth sufficient pam_winbind.so use_first_pass krb5_auth
auth required pam_deny.so
account required pam_permit.so
================================================================
Before I set up Informix this way, I made sure that other pam
configuration files made it possible for people to ssh into the
server. - To make sure that all the AD-integrated authentication/
authorization stuff actually worked.
Again, this is on Linux. The pam configurations most certainly need
to look different on AIX.
We actually use Centrify (only used for AIX LPARs), but I don't
much like it: It maintains a separate LDAP sub-tree in the AD
where the unix-specific information about users/groups are kept.
This way, users and groups live in two "spaces" in the LDAP tree:
Partly in the "normal" AD structures, and partly in Centrify's
special sub-tree.
The consequence is that all out-of-the-box LDAP+Kerberos
integration software which is part of modern unixes don't work
well (especially regarding group memberships), so special Centrify
software needs to run on the Centrified unixes (special Centrified
Apache + special Centrified openssh + ...). It also means that
the many good guides on AD+unix integration on the Web don't apply.
We are currently stuck with Centrify (which was introduced before
I started working there). If I were to start from scratch, I would
have investigated if Winbind would be sufficient (it seems to be on
Linux - I don't know if Winbind works well on AIX). If not, I would
look into Microsoft's unix integration add-ons which are supposed
to be part of Windows Server since version 2003 R2:
http://technet.microsoft.com/en-us/library/bb496504.aspx
http://en.wikipedia.org/wiki/Interix
--
Regards,
Troels Arvin <troels@arvin.dk>
http://troels.arvin.dk/
Fernando,
Thank you for the reply.
Here are the answers to your questions. For clarity I'll prepend a
Q: before your questions and an A: before my answers.
Q:When you say that dbaccess ask for user and password, with PAM, are
you using centrify or not?
A:Yes, I am using Centrify to provide user login names and passwords.
It gets that information from Active Directory.
Q:What exactly do you do before the request (what menu options do you
choose)?
A: following....
dbaccess->database->select
highlight the pam enabled ALIAS, in my case called mtso0sdedevad
Now I get the "USER NAME >>" prompt. I enter my login name for AD.
Now I get the "PASSWORD >>" prompt. I enter my password for AD.
I wait 30 seconds while Centrify queries AD.
Now I select my database, in this case called mtras.
In other words, pam is working and authenticating to AD. However, on
NIS I was not prompted for a login name and password.
Q: Which Informix ALIAS are you using? The PAM or other?
A: I'm using the pam enabled ALIAS.
Q:What do you mean by "changing the applications"?
A:We have at least 29 Informix frontend applications that users run to
access one of two Informix instances. Some of them are text based
menu systems where the user logs into our central AIX server with
ssh. Some of these that started text based have been converted to use
Microsoft Access as a front end. The SDE databases use various ESRI
applications running on MS Windows.
Of our 2 production Informix instances one has 17 databases, the other
has 10 database, 2 of which are the very complex ESRI SDE databases.
Q:What change are you thinking about that might help you?
A:Based on my limited understanding (I'm not an Informix DBA, I'm an
AIX/Linux/Windows SA) of your excellent white papers I thought I
would need to write and integrate a pam module that would perform
challenge/response and implicit connection for each of the above
mentioned applications. I allow for me not understanding this issue.
FYI, before we could buy Centrify I had to figure out how to make
Informix work with Centrify. I did a lot of reading and got some help
and came up with the pam solution. Interestingly, shortly after I
provided that solution to Centrify in the summer of 2007, last summer,
they had a white paper on their web site for the same. I was
touched. :) The mistake I made was that I did all my testing on one
server and when I run dbaccess on the same server as the Informix
instance it does not prompt for a password. When I tried to scale to
my production environment it prompted for a password. This made me
fall back to NIS since my users are already beleaguered with too many
password prompts.
That being said, I could never get Centrify to work with SDE.
Centrify corp blamed Informix so I opened a ticket with them.
Informix blamed ESRI, so I opened a ticket with them. ESRI assigned
their new temp to the issue and I finally gave up when she did not
understand the sqlhosts file and that the problem was between sde and
Informix, not out on the client. She kept having me go to the client,
install new window odbc drivers and such. I remained polite and let
her off the hook.
I agree that 9.40.UC3 is old. I don't have a choice. We hire legions
of contractors to make sure that the few of us who actually do techy
work are doing it right. Trying to roll out a new version of
something as complex and expensive as Informix takes literally years.
Very sad but that is the hand I'm dealt.
I'll see if I can open a ticket with Informix this next week and see
if they will help me on pam. I'll keep you posted.
prichard@blm.gov wrote:
> Fernando,
>
> Thank you for the reply.
>
> Here are the answers to your questions. For clarity I'll prepend a
> Q: before your questions and an A: before my answers.
This is really a big mess... A typical scenario nowadays when we get a log of
suppliers. Not that this is a bad thing, but everybody tends to play tennis
(keep the ball on the air or on the opponent side) :)
>
> Q:When you say that dbaccess ask for user and password, with PAM, are
> you using centrify or not?
>
> A:Yes, I am using Centrify to provide user login names and passwords.
> It gets that information from Active Directory.
>
> Q:What exactly do you do before the request (what menu options do you
> choose)?
>
> A: following....
>
> dbaccess->database->select
> highlight the pam enabled ALIAS, in my case called mtso0sdedevad
> Now I get the "USER NAME >>" prompt. I enter my login name for AD.
> Now I get the "PASSWORD >>" prompt. I enter my password for AD.
>
> I wait 30 seconds while Centrify queries AD.
>
> Now I select my database, in this case called mtras.
>
> In other words, pam is working and authenticating to AD. However, on
> NIS I was not prompted for a login name and password.
I'm still a bit confused by your environment. After reading some paragraphs
apparently you used to have a Unix application server and Unix database server.
If this is correct you probably used trust relations/connection between the two.
Now you want to centralize the Unix users in AD and as a consequence of
configuring PAM and Centrify you are prompted to input a user and password.
If all this is correct it would be useful to see your INFORMIXSQLHOSTS file and
your PAM configuration file(s) to start with...
But I imagine PAM is configured to password authentication...
One thing that keeps popping in my head is why do you need Centrify...
AFAIK you can configure AIX to get the users from AD using PAM. If the OS
recognizes the user Informix, without PAM, should be able to work as usual.
But assuming you want to use Centrify, again I don't see how this is an
IBM/Informix problem... They say they support it, they should know how to
configure. What is different in your environment? Is the fact that you want to
use implicit connections and they possibly don't support it?
>
> Q:What change are you thinking about that might help you?
>
> A:Based on my limited understanding (I'm not an Informix DBA, I'm an
> AIX/Linux/Windows SA) of your excellent white papers I thought I
> would need to write and integrate a pam module that would perform
> challenge/response and implicit connection for each of the above
> mentioned applications. I allow for me not understanding this issue.
But then again, what would you gain from Centrify? AD is/has an LDAP server.
AFAIK AIX can be configured to authenticate in an LDAP server (possibly you
have two install Services For Unix (SFU) on the AD server to extend your LDAP
attributes to support Unix specific features.
> FYI, before we could buy Centrify I had to figure out how to make
> Informix work with Centrify. I did a lot of reading and got some help
> and came up with the pam solution. Interestingly, shortly after I
> provided that solution to Centrify in the summer of 2007, last summer,
> they had a white paper on their web site for the same. I was
> touched. :) The mistake I made was that I did all my testing on one
> server and when I run dbaccess on the same server as the Informix
> instance it does not prompt for a password. When I tried to scale to
> my production environment it prompted for a password. This made me
> fall back to NIS since my users are already beleaguered with too many
> password prompts.
Although I have not done extensively tests or investigations about this, don't
test PAM on the DB server machine. Test it remotely...
>
> That being said, I could never get Centrify to work with SDE.
> Centrify corp blamed Informix so I opened a ticket with them.
If they blame Informix, they should explain why their sites says they support
it... Obviously there can be a problem with some IDS version... PAM is a
subsystem and every subsystems can have bugs... But if they support it we would
assume they did test it successfully with some version... If it doesn't work
with another version IBM can help investigate why...
> Informix blamed ESRI, so I opened a ticket with them. ESRI assigned
> their new temp to the issue and I finally gave up when she did not
> understand the sqlhosts file and that the problem was between sde and
> Informix, not out on the client. She kept having me go to the client,
> install new window odbc drivers and such. I remained polite and let
> her off the hook.
"If you want something done, sometimes you have to do it yourself" :)
> I agree that 9.40.UC3 is old. I don't have a choice. We hire legions
> of contractors to make sure that the few of us who actually do techy
> work are doing it right. Trying to roll out a new version of
> something as complex and expensive as Informix takes literally years.
> Very sad but that is the hand I'm dealt.
Well, I won't comment on the expensive part, but Informix migrations, specially
on the same machine tend to be very simple (provided you have enough resources
to test it...)
But if you feel that about and Informix upgrade I really admire your management
even more ;)
> I'll see if I can open a ticket with Informix this next week and see
> if they will help me on pam. I'll keep you posted.
It can be a bit difficult if your PAM configuration has Centrify modules in
their... But It's certainly worth the try.
Keep us informed
As a side note... I really don't know how to say this... But the new beta
version of IDS could be worth a look... New version means new features, and we
can only know about them and about their usefulness if we check the beta site.
It could be different if we had no NDA...
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Frenando,
Thank you again for your reply. After doing more reading with the
understanding you and other respondents gave me I realize pam is
working exactly as it should in my environment in that it is prompting
for a name and password. I'm going to re-read your papers and see if
I can write a challenge and response pam module that will function in
my environment.
To clarify my environment:
I have an Informix server on an AIX box. This I will call db1. On
another AIX server I have some text based applications written in
isql. I'll call it ap1. Then I have mutiple WindowsXP PC's running
an MS Access front end that uses odbc to get to db1.
The only trust relationship I have between the servers is the NIS
login name and password.
You are correct in that I'm trying to centralize the Unix users in AD
and as a consequence of
configuring PAM I am prompted to input a user and password.
INFORMIXSQLHOSTS file on the db1 and ap1:
mtso0sdedevad onsoctcp db1 sdead
s=4,pam_serv=(infrmx),pamauth=(password)
tail of /etc/pam.conf on db1 and ap1:
#
# Informix authenticate to AD
#
infrmx auth required /usr/lib/security/pam_aix
infrmx account required /usr/lib/security/pam_aix
infrmx session optional /usr/lib/security/pam_aix
I've not been able to figure out how to have AIX get the users from AD
using PAM without using Centrify. The organization that controls AD
will not allow any changes to the AD schema such as MS SFU. Hence,
Centrify seemed like a good solution.
The user informix is a local user in the /etc/passwd.
-Park
prichard@blm.gov wrote:
> Frenando,
>
> Thank you again for your reply. After doing more reading with the
> understanding you and other respondents gave me I realize pam is
> working exactly as it should in my environment in that it is prompting
> for a name and password. I'm going to re-read your papers and see if
> I can write a challenge and response pam module that will function in
> my environment.
>
> To clarify my environment:
>
> I have an Informix server on an AIX box. This I will call db1. On
> another AIX server I have some text based applications written in
> isql. I'll call it ap1. Then I have mutiple WindowsXP PC's running
> an MS Access front end that uses odbc to get to db1.
>
> The only trust relationship I have between the servers is the NIS
> login name and password.
>
> You are correct in that I'm trying to centralize the Unix users in AD
> and as a consequence of
> configuring PAM I am prompted to input a user and password.
>
> INFORMIXSQLHOSTS file on the db1 and ap1:
>
> mtso0sdedevad onsoctcp db1 sdead
> s=4,pam_serv=(infrmx),pamauth=(password)>
> tail of /etc/pam.conf on db1 and ap1:
>
> #
> # Informix authenticate to AD
> #
> infrmx auth required /usr/lib/security/pam_aix
> infrmx account required /usr/lib/security/pam_aix
> infrmx session optional /usr/lib/security/pam_aix
Good. Now I have a much clear idea of what's going on :)
>
> I've not been able to figure out how to have AIX get the users from AD
> using PAM without using Centrify. The organization that controls AD
> will not allow any changes to the AD schema such as MS SFU. Hence,
> Centrify seemed like a good solution.
I have my doubts that this can be done without changes in the AD LDAP tree.
I would have to check pam_aix. Is this an AIX native module or is this a module
provided by Centrify?
Coincidently I'll be working with two AIX machines in the next few weeks.
Although I won't be able to change their configurations I can try to check the
man pages etc.
If I found something relevant I'll post it here.
Meanwhile if I can spare some minutes I'll try to review a PMR I worked on with
AIX and IDS and PAM authentication...
> The user informix is a local user in the /etc/passwd.
It's a good idea to keep key users as local users. You'll be able to login even
if something breaks...
Regards,
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...