Re: IDS - PAM AUTHENTICATION ANYONE WHO HAVE ACTUALLY MANAGED TO USE
Posted in 2005
This is a multipart message in MIME format. --=_related 00527B0E8625704C_= Content-Type: text/html; charset="US-ASCII" <br><font size=2 face="sans-serif">Hi,</font> <br><font size=2 face="sans-serif"> I think the location of the pam_serv file is not correct. I believe it should be under /usr/lib/security. Also, the pam_serv file is a PAM service module written by the user (typically a shared object ) and placed in the /usr/lib/security directory on the machine where the server is located.</font> <br> <br><font size=2 face="sans-serif"> Please also refer to the following article for more details - http://www-128.ibm.com/developerworks/db2/zones/informix/library/techarticle/030 6mathur/0306mathur.html</font> <br> <br><font size=2 face="sans-serif">Thanks and Regards,<br> </font> <table width=100%> <tr> <td width=37% bgcolor=white><font size=2 face="Verdana"><b>Abhishek Mathur<br> <br> <br> IBM - Information Management</b></font><font size=2 face="Arial"><b><br> 913-599-7109 (T/L - 337-7109)<br> abhishek@us.ibm.com</b></font> <td width=62% bgcolor=white><a href=http://www.ibm.com/ibm/values/><img src=cid:_2_0A9116F009625BE000527B098625704C></a></table> <br> <br> <br> <br> <table width=100%> <tr valign=top> <td width=40%><font size=1 face="sans-serif"><b>"Stefan Sammut" <ssammut@ptl.com.mt></b> </font> <br><font size=1 face="sans-serif">Sent by: forum.subscriber@iiug.org</font> <p><font size=1 face="sans-serif">07/28/2005 06:14 AM</font> <td width=59%> <table width=100%> <tr valign=top> <td> <div align=right><font size=1 face="sans-serif">To</font></div> <td><font size=1 face="sans-serif">ids@iiug.org</font> <tr valign=top> <td> <div align=right><font size=1 face="sans-serif">cc</font></div> <td> <tr valign=top> <td> <div align=right><font size=1 face="sans-serif">Subject</font></div> <td><font size=1 face="sans-serif">IDS - PAM AUTHENTICATION ANYONE WHO HAVE ACTUALLY MANAGED TO USE IT PLEASE??? [5503]</font></table> <br> <table> <tr valign=top> <td> <td></table> <br></table> <br> <br> <br><tt><font size=2>Hello People.<br> <br> We've been trying to use the IDS PAM authentication module for the past 2<br> weeks, but we seem done only a little progresses.<br> We followed the release notes under $INFORMIXDIR/release/en_us/0333/pam.txt;<br> The sqlhosts file is set up as follows.<br> <br> tadinda_tcp onsoctcp acilia 1525<br> s=4,pam_serv=(informix),pamauth=(challenge)<br> <br> The informix file (pam_serv) under /etc/init.d reads as follows:<br> #%PAM-1.0<br> #auth optional pam_toledo.so /usr/informix tadinda_tcp<br> auth required pam_rps.so debug<br> account required pam_rps.so debug<br> password required pam_rps.so debug<br> session required pam_rps.so debug<br> <br> We have tried many of the available services ( pam_unix_passwd,even our<br> own!) , but with this configuration (using the pam_rps service) we the<br> nearest since when running the esqlc pam_demo example prompts back with a<br> challenge. However it consistently returns the -1809 error!<br> <br> We're running IDS 10.0.3 and seems pam documentation is rather misleading<br> and incomplete. We looked throughout the whole net but found nothing<br> helpful. We need to use PAM with PowerBuilder and so far we've managed to<br> get PowerBuilder 10 to talk to an esqlc generated DLL (already a big step).<br> The first person who manages to get the callback function example working,<br> we can update IIUG with new relevant PAM documentation including<br> PowerBuilder connectivity.<br> <br> Many thanks for your help.<br> <br> The esqlc pam_demo ($INFORMIXDIR/demo/esqlc/pam_demo.ec reads as follows:<br> <br> #include <stdio.h><br> #include <string.h><br> <br> #define PAM_PROMPT_ECHO_OFF 1<br> #define PAM_PROMPT_ECHO_ON 2<br> #define PAM_ERROR_MSG 3<br> #define PAM_TEXT_INFO 4<br> #define PAM_MAX_MSG_SIZE 512<br> <br> EXEC SQL define FNAME_LEN 40;<br> EXEC SQL define LNAME_LEN 40;<br> <br> int callback(char *challenge, char *response, int msg_style);<br> <br> int main()<br> {<br> EXEC SQL BEGIN DECLARE SECTION;<br> char fname[ FNAME_LEN + 1 ];<br> char lname[ LNAME_LEN + 1 ];<br> char dbpass[20];<br> char dbuser[20];<br> char dbname[20];<br> EXEC SQL END DECLARE SECTION;<br> <br> int retval = 0;<br> <br> /* First register the callback. This needs to be done before establishing<br> the<br> * connection as done here.<br> */<br> <br> printf("Starting PAM demo \\ ");<br> EXEC SQL WHENEVER ERROR STOP;<br> <br> retval = ifx_pam_callback(callback);<br> <br> if (retval == -1)<br> {<br> printf("Error in registering callback\\ ");<br> return (-1);<br> }<br> else<br> {<br> printf("Callback Registered. Status=%d\\ ",retval);<br> strcpy(dbpass,"mibobva");<br> strcpy(dbuser,"acilia");<br> strcpy(dbname,"cell");<br> printf( "Callback function registered.\\ ");<br> /* EXEC SQL connect to :dbname user :dbuser using :dbpass; */<br> EXEC SQL database :dbname ;<br> printf ("SQLCODE ON CONNECT = %d\\ ", SQLCODE);<br> <br> EXEC SQL declare pamcursor cursor for<br> select customer,name<br> into :fname, :lname<br> from slcustm;<br> <br> EXEC SQL open pamcursor;<br> for (;;)<br> {<br> EXEC SQL fetch pamcursor;<br> if (strncmp(SQLSTATE, "00", 2) != 0) {<br> break; }<br> <br> printf("%s %s\\ ",fname, lname);<br> <br> }<br> <br> if (strncmp(SQLSTATE, "02", 2) != 0)<br> printf("SQLSTATE after fetch is %s\\ ", SQLSTATE);<br> <br> EXEC SQL close pamcursor;<br> &nbs