Windows Authentication for Informix on UNIX
Posted in 2014
Topics: Platform-Specific Issues
Is it possible for a user to use his/her Windows Authentication ( Active Directory) to access Informix running on HP-UX. If so, how is this done? We are running Informix 11.70.FC7 on HP_UX B.11.31 U ia64.
Yes. There are more than one way to do it, and it's usually a bit tricky because that sort of environment is hard to debug. Option 1: If your OS can be configured to use LDAP authentication as it's native authentication AND the LDAP server sends the encrypted password when it receives a request for the user info. Note that currently most LDAP servers will not do this, and even if they do, the encryption used by LDAP would need to be exactly the same used by the native OS crypt() function. For these reasons, this option USUALLY DOES NOT WORK. If it works you don't have to do anything in Informix. Option 2: As Stefan mention, you can configure PAM in Informix and use a pam_ldap module. Here you'll have an issue. By default Informix will require that the user identity is known to the underlying OS (because it uses the user identity for 3 things: - SYSTEM() instruction inside stored procedures - Creation of explain files - Creation of stored procedures debug/trace files So this can be a bit confusing.... You're checking the password on the LDAP (AD) server, but the local machine must recognize the user identity as an OS user. The solution for this was introduced in 11.70 and it's called mapped users. With this you can create external users (not recognized by local OS) which are mapped to one or more local users for the 3 purposes above.. Your version can use this. Older versions would require the OS to be configured to recognize the LDAP users (although the native Informix/OS authentication would probably not work - without PAM- because of the fact that the LDAP does not send back the password - even in encrypted format - ) Regards On Tue, Dec 2, 2014 at 8:31 PM, MURALI PAZHAYANNUR <pmurali@ftportfolios.com > wrote: > Is it possible for a user to use his/her Windows Authentication ( Active > Directory) to access Informix running on HP-UX. If so, how is this done? We > are running Informix 11.70.FC7 on HP_UX B.11.31 U ia64. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --001a113fd708386ab605094ebb14
Thank you Fernando and Stephan. Here is a follow-up question for Fernando. I have review 'mapped users' and 'surrogate users' on the Informix Info. Center and the Informix Security guide. How do I link AD authenticated user(s) to a surrogate user? I'd like to review documentation/blogs specific to this and any test cases or examples to experiment with in a test environment. Also, since the authentication (AD) is on a Win server 2008 and Informix is on HP-UX 11.31. ia, would I need a plugin-in to the AD to provide this link? I am not familiar with/not used the pam module.