RE: suppressing username and password prompts in dbaccess
Posted in 2007
Geez!
How many times does it take before the message sinks in.
.rhosts BAD. VERY BAD.
BAD IDEA FROM THE START.
You should NEVER, EVER LET YOUR USERS use .rhosts since it effectively allows them to say that Machine A is a safe and trustworthy machine.
Not a problem if Machine A is sitting next to your server in the machine room.
BIG PROBLEM if Machine A is sitting somewhere well outside your firewall and outside of your control.
Since most DBAs are NOT system administrators, talk to your system administrators and see what they say.
Hosts.equiv is controlled by your system administrator (root access). You should use this only for machines that are truly equivalent.
(Like machine A load balances for machine B ...)
Think of this as being much worse than running your IDS engine on a RAID 5 system.
If I were your system administrator and you did this on one of my systems? I'd consider it a terminating offense. One where the use of a firing squad is a form of mercy.
Please be paranoid. We don't want to see another TJX situation on an IDS platform now do we? (TJX was running Oracle. ;-)
-G
PS. Yes, I was at one time a BOFH ;-)
> From: dcruncher4@aim.com
> Subject: Re: suppressing username and password prompts in dbaccess
> Date: Wed, 19 Dec 2007 10:48:15 -0800
> To: informix-list@iiug.org
>
> In article <e89947bf-d9fc-4f33-9ef4-dacf60193a7a@v4g2000hsf.googlegroups.com>,
> skurlander@yahoo.com says...
> >
> >Hi,
> >
> >Our site is running Informix Dynamic Server 11 on Linux. Currently,
> >when connecting to a server using dbaccess the user is prompted for
> >his user name and password. What options are available so providing a
> >user name and password is unnecessary, as the username and password is
> >the same one as they used to log into their machine.
>
> One the server machine (where IDS 11 is running), in that user's home
> directory you have to create a file .rhosts in which you mention the
> name of the client machine from where the users will connect.
>
> Also I am not sure how dbaccess is prompting for user name/password.
> AFAIK dbaccess does not prompt. You will get error from the database
> if you don't have appropriate permission.
>
> try this
> create a file test.sql with some dummy statement
> like
> database sysmaster;
> select 1 from systables where tabid = 1 ;>
> run it
> $ dbaccess - test>
> dbaccess should not prompt for password. It will fail unless you
> create the trust relationship between the client and the server
> via that .rhosts file I described above.
>
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
_________________________________________________________________
Get the power of Windows + Web with the new Windows Live.
http://www.windowslive.com?ocid=TXT_TAGHM_Wave2_powerofwindows_122007