IDS authentication question
Posted in 2007
Topics: Installation, Setup & Upgrades, Networking & sqlhosts Configuration, Platform-Specific Issues
We have upgraded a few instances to IDS v10 from 9.4 and are now experiencing a difference in the authentication process. We use a stand alone AIX database server with multiple AIX application servers communicating via onsoctcp protocol. Under 9.4 we have the end user IDs listed in the /etc/passwd file only and all works fine. Under 10.0 we now need to have the IDs listed in the /etc/security/passwd file also. Informix support assures us, that this has not changed from 9.4 to 10.0. So the question are; what did we do to in 9.4 that allowed this to work without the entries in the /etc/security/passwd file? And is there a security vulnerability to continue this practice? (in either case the IDs do not have any direct login rights to the database server). Thanks
Hi, I am also pretty sure that in IDS itself we did not change the behaviour regarding authentication between IDS 9.40 and IDS 10.00. I would assume that at the same time of IDS upgrade you also upgraded the OS, or at least applied some changes (patches) to the OS. IDS uses system calls to get the password credentials. And these system calls may do different things depending on some configuration in the OS. I would look more closely on the OS side to figure out why this is happening. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management IBM Deutschland GmbH Chairman of the Supervisory Board: Hans Ulrich Märki Board of Management: Martin Jetter (Chairman), Rudolf Bauer, Christian Diedrich, Christoph Grandpierre, Matthias Hartmann, Andreas Kerstan Corporate Seat: Stuttgart, Germany; Reg.-Gericht: Amtsgericht Stuttgart, HRB-Nr.: 14 562 WEEE-Reg.-Nr. DE 99369940 ids-bounces@iiug.org wrote on 02.05.2007 21:27:02: > We have upgraded a few instances to IDS v10 from 9.4 and are now experiencing > a difference in the authentication process. > > We use a stand alone AIX database server with multiple AIX application servers > communicating via onsoctcp protocol. > > Under 9.4 we have the end user IDs listed in the /etc/passwd file only and all > works fine. > > Under 10.0 we now need to have the IDs listed in the /etc/security/passwd file > also. Informix support assures us, that this has not changed from 9.4 to 10.0. > > So the question are; what did we do to in 9.4 that allowed this to work > without the entries in the /etc/security/passwd file? And is there a security > vulnerability to continue this practice? (in either case the IDs do not have > any direct login rights to the database server). > > Thanks > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Thanks for the response Martin, but no OS changes were made durring the upgrade. We are at AIX 5.3 Something with the IDS version is different or because we changed something in the $INFORMIXDIR .......????
Rogers, Here are my case notes from the same problem. Have tech support look up the bug number mentioned below. Here is the bug description, remember that this is a 9.40 bug, so 10.0 is not mentioned Bug: 170784 DIFFERENCE IN AUTHENTICATION BETWEEN 32 AND 64 BIT AIX ENGINES Description: There seems to be a difference in the mechanism used to authenticate users between 32 and 64 bit version of the server when a user remotely logs in from a trusted machine. On AIX encrypted passwords are stored in the /etc/security/passwd file. The /etc/passwd file merely contains a ! to indicate that the password is stored elsewhere. If you remove the encrypted password from the /etc/security/passwd file, then users cannot log onto the machine. However, if the user is correctly configured on a second server and that machine is trusted, then on 64 bit versions of 9.40 we allow that user to connect remotely. On 32 bit versions the engine recognizes that the user doesn't have a valid account and denies access with a 951 error. 7.31 versions of the server also appear to allow full access under these circumstances. Thank you, Elliot Waldman Technical Support Engineer IBM Data Management Solutions Phone: 800-274-8184 Fax: 913-894-0074 www.ibm.com/software/data/informix/service "ROGERS PATTERSON" <rogers.patterson To @arkansas.gov> ids@iiug.org Sent by: cc ids-bounces@iiug. org Subject IDS authentication question [9060] 05/02/2007 02:27 PM Please respond to ids@iiug.org We have upgraded a few instances to IDS v10 from 9.4 and are now experiencing a difference in the authentication process. We use a stand alone AIX database server with multiple AIX application servers communicating via onsoctcp protocol. Under 9.4 we have the end user IDs listed in the /etc/passwd file only and all works fine. Under 10.0 we now need to have the IDs listed in the /etc/security/passwd file also. Informix support assures us, that this has not changed from 9.4 to 10.0. So the question are; what did we do to in 9.4 that allowed this to work without the entries in the /etc/security/passwd file? And is there a security vulnerability to continue this practice? (in either case the IDs do not have any direct login rights to the database server). Thanks ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.