Re: /etc/hosts.equiv
Posted in 1997
Both the use of .rhosts and hosts.equiv are security holes. Informix has yet to answer this issue. Think about having 200+ clients. Informix's Client/Server solutions suck! The only good thing is that you can create a java based app and use a thin client. Three tier architecture. This means only the app server needs to be in the hosts.equiv. DO NOT USE .rhosts! If you want, I could post some notes from some texts on why not to use .rhosts. -Just a tip from your uncle mike ;-) Bill Ennis wrote: > > This can be done at a more atomic level in each users .rhosts > file on the server machine. The format of the .rhosts file > is: > machine user > > } > } I/Net v7.2 for Windows requires you to setup an hosts.equiv file. Under > } I/Net v5.01, the hosts.equiv file was not required because the "trusted" > } login was managed by I/Net. > } > } I guess the easy to grant remote access to all clients is to place a "+" > } in hosts.equiv. To me, it seems like a security whole! With a large > } end-user population, how do you manage the hosts.equiv file? Do you > } need the hosts.equiv file? > } > } Regards, > } > } Steve Romankiw > } Executive Risk Inc. > } > > -- > Bill Ennis Voice: 312-474-7516 > SSA Fax: 312-474-7460 > 500 W. Madison email: ennis@ssax.com ennis@accesschicago.net -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif