Informix and LDAP
Posted in 2006
Topics: Security, Permissions & Auditing, Platform-Specific Issues
Hi, We are trying to implement LDAP authentication in our Informix environment. Not having much luck. Any advice/examples of what needs to be done would be greatly appreciated. Environment: AIX 5.2, Informix 9.40.FC3W3. Thanks, Wayne Please do not transmit orders or instructions regarding a UBS account by e-mail. The information provided in this e-mail or any attachments is not an official transaction confirmation or account statement. For your protection, do not include account numbers, Social Security numbers, credit card numbers, passwords or other non-public information in your e-mail. Because the information contained in this message may be privileged, confidential, proprietary or otherwise protected from disclosure, please notify us immediately by replying to this message and deleting it from your computer if you have received this communication in error. Thank you. UBS Financial Services Inc. UBS International Inc.
Hi, at best look into utilizing PAM (Pluggable Authentication Modules). It is supported since 9.40.UC2, also on AIX. You may need to check if this is true for 9.40.FC2 and newer (64-bit) on AIX (currently I'm not 100% sure). There should be a file "pam.txt" in the release notes directory ($INFORMIXDIR/release/en_us/0333) which has more information, even a bit of an example (though a general one, not exactly for LDAP). There are also certain implementations of NIS/NIS+ that do LDAP authentication, where this is transparent to the application utilizing the NIS/NIS+. That way it is also transparent for IDS and thus should work. But I've never really tried this. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management ids-bounces@iiug.org wrote on 03.04.2006 17:50:37: > > Hi, > > We are trying to implement LDAP authentication in our Informix environment. > Not having much luck. Any advice/examples of what needs to be done would be > greatly appreciated. > Environment: AIX 5.2, Informix 9.40.FC3W3. > > Thanks, > Wayne > > ... > UBS Financial Services Inc. > UBS International Inc. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Thanks for the quick response. Unfortunately PAM is not an option...This is a vendor application and they have no intentions of changing it. Wayne -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Martin Fuer.... Sent: Monday, April 03, 2006 12:12 PM To: ids@iiug.org Subject: Re: Informix and LDAP [6554] Hi, at best look into utilizing PAM (Pluggable Authentication Modules). It is supported since 9.40.UC2, also on AIX. You may need to check if this is true for 9.40.FC2 and newer (64-bit) on AIX (currently I'm not 100% sure). There should be a file "pam.txt" in the release notes directory ($INFORMIXDIR/release/en_us/0333) which has more information, even a bit of an example (though a general one, not exactly for LDAP). There are also certain implementations of NIS/NIS+ that do LDAP authentication, where this is transparent to the application utilizing the NIS/NIS+. That way it is also transparent for IDS and thus should work. But I've never really tried this. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management ids-bounces@iiug.org wrote on 03.04.2006 17:50:37: > > Hi, > > We are trying to implement LDAP authentication in our Informix environment. > Not having much luck. Any advice/examples of what needs to be done would be > greatly appreciated. > Environment: AIX 5.2, Informix 9.40.FC3W3. > > Thanks, > Wayne > > ... > UBS Financial Services Inc. > UBS International Inc. > > > **************************************************************************** *** > Forum Note: Use "Reply" to post a response in the discussion forum. > **************************************************************************** *** Forum Note: Use "Reply" to post a response in the discussion forum. Please do not transmit orders or instructions regarding a UBS account by e-mail. The information provided in this e-mail or any attachments is not an official transaction confirmation or account statement. For your protection, do not include account numbers, Social Security numbers, credit card numbers, passwords or other non-public information in your e-mail. Because the information contained in this message may be privileged, confidential, proprietary or otherwise protected from disclosure, please notify us immediately by replying to this message and deleting it from your computer if you have received this communication in error. Thank you. UBS Financial Services Inc. UBS International Inc.
Hi, hmm. Not necessarily. If you take a closer look at PAM and how it is supported by IDS, you will come to a conclusion like the following: -> As it has already been explained, IDS supports PAM in -> password authentication mode. In this mode a (normal) -> UNIX-style password is required, but no challenge is done. -> Since the SQLI protocol between client and server already -> allows for the password to be passed along in the connect -> request, this can be supported by the IDS server. The -> password is already there and the server can hand it on to -> the PAM. Thus the challenge is not necessary and no extra -> communication with the client is needed. -> -> But since a password is required in password authentication -> mode, implicit connections (not providing the password in -> the connect request) are not possible. They will always be -> rejected in this mode. -> -> An exception is (again) the local user informix. As he does -> not get a challenge in challenge mode, so is there no need -> to supply password for this user in password mode. -> Therefore the local user informix is the only user who can -> successfully connect via an implicit connection in this mode. -> However, if the user informix is not local (i.e. from a remote -> machine), then the password is mandatory for him as well. -> Thus a remote user informix can't use implicit connections -> in password mode. Now, this is not text from the release notes. It is from an internal "paper" explaining the PAM support. As it is internal I can't hand it out just like that ... :-( But as I've written it myself for a class/workshop I once did on the topic I take the freedom to quote the above excerpt ... :-) You can find a similar explanation (albeit in different words) in that file "pam.txt" which I mentioned before. Regards, Martin -- Martin Fuerderer IBM Informix Development Munich, Germany Information Management ids-bounces@iiug.org wrote on 03.04.2006 18:19:22: > > Thanks for the quick response. Unfortunately PAM is not an option...This is > a vendor application and they have no intentions of changing it. > > Wayne > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Martin > Fuer.... > Sent: Monday, April 03, 2006 12:12 PM > To: ids@iiug.org > Subject: Re: Informix and LDAP [6554] > > Hi, > > at best look into utilizing PAM (Pluggable Authentication Modules). > It is supported since 9.40.UC2, also on AIX. You may need to check > if this is true for 9.40.FC2 and newer (64-bit) on AIX (currently I'm > not 100% sure). > > There should be a file "pam.txt" in the release notes directory > ($INFORMIXDIR/release/en_us/0333) which has more information, > even a bit of an example (though a general one, not exactly for LDAP). > > There are also certain implementations of NIS/NIS+ that do > LDAP authentication, where this is transparent to the application > utilizing the NIS/NIS+. That way it is also transparent for IDS and thus > should work. But I've never really tried this. > > Regards, > Martin > -- > Martin Fuerderer > IBM Informix Development Munich, Germany > Information Management > > ids-bounces@iiug.org wrote on 03.04.2006 17:50:37: > > > > Hi, > > > > We are trying to implement LDAP authentication in our Informix > environment. > > Not having much luck. Any advice/examples of what needs to be done would > be > > greatly appreciated. > > Environment: AIX 5.2, Informix 9.40.FC3W3. > > > > Thanks, > > Wayne > > > > ... > > UBS Financial Services Inc. > > UBS International Inc. > **************************************************************************** > Forum Note: Use "Reply" to post a response in the discussion forum.
On 4/3/06, Zablatzky, .... <Wayne.Zablatzky@ubs.com> wrote: > Thanks for the quick response. Unfortunately PAM is not an option...This is > a vendor application and they have no intentions of changing it. Implementing PAM means that you'd get an LDAP module to plug into your system, and you would configure the LDAP module to talk to your LDAP server, and you'd configure IDS to use the LDAP PAM so that when the user said "I'm me, and this is my password", your IDS would end up talking to the LDAP server which would pontificate "Yea" or "Nay" and let IDS get on with life - all without changing any code in any application. So, what is the problem with using PAM? Also, since PAM *is* the answer, if you choose to reject the answer, then the alternative answer is "you cannot use LDAP unless you use PAM". > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Martin > Fuer.... > Sent: Monday, April 03, 2006 12:12 PM > To: ids@iiug.org > Subject: Re: Informix and LDAP [6554] > > at best look into utilizing PAM (Pluggable Authentication Modules). > It is supported since 9.40.UC2, also on AIX. You may need to check > if this is true for 9.40.FC2 and newer (64-bit) on AIX (currently I'm > not 100% sure). > > There should be a file "pam.txt" in the release notes directory > ($INFORMIXDIR/release/en_us/0333) which has more information, > even a bit of an example (though a general one, not exactly for LDAP). > > There are also certain implementations of NIS/NIS+ that do > LDAP authentication, where this is transparent to the application > utilizing the NIS/NIS+. That way it is also transparent for IDS and thus > should work. But I've never really tried this. > > Regards, > Martin > -- > Martin Fuerderer > IBM Informix Development Munich, Germany > Information Management > > ids-bounces@iiug.org wrote on 03.04.2006 17:50:37: > > We are trying to implement LDAP authentication in our Informix environment. > > Not having much luck. Any advice/examples of what needs to be done would be > > greatly appreciated. > > Environment: AIX 5.2, Informix 9.40.FC3W3. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/