Informix

Informix

Connect with Db2, Informix, Netezza, open source, and other data experts to gain value from your data, share insights, and solve problems.

 View Only
  • 1.  PAM/LDAP & Informix Authentication Methods

    Posted Fri February 18, 2022 02:35 PM
    I have a client wanting to move off LDAP authentication (long story). Does PAM (pluggable authentication modules) require LDAP? OR - what other authentication methods can folks vouch for in an AIX environment other than LDAP? Does 14 bring anything new? 

    Thanks in advance -
    Mark Scranton
    mark@markscranton.com

    ------------------------------
    Mark Scranton
    ------------------------------

    #Informix


  • 2.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Mon February 21, 2022 04:41 AM

    Hello Mark,

    If long passwords and other encryption than standard crypt is enough, than you can use AIX PAM authentication with informix and you do not need to use LDAP.

    Her is a link how to configure.

    One more comment – in order to work you need either add user informix to „security" AIX group or allow others to read and access direktory /etc/security a file /etc/security/pwdalg.cfg

     

    https://www.ibm.com/support/pages/951-952-when-using-loadable-password-algorithm-lpa-ie-ssha1-ssha256-blowfish-smb5-aix

    in point 4) you can use any algorithm defined in /etc/security/pwdalg, i.e. ssha-512

     

    One more comment – after reconfiguring you can you PAM dbserveralias ONLY with user and password (no equivalency). If you need trusted users for some connectivity, you should use non-pam dbserveralias (i.e. for HDR/ER)

     

    Obsah obrázku text, klipart  Popis byl vytvořen automaticky

    Milan Rafaj

    Infrastructure Architects & Specialists Teamleader

    TC&IS

    +420 737 264 248

    www.kyndryl.com

     

    Kyndryl Česká republika, spol. s r. o.

    Sídlo: Praha 4, Chodov, V Parku 2294/4, PSČ: 148 00,

    IČ: 14890992

    Zapsaná v obchodním rejstříku, vedeném Městským soudem v Praze (oddíl C, vložka 339277)

    Registered address: Prague 4, Chodov, V Parku, 2294/4, Zip code: 148 00

    Company ID: 14890992

    Entered in the Commercial Register maintained by the Municipal Court in Prague (Part C, Entry 339277)






  • 3.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Mon February 21, 2022 05:11 AM
    Hi Mark,

    PAM does not require LDAP. It's more the other way round: using an appropriate PAM module that implements LDAP, you can do LDAP authentication via PAM.

    PAM uses a rather generic API definition that lets you use different PAM modules for different authentication methods. Usually, PAM is used to implement the authentication methods that are not offered otherwise, e.g. by the OS itself. Adhering to the API definition, you can even implement your own authentication method in your own PAM module, theoretically even for a retina scan or similar complicated stuff.

    However, I do not not know, what PAM modules are readily available for AIX. There may be something from IBM itself, or from some third party. In the latter case it's also a question of how much you trust such a third party.

    Apart from PAM and OS provided authentication methods, you can also create database internal users that have their own password inside the database instance. In the "Security" manual look for "Securing data" -> "Connection security" for more information on this topic.

    Regards, Martin

    --

    Martin Fuerderer

    Software Engineer, Software Development

    HCL Technologies Ltd.

    Frankfurter Ring 17

    80807 Munich, Germany

    www.hcltechsw.com


    ::DISCLAIMER::

    The contents of this e-mail and any attachment(s) are confidential and intended for the named recipient(s) only. E-mail transmission is not guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, destroyed, arrive late or incomplete, or may contain viruses in transmission. The e mail and its contents (with or without referred errors) shall therefore not attach any liability on the originator or HCL or its affiliates. Views or opinions, if any, presented in this email are solely those of the author and may not necessarily reflect the views or opinions of HCL or its affiliates. Any form of reproduction, dissemination, copying, disclosure, modification, distribution and / or publication of this message without the prior written consent of authorized representative of HCL is strictly prohibited. If you have received this email in error please delete it and notify the sender immediately. Before opening any email and/or attachments, please check them for viruses and other defects.






  • 4.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Mon February 21, 2022 10:45 AM
    We use PAM with Active Directory here and it works reasonably well. But unless you've got some sort of single-sign-on platform running (LDAP and AD are the two main ones I know about), PAM doesn't really buy you anything.

    Tom Girsch

    Lead System Architect
    Auto Europe Group
    tgirsch@autoeurope.com
    Office #207-842-2139


    " If you think there is something more important than a Client ... think again "





  • 5.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Wed April 05, 2023 09:34 AM

    Hi. We have IBM Informix Dynamic Server Version 14.10.FC6 installed on linux and we want to access informix through Active Directory, what configurations should we do to make it work?



    ------------------------------
    Gustavo Tobares
    ------------------------------



  • 6.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Wed April 05, 2023 10:00 AM
    Install and configure SSSD, works fine
    --  Paul Watson Oninit www.oninit.com Tel: +1 913 364 0360 Cell: +1 913 387 7529  Oninit?? is a registered trademark of Oninit LLC  If you want to improve, be content to be thought foolish and stupid Failure is not as frightening as regret





  • 7.  RE: PAM/LDAP & Informix Authentication Methods

    Posted Wed April 05, 2023 09:48 AM
    Edited by Gustavo Tobares Wed April 05, 2023 12:58 PM


    Thanks for the reply. We can connect to Linux through Winbind. The problem is how to configure the informix? We want it to recognize the users and they can use the different instances.

    Regards.