Skip to main content
Question

dbadmin: client SSL authentication from host1, and hash authentication from host2

  • January 16, 2019
  • 0 replies
  • 8 views

ankitdm

Hi,

I have a need to configure different authentication methods for the dbadmin (verticadba in my case) from different hosts: 'has' when connecting from host1, and 'client SSL' when connecting from host2. I have created the two different authentications as below:
CREATE AUTHENTICATION v_dbadmin_hash_host1 METHOD 'hash' HOST '16.184.1.1';
CREATE AUTHENTICATION v_client_ssl_host2 METHOD 'tls' HOST TLS '16.184.1.2';
GRANT AUTHENTICATION v_dbadmin_hash_host1 to verticadba;
GRANT AUTHENTICATION v_client_ssl_host2 to verticadba;

I have created the corresponding client certificate, with the username as the CN 'verticadba'.

Now I can login fine using the dbadmin username/password from host1. However, I cannot login using the SSL authentication from host2. I get the following error:
vsql -h -U verticadba
vsql: FATAL 2248: Authentication failed for username "verticadba"

I have tried the SSL authentication from the same host2 with a different user (reader1), which works fine. When I want to use verticadba, I have replaced the right certificate for the verticadba user in $VSQL_HOME/.vsql directory.

Some basic Qs:

  • I suppose I am allowed to have SSL authentication for different users from the same client host?
  • If above is YES, then how do I place the different certificates? Just copy all of them in $VSQL_HOME/.vsql directory?

I would be glad to share the requisite files (certificates) to help debug this issue.

Thanks
-Ankit