We have set up Session Idle Time on Netezza. We see that sessions are being destroyed after the Session Idle Timeout on the Netezza side.
However, this is not the case for users querying Netezza from Aginity. After the Session Idle Timeout is reached (or way after logging onto Aginity and leaving it opened for more than 12 hours after the Session idle Timeout is reached, just to get rid of any cache to test), users are still able to query Netezza Databases from Aginity without being prompted to log on to Aginity again. We then see the sessions created and ended on Netezza side as expected.
This has been identified as a Security Risk. We expect that Aginity would also invalidate the session and prompt the user to log in again. But that's not the case.
I've tested the behavior using the latest version of Aginity https://www.aginity.com/documentation/WB/NZ/Default.htm#Aginity_Topics/Aginity_Workbench/Workbench_Downloads.htm%3FTocPath%3D_____4
Issue is seen for all Netezza Appliances we use - TwinFin, Striper, Mako
We've talked to IBM on this, but since the sessions are getting terminated after the Session Idle Timeout on the Netezza side, they've asked us to reach out to you.
In Aginity, under Query Options, "Keep connections open between connections" is unchecked. Also, on the login page, Connection Timeout is set to 120 sec default for the tests performed.
Is there a way for Aginity to respect the Session Idle Timeout set on Netezza?
Looking forward to hear back from you soon.
Please sign in to leave a comment.