not trusted
Posted in 2014
On a fresh IDS 12.10.TC4IE install on Windows Server 2012 R2, ontape -a failed with error -956 "Client host or user Administrator@LastDitch.home[LastDitch] is not trusted". Fernando Nunes attributed it to name-resolution mismatch (FQDN vs short hostname) and suggested a trusted-hosts file in %INFORMIXDIR%\\etc listing both names, enabled via REMOTE_SERVER_CFG; that cleared the -956 but left a -951 on ontape. Jeff Filippi suggested adding CHECKALLDOMAINSFORUSER 1 to onconfig. The poster found everything worked when logged in as user informix rather than Administrator; the Administrator problem and a stray lo_ifx sqlhosts/alias entry were left unresolved in the thread.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Backup & Restore, Installation, Setup & Upgrades, Platform-Specific Issues
This concerns on IDS12.10.TC4IE on windows server 2012 R2.
This was a fresh install.
When I run ontape âa I get:
17:09:36 listener-thread: err = -956: oserr = 0: errstr =
Administrator@LastDitch.home[LastDitch]:
Client host or user Administrator@LastDitch.home[LastDitch] is not trusted by
the server.
The finderr help file says:
âClient client-name or user is not trusted by the database server.
The desired database server does not consider the client computer or your user
ID trusted. â
This is on the server so is the client computer is the server.
This happens with user Administrator and user Informix.
They are both administrators on the server. Why would they not be
âtrustedâ?
How do I make them trusted?
Somehow the Informix process doesn't see it self as that name... That's
easy to happen if you have multiple TCP interfaces (I assume you're
connecting through TCP).
It would be interesting to see your "sqlhosts" configuration.
The message cleary says that the server resolved the IP address from where
it's receiving the connection as "LastDitch.home" while the client software
thinks the hostname is the short name (LastDitch).
I honestly would have to test something.... Depending on the version,
Informix may require both of these to be "trusted"
You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc and
call it (for example) instance_trusts.
Inside that file put:
LastDitch.home informix
LastDitch informix
and change the REMOTE_SERVER_CFG parameter to that filename:
onmode -wf REMOTE_SERVER_CFG=instance_trusts
Then try to connect again.
Ideally you should solve your machine DNS issues... (or if you're not using
DNS, the equivalent file configuration)
Regards
On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> This was a fresh install.
> When I run ontape a I get:
> 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> Administrator@LastDitch.home[LastDitch]:
>
> Client host or user Administrator@LastDitch.home[LastDitch] is not
> trusted by
> the server.
>
> The finderr help file says:
> Client client-name or user is not trusted by the database server.
> The desired database server does not consider the client computer or your
> user
> ID trusted.
>
> This is on the server so is the client computer is the server.
> This happens with user Administrator and user Informix.
> They are both administrators on the server. Why would they not be
> trusted?
> How do I make them trusted?
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--047d7b10c847bcec7d05039a3bef
I set REMOTE_SERVER_CFG as you said and that error went away.
Now when I run ontape -a I get this:
Performing automatic backup of logical logs.
could not fork server connection, SQLCODE -951
Program over.
The error 951 says:
User username is not known on the database server.
The database server that you tried to access does not accept either your
user ID, the login name that is specified for the desired server host in
your ~/.netrc file, or the user name that is specified in the USER clause of
a CONNECT statement. If you are explicitly specifying your user name in the
~/.netrc file or in a CONNECT statement, check that the name is correct.
Where is the .netrc file on Windows? in the registry?
Also please note that my sqlhosts.[servicename] has a new line that I did
not have on another install of 12.10c4:
lo_ifx olsoctcp 127.0.0.1 lo_ifx
This seems to be for large objects which I don't deal with.
Is this related? how do I get rid of it?
-----Original Message-----
From: Fernando Nunes
Sent: Sunday, September 21, 2014 4:44 PM
To: ids@iiug.org
Subject: Re: not trusted [33834]
Somehow the Informix process doesn't see it self as that name... That's
easy to happen if you have multiple TCP interfaces (I assume you're
connecting through TCP).
It would be interesting to see your "sqlhosts" configuration.
The message cleary says that the server resolved the IP address from where
it's receiving the connection as "LastDitch.home" while the client software
thinks the hostname is the short name (LastDitch).
I honestly would have to test something.... Depending on the version,
Informix may require both of these to be "trusted"
You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc and
call it (for example) instance_trusts.
Inside that file put:
LastDitch.home informix
LastDitch informix
and change the REMOTE_SERVER_CFG parameter to that filename:
onmode -wf REMOTE_SERVER_CFG=instance_trusts
Then try to connect again.
Ideally you should solve your machine DNS issues... (or if you're not using
DNS, the equivalent file configuration)
Regards
On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> This was a fresh install.
> When I run ontape a I get:
> 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> Administrator@LastDitch.home[LastDitch]:
>
> Client host or user Administrator@LastDitch.home[LastDitch] is not
> trusted by
> the server.
>
> The finderr help file says:
> Client client-name or user is not trusted by the database server.
> The desired database server does not consider the client computer or your
> user
> ID trusted.
>
> This is on the server so is the client computer is the server.
> This happens with user Administrator and user Informix.
> They are both administrators on the server. Why would they not be
> trusted?
> How do I make them trusted?
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--047d7b10c847bcec7d05039a3bef
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
If you have a -951 error you should have a message in online.log. I'd like
to know what was it. It's probably a -956 or a -951.
Any error -951, -952 and -956 generates a -951 on the client side (for
security reasons we don't want to tell the client exactly what is the
problem).
For now ignore the mention to .netrc... it's not related to your problem.
As for that entry... "lo_ifx" is one of your server's ALIAS... check the
$ONCONFIG. Did you create an instance automatically during the installation?
Regards
On Mon, Sep 22, 2014 at 6:35 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> I set REMOTE_SERVER_CFG as you said and that error went away.
> Now when I run ontape -a I get this:
>
> Performing automatic backup of logical logs.
> could not fork server connection, SQLCODE -951
> Program over.
>
> The error 951 says:
> User username is not known on the database server.
> The database server that you tried to access does not accept either your
> user ID, the login name that is specified for the desired server host in
> your ~/.netrc file, or the user name that is specified in the USER clause
> of
> a CONNECT statement. If you are explicitly specifying your user name in the
> ~/.netrc file or in a CONNECT statement, check that the name is correct.
>
> Where is the .netrc file on Windows? in the registry?
> Also please note that my sqlhosts.[servicename] has a new line that I did
> not have on another install of 12.10c4:
> lo_ifx olsoctcp 127.0.0.1 lo_ifx>
> This seems to be for large objects which I don't deal with.
> Is this related? how do I get rid of it?
>
> -----Original Message-----
> From: Fernando Nunes
> Sent: Sunday, September 21, 2014 4:44 PM
> To: ids@iiug.org
> Subject: Re: not trusted [33834]
>
> Somehow the Informix process doesn't see it self as that name... That's
> easy to happen if you have multiple TCP interfaces (I assume you're
> connecting through TCP).
> It would be interesting to see your "sqlhosts" configuration.
> The message cleary says that the server resolved the IP address from where
> it's receiving the connection as "LastDitch.home" while the client software
> thinks the hostname is the short name (LastDitch).
> I honestly would have to test something.... Depending on the version,
> Informix may require both of these to be "trusted"
>
> You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc and
> call it (for example) instance_trusts.
>
> Inside that file put:
>
> LastDitch.home informix
> LastDitch informix
>
> and change the REMOTE_SERVER_CFG parameter to that filename:
>
> onmode -wf REMOTE_SERVER_CFG=instance_trusts>
> Then try to connect again.
> Ideally you should solve your machine DNS issues... (or if you're not using
> DNS, the equivalent file configuration)
>
> Regards
>
> On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon <garage_dba@verizon.net>
> wrote:
>
> > This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> > This was a fresh install.
> > When I run ontape a I get:
> > 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> > Administrator@LastDitch.home[LastDitch]:
> >
> > Client host or user Administrator@LastDitch.home[LastDitch] is not
> > trusted by
> > the server.
> >
> > The finderr help file says:
> > Client client-name or user is not trusted by the database server.
> > The desired database server does not consider the client computer or your
> > user
> > ID trusted.
> >
> > This is on the server so is the client computer is the server.
> > This happens with user Administrator and user Informix.
> > They are both administrators on the server. Why would they not be
> > trusted?
> > How do I make them trusted?
> >
> >
> >
> >
>
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
>
> --047d7b10c847bcec7d05039a3bef
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--047d7b10c8478312a90503aec228
For the -951 errors, try adding the following to your onconfig, make sure
you add a carriage return at the end of the line.
This helps for users connecting into the database server.
CHECKALLDOMAINSFORUSER 1
Jeff
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of
Fernando Nunes
Sent: Monday, September 22, 2014 5:14 PM
To: ids@iiug.org
Subject: Re: not trusted [33848]
If you have a -951 error you should have a message in online.log. I'd like
to know what was it. It's probably a -956 or a -951.
Any error -951, -952 and -956 generates a -951 on the client side (for
security reasons we don't want to tell the client exactly what is the
problem).
For now ignore the mention to .netrc... it's not related to your problem.
As for that entry... "lo_ifx" is one of your server's ALIAS... check the
$ONCONFIG. Did you create an instance automatically during the installation?
Regards
On Mon, Sep 22, 2014 at 6:35 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> I set REMOTE_SERVER_CFG as you said and that error went away.
> Now when I run ontape -a I get this:
>
> Performing automatic backup of logical logs.
> could not fork server connection, SQLCODE -951 Program over.
>
> The error 951 says:
> User username is not known on the database server.
> The database server that you tried to access does not accept either
> your user ID, the login name that is specified for the desired server
> host in your ~/.netrc file, or the user name that is specified in the
> USER clause of a CONNECT statement. If you are explicitly specifying
> your user name in the ~/.netrc file or in a CONNECT statement, check
> that the name is correct.
>
> Where is the .netrc file on Windows? in the registry?
> Also please note that my sqlhosts.[servicename] has a new line that I
> did not have on another install of 12.10c4:
> lo_ifx olsoctcp 127.0.0.1 lo_ifx>
> This seems to be for large objects which I don't deal with.
> Is this related? how do I get rid of it?
>
> -----Original Message-----
> From: Fernando Nunes
> Sent: Sunday, September 21, 2014 4:44 PM
> To: ids@iiug.org
> Subject: Re: not trusted [33834]
>
> Somehow the Informix process doesn't see it self as that name...
> That's easy to happen if you have multiple TCP interfaces (I assume
> you're connecting through TCP).
> It would be interesting to see your "sqlhosts" configuration.
> The message cleary says that the server resolved the IP address from
> where it's receiving the connection as "LastDitch.home" while the
> client software thinks the hostname is the short name (LastDitch).
> I honestly would have to test something.... Depending on the version,
> Informix may require both of these to be "trusted"
>
> You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc
> and call it (for example) instance_trusts.
>
> Inside that file put:
>
> LastDitch.home informix
> LastDitch informix
>
> and change the REMOTE_SERVER_CFG parameter to that filename:
>
> onmode -wf REMOTE_SERVER_CFG=instance_trusts>
> Then try to connect again.
> Ideally you should solve your machine DNS issues... (or if you're not
> using DNS, the equivalent file configuration)
>
> Regards
>
> On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon
> <garage_dba@verizon.net>
> wrote:
>
> > This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> > This was a fresh install.
> > When I run ontape a I get:
> > 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> > Administrator@LastDitch.home[LastDitch]:
> >
> > Client host or user Administrator@LastDitch.home[LastDitch] is not
> > trusted by the server.
> >
> > The finderr help file says:
> > Client client-name or user is not trusted by the database server.
> > The desired database server does not consider the client computer or
> > your user ID trusted.
> >
> > This is on the server so is the client computer is the server.
> > This happens with user Administrator and user Informix.
> > They are both administrators on the server. Why would they not be
> > trusted?
> > How do I make them trusted?
> >
> >
> >
> >
>
>
>
****************************************************************************
***
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
>
> --047d7b10c847bcec7d05039a3bef
>
>
>
>
****************************************************************************
***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
****************************************************************************
***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--047d7b10c8478312a90503aec228
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
The sqlhosts has this:
mystiq olsoctcp *LastDitch turbo
lo_ifx olsoctcp 127.0.0.1 lo_ifx
-----Original Message-----
From: Fernando Nunes
Sent: Sunday, September 21, 2014 4:44 PM
To: ids@iiug.org
Subject: Re: not trusted [33834]
Somehow the Informix process doesn't see it self as that name... That's
easy to happen if you have multiple TCP interfaces (I assume you're
connecting through TCP).
It would be interesting to see your "sqlhosts" configuration.
The message cleary says that the server resolved the IP address from where
it's receiving the connection as "LastDitch.home" while the client software
thinks the hostname is the short name (LastDitch).
I honestly would have to test something.... Depending on the version,
Informix may require both of these to be "trusted"
You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc and
call it (for example) instance_trusts.
Inside that file put:
LastDitch.home informix
LastDitch informix
and change the REMOTE_SERVER_CFG parameter to that filename:
onmode -wf REMOTE_SERVER_CFG=instance_trusts
Then try to connect again.
Ideally you should solve your machine DNS issues... (or if you're not using
DNS, the equivalent file configuration)
Regards
On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> This was a fresh install.
> When I run ontape a I get:
> 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> Administrator@LastDitch.home[LastDitch]:
>
> Client host or user Administrator@LastDitch.home[LastDitch] is not
> trusted by
> the server.
>
> The finderr help file says:
> Client client-name or user is not trusted by the database server.
> The desired database server does not consider the client computer or your
> user
> ID trusted.
>
> This is on the server so is the client computer is the server.
> This happens with user Administrator and user Informix.
> They are both administrators on the server. Why would they not be
> trusted?
> How do I make them trusted?
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--047d7b10c847bcec7d05039a3bef
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
I logged in as Informix and the 'not trusted' problems went away.
The lo_ifx service also does not show up in dbaccess when logged in as
administrator.
I don't know why the administrator account is broken.
Maybe IBM has not tested IDS on Windows Server 2012 R2 .
You asked about tcp.
When I boot to 2012 R2 the ipconfig/all gives :
Ethernet adapter vEthernet (Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet
Controller (NDIS 6.30) - Virtual Switch):
Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : Hyper-V Virtual Ethernet Adapter #2
Physical Address. . . . . . . . . : 90-2B-34-DA-11-43
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . :
fe80::249a:1b98:db32:5bb6%17(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.3(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Monday, September 22, 2014 8:02:24 PM
Lease Expires . . . . . . . . . . : Wednesday, September 24, 2014 8:02:24
PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 361769780
DHCPv6 Client DUID. . . . . . . . :
00-01-00-01-1A-22-F4-E9-90-2B-34-DA-11-43
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled
but when I boot to 2008 R2 (on same machine) I get this:
Ethernet adapter Local Area Connection 5:
Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : LD External
Physical Address. . . . . . . . . : 90-2B-34-DA-11-43
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . :
fe80::c95a:e67d:35d9:f50d%21(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.3(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Monday, September 22, 2014 7:31:39 AM
Lease Expires . . . . . . . . . . : Wednesday, September 24, 2014 7:31:38
AM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 361769780
DHCPv6 Client DUID. . . . . . . . :
00-01-00-01-18-FC-CA-44-90-2B-34-DA-11-43
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled
But I don't know what to make of the Virtual Switch.
Incidentally, there are no server aliases in the onconfig file.
The services file has
ifx 9088/tcp
lo_ifx 9090/tcp
mystiq_json 27017/tcp #JSON listener for
mystiq
turbo 9089/tcp #mystiq
The turbo service works fine for ODBC connections to informix from programs
on the same box.
I must have checked a box during install that caused the lo_ifx to be added.
It is in the services file and sqlhosts file and the registry under
sqlhosts.
How do I get rid of it?
-----Original Message-----
From: Fernando Nunes
Sent: Monday, September 22, 2014 5:13 PM
To: ids@iiug.org
Subject: Re: not trusted [33848]
If you have a -951 error you should have a message in online.log. I'd like
to know what was it. It's probably a -956 or a -951.
Any error -951, -952 and -956 generates a -951 on the client side (for
security reasons we don't want to tell the client exactly what is the
problem).
For now ignore the mention to .netrc... it's not related to your problem.
As for that entry... "lo_ifx" is one of your server's ALIAS... check the
$ONCONFIG. Did you create an instance automatically during the installation?
Regards
On Mon, Sep 22, 2014 at 6:35 PM, BillHatVerizon <garage_dba@verizon.net>
wrote:
> I set REMOTE_SERVER_CFG as you said and that error went away.
> Now when I run ontape -a I get this:
>
> Performing automatic backup of logical logs.
> could not fork server connection, SQLCODE -951
> Program over.
>
> The error 951 says:
> User username is not known on the database server.
> The database server that you tried to access does not accept either your
> user ID, the login name that is specified for the desired server host in
> your ~/.netrc file, or the user name that is specified in the USER clause
> of
> a CONNECT statement. If you are explicitly specifying your user name in
> the
> ~/.netrc file or in a CONNECT statement, check that the name is correct.
>
> Where is the .netrc file on Windows? in the registry?
> Also please note that my sqlhosts.[servicename] has a new line that I did
> not have on another install of 12.10c4:
> lo_ifx olsoctcp 127.0.0.1 lo_ifx>
> This seems to be for large objects which I don't deal with.
> Is this related? how do I get rid of it?
>
> -----Original Message-----
> From: Fernando Nunes
> Sent: Sunday, September 21, 2014 4:44 PM
> To: ids@iiug.org
> Subject: Re: not trusted [33834]
>
> Somehow the Informix process doesn't see it self as that name... That's
> easy to happen if you have multiple TCP interfaces (I assume you're
> connecting through TCP).
> It would be interesting to see your "sqlhosts" configuration.
> The message cleary says that the server resolved the IP address from where
> it's receiving the connection as "LastDitch.home" while the client
> software
> thinks the hostname is the short name (LastDitch).
> I honestly would have to test something.... Depending on the version,
> Informix may require both of these to be "trusted"
>
> You may easily workaround it by creating a file in %INFORMIXDIR%\\\\etc and
> call it (for example) instance_trusts.
>
> Inside that file put:
>
> LastDitch.home informix
> LastDitch informix
>
> and change the REMOTE_SERVER_CFG parameter to that filename:
>
> onmode -wf REMOTE_SERVER_CFG=instance_trusts>
> Then try to connect again.
> Ideally you should solve your machine DNS issues... (or if you're not
> using
> DNS, the equivalent file configuration)
>
> Regards
>
> On Sun, Sep 21, 2014 at 10:02 PM, BillHatVerizon <garage_dba@verizon.net>
> wrote:
>
> > This concerns on IDS12.10.TC4IE on windows server 2012 R2.
> > This was a fresh install.
> > When I run ontape a I get:
> > 17:09:36 listener-thread: err = -956: oserr = 0: errstr =
> > Administrator@LastDitch.home[LastDitch]:
> >
> > Client host or user Administrator@LastDitch.home[LastDitch] is not
> > trusted by
> > the server.
> >
> > The finderr help file says:
> > Client client-name or user is not trusted by the database server.
> > The desired database server does not consider the client computer or
> > your
> > user
> > ID trusted.
> >
> > This is on the server so is the client computer is the server.
> > This happens with user Administrator and user Informix.
> > They are both administrators on the server. Why would they not be
> > trusted?
> > How do I make them trusted?
> >
> >
> >
> >
>
>
>
*******************************************************************************
> >