Accessing remote database table
Posted in 2010
A user querying tables on a remote IDS 10 server (Solaris 10) from an IDS 7.30 server suddenly began getting error -956 "Client host or user ... is not trusted by the server", despite no reported OS or Informix changes. Suggestions were to check the user's .rhosts file (existence, ownership, permissions) and /etc/hosts.equiv, and to compare the name in the online log with the .rhosts entry, since fully-qualified vs. short hostname mismatches caused by name-resolution order (/etc/netsvc.conf, missing /etc/hosts entry) can trigger this; engine restart is needed after such changes. The log showed an FQDN and the host was missing from /etc/hosts, but the thread records no confirmed fix.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Platform-Specific Issues, Versions, Editions & End-of-Life
I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com
Did he have .rhosts file in his home directory and are the permission and ownership correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:00 PM To: ids@iiug.org Subject: Accessing remote database table [20821] I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
I looked into the rhosts files and the SA said that it made no sense that those files would be the culprit because they haven't been changed for months. Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Link, David A Sent: Tuesday, August 10, 2010 4:10 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20822] Did he have .rhosts file in his home directory and are the permission and ownership correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:00 PM To: ids@iiug.org Subject: Accessing remote database table [20821] I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
Keith, Are you using /etc/hosts or DNS? Exactly what does your online log say for the 956 error? The reason that I ask is that one time we had .rhosts to trust a machine named for example, "atlas" and the error coming through in the online log was something to the effect of " err = -956: oserr = 0: errstr = jadams@atlas.xxx.xxx.com: Client host or user jadams@atlas.xxx.xxx.com is not trusted by the server. The entry in the rhosts was for atlas, not the fully qualified name.... which was being caused by an incorrectly configured /etc/netsvc.conf file. Since we use the /etc/hosts, the netsvc.conf file needs to have this stanza: hosts = local,bind So if you are using the /etc/hosts for resolution, make sure that your machine is still in /etc/hosts and that the stanza is there and you will have to bounce the engine to get the change to take effect, as that file is read in when the engine starts up. joe -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:13 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20823] I looked into the rhosts files and the SA said that it made no sense that those files would be the culprit because they haven't been changed for months. Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Link, David A Sent: Tuesday, August 10, 2010 4:10 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20822] Did he have .rhosts file in his home directory and are the permission and ownership correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:00 PM To: ids@iiug.org Subject: Accessing remote database table [20821] I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Joe, Here is what the Informix log says: 12:15:48 listener-thread: err = -956: oserr = 0: errstr = jsoude1@XXXXdbs.csc.XXXXX.com: Client host or user jsoude1@XXXXdbs.csc.XXXXX.com is not trusted by the server. It doesn't look like we have a netsvc.conf file on the server currently. The /etc/hosts file doesn't have the IP address for XXXXdbs.csc.XXXXX.com, so maybe that is the issue? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Plugge, Joe R. Sent: Tuesday, August 10, 2010 4:37 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20826] Keith, Are you using /etc/hosts or DNS? Exactly what does your online log say for the 956 error? The reason that I ask is that one time we had .rhosts to trust a machine named for example, "atlas" and the error coming through in the online log was something to the effect of " err = -956: oserr = 0: errstr = jadams@atlas.xxx.xxx.com: Client host or user jadams@atlas.xxx.xxx.com is not trusted by the server. The entry in the rhosts was for atlas, not the fully qualified name.... which was being caused by an incorrectly configured /etc/netsvc.conf file. Since we use the /etc/hosts, the netsvc.conf file needs to have this stanza: hosts = local,bind So if you are using the /etc/hosts for resolution, make sure that your machine is still in /etc/hosts and that the stanza is there and you will have to bounce the engine to get the change to take effect, as that file is read in when the engine starts up. joe -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:13 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20823] I looked into the rhosts files and the SA said that it made no sense that those files would be the culprit because they haven't been changed for months. Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Link, David A Sent: Tuesday, August 10, 2010 4:10 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20822] Did he have .rhosts file in his home directory and are the permission and ownership correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:00 PM To: ids@iiug.org Subject: Accessing remote database table [20821] I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
Sorry, I overlooked that you are using Solaris 10. Try having your sys admins add the entry in the /etc/hosts file for XXXXdbs.csc.XXXXX.com and see if that corrects the issue. You have verified that there is an entry for XXXXdbs.csc.XXXXX.com in the .rhosts file in ~jsoude1 , correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Wednesday, August 11, 2010 9:07 AM To: ids@iiug.org Subject: RE: Accessing remote database table [20835] Joe, Here is what the Informix log says: 12:15:48 listener-thread: err = -956: oserr = 0: errstr = jsoude1@XXXXdbs.csc.XXXXX.com: Client host or user jsoude1@XXXXdbs.csc.XXXXX.com is not trusted by the server. It doesn't look like we have a netsvc.conf file on the server currently. The /etc/hosts file doesn't have the IP address for XXXXdbs.csc.XXXXX.com, so maybe that is the issue? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Plugge, Joe R. Sent: Tuesday, August 10, 2010 4:37 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20826] Keith, Are you using /etc/hosts or DNS? Exactly what does your online log say for the 956 error? The reason that I ask is that one time we had .rhosts to trust a machine named for example, "atlas" and the error coming through in the online log was something to the effect of " err = -956: oserr = 0: errstr = jadams@atlas.xxx.xxx.com: Client host or user jadams@atlas.xxx.xxx.com is not trusted by the server. The entry in the rhosts was for atlas, not the fully qualified name.... which was being caused by an incorrectly configured /etc/netsvc.conf file. Since we use the /etc/hosts, the netsvc.conf file needs to have this stanza: hosts = local,bind So if you are using the /etc/hosts for resolution, make sure that your machine is still in /etc/hosts and that the stanza is there and you will have to bounce the engine to get the change to take effect, as that file is read in when the engine starts up. joe -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:13 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20823] I looked into the rhosts files and the SA said that it made no sense that those files would be the culprit because they haven't been changed for months. Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Link, David A Sent: Tuesday, August 10, 2010 4:10 PM To: ids@iiug.org Subject: RE: Accessing remote database table [20822] Did he have .rhosts file in his home directory and are the permission and ownership correct? -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Schleicher, Keith Sent: Tuesday, August 10, 2010 4:00 PM To: ids@iiug.org Subject: Accessing remote database table [20821] I have a user that is querying tables from a database from server B while logged onto server A. He previously had no problems with this, but now he is getting a not trusted error (956). Server A is running IDS 7.30.UC11 on Solaris 10. Server B is running IDS 10.00.UC6 on Solaris 10. I contacted the SA and he said that nothing has changed on the Solaris side. There haven't been any changes on the Informix side and he has the correct permissions assigned on the database. We aren't using the /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the user's home directory. Does anyone have any idea how this could work last week and then suddenly not work? Keith Schleicher IT Database Administrator B2-253B-A Office: 847-286-4027 Cell: 224-210-8358 Blackberry: 2242108358@messaging.sprintpcs.com Page: 2242108358@sprint.skytel.com ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Hello. Also check if the remote server is listed on your /etc/hosts.equiv file, ok? Regards! Em 11/08/2010 10:13, Plugge, Joe R. escreveu: > Sorry, I overlooked that you are using Solaris 10. > > Try having your sys admins add the entry in the /etc/hosts file for > XXXXdbs.csc.XXXXX.com and see if that corrects the issue. > > You have verified that there is an entry for XXXXdbs.csc.XXXXX.com in the > ..rhosts file in ~jsoude1 , correct? > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Schleicher, Keith > Sent: Wednesday, August 11, 2010 9:07 AM > To: ids@iiug.org > Subject: RE: Accessing remote database table [20835] > > Joe, > > Here is what the Informix log says: > > 12:15:48 listener-thread: err = -956: oserr = 0: errstr = > jsoude1@XXXXdbs.csc.XXXXX.com: Client host or user > jsoude1@XXXXdbs.csc.XXXXX.com is not trusted by the server. > > It doesn't look like we have a netsvc.conf file on the server currently. > The /etc/hosts file doesn't have the IP address for > XXXXdbs.csc.XXXXX.com, so maybe that is the issue? > > Keith Schleicher > IT Database Administrator > B2-253B-A > Office: 847-286-4027 > Cell: 224-210-8358 > Blackberry: 2242108358@messaging.sprintpcs.com > Page: 2242108358@sprint.skytel.com > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Plugge, Joe R. > Sent: Tuesday, August 10, 2010 4:37 PM > To: ids@iiug.org > Subject: RE: Accessing remote database table [20826] > > Keith, > > Are you using /etc/hosts or DNS? > > Exactly what does your online log say for the 956 error? The reason that > I ask > is that one time we had .rhosts to trust a machine named for example, > "atlas" > and the error coming through in the online log was something to the > effect of > " err = -956: oserr = 0: errstr = jadams@atlas.xxx.xxx.com: Client host > or > user jadams@atlas.xxx.xxx.com is not trusted by the server. > > The entry in the rhosts was for atlas, not the fully qualified name.... > which > was being caused by an incorrectly configured /etc/netsvc.conf file. > Since we > use the /etc/hosts, the netsvc.conf file needs to have this stanza: > > hosts = local,bind > > So if you are using the /etc/hosts for resolution, make sure that your > machine > is still in /etc/hosts and that the stanza is there and you will have to > > bounce the engine to get the change to take effect, as that file is read > in > when the engine starts up. > > joe > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Schleicher, Keith > Sent: Tuesday, August 10, 2010 4:13 PM > To: ids@iiug.org > Subject: RE: Accessing remote database table [20823] > > I looked into the rhosts files and the SA said that it made no sense > that those files would be the culprit because they haven't been changed > for months. > > Keith Schleicher > IT Database Administrator > B2-253B-A > Office: 847-286-4027 > Cell: 224-210-8358 > Blackberry: 2242108358@messaging.sprintpcs.com > Page: 2242108358@sprint.skytel.com > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Link, David A > Sent: Tuesday, August 10, 2010 4:10 PM > To: ids@iiug.org > Subject: RE: Accessing remote database table [20822] > > Did he have .rhosts file in his home directory and are the permission > and > ownership correct? > > -----Original Message----- > From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of > Schleicher, Keith > Sent: Tuesday, August 10, 2010 4:00 PM > To: ids@iiug.org > Subject: Accessing remote database table [20821] > > I have a user that is querying tables from a database from server B > while logged onto server A. He previously had no problems with this, > but now he is getting a not trusted error (956). > > Server A is running IDS 7.30.UC11 on Solaris 10. > > Server B is running IDS 10.00.UC6 on Solaris 10. > > I contacted the SA and he said that nothing has changed on the Solaris > side. There haven't been any changes on the Informix side and he has > the correct permissions assigned on the database. We aren't using the > /etc/hosts.equiv file. There doesn't seem to be a .netrc file in the > user's home directory. Does anyone have any idea how this could work > last week and then suddenly not work? > > Keith Schleicher > > IT Database Administrator > > B2-253B-A > > Office: 847-286-4027 > > Cell: 224-210-8358 > > Blackberry: 2242108358@messaging.sprintpcs.com > > Page: 2242108358@sprint.skytel.com > > ************************************************************************ > > ******* > Forum Note: Use "Reply" to post a response in the discussion forum. > > ************************************************************************ > > ******* > Forum Note: Use "Reply" to post a response in the discussion forum. > > ************************************************************************ > ******* > Forum Note: Use "Reply" to post a response in the discussion forum. > > ************************************************************************ > ******* > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Alexandre Marini Tecnologia da Informação - DBA SEFAZ-MS / SGI-UGSR / Sistemas IBM-Informix Cert-Info-Mgmt_color <Cert-Info-Mgmt_color.jpg> IBM Informix Dynamic Server Certified Professional V10 / V11