dbaccess connection via script.
Posted in 2013
Topics: Stored Procedures & SPL, Server Administration, Security, Permissions & Auditing
OS: Windows 2000
IDS: 9.40.TC1
We are getting this error when the application server is trying to execute
DBaccess from their scripts. The user logs in with the ID rptadmin with the OS
password, but uses the same ID rptadmin with a different password to connect
to the remote server and receiving the following error. Is there a location in
informix, OS, or registry that will contain/maintain the remote host password
for dbaccess to use.
20:59:21 Maximum server connections 16
21:00:35 listener-thread: err = -956: oserr = 2: errstr =
(rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>): Client
host or user
(rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>) is not
trusted by the server.
System error = 2.
Thanks,
********************************************************************************
**********
Ernie Knox
Sr. Technical Specialist, I&TG - IT Operations & Governance
Sears Holdings Management Corp
3333 Beverly Rd.
Hoffman Estates, IL. 60179
Office: (847) 286-5735
Email: Ernest.Knox@searshc.com<mailto:Ernest.Knox@searshc.com>
Blackberry:
2244650553@messaging.sprintpcs.com<mailto:2244650553@messaging.sprintpcs.com>
Informix Email: ifmxdba@searshc.com<mailto:ifmxdba@searshc.com> and Team:
InformixDBA@searshc.com<mailto:InformixDBA@searshc.com>
Informix Primary:
INFORMIXDBAPrimaryPager@searshc.com<mailto:INFORMIXDBAPrimaryPager@searshc.com>
Informix Secondary:
INFORMIXDBASecondaryPager@searshc.com<mailto:INFORMIXDBASecondaryPager@searshc.c
om>
MySQL Email: MYSQLDBAe@searshc.com<mailto:MYSQLDBAe@searshc.com> and Team:
MySQLDBA2@searshc.com<mailto:MySQLDBA2@searshc.com>
MySQL Primary:
MYSQLDBAPrimaryPager@searshc.com<mailto:MYSQLDBAPrimaryPager@searshc.com>
MySQL Secondary:
MYSQLDBASecondaryPager@searshc.com<mailto:MYSQLDBASecondaryPager@searshc.com>
For more information, view our DBA Wiki page link below:
http://wiki.intra.sears.com/confluence/display/TechStrag/Database+Management#Dat
abaseManagement<http://wiki.intra.sears.com/confluence/display/TechStrag/Databas
e+Management>
" Yes we can make a Change! "
" It's always a great day to watch Sports: FOOTBALL "
GSU
MISSION:
" The focus of my life begins at home with family, loved ones, and friends. I
want to use my resources to create a
secure environment that fosters love, learning, laughter, and mutual success.
I will protect and value integrity. I
will admit and quickly correct my mistakes. I will be a self-starter. I will
be a caring person. I will be a good listener
with an open mind. I will continue to grow and learn. I will facilitate and
celebrate the success of others. "
********************************************************************************
**********
This message, including any attachments, is the property of Sears Holdings
Corporation and/or one of its subsidiaries. It is confidential and may contain
proprietary or legally privileged information. If you are not the intended
recipient, please delete it without reading the contents. Thank you.
On Sun, Feb 24, 2013 at 2:08 PM, Knox, Ernest <Ernest.Knox@searshc.com>wrote:
> OS: Windows 2000
> IDS: 9.40.TC1
>
> We are getting this error when the application server is trying to execute
> DBaccess from their scripts. The user logs in with the ID rptadmin with
> the OS
> password, but uses the same ID rptadmin with a different password to
> connect
> to the remote server and receiving the following error. Is there a
> location in
> informix, OS, or registry that will contain/maintain the remote host
> password
> for dbaccess to use.
> 20:59:21 Maximum server connections 16
> 21:00:35 listener-thread: err = -956: oserr = 2: errstr =
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>):
> Client
> host or user
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>) is not
> trusted by the server.
> System error = 2.
>
AFAIK, DB-Access has no provision to allow you to specify the password
programmatically it expects the password to be typed in. This is good
for security; it is not so good for practical purposes.
Except that you're using Windows, you could consider SQLCMD; it has a
variety of mechanisms of greater or lesser security for providing the
password (command line arguments if you don't care; in the SQL script; in a
file that should be readable only by the user). However, I've not ported
SQLCMD to Windows for a number of years so, while I've not gone out of my
way to break Windows compatibility, it probably won't be trivial to port.
All else apart, I expect to use C99 on occasion, and Windows (MSVC) does
not support C99. It also has a number of other most peculiar attitudes to
code that is not native to Windows.
You could perhaps extract the relevant code for your own derivative code.
--
Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
Guardian of DBD::Informix - v2013.0118 - http://dbi.perl.org
"Blessed are we who can laugh at ourselves, for we shall never cease to be
amused."
--047d7b67098f3789d604d684a22a
Ernest,
You will need to create a trust relationship between your 2 servers. See the
extract below from the Informix documentation.
Good luck.
The hosts.equiv file
The hosts.equiv file lists the remote hosts
and users that are trusted by the computer on which the database server
is located. Trusted users, and users who log-in from trusted hosts,
can access the computer without supplying a password. The operating
system uses the hosts.equiv file to determine
whether a user is allowed access to the computer without specifying
a password. IBM® Informix® requires
a hosts.equiv file for its default authentication
policy.
If a client application supplies an invalid account name and password,
the database server rejects the connection even if the hosts.equiv file
contains an entry for the client computer. You must use the hosts.equiv file
only for client applications that do not supply a user account or
password. On UNIX, the hosts.equiv file
is in the /etc directory. On Windows, the hosts.equiv file
is in the \\\\%WINDIR%\\\\system32\\\\drivers\\\\etc directory.
If you do not have a hosts.equiv file, you must
create one.
On some networks, the host name that a remote host uses to connect
to a particular computer might not be the same as the host name that
the computer uses to refer to itself. For example, the network host
name might contain the fully qualified domain name (FQDN), as in the
following example:
> To: ids@iiug.org
> From: Ernest.Knox@searshc.com
> Subject: dbaccess connection via script. [29585]
> Date: Sun, 24 Feb 2013 17:08:38 -0500
>
> OS: Windows 2000
> IDS: 9.40.TC1
>
> We are getting this error when the application server is trying to execute
> DBaccess from their scripts. The user logs in with the ID rptadmin with the
OS
> password, but uses the same ID rptadmin with a different password to connect
> to the remote server and receiving the following error. Is there a location
in
> informix, OS, or registry that will contain/maintain the remote host password
> for dbaccess to use.
> 20:59:21 Maximum server connections 16
> 21:00:35 listener-thread: err = -956: oserr = 2: errstr =
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>): Client
> host or user
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>) is not
> trusted by the server.
> System error = 2.
>
> Thanks,
>
>
********************************************************************************
**********
> Ernie Knox
> Sr. Technical Specialist, I&TG - IT Operations & Governance
> Sears Holdings Management Corp
> 3333 Beverly Rd.
> Hoffman Estates, IL. 60179
> Office: (847) 286-5735
> Email: Ernest.Knox@searshc.com<mailto:Ernest.Knox@searshc.com>
> Blackberry:
> 2244650553@messaging.sprintpcs.com<mailto:2244650553@messaging.sprintpcs.com>
> Informix Email: ifmxdba@searshc.com<mailto:ifmxdba@searshc.com> and Team:
> InformixDBA@searshc.com<mailto:InformixDBA@searshc.com>
> Informix Primary:
>
INFORMIXDBAPrimaryPager@searshc.com<mailto:INFORMIXDBAPrimaryPager@searshc.com>
> Informix Secondary:
>
INFORMIXDBASecondaryPager@searshc.com<mailto:INFORMIXDBASecondaryPager@searshc.c
om>
> MySQL Email: MYSQLDBAe@searshc.com<mailto:MYSQLDBAe@searshc.com> and Team:
> MySQLDBA2@searshc.com<mailto:MySQLDBA2@searshc.com>
> MySQL Primary:
> MYSQLDBAPrimaryPager@searshc.com<mailto:MYSQLDBAPrimaryPager@searshc.com>
> MySQL Secondary:
> MYSQLDBASecondaryPager@searshc.com<mailto:MYSQLDBASecondaryPager@searshc.com>
>
> For more information, view our DBA Wiki page link below:
>
>
http://wiki.intra.sears.com/confluence/display/TechStrag/Database+Management#Dat
abaseManagement<http://wiki.intra.sears.com/confluence/display/TechStrag/Databas
e+Management>
>
> " Yes we can make a Change! "
> " It's always a great day to watch Sports: FOOTBALL "
> GSU
> MISSION:
> " The focus of my life begins at home with family, loved ones, and friends. I
> want to use my resources to create a
> secure environment that fosters love, learning, laughter, and mutual success.
> I will protect and value integrity. I
> will admit and quickly correct my mistakes. I will be a self-starter. I will
> be a caring person. I will be a good listener
> with an open mind. I will continue to grow and learn. I will facilitate and
> celebrate the success of others. "
>
>
********************************************************************************
**********
>
> This message, including any attachments, is the property of Sears Holdings
> Corporation and/or one of its subsidiaries. It is confidential and may
contain
> proprietary or legally privileged information. If you are not the intended
> recipient, please delete it without reading the contents. Thank you.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
By coincidence, I was discussing this with a customer today who told me
that it can be done with dbaccess. The told me, showed me, and I tested it:
cat test.sql
--- start
CONNECT TO 'stores' USER 'informix' USING 'some_pass';
SELECT tabname FROM systables;--- end
dbaccess - test.sql
In interactive mode it does not work.
Be carefull with passwords written explicitly in scripts...
Regards
On Mon, Feb 25, 2013 at 4:04 AM, Jonathan Leffler <
jonathan.leffler@gmail.com> wrote:
> On Sun, Feb 24, 2013 at 2:08 PM, Knox, Ernest <Ernest.Knox@searshc.com
> >wrote:
>
> > OS: Windows 2000
> > IDS: 9.40.TC1
> >
> > We are getting this error when the application server is trying to
> execute
> > DBaccess from their scripts. The user logs in with the ID rptadmin with
> > the OS
> > password, but uses the same ID rptadmin with a different password to
> > connect
> > to the remote server and receiving the following error. Is there a
> > location in
> > informix, OS, or registry that will contain/maintain the remote host
> > password
> > for dbaccess to use.
> > 20:59:21 Maximum server connections 16
> > 21:00:35 listener-thread: err = -956: oserr = 2: errstr =
> > (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>):
> > Client
> > host or user
> > (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>) is
> not
> > trusted by the server.
> > System error = 2.
> >
>
> AFAIK, DB-Access has no provision to allow you to specify the password
> programmatically it expects the password to be typed in. This is good
> for security; it is not so good for practical purposes.
>
> Except that you're using Windows, you could consider SQLCMD; it has a
> variety of mechanisms of greater or lesser security for providing the
> password (command line arguments if you don't care; in the SQL script; in a
> file that should be readable only by the user). However, I've not ported
> SQLCMD to Windows for a number of years so, while I've not gone out of my
> way to break Windows compatibility, it probably won't be trivial to port.
> All else apart, I expect to use C99 on occasion, and Windows (MSVC) does
> not support C99. It also has a number of other most peculiar attitudes to
> code that is not native to Windows.
>
> You could perhaps extract the relevant code for your own derivative code.
>
> --
> Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
> Guardian of DBD::Informix - v2013.0118 - http://dbi.perl.org
> "Blessed are we who can laugh at ourselves, for we shall never cease to be
> amused."
>
> --047d7b67098f3789d604d684a22a
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--f46d043c7ca69ef7d404d6a86c19
On 24/02/13 22:08, Knox, Ernest wrote:
> OS: Windows 2000
> IDS: 9.40.TC1
>
> We are getting this error when the application server is trying to execute
> DBaccess from their scripts. The user logs in with the ID rptadmin with the
OS
> password, but uses the same ID rptadmin with a different password to connect
> to the remote server and receiving the following error. Is there a location
in
> informix, OS, or registry that will contain/maintain the remote host password
> for dbaccess to use.
> 20:59:21 Maximum server connections 16
> 21:00:35 listener-thread: err = -956: oserr = 2: errstr =
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>): Client
> host or user
> (rptadmin@shoautofin02.ds.com<mailto:rptadmin@shoautofin02.ds.com>) is not
> trusted by the server.
> System error = 2.
>
> Thanks,
If you want to provide a password to the CONNECT statement, you could use my
SQSL tool. It offers several ways to provide a password to the engine (prompt,
variables, result of a select, reading from file or pipe) and even from your
scripting tool of choice to SQSL (environmental variables, command line).
There is a win32 port that is actively maintained which sports a CLI and an
Aubit based curses interface. Details in sig.
--
Ciao,
Marco
______________________________________________________________________________
Marco Greco /UK /IBM Standard disclaimers apply!
Structured Query Scripting Language http://www.4glworks.com/sqsl.htm
4glworks http://www.4glworks.com
Informix on Linux http://www.4glworks.com/ifmxlinux.htm