HDR setup issues pertaining to hosts.equiv
Posted in 2016
Topics: High Availability & Replication, Stored Procedures & SPL, Platform-Specific Issues, Versions, Editions & End-of-Life
Before testing Informix HDR to a new box (uxtest-drunix) I had setup HDR between two other boxes (uxdev-uxtest). I encountered a few issues setting up this (the uxtest-drunix HDR). One of the most persistent error I noted in the log was: 12:01:11 listener-thread: err = -956: oserr = 0: errstr = informix@uxtest.nikeseclp.com[uxtest]: Client host or user informix@uxtest.nikeseclp.com[uxtest] is not trusted by the server. I tracked it down to include the fully qualified hostname in the hosts.equiv file. So here are my questions: 1. Why was this not required with the uxdev-uxtest setup? What could be different with drunix? 2. Is it necessary to have hosts.equiv in $INFORMIXDIR/etc. I already have it in /etc. So is this new with version 12.10? 3. If I did not set REMOTE_SERVER_CFG hosts.equiv, would the complete hostename have to be in /etc/hosts.equiv? 4. Also, is this a new standard to have the full hostname (uxtest.nikeseclp.com) instead of 'uxtest'. 5. Would it not be a good idea for this to be indicated as a'Warning' in the log and then display the error message and fail the HDR? System Information for uxdev, uxtest, drunix: HP-UX B.11.31 U ia64 IBM Informix Dynamic Server Version 12.10.FC6 Thanks
Whether short name or fully qualified host name depends on DNS and=20 /etc/hosts configuration, and look up order. I would always add both short = name and fully qualified name to the trusted host file. Also trusted host file lookup order is REMOTE=5FSERVER=5FCFG, /etc/hosts.eq= uiv=20 and $INFORMIXDIR/etc/hosts.equiv(if sqlhost file record is configured with = s=3D6 option). So as a best practice I would configure REMOTE=5FSERVER=5FCFG and add both = short and fully qualified host name to the file. Thanks & Regards, Nagaraju From: "MURALI PAZHAYANNUR" <pmurali@ftportfolios.com> To: ids@iiug.org Date: 04/07/2016 02:39 PM Subject: HDR setup issues pertaining to hosts.equiv [36928] Sent by: ids-bounces@iiug.org Before testing Informix HDR to a new box (uxtest-drunix) I had setup HDR=20 between two other boxes (uxdev-uxtest). I encountered a few issues setting = up=20 this (the uxtest-drunix HDR). One of the most persistent error I noted in=20 the=20 log was:=20 12:01:11 listener-thread: err =3D -956: oserr =3D 0: errstr =3D=20 informix@uxtest.nikeseclp.com[uxtest]: Client host or user=20 informix@uxtest.nikeseclp.com[uxtest] is not trusted by the server.=20 I tracked it down to include the fully qualified hostname in the=20 hosts.equiv=20 file. So here are my questions:=20 1. Why was this not required with the uxdev-uxtest setup? What could be=20 different with drunix?=20 2. Is it necessary to have hosts.equiv in $INFORMIXDIR/etc. I already have = it=20 in /etc. So is this new with version 12.10?=20 3. If I did not set REMOTE=5FSERVER=5FCFG hosts.equiv, would the complete=20 hostename have to be in /etc/hosts.equiv?=20 4. Also, is this a new standard to have the full hostname=20 (uxtest.nikeseclp.com) instead of 'uxtest'.=20 5. Would it not be a good idea for this to be indicated as a'Warning' in=20 the=20 log and then display the error message and fail the HDR?=20 System Information for uxdev, uxtest, drunix:=20 HP-UX B.11.31 U ia64=20 IBM Informix Dynamic Server Version 12.10.FC6=20 Thanks=20 ***************************************************************************= ****=20 Forum Note: Use "Reply" to post a response in the discussion forum.=20
Current versions of Informix most probably validate two entries agains the trust file configurations: 1- The reverse DNS (or /etc/hosts file) name of the client IP address (this is what the server "sees" 2- The name sent by the client as the client sees itself These two entries are shown in the -956 error. And both have to be trusted. In a perfect workd they should be the same.... In many cases they aren't due to misconfiguration. The reason for this lies in an obscure security issue when connections without passwords are passing a connection manager. My understanding is that the "workaround" doesn't make them safe in any case... So,yes, if your systems are not perfectly configured you need to add both. The order is the already mentioned. I advise strongly to avoid using the systemfiles (/etc/hosts.equiv). It took us 25 or 30 years to solve this. Before customers would complain about it (in most cases without a practical reason), now that we solved it, customers ignore the fix ;) Regards. On Fri, Apr 8, 2016 at 1:12 AM, Nagaraju Inturi <nagaraju@us.ibm.com> wrote: > Whether short name or fully qualified host name depends on DNS and=20 > /etc/hosts configuration, and look up order. I would always add both short > = > > name and fully qualified name to the trusted host file. > Also trusted host file lookup order is REMOTE=5FSERVER=5FCFG, > /etc/hosts.eq= > uiv=20 > and $INFORMIXDIR/etc/hosts.equiv(if sqlhost file record is configured with > = > > s=3D6 option). > > So as a best practice I would configure REMOTE=5FSERVER=5FCFG and add both > = > > short and fully qualified host name to the file. > > Thanks & Regards, > Nagaraju > > From: "MURALI PAZHAYANNUR" <pmurali@ftportfolios.com> > To: ids@iiug.org > Date: 04/07/2016 02:39 PM > Subject: HDR setup issues pertaining to hosts.equiv [36928] > Sent by: ids-bounces@iiug.org > > Before testing Informix HDR to a new box (uxtest-drunix) I had setup HDR=20 > between two other boxes (uxdev-uxtest). I encountered a few issues setting > = > > up=20 > this (the uxtest-drunix HDR). One of the most persistent error I noted > in=20 > the=20 > log was:=20 > > 12:01:11 listener-thread: err =3D -956: oserr =3D 0: errstr =3D=20 > informix@uxtest.nikeseclp.com[uxtest]: Client host or user=20 > informix@uxtest.nikeseclp.com[uxtest] is not trusted by the server.=20 > > I tracked it down to include the fully qualified hostname in the=20 > hosts.equiv=20 > file. So here are my questions:=20 > > 1. Why was this not required with the uxdev-uxtest setup? What could be=20 > different with drunix?=20 > 2. Is it necessary to have hosts.equiv in $INFORMIXDIR/etc. I already have > = > > it=20 > in /etc. So is this new with version 12.10?=20 > 3. If I did not set REMOTE=5FSERVER=5FCFG hosts.equiv, would the > complete=20 > hostename have to be in /etc/hosts.equiv?=20 > 4. Also, is this a new standard to have the full hostname=20 > (uxtest.nikeseclp.com) instead of 'uxtest'.=20 > 5. Would it not be a good idea for this to be indicated as a'Warning' in=20 > the=20 > log and then display the error message and fail the HDR?=20 > > System Information for uxdev, uxtest, drunix:=20 > > HP-UX B.11.31 U ia64=20 > IBM Informix Dynamic Server Version 12.10.FC6=20 > > Thanks=20 > > > ***************************************************************************= > ****=20 > > Forum Note: Use "Reply" to post a response in the discussion forum.=20 > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --047d7bdca44ca22032052ff75eb4