Password Errors Flood
Posted in 2008
Topics: Security, Permissions & Auditing
Application servers are used in our environment to provide database connections to the informixservers. When the application universal connection account's password is changed, the Informix message log will be flooded with "password is not correct for the database server" messages indicating a mismatch between the application's stored password and that in /etc/shadow (usually due to erroneous implementation, or simple omission). The same occurs if an informixserver is bounced with no parallel halt & restart of the appserver. The upshot is an enormous, useless message log with the same error message repeated millions of times. Is there a way to halt the informixserver from reporting or repeating this message?
On 9 Dec, 15:35, "red_val...@yahoo.com" <red_val...@yahoo.com> wrote: > Application servers are used in our environment to provide database > connections to the informixservers. When the application universal > connection account's password is changed, the Informix message log > will be flooded with "password is not correct for the database server" > messages indicating a mismatch between the application's stored > password and that in /etc/shadow (usually due to erroneous > implementation, or simple omission). The same occurs if an > informixserver is bounced with no parallel halt & restart of the > appserver. The upshot is an enormous, useless message log with the > same error message repeated millions of times. > > Is there a way to halt the informixserver from reporting or repeating > this message? no
david@smooth1.co.uk wrote: > On 9 Dec, 15:35, "red_val...@yahoo.com" <red_val...@yahoo.com> wrote: >> Application servers are used in our environment to provide database >> connections to the informixservers. When the application universal >> connection account's password is changed, the Informix message log >> will be flooded with "password is not correct for the database server" >> messages indicating a mismatch between the application's stored >> password and that in /etc/shadow (usually due to erroneous >> implementation, or simple omission). The same occurs if an >> informixserver is bounced with no parallel halt & restart of the >> appserver. The upshot is an enormous, useless message log with the >> same error message repeated millions of times. >> >> Is there a way to halt the informixserver from reporting or repeating >> this message? > > no Yes. 1. Set up admin procedures for changing passwords and bouncing servers. Scripts for stop_services and start_services which implement stopping and starting Informix and appservers together would help. 2. Ensure the admins know these procedures and adhere to them. Anyone failing to do so gets the job of cleaning out the logs by hand ;-) 3. Prevent anyone else but the trained admins changing passwords and bouncing servers. In other words, do things right. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk