Connecting to a remote server
Posted in 2013
John wanted a Linux IDS 11.7 server to accept connections from an AIX client without supplying a password. Advice covered: installing CSDK/iConnect on the client, matching sqlhosts and /etc/services entries, and using REMOTE_SERVER_CFG in the onconfig (rather than hosts.equiv/.rhosts) for trusted connections, plus GRANT CONNECT for non-informix users. He hit -908, then -951/-387 errors while debugging ports, listeners and telnet tests. Resolution: with help from Paul at Oninit, the cause turned out to be an errant .netrc entry; connections then worked.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Migration, Import/Export & Data Conversion, Platform-Specific Issues
I have a Linux box set up with IDS 11.7 on it, and a database which has been
loaded using dbimport is on it. I want to be able to connect to it from
another AIX box. Is this possible? Do I have to have identical UIDs on both
boxes? Or do I have to have a corresponding user account on the Linux box? The
IDS version on the Linux box is identical to the AIX box.
See notes below:
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, Jan 17, 2013 at 3:50 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> I have a Linux box set up with IDS 11.7 on it, and a database which has
> been
> loaded using dbimport is on it. I want to be able to connect to it from
> another AIX box. Is this possible?
Absolutely. On the AIX box, you need either the iConnect or CSDK module
installed. If you have an Informix engine installed there then the CSDK is
installed along with it as a default (unless you manually deselected it at
install time). If not, iConnect and CSDK are free products you can
download from the IBM Web site, or download the free Innovator Edition for
AIX and go to custom install and deselect everything except iConnect or
CSDK (both are included). Then you just need to copy over your sqlhosts
file from the Linux
> Do I have to have identical UIDs on both
> boxes? Or do I have to have a corresponding user account on the Linux box?
> The
>
In order to connect from one machine to the other without using an id and
password, the usernames have to be the same and the machines have to have a
reciprocal trusted relationship. If you are connecting to the remote (ie
Linux) server using login and password, then the local UID/username can be
different. The username on the remote server does not have to be
login-able (ie it does not have to have a shell defined) but it must have a
home directory that is writable by the username that is connecting. The
remote user on the server side does not even need a valid password if you
are connecting using the trusted relationship and not username and
password. (See the USER and USING clauses of the CONNECT statement for
details.)
>
IDS version on the Linux box is identical to the AIX box.
>
OK, so you should be good to go. If you try to connect and are getting
errors, either report them to the forums and we will help (chances are
we've seen them all long ago) or open a PMR with IBM.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae93408c145672804d3828e1c
We want to be able to connect without logging in. I think this may have to do with a trusted host, and I'm not that familiar with the setup on that. I am Googling as I speak.
Check out the /etc/hosts.equiv and <home>/.rhosts files. Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Thu, Jan 17, 2013 at 4:31 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu > wrote: > We want to be able to connect without logging in. I think this may have to > do > with a trusted host, and I'm not that familiar with the setup on that. I am > Googling as I speak. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --14dae934077f68e0db04d3838507
Check the host.equiv in both servers /etc/hosts (include the i.p. adress)
/etc/hosts.equiv (include the host name that you want to connect) Edit
sqlhosts file, the reference servicetcp onsoctcp 192.x.x.x servicetcp
Check the connectionselect * from server@servicetcp:table_name
> To: ids@iiug.org
> From: john.callicotte@ottawa.edu
> Subject: Connecting to a remote server [29292]
> Date: Thu, 17 Jan 2013 15:50:48 -0500
>
> I have a Linux box set up with IDS 11.7 on it, and a database which has been
> loaded using dbimport is on it. I want to be able to connect to it from
> another AIX box. Is this possible? Do I have to have identical UIDs on both
> boxes? Or do I have to have a corresponding user account on the Linux box?
The
> IDS version on the Linux box is identical to the AIX box.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Art,
I apologize to go against your recommendation, but the OP has 11.7. In that
case forget about /etc/hosts.equiv and ~/.rhosts.
Just use REMOTE_SERVER_CFG parameter in $ONCONFIG. It should be a file name
that you need to create in $INFORMIXDIR/etc. The usage is just the same as
with the other files:
remote_server_name remote_user
Keep in mind that on new versions you probably have to include two lines if
the result of "hostname" run on the remote server name is different from
the result of the reverse DNS of the remote server IP address, run on the
database server.
For example, if you get a message in your online.log saying something like
"-956 user REMOTE_USER@reverse_dns.domain.name[RESULT_OF_HOSTNAME] you'd
need the two following lines:
reverse_dns.domain.name REMOTE_USER
RESULT_OF_HOSTNAME REMOTE_USER
(with this error, you'll get a -951 error on the client)
REMOTE_SERVER_CFG can be changed dinamically with:
onmode -wf REMOTE_SERVER_CFG=file_name
Regards
On Thu, Jan 17, 2013 at 10:29 PM, Art Kagel <art.kagel@gmail.com> wrote:
> Check out the /etc/hosts.equiv and <home>/.rhosts files.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> other organization with which I am associated either explicitly,
> implicitly, or by inference. Neither do those opinions reflect those of
> other individuals affiliated with any entity with which I am affiliated nor
> those of the entities themselves.
>
> On Thu, Jan 17, 2013 at 4:31 PM, JOHN CALLICOTTE <
> john.callicotte@ottawa.edu
> > wrote:
>
> > We want to be able to connect without logging in. I think this may have
> to
> > do
> > with a trusted host, and I'm not that familiar with the setup on that. I
> am
> > Googling as I speak.
> >
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --14dae934077f68e0db04d3838507
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--f46d04339ce4fa2c5d04d383bffb
Don't apologize. I'm hidebound and forget about some of the newer features.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Thu, Jan 17, 2013 at 5:45 PM, Fernando Nunes <domusonline@gmail.com>wrote:
> Art,
> I apologize to go against your recommendation, but the OP has 11.7. In that
> case forget about /etc/hosts.equiv and ~/.rhosts.
> Just use REMOTE_SERVER_CFG parameter in $ONCONFIG. It should be a file name
> that you need to create in $INFORMIXDIR/etc. The usage is just the same as
> with the other files:
>
> remote_server_name remote_user
>
> Keep in mind that on new versions you probably have to include two lines if
> the result of "hostname" run on the remote server name is different from
> the result of the reverse DNS of the remote server IP address, run on the
> database server.
> For example, if you get a message in your online.log saying something like
> "-956 user REMOTE_USER@reverse_dns.domain.name[RESULT_OF_HOSTNAME] you'd
> need the two following lines:
>
> reverse_dns.domain.name REMOTE_USER
> RESULT_OF_HOSTNAME REMOTE_USER
>
> (with this error, you'll get a -951 error on the client)
> REMOTE_SERVER_CFG can be changed dinamically with:
>
> onmode -wf REMOTE_SERVER_CFG=file_name>
> Regards
>
> On Thu, Jan 17, 2013 at 10:29 PM, Art Kagel <art.kagel@gmail.com> wrote:
>
> > Check out the /etc/hosts.equiv and <home>/.rhosts files.
> >
> > Art
> >
> > Art S. Kagel
> > Advanced DataTools (www.advancedatatools.com)
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own opinions
> > and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> > other organization with which I am associated either explicitly,
> > implicitly, or by inference. Neither do those opinions reflect those of
> > other individuals affiliated with any entity with which I am affiliated
> nor
> > those of the entities themselves.
> >
> > On Thu, Jan 17, 2013 at 4:31 PM, JOHN CALLICOTTE <
> > john.callicotte@ottawa.edu
> > > wrote:
> >
> > > We want to be able to connect without logging in. I think this may have
> > to
> > > do
> > > with a trusted host, and I'm not that familiar with the setup on that.
> I
> > am
> > > Googling as I speak.
> > >
> > >
> > >
> > >
> >
> >
>
>
*******************************************************************************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --14dae934077f68e0db04d3838507
> >
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
>
> --f46d04339ce4fa2c5d04d383bffb
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae9340ca3be61dc04d384a7b9
I have done all of that, but get:
908: Attempt to connect to database server (istartrain, conerr=-931, oserr=0)
failed.
I can rlogin into the remote server just fine.
908 means you're trying to connect to a port/IP that has no Informix
listener running...
Maybe if you can show us the $INFORMIXSQLHOSTS on the server and client...?
On Fri, Jan 18, 2013 at 1:46 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> I have done all of that, but get:
>
> 908: Attempt to connect to database server (istartrain, conerr=-931,
> oserr=0)
> failed.>
> I can rlogin into the remote server just fine.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--bcaec501624146051804d39068ea
Here is the client's sqlhost:
uwin2 onsoctcp uwin2 istarcars2
uwin2_shm onipcshm uwin2 uwin2
istarcars onsoctcp uwin2 istarcars
ksotinfx01 onsoctcp ksotinfx01 istartrain2
ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
istartrain onsoctcp ksotinfx01 istartrain
Here is the server's:
ksotinfx01 onsoctcp ksotinfx01 istartrain2
ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
istartrain onsoctcp ksotinfx01 istartrain
I have a quick start guide at my blog informix-dba.com that might be helpful
for you if you're setting up Informix for the first time.
http://www.informix-dba.com/p/informix-innovator-c-quick-start-guide.html
I try to walk you through step by step everything you need to do to get the
engine running for the first time.
If you find any steps missing or find something confusing, let me know and
I'll make a change.
Andrew
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of JOHN
CALLICOTTE
Sent: Friday, January 18, 2013 7:53 AM
To: ids@iiug.org
Subject: Re: RE: Connecting to a remote server [29308]
Here is the client's sqlhost:
uwin2 onsoctcp uwin2 istarcars2
uwin2_shm onipcshm uwin2 uwin2
istarcars onsoctcp uwin2 istarcars
ksotinfx01 onsoctcp ksotinfx01 istartrain2 ksotinfx01_shm onipcshm
ksotinfx01 ksotinfx01 istartrain onsoctcp ksotinfx01 istartrain
Here is the server's:
ksotinfx01 onsoctcp ksotinfx01 istartrain2 ksotinfx01_shm onipcshm
ksotinfx01 ksotinfx01 istartrain onsoctcp ksotinfx01 istartrain
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
Hmmm.... there is nothing evidently wrong with these (unless I'm missing
something). Let's go step by step:
Server:
ksotinfx01 onsoctcp ksotinfx01 istartrain2
ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
istartrain onsoctcp ksotinfx01 istartrain
Client:
ksotinfx01 onsoctcp ksotinfx01 istartrain2
ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
istartrain onsoctcp ksotinfx01 istartrain
They seem equal... But:
1- the names "istartrain2" and "istartrain" have the same values in
/etc/services on both machines?
2- The hostname ksotinfx01 resolves exactly to the same IP address on both
machines?
3- Your $INFORMIXSERVER variable on the client is setup to "ksotinfx01" or
"istartrain"?
4- The engine was up, and the listener was up (onstat -g ntt) when you
tried it?
5- Remote clients cannot connect through shared memory (there is no memory
shared between machines)
6- Instead of the port names (istartrain2 and istartrain) you can use real
port numbers. It's a question of personal choice. I don't see the advantage
of using names.... Unless the /etc/services is somehow shared (or you're
using a service like NIS)
As a side note, if it's possible try to include some context (previous
messages) in your emails... It helps.
Regards.
On Fri, Jan 18, 2013 at 1:52 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> Here is the client's sqlhost:
>
> uwin2 onsoctcp uwin2 istarcars2
> uwin2_shm onipcshm uwin2 uwin2
> istarcars onsoctcp uwin2 istarcars
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
> Here is the server's:
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--20cf307abe454350e504d3908b4f
OK,
what do you have in the following files :
$INFORMIXDIR/etc/sqlhosts
$INFORMIXDIR/etc/$ONCONFIG
/etc/services
/etc/inet/hosts
Regards,
Jacques
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of JOHN
CALLICOTTE
Sent: Friday, January 18, 2013 2:47 PM
To: ids@iiug.org
Subject: Re: RE: Connecting to a remote server [29306]
I have done all of that, but get:
908: Attempt to connect to database server (istartrain, conerr=-931, oserr=0)
failed.
I can rlogin into the remote server just fine.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
That would be a great idea. I believe Eric Herber also has something in
http://www.informix-zone.com
Regards.
On Fri, Jan 18, 2013 at 1:59 PM, Andrew Ford <andrew@informix-dba.com>wrote:
> I have a quick start guide at my blog informix-dba.com that might be
> helpful
> for you if you're setting up Informix for the first time.
>
> http://www.informix-dba.com/p/informix-innovator-c-quick-start-guide.html
>
> I try to walk you through step by step everything you need to do to get the
> engine running for the first time.
>
> If you find any steps missing or find something confusing, let me know and
> I'll make a change.
>
> Andrew
>
> -----Original Message-----
> From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of JOHN
> CALLICOTTE
> Sent: Friday, January 18, 2013 7:53 AM
> To: ids@iiug.org
> Subject: Re: RE: Connecting to a remote server [29308]
>
> Here is the client's sqlhost:
>
> uwin2 onsoctcp uwin2 istarcars2
> uwin2_shm onipcshm uwin2 uwin2
> istarcars onsoctcp uwin2 istarcars>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2 ksotinfx01_shm onipcshm
> ksotinfx01 ksotinfx01 istartrain onsoctcp ksotinfx01 istartrain
>
> Here is the server's:
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2 ksotinfx01_shm onipcshm
> ksotinfx01 ksotinfx01 istartrain onsoctcp ksotinfx01 istartrain
>
>
> ****************************************************************************
> ***
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--bcaec54eede8b29bfc04d3908fcc
I will assume you are using INFORMIXSERVER set to "ksotinfx01" ( the
ksotinfx01_shm connection will not work remotely). Did you define the
service name, istartrain2, in the /etc/services file on the client?
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Fri, Jan 18, 2013 at 8:52 AM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> Here is the client's sqlhost:
>
> uwin2 onsoctcp uwin2 istarcars2
> uwin2_shm onipcshm uwin2 uwin2
> istarcars onsoctcp uwin2 istarcars
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
> Here is the server's:
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--14dae93408c14bf68404d390f637
Sorry for the delay. I got pulled off on something else.
Answers:
1- the names "istartrain2" and "istartrain" have the same values in
/etc/services on both machines?
A#1: I only have istartrain2 on my client machine's services, but it is the
same port as the server.
2- The hostname ksotinfx01 resolves exactly to the same IP address on both
machines?
A#2: Yes
3- Your $INFORMIXSERVER variable on the client is setup to "ksotinfx01" or
"istartrain"?
A#3: ksotinfx01
4- The engine was up, and the listener was up (onstat -g ntt) when you
tried it?
A#4:
IBM Informix Dynamic Server Version 11.70.FC4 -- On-Line -- Up 00:00:50 --4336728 Kbytes
global network information:
#netscb connects read write q-free q-limits q-exceed alloc/max
9/ 9 0 0 0 0/ 0 240/ 10 0/ 0 0/ -1
Individual thread network information (times):
netscb thread name sid open read write address
5238cbb8 28 10:05:04
50a53cb8 27 10:05:04
50a57cb8 26 10:05:04
50a3bcb8 soctcplst 7 10:04:58 ksotinfx01|istartrain|soctcp
50a37cb8 soctcplst 6 10:04:58 ksotinfx01|istartrain2|soctcp
50a33cb8 soctcppoll 5 10:04:58
50a2dcc8 soctcppoll 4 10:04:58
50a2bcb8 soctcppoll 3 10:04:58
50a25cb8 soctcppoll 2 10:04:58
5- Remote clients cannot connect through shared memory (there is no memory
shared between machines)
A#5: OK. I removed the reference from the client's sqlhosts file
6- Instead of the port names (istartrain2 and istartrain) you can use real
port numbers. It's a question of personal choice. I don't see the advantage
of using names.... Unless the /etc/services is somehow shared (or you're
using a service like NIS)
sqlhosts:
ksotinfx01 onsoctcp ksotinfx01 istartrain2
ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
istartrain onsoctcp ksotinfx01 istartrain
onconf.cars: Too long to post here, but I emailed it to you.
/etc/services:
istartrain 38001/tcp # Port for istar connection
istartrain2 38002/tcp # Port for istar connection
The /etc/inet/hosts file doesn't exist.
I am also using the REMOTE stuff that someone recommended on here:
REMOTE_SERVER_CFG "remote.host"
REMOTE_USERS_CFG "remote.users"
S6_USE_REMOTE_SERVER_CFG 1
remote.host has the name of the client, and remote.users has my username in it.
Do my informix UIDs need to be the same on both boxes? They aren't at the moment.
On Fri, Jan 18, 2013 at 4:06 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> Sorry for the delay. I got pulled off on something else.
>
> Answers:
>
> 1- the names "istartrain2" and "istartrain" have the same values in
> /etc/services on both machines?
> A#1: I only have istartrain2 on my client machine's services, but it is the
> same port as the server.
>
Are you sure? In that case how does it start the listener on that port on
the database server?
> 2- The hostname ksotinfx01 resolves exactly to the same IP address on both
> machines?
> A#2: Yes
>
> 3- Your $INFORMIXSERVER variable on the client is setup to "ksotinfx01" or
> "istartrain"?
> A#3: ksotinfx01
>
> 4- The engine was up, and the listener was up (onstat -g ntt) when you
> tried it?
> A#4:
>
> IBM Informix Dynamic Server Version 11.70.FC4 -- On-Line -- Up 00:00:50 --> 4336728 Kbytes
>
> global network information:
> #netscb connects read write q-free q-limits q-exceed alloc/max
>
> 9/ 9 0 0 0 0/ 0 240/ 10 0/ 0 0/ -1
>
> Individual thread network information (times):
>
> netscb thread name sid open read write address
>
> 5238cbb8 28 10:05:04
>
> 50a53cb8 27 10:05:04
>
> 50a57cb8 26 10:05:04
>
> 50a3bcb8 soctcplst 7 10:04:58 ksotinfx01|istartrain|soctcp
>
> 50a37cb8 soctcplst 6 10:04:58 ksotinfx01|istartrain2|soctcp
>
>
Here we have the two TCP ports... It would be interesting to try the
following:
nestat -a | grep istartrain
On the database server machine. It should report two entries in "LISTEN".
Using the port numbers you could also:
netstat -an | grep -e PORT_NUMBER_OF_istartrain -e
PORT_NUMBER_OF_istartrain2
This should show you the IP address...
Then on the client machine run:
telnet ksotinfx01 PORT_NUMBER_OF_istartrain
If it doesn't connect you have a TCP/firewall problem.
If it connects, and you still have the 908 error than you have a
configuration issue on the client side...
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--bcaec54eede8db4fdd04d393f5a1
On Fri, Jan 18, 2013 at 4:14 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> sqlhosts:
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
> onconf.cars: Too long to post here, but I emailed it to you.
>
> /etc/services:
>
> istartrain 38001/tcp # Port for istar connection
> istartrain2 38002/tcp # Port for istar connection
>
> The /etc/inet/hosts file doesn't exist.
>
> I am also using the REMOTE stuff that someone recommended on here:
>
> REMOTE_SERVER_CFG "remote.host"
> REMOTE_USERS_CFG "remote.users"
> S6_USE_REMOTE_SERVER_CFG 1>
Wrong...:
1- Remove the quotes (not sure if they will cause problems, but they're not
needed
2- Ignore REMOTE_USERS_CFG. The practical use is exactly the same as
REMOTE_SERVER_CFG (baically a redundancy)3- Ignore S6_USE_REMOTE_SERVER_CFG. It's mean for environment with
replication dedicated ports (tells the engine to use REMOTE_SERVER_CFG for
those ports also - typically they'd use $INFORMIXDIR/etc/hosts.equiv)
>
> remote.host has the name of the client, and remote.users has my username in
> it.
>
Wrong:
1- Both these files should use exactly the setup I explained a few answers
ago:
remote_server remote_user
But all this is important once you have a -956 error on the server side
online.log and a -951 error on the client side.
While you have -908 you're not reaching the database listener.
Regards
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--f46d043be17c880da904d394143a
No. Regards On Fri, Jan 18, 2013 at 5:46 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu > wrote: > Do my informix UIDs need to be the same on both boxes? They aren't at the > moment. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --20cf307cffccdc7e9304d3941b65
What happens if you telnet the port on the machine ? you should see an 401
in the online.log - if you don't then you are not listening on that port, or
at least informix isn't
-----Original Message-----
From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of
Fernando Nunes
Sent: Friday, January 18, 2013 12:14 PM
To: ids@iiug.org
Subject: Re: RE: RE: Connecting to a remote server [29320]
On Fri, Jan 18, 2013 at 4:14 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu
> wrote:
> sqlhosts:
>
> ksotinfx01 onsoctcp ksotinfx01 istartrain2
> ksotinfx01_shm onipcshm ksotinfx01 ksotinfx01
> istartrain onsoctcp ksotinfx01 istartrain>
> onconf.cars: Too long to post here, but I emailed it to you.
>
> /etc/services:
>
> istartrain 38001/tcp # Port for istar connection
> istartrain2 38002/tcp # Port for istar connection
>
> The /etc/inet/hosts file doesn't exist.
>
> I am also using the REMOTE stuff that someone recommended on here:
>
> REMOTE_SERVER_CFG "remote.host"
> REMOTE_USERS_CFG "remote.users"
> S6_USE_REMOTE_SERVER_CFG 1>
Wrong...:
1- Remove the quotes (not sure if they will cause problems, but they're not
needed
2- Ignore REMOTE_USERS_CFG. The practical use is exactly the same as
REMOTE_SERVER_CFG (baically a redundancy)3- Ignore S6_USE_REMOTE_SERVER_CFG. It's mean for environment with
replication dedicated ports (tells the engine to use REMOTE_SERVER_CFG for
those ports also - typically they'd use $INFORMIXDIR/etc/hosts.equiv)
>
> remote.host has the name of the client, and remote.users has my username
in
> it.
>
Wrong:
1- Both these files should use exactly the setup I explained a few answers
ago:
remote_server remote_user
But all this is important once you have a -956 error on the server side
online.log and a -951 error on the client side.
While you have -908 you're not reaching the database listener.
Regards
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--f46d043be17c880da904d394143a
****************************************************************************
***
Forum Note: Use "Reply" to post a response in the discussion forum.
I made the changes you described, and still nothing. I am not getting any errors from this in my client's log.
I get "12:41:15 listener-thread: err = -27001: oserr = 0: errstr = : Read error occurred during connection attempt." On my client screen I had: Trying... Connected to ksotinfx01.ottawa.edu. Escape character is '^]'. Connection closed.
Everything looks fine. The ports are being listened to.
I am wondering if I have a bad installation of Informix. Will it overwrite my configuration if I reinstall?
nope -------------------------------------------------- From: "JOHN CALLICOTTE" <john.callicotte@ottawa.edu> Sent: Friday, January 18, 2013 2:52 PM To: <ids@iiug.org> Subject: Re: Connecting to a remote server [29326] > I am wondering if I have a bad installation of Informix. Will it overwrite > my > configuration if I reinstall? > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
maker sure you have a copy of existing onconfig file. Frank On Fri, Jan 18, 2013 at 3:17 PM, Dan Mueller <danmueller71@comcast.net>wrote: > nope > > -------------------------------------------------- > From: "JOHN CALLICOTTE" <john.callicotte@ottawa.edu> > Sent: Friday, January 18, 2013 2:52 PM > To: <ids@iiug.org> > Subject: Re: Connecting to a remote server [29326] > > > I am wondering if I have a bad installation of Informix. Will it > overwrite > > my > > configuration if I reinstall? > > > > > > > > ******************************************************************************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --20cf3071d16af327e804d3960106
Here is something interesting: client name: uwin2 server name: ksotinfx01 When I am logged in on the client as callj, and do "database train@ksotinfx01" I get "387: No connect permission. 111: ISAM error: no record found." When I am logged in on the client as informix, and do the same SQL I get "951: Incorrect password or user informix@uwin2.ottawa.edu[uwin2] is not known on the database server." Why is it wrapping around on the server? This is really getting confusing.
Something else interesting: I can connect as callj from the client if I connect explicitly to the ksotinfx01 server, and put my password in.
Login as informix first, grant connect or grant resource to public or.... whatever you like in the database. Make sure you use the right passwd of the acount in the server box. Frank On Fri, Jan 18, 2013 at 3:41 PM, JOHN CALLICOTTE <john.callicotte@ottawa.edu > wrote: > Here is something interesting: > > client name: uwin2 > server name: ksotinfx01 > > When I am logged in on the client as callj, and do "database > train@ksotinfx01" > I get "387: No connect permission. 111: ISAM error: no record found." > > When I am logged in on the client as informix, and do the same SQL I get > "951: > Incorrect password or user informix@uwin2.ottawa.edu[uwin2] is not known > on > the database server." > > Why is it wrapping around on the server? This is really getting confusing. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --047d7b676e6eae5cf904d3968b56
John,
Here is my checklist for trusted connection troubleshooting (from years of
dealing with it not working)
1 - verify /etc/services is setup on both servers
2 - verify sqlhosts is right on both servers
3 - verify either /etc/hosts has your target server name, or DNS is setup
properly (ie...you can PING your server)
4 - verify hosts.equiv (or the 11.7 equivalent) is setup properly
5 - verify rlogin works at the command line if you are using server level
trusted
6 - verify user aliasing is setup in the engine if you are using logins on a
client that don't exist on the server
7 - test logging in both directions from dbaccess. Use the informix userid and
use the "Connect" option, don't enter a user or password (just hit enter).
This should work if trusted is setup right
If it still doesn't work, start looking at firewall level port issues. SUSE
11.2 Enterprise comes with the thing on, and it is very, very aggressive. You
have to open your port specifically....best to turn it off until you are ready
to go to production...then turn it on and figure out how to make
communications work.
and as previously mentioned...if it works for informix and not other users, you need to "GRANT CONNECT" to the other user. Informix (and root when a root install was done) get connect automatically to the server.
I spent quite a bit of the afternoon with Paul from Oninit, and we got the connection working. Mainly, it was due to an errant .netrc entry. Thanks, Paul!! You were extremely helpful.