PAM issue
Posted in 2012
Topics: Error Codes & Troubleshooting, Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Platform-Specific Issues
Fernando or other Experts,
How are you doing?
Build Version: 11.50.FC8
Build OS: Linux 2.6.9-34.ELsmp
We used your approach of PAM for our Likewise product (central user
account management)
http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam
-for.html
We successfully set up and tested in one standalone IDS server , all
are working perfectly! ( can be accessed on both server box and client
boxes!)
But, when we did the same setup on another IDS server ( this server
involves ER replication), it does not work. Basically, we can only
connect the PAM instance name in the database server box, NOT from other
client boxes . When we db access from other client box , it will wait
for a while and finally,
908: Attempt to connect to database server (nsofintpam_tcp) failed.
ISAM error: record is locked.
I attached both setups and hopefully you may have some suggestions.
Please let me know if you need more info.
Thanks,
Frank
Working one( standalone server):
/etc/pam.d/informix_pam_service:
auth required /lib64/security/pam_lsass.so
account required /lib64/security/pam_lsass.so
onconfig.nsofpal:
....
DBSERVERALIASES nsofpal,nsofpalpam_tcp
....
sqlhosts:
...
nsofpalpam_tcp onsoctcp stephanie-dat online9154
s=4,pam_serv=(informix_pam_service),pamauth=(password)
...
Nonworking one ( involves ER )
/etc/pam.d/informix_pam_service:
auth required /lib64/security/pam_lsass.so
account required /lib64/security/pam_lsass.so
onconfig.nsofint:
...
DBSERVERALIASES nsofint,nsofint_er,nsofintpam_tcp
....
sqlhosts:
...
g_nsofint group - - i=11
nsofint_er onsoctcp ivan-dat online9164
s=6,g=g_nsofintnsofint_tcp onsoctcp ivan-dat online9162 g=g_nsofint
nsofintpam_tcp onsoctcp ivan-dat online9168
s=4,pam_serv=(informix_pam_service),pamauth=(password)
nsofint onipcshm ivan-dat serviceint
...
--f46d0437463b0fd4cf04b88fedfc
Hmmm.... 908 is not a PAM error...
Please check the client SQLHOSTS configuration and network layer
connectivity (although I don't recommend this, you could try a telnet to
the Informix pam port....?)
Typically 908 happens when you're not connecting to the right place, or
that place is blocked...
Regards.
On Thu, Feb 9, 2012 at 11:04 PM, FRANK <yunyaoqu@gmail.com> wrote:
> Fernando or other Experts,
>
> How are you doing?
>
> Build Version: 11.50.FC8
> Build OS: Linux 2.6.9-34.ELsmp
>
> We used your approach of PAM for our Likewise product (central user
> account management)
>
>
>
>
http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam
-for.html
>
> We successfully set up and tested in one standalone IDS server , all
> are working perfectly! ( can be accessed on both server box and client
> boxes!)
>
> But, when we did the same setup on another IDS server ( this server
> involves ER replication), it does not work. Basically, we can only
> connect the PAM instance name in the database server box, NOT from other
> client boxes . When we db access from other client box , it will wait
> for a while and finally,
>
> 908: Attempt to connect to database server (nsofintpam_tcp) failed.
> ISAM error: record is locked.>
> I attached both setups and hopefully you may have some suggestions.
> Please let me know if you need more info.
>
> Thanks,
> Frank
>
> Working one( standalone server):
>
> /etc/pam.d/informix_pam_service:
>
> auth required /lib64/security/pam_lsass.so
> account required /lib64/security/pam_lsass.so
>
> onconfig.nsofpal:
> .....
> DBSERVERALIASES nsofpal,nsofpalpam_tcp
> .....
>
> sqlhosts:
> ....
> nsofpalpam_tcp onsoctcp stephanie-dat online9154
> s=4,pam_serv=(informix_pam_service),pamauth=(password)
> ....>
> Nonworking one ( involves ER )
>
> /etc/pam.d/informix_pam_service:
> auth required /lib64/security/pam_lsass.so
> account required /lib64/security/pam_lsass.so
>
> onconfig.nsofint:
> ....
> DBSERVERALIASES nsofint,nsofint_er,nsofintpam_tcp
> .....
>
> sqlhosts:
> ....
> g_nsofint group - - i=11
> nsofint_er onsoctcp ivan-dat online9164
> s=6,g=g_nsofint> nsofint_tcp onsoctcp ivan-dat online9162 g=g_nsofint
> nsofintpam_tcp onsoctcp ivan-dat online9168
> s=4,pam_serv=(informix_pam_service),pamauth=(password)
> nsofint onipcshm ivan-dat serviceint
> ....>
> --f46d0437463b0fd4cf04b88fedfc
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--0022158c0f295c8fe904b89ce3d9
Hey, Fernamdo!
Issue resolved!!
The port was blocked by firewall ( not in iptable ports)
After added the ports there, all flowed perfectly!
Thanks in Huge!
Frank
On Fri, Feb 10, 2012 at 9:24 AM, Fernando Nunes <domusonline@gmail.com>wrote:
> Hmmm.... 908 is not a PAM error...
> Please check the client SQLHOSTS configuration and network layer
> connectivity (although I don't recommend this, you could try a telnet to
> the Informix pam port....?)
>
> Typically 908 happens when you're not connecting to the right place, or
> that place is blocked...
>
> Regards.
>
> On Thu, Feb 9, 2012 at 11:04 PM, FRANK <yunyaoqu@gmail.com> wrote:
>
> > Fernando or other Experts,
> >
> > How are you doing?
> >
> > Build Version: 11.50.FC8
> > Build OS: Linux 2.6.9-34.ELsmp
> >
> > We used your approach of PAM for our Likewise product (central user
> > account management)
> >
> >
> >
> >
>
>
http://informix-technology.blogspot.com/2007/11/informix-user-authentication-pam
-for.html
> >
> > We successfully set up and tested in one standalone IDS server , all
> > are working perfectly! ( can be accessed on both server box and client
> > boxes!)
> >
> > But, when we did the same setup on another IDS server ( this server
> > involves ER replication), it does not work. Basically, we can only
> > connect the PAM instance name in the database server box, NOT from other
> > client boxes . When we db access from other client box , it will wait
> > for a while and finally,
> >
> > 908: Attempt to connect to database server (nsofintpam_tcp) failed.
> > ISAM error: record is locked.> >
> > I attached both setups and hopefully you may have some suggestions.
> > Please let me know if you need more info.
> >
> > Thanks,
> > Frank
> >
> > Working one( standalone server):
> >
> > /etc/pam.d/informix_pam_service:
> >
> > auth required /lib64/security/pam_lsass.so
> > account required /lib64/security/pam_lsass.so
> >
> > onconfig.nsofpal:
> > .....
> > DBSERVERALIASES nsofpal,nsofpalpam_tcp
> > .....
> >
> > sqlhosts:
> > ....
> > nsofpalpam_tcp onsoctcp stephanie-dat online9154
> > s=4,pam_serv=(informix_pam_service),pamauth=(password)
> > ....> >
> > Nonworking one ( involves ER )
> >
> > /etc/pam.d/informix_pam_service:
> > auth required /lib64/security/pam_lsass.so
> > account required /lib64/security/pam_lsass.so
> >
> > onconfig.nsofint:
> > ....
> > DBSERVERALIASES nsofint,nsofint_er,nsofintpam_tcp
> > .....
> >
> > sqlhosts:
> > ....
> > g_nsofint group - - i=11
> > nsofint_er onsoctcp ivan-dat online9164
> > s=6,g=g_nsofint> > nsofint_tcp onsoctcp ivan-dat online9162 g=g_nsofint
> > nsofintpam_tcp onsoctcp ivan-dat online9168
> > s=4,pam_serv=(informix_pam_service),pamauth=(password)
> > nsofint onipcshm ivan-dat serviceint
> > ....> >
> > --f46d0437463b0fd4cf04b88fedfc
> >
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
>
> --0022158c0f295c8fe904b89ce3d9
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--f46d040124e9fdcb3e04b89edca7