Re: -952 Authentication Error on Solaris 10
Posted in 2009
> -----Original Message-----
> From: informix-list-bounces@iiug.org
> [mailto:informix-list-bounces@iiug.org]On Behalf Of Fernando Nunes
> Sent: Saturday, March 28, 2009 3:34 AM
> To: informix-list@iiug.org
> Subject: Re: -952 Authentication Error on Solaris 10
>
>
> Ian Michael Gumby wrote:
> > On Mar 27, 8:17 pm, Fernando Nunes <domusonl...@gmail.com> wrote:
> >> nate...@kc.rr.com wrote:
> >>> On Mar 27, 7:59 am, "Habichtsberg, Reinhard" <RHabichtsb...@arz-
> >>> emmendingen.de> wrote:
> >>>> Hallo Nate,
> >>>> You have .rhosts or hosts.equiv set up? AFAIK they are
> needed with ssh to.
> >>>> Regards
> >>>> Reinhard
> >>>>> -----Original Message-----
> >>>>> From: informix-list-boun...@iiug.org
> >>>>> [mailto:informix-list-boun...@iiug.org]On Behalf Of
> nate...@kc.rr.com
> >>>>> Sent: Friday, March 27, 2009 1:39 PM
> >>>>> To: informix-l...@iiug.org
> >>>>> Subject: Re: -952 Authentication Error on Solaris 10
> >>>>> On Mar 27, 5:44 am, superbo...@t-online.de wrote:
> >>>>>> Hello Nate,
> >>>>>> maybe oninit does not have suid bits set or is not
> owned by root??
> >>>>>> eq
> >>>>>> -rwsr-sr-- 1 root informix
> >>>>>> Superboer.
> >>>>>> On 27 mrt, 00:53, wcottishpoet <drybur...@yahoo.com> wrote:
> >>>>>>> No idea what the problem is but IDS 9.40 will not be
> >>>>> supported by IBM
> >>>>>>> after next month
> >>>>>>> Do you have plans to upgrade to IDS 11?
> >>>>> Permissions on oninit are correct.
> >>>>> I know IDS9 is on the way out, and we're certifying IDS
> 11.5 right
> >>>>> now, but that's still going to be several months out.
> >>>>> Thanks,
> >>>>> Nate
> >>>>> _______________________________________________
> >>>>> Informix-list mailing list
> >>>>> Informix-l...@iiug.org
> >>>>> http://www.iiug.org/mailman/listinfo/informix-list
> >>> Reinhard
> >>> These files are not set up on the functioning production server. I
> >>> tried adding a hosts.equiv on the test server, but it
> didn't get rid
> >>> of the error.
> >>> Thanks,
> >>> Nate
> >> Those files are used for "implicit" connections. Not for
> explicit (using
> >> password) connections.
> >>
> >> Regards.
> >>
> >> --
> >> Fernando Nunes
> >> Portugal
> >
> > And you should never, ever use them except in a very controlled
> > environment. Hosts.equiv that is. NEVER EVER USE .rhosts, or
> > ALLOW .rhosts ON YOUR SYSTEMS. But then again, you're probably too
> > young to know who Morris was or who his father was.... ;-)
> >
> > (Sort of like never pointing a gun at someone unless its loaded and
> > you intend to pull the trigger if necessary.)
> >
>
> As usual, we're getting completely off-topic... but...
> You don't need to be hanging on a tree to know who/what the
> "missing link"
> was... As such, people younger than you surely have heard
> about or have read
> about the internet worm... and precisely because of that, I
> went digging...
> As it happens very often, you're confusing
> .rhosts/hosts.equiv with the
> services that use them. If you care about a safe environment
> than turn off the
> services... the files per si are just that... files.
> The worm used the r* commands to spread inside the networks, and
> sendmail/finger to spread across networks. It actually took
> advantage of a
> buffer overflow issue in sendmail/finger... it become so well
> know, probably
> because it was the first one to spread in such a large
> scale... not because it
> does anything special (at the time it might have been, but
> today it's just a
> trivial attack).
>
> In short: you can use the files for Informix, if your r*
> services are not
> running. Also, Informix does allow configuration options in
> order to look for
> only one of the files or both.
>
> Regards.
>
> --
> Fernando Nunes
> Portugal
Glad you explained about this. I was confused about the services and the
files myself since recently. And yes, it's for implicte connections so my
hint wasn't adaquate.
Regard,
Reinhard.