dostats IDS 11.70
Posted in 2010
Topics: Error Codes & Troubleshooting, Security, Permissions & Auditing
Hello,
dostats no longer seems to work in IDS 11.70.
First there seems to be an issue with trusted contexts.
informix@dbhostname:~> dostats -d isent98
FAILED: Cannot connect to SMI DATABASE (@ol_dbhostname); error=-28021, isam=2
DatabaseError: SQLCODE -28021 in CONNECT: A trusted connection was not
established because a trusted context is not defined or enabled for the
specified authorization ID.
To work around this (considering this is a command I am trying to run on the
database server itself) I have done;
GRANT DBSECADM TO User;CREATE TRUSTED CONTEXT CTX1
BASED UPON CONNECTION USING SYSTEM AUTHID 'User'
ATTRIBUTES (ADDRESS 'dbhostnasme')
WITH USE FOR PUBLIC WITHOUT AUTHENTICATION
ENABLE;
I now get;
User@dbhostname:/opt/informix> dostats -d isent98
dostats_ng only supports IDS version 10.00 and later!
PS; I had to create the security context for the user 'User' as I couldn't
create a security context for informix!
What is the best/correct way to allow 'informix' to do what ever it wants when
coming from the local host?
Thanks in advance.
Andy.
The problem with trusted contexts occurs when:
(A) The program uses CONNECT and WITH CONCURRENT CONNECTIONS, and
(B) Was compiled with CSDK 3.50 or earlier, and
(C) Is run against CSDK 3.70.xC1
Iibraries.
This is a bug, and an awkward one. There are two immediate workarounds available:
1. Run programs compile with CSDK 3.50 with the CSDK 3.50 runtime (presumably in a separate INFORMIXDIr)m
2. Recompile the programs with CSDK 3.70.
There should be a fix in CSDK 3.70.xC2, but that may require another recompilation.
Unless you really want a Trusted Context (and you almost certainly don't in this context!),
Please DO NOT CREATE A TRUSTED CONTEXT to work around this bug.
Doing so exposes your DBMS to security violations.
JL
------Original Message------
From: ANDREW LEMIN
Sender: ids-bounces@iiug.org
To: ids@iiug.org
ReplyTo: ids@iiug.org
Subject: dostats IDS 11.70 [22195]
Sent: Dec 13, 2010 03:48
Hello,
dostats no longer seems to work in IDS 11.70.
First there seems to be an issue with trusted contexts.
informix@dbhostname:~> dostats -d isent98
FAILED: Cannot connect to SMI DATABASE (@ol_dbhostname); error=-28021, isam=2
DatabaseError: SQLCODE -28021 in CONNECT: A trusted connection was not
established because a trusted context is not defined or enabled for the
specified authorization ID.
To work around this (considering this is a command I am trying to run on the
database server itself) I have done;
GRANT DBSECADM TO User; CREATE TRUSTED CONTEXT CTX1
BASED UPON CONNECTION USING SYSTEM AUTHID 'User'
ATTRIBUTES (ADDRESS 'dbhostnasme')
WITH USE FOR PUBLIC WITHOUT AUTHENTICATION
ENABLE;
I now get;
User@dbhostname:/opt/informix> dostats -d isent98
dostats_ng only supports IDS version 10.00 and later!
PS; I had to create the security context for the user 'User' as I couldn't
create a security context for informix!
What is the best/correct way to allow 'informix' to do what ever it wants when
coming from the local host?
Thanks in advance.
Andy.
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Sent from my BlackBerry® smartphone, powered by CREDO Mobile.
You don't say?
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
IIUG Board of Directors (art@iiug.org)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Mon, Dec 13, 2010 at 11:41 AM, jonathan.leffler@gmail.com <
jonathan.leffler@gmail.com> wrote:
>
> The problem with trusted contexts occurs when:
> (A) The program uses CONNECT and WITH CONCURRENT CONNECTIONS, and
> (B) Was compiled with CSDK 3.50 or earlier, and
> (C) Is run against CSDK 3.70.xC1
> Iibraries.
>
> This is a bug, and an awkward one. There are two immediate workarounds available:
>
> 1. Run programs compile with CSDK 3.50 with the CSDK 3.50 runtime (presumably in a separate INFORMIXDIr)m
> 2. Recompile the programs with CSDK 3.70.
>
> There should be a fix in CSDK 3.70.xC2, but that may require another recompilation.
>
> Unless you really want a Trusted Context (and you almost certainly don't in this context!),
>
> Please DO NOT CREATE A TRUSTED CONTEXT to work around this bug.
>
> Doing so exposes your DBMS to security violations.
>
> JL
>
>
> ------Original Message------
> From: ANDREW LEMIN
> Sender: ids-bounces@iiug.org
> To: ids@iiug.org
> ReplyTo: ids@iiug.org
> Subject: dostats IDS 11.70 [22195]
> Sent: Dec 13, 2010 03:48
>
> Hello,
> dostats no longer seems to work in IDS 11.70.
>
> First there seems to be an issue with trusted contexts.
>
> informix@dbhostname:~> dostats -d isent98
> FAILED: Cannot connect to SMI DATABASE (@ol_dbhostname); error=-28021, isam=2
>
> DatabaseError: SQLCODE -28021 in CONNECT: A trusted connection was not
> established because a trusted context is not defined or enabled for the
> specified authorization ID.
>
> To work around this (considering this is a command I am trying to run on the
> database server itself) I have done;
>
> GRANT DBSECADM TO User; > CREATE TRUSTED CONTEXT CTX1
> BASED UPON CONNECTION USING SYSTEM AUTHID 'User'
> ATTRIBUTES (ADDRESS 'dbhostnasme')
> WITH USE FOR PUBLIC WITHOUT AUTHENTICATION
> ENABLE;
>
> I now get;
> User@dbhostname:/opt/informix> dostats -d isent98
> dostats_ng only supports IDS version 10.00 and later!
>
> PS; I had to create the security context for the user 'User' as I couldn't
> create a security context for informix!
> What is the best/correct way to allow 'informix' to do what ever it wants when
> coming from the local host?
>
> Thanks in advance.
> Andy.
>
>
> *******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
>
> Sent from my BlackBerry® smartphone, powered by CREDO Mobile.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--001636c5b15bc9294e04974d6ca4
Dostats works fine on my 11.70 instance as informix or any user with proper
privileges. At any rate, at the point where this error occured, dostats was
just connecting to the server which requires no privileges at all except to
be a valid user on the system (or have a trusted context). Can you run:
dbaccess - -
> CONNECT TO '@ol_dbhostname';
?? as user 'informix'?? On my server it looks like this:
$ echo $INFORMIXSERVER
my_1170_server
art@galadriel-ii:~/SharedDocuments/Latest Art's Stuff/myschema.d$ dbaccess -
-
> connect to '@my_1170_server';
Connected.
>
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
IIUG Board of Directors (art@iiug.org)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Mon, Dec 13, 2010 at 6:48 AM, ANDREW LEMIN <a_lemin@hotmail.com> wrote:
> Hello,
> dostats no longer seems to work in IDS 11.70.
>
> First there seems to be an issue with trusted contexts.
>
> informix@dbhostname:~> dostats -d isent98
> FAILED: Cannot connect to SMI DATABASE (@ol_dbhostname); error=-28021,
> isam=2
>
> DatabaseError: SQLCODE -28021 in CONNECT: A trusted connection was not
> established because a trusted context is not defined or enabled for the
> specified authorization ID.
>
> To work around this (considering this is a command I am trying to run on
> the
> database server itself) I have done;
>
> GRANT DBSECADM TO User;> CREATE TRUSTED CONTEXT CTX1
> BASED UPON CONNECTION USING SYSTEM AUTHID 'User'
> ATTRIBUTES (ADDRESS 'dbhostnasme')
> WITH USE FOR PUBLIC WITHOUT AUTHENTICATION
> ENABLE;
>
> I now get;
> User@dbhostname:/opt/informix> dostats -d isent98
> dostats_ng only supports IDS version 10.00 and later!
>
> PS; I had to create the security context for the user 'User' as I couldn't
> create a security context for informix!
> What is the best/correct way to allow 'informix' to do what ever it wants
> when
> coming from the local host?
>
> Thanks in advance.
> Andy.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--001636c5afe92c0d5304974d7ea9
Apologies for the Base-64 message - not sure what happened yet...
Resent with a few typos fixed.
---------- Forwarded message ----------
From: <jonathan.leffler@gmail.com>
Date: Mon, Dec 13, 2010 at 08:40
Subject: Re: dostats IDS 11.70 [22195]
To: ids@iiug.org
The problem with trusted contexts occurs when:
(A) The program uses CONNECT and WITH CONCURRENT CONNECTIONS, and
(B) Was compiled with CSDK 3.50 or earlier, and
(C) Is run against CSDK 3.70.xC1 Iibraries.
This is a bug, and an awkward one. There are two immediate workarounds
available:
1. Run programs compile with CSDK 3.50 with the CSDK 3.50 runtime
(presumably in a separate INFORMIXDIR).
2. Recompile the programs with CSDK 3.70.
There should be a fix in CSDK 3.70.xC2, but that may require another
recompilation.
Unless you really want a Trusted Context (and you almost certainly don't in
this context!):
Please DO NOT CREATE A TRUSTED CONTEXT to work around this bug.
JL
------Original Message------
From: ANDREW LEMIN
Sender: ids-bounces@iiug.org
To: ids@iiug.org
ReplyTo: ids@iiug.org
Subject: dostats IDS 11.70 [22195]
Sent: Dec 13, 2010 03:48
Hello,
dostats no longer seems to work in IDS 11.70.
First there seems to be an issue with trusted contexts.
informix@dbhostname:~> dostats -d isent98
FAILED: Cannot connect to SMI DATABASE (@ol_dbhostname); error=-28021,
isam=2
DatabaseError: SQLCODE -28021 in CONNECT: A trusted connection was not
established because a trusted context is not defined or enabled for the
specified authorization ID.
To work around this (considering this is a command I am trying to run on the
database server itself) I have done;
GRANT DBSECADM TO User;CREATE TRUSTED CONTEXT CTX1
BASED UPON CONNECTION USING SYSTEM AUTHID 'User'
ATTRIBUTES (ADDRESS 'dbhostnasme')
WITH USE FOR PUBLIC WITHOUT AUTHENTICATION
ENABLE;
I now get;
User@dbhostname:/opt/informix> dostats -d isent98
dostats_ng only supports IDS version 10.00 and later!
PS; I had to create the security context for the user 'User' as I couldn't
create a security context for informix!
What is the best/correct way to allow 'informix' to do what ever it wants
when
coming from the local host?
Thanks in advance.
Andy.
--
Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h>
Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org
"Blessed are we who can laugh at ourselves, for we shall never cease to be
amused."
--001636c5afe911f6d4049751cd64