IDS with GSSAPI SSO
Posted in 2013
Pete McDonnell tried to set up Kerberos/GSSAPI single sign-on from Windows 7 clients to IDS 11.70 on RHEL 6.2 with an Active Directory KDC (SPN plus keytab, GSSCSM entry in concsm.cfg, s=7,csm=(GSSCSM) in sqlhosts). Connections failed with "5000: CSM error" and online log entries -14565 (CSS: error reading data) and -25582. Suggestions included disabling NS_CACHE (no effect), raising INFORMIXCONTIME/CONRETRY and NETTYPE pool sizes, and enabling Windows Kerberos event logging for debugging. The published docs covered only all-Unix or all-Windows setups, and no resolution is recorded in the thread.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Networking & sqlhosts Configuration
I have a scenario where I'm connecting to Informix using a GSSAPI login from a Windows 7 workstation to a RHEL6.2 server running IDS 11.70FC6GE (or 11.7FC5W1) The central authentication system is Active Directory on Windows Server 2008 R2. I'm intermittently getting Error 25590 (authentication error). (Yes, I can usually sign in and work in the DB fine - only intermittently is my connect/select, etc blocked with a 25590). Kerberos logins using winbind are already setup and working properly on the RHEL6.2 host. I can connect using GSSAPI from a Windows workstation successfully. I've started configuring the GSSAPI and Kerberos for IDS as per: http://www.ibm.com/developerworks/data/library/techarticle/dm-0809govindarajan/i ndex.html (adapting as best I can my my scenario) and specifically I've done the following: - created an SPN on the server (associated with a user account - associating with the machine account may not work from what I've read?) - merged the resulting keytab info into the primary keytab file on the RHEL6.2 system - configured a concsm.cfg in $INFORMIXDIR/etc with the following entry: GSSCSM("/path/to/informix.ids/lib/csm/igsss11a.so", "", "c=1, i=1") - added "s=7,csm=(GSSCSM)" to the end of my sqlhosts entry (for both client and server sqlhosts files) When I try to connect to the IDS instance with either a local account or a GSSAPI login session I'm not getting the following message: "5000: CSM error: " and I have the following errors in the online log: 10:55:49 listener-thread: err = -14565: oserr = 0: errstr = : CSS: error reading data. 10:55:51 listener-thread: err = -25582: oserr = 0: errstr = : Network connection is broken. which according to the referenced article is: "An authentication error will occur if the user trying to connect is not same as the user whose credential is in the Kerberos cache." While I continue to hack away at this I wanted to post this scenario to see if anyone else has faced a similar configuration and if anyone has any tips or tricks that they could share. Thanks, folks! Pete McDonnell
Hello.
I think your steps are just fine... so I would suggest you to disable your
NS_CACHE in Informix (11.70):
onmode -wm NS_CACHE=host=0,service=0,user=0,group=0
And test again, if everything is fine, you may want to restart your cache, to
avoid any possible issue.
Hope it helps.
Regards.
Alexandre Marini
IBM Informix Certified Professional v10 / v11.50 / v11.70
IBM Information Management Informix Technical Professional
IBM Infosphere DataStage Technical Professional
Informix Senior DBA - Orizon Brasil
BRIUG website administrator
Informix independent consultant
> To: ids@iiug.org
> From: pete.mcdonnell@ejustsystems.com
> Subject: IDS with GSSAPI SSO [30570]
> Date: Tue, 18 Jun 2013 11:57:04 -0400
>
> I have a scenario where I'm connecting to Informix using a GSSAPI login from
a
> Windows 7 workstation to a RHEL6.2 server running IDS 11.70FC6GE (or
> 11.7FC5W1) The central authentication system is Active Directory on Windows
> Server 2008 R2.
>
> I'm intermittently getting Error 25590 (authentication error). (Yes, I can
> usually sign in and work in the DB fine - only intermittently is my
> connect/select, etc blocked with a 25590).
>
> Kerberos logins using winbind are already setup and working properly on the
> RHEL6.2 host. I can connect using GSSAPI from a Windows workstation
> successfully.
>
> I've started configuring the GSSAPI and Kerberos for IDS as per:
>
http://www.ibm.com/developerworks/data/library/techarticle/dm-0809govindarajan/i
ndex.html
> (adapting as best I can my my scenario) and specifically I've done the
> following:
>
> - created an SPN on the server (associated with a user account - associating
> with the machine account may not work from what I've read?)
> - merged the resulting keytab info into the primary keytab file on the
RHEL6.2
> system
> - configured a concsm.cfg in $INFORMIXDIR/etc with the following entry:
> GSSCSM("/path/to/informix.ids/lib/csm/igsss11a.so", "", "c=1, i=1")
> - added "s=7,csm=(GSSCSM)" to the end of my sqlhosts entry (for both client
> and server sqlhosts files)
>
> When I try to connect to the IDS instance with either a local account or a
> GSSAPI login session I'm not getting the following message: "5000: CSM error:
> "
> and I have the following errors in the online log:
>
> 10:55:49 listener-thread: err = -14565: oserr = 0: errstr = : CSS: error
> reading data.
> 10:55:51 listener-thread: err = -25582: oserr = 0: errstr = : Network
> connection is broken.
>
> which according to the referenced article is: "An authentication error will
> occur if the user trying to connect is not same as the user whose credential
> is in the Kerberos cache."
>
> While I continue to hack away at this I wanted to post this scenario to see
if
> anyone else has faced a similar configuration and if anyone has any tips or
> tricks that they could share.
>
> Thanks, folks!
>
> Pete McDonnell
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Thank you very much for your suggestion, but unfortunately I have the same errors in the online log after making that change: 13:43:07 listener-thread: err = -14565: oserr = 0: errstr = : CSS: error reading data. 13:43:10 listener-thread: err = -25582: oserr = 0: errstr = : Network connection is broken.
Ok Pete, so it is not a cache issue. Have you seen this article? http://www.ibm.com/developerworks/data/library/techarticle/dm-0809govindarajan/ It explains some errors in single sign on use. Another thing: did you try to increase the INFORMIXCONTIME, and INFORMIXCONRETRY variables, in client side, as suggested by the error code 14565? Regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 IBM Information Management Informix Technical Professional IBM Infosphere DataStage Technical Professional Informix Senior DBA - Orizon Brasil BRIUG website administrator Informix independent consultant > To: ids@iiug.org > From: pete.mcdonnell@ejustsystems.com > Subject: Re: RE: IDS with GSSAPI SSO [30573] > Date: Tue, 18 Jun 2013 13:46:36 -0400 > > Thank you very much for your suggestion, but unfortunately I have the same > errors in the online log after making that change: > > 13:43:07 listener-thread: err = -14565: oserr = 0: errstr = : CSS: error > reading data. > 13:43:10 listener-thread: err = -25582: oserr = 0: errstr = : Network > connection is broken. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. >
Pete, another line of investigation:
How are your NETTYPE configurations? Could you post them here, with the
average number of simultaneous connections you have, in both instances?
That might be an issue if the engine cannot have time enough to validate users
+ too many users trying to connect.
A good report output would be the first "onstat -g ntt", see if there is some
q-exceed section....
Regards.
Alexandre Marini
IBM Informix Certified Professional v10 / v11.50 / v11.70
IBM Information Management Informix Technical Professional
IBM Infosphere DataStage Technical Professional
Informix Senior DBA - Orizon Brasil
BRIUG website administrator
Informix independent consultant
From: alexandre@briug.org
To: ids@iiug.org
Subject: RE: IDS with GSSAPI SSO [30573]
Date: Tue, 18 Jun 2013 15:02:04 -0300
Ok Pete, so it is not a cache issue.
Have you seen this article?
http://www.ibm.com/developerworks/data/library/techarticle/dm-0809govindarajan/
It explains some errors in single sign on use.
Another thing: did you try to increase the INFORMIXCONTIME, and
INFORMIXCONRETRY variables, in client side, as suggested by the error code
14565?
Regards.
Alexandre Marini
IBM Informix Certified Professional v10 / v11.50 / v11.70
IBM Information Management Informix Technical Professional
IBM Infosphere DataStage Technical Professional
Informix Senior DBA - Orizon Brasil
BRIUG website administrator
Informix independent consultant
> To: ids@iiug.org
> From: pete.mcdonnell@ejustsystems.com
> Subject: Re: RE: IDS with GSSAPI SSO [30573]
> Date: Tue, 18 Jun 2013 13:46:36 -0400
>
> Thank you very much for your suggestion, but unfortunately I have the same
> errors in the online log after making that change:
>
> 13:43:07 listener-thread: err = -14565: oserr = 0: errstr = : CSS: error
> reading data.
> 13:43:10 listener-thread: err = -25582: oserr = 0: errstr = : Network
> connection is broken.
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
I have reviewed the URL you referenced. Unfortunately it references a scenario
with everything running on Unix/Linux and a non-Windows KDC. I have been in
contact with IBM support (and continue to work with them). They provided me
with a document for Informix SSO with Windows, but it references a purely
Windows environment, where IDS is running on a Windows domain member server.
I'm in between those two scenarios :-)
I should mention that this is a lab system - there is no chance of running
into a problem with max connections :-)
For reference though, here is the output of the netstat -g ntt:
IBM Informix Dynamic Server Version 11.70.FC6GE -- On-Line -- Up 00:18:22 --1951804 Kbytes
global network information:
#netscb connects read write q-free q-limits q-exceed alloc/max
9/ 13 1 1 1 2/ 2 275/ 10 0/ 0 2/ 2
Individual thread network information (times):
netscb thread name sid open read write address
7faeee90dc90 30 15:10:19
7faef6c45b90 dbWorker2 28 15:10:06
7faeee8fdc90 dbWorker1 27 15:10:06
7faeee8e7c90 dbScheduler 26 15:10:06
7faeee8c3c90 sm_discon 7 15:10:02
7faeee8bdc90 sm_listen 5 15:10:02
7faeee8b7c90 soctcplst 4 15:10:02 15:10:19 myhostname|informixservername|soctcp
7faef6379cb0 sm_poll 3 15:10:02
7faeee8b1c90 soctcppoll 2 15:10:19
One other point - this has never worked on this system. This is a new
configuration that I am putting together, so I could very well be missing
something.
In the meantime, I've recreated the AD account that my SPN is linked to. IBM
Windows documentation show that account name is the same as the service name.
Do you know if that account *has* to be the same as the service name?
Thanks!
Ok maybe someone else could help you with this mix environment....
Meantime, I think you must be using a very small NETTYPE configuration.
Please see this technote, and adjust your settings, make at least a baseline,
and let some for shm in case that you need to speed up internal/administrative
tasks.
http://www-01.ibm.com/support/docview.wss?uid=swg21592040
I would suggest this:
NETTYPE ipcshm,1,50,CPU
NETTYPE soctcp,1,30,NET
Rebounce the instance, and see if it speed up your network traffic/engine
response ok?
Maybe some of our IBMer friends would suggest you to increment the pool size,
even more (maybe there would be a benefit in using more than 1 pool thread, in
your specific case).
Hope it helps.
Regards.
Alexandre Marini
IBM Informix Certified Professional v10 / v11.50 / v11.70
IBM Information Management Informix Technical Professional
IBM Infosphere DataStage Technical Professional
Informix Senior DBA - Orizon Brasil
BRIUG website administrator
Informix independent consultant
> To: ids@iiug.org
> From: pete.mcdonnell@ejustsystems.com
> Subject: Re: RE: IDS with GSSAPI SSO [30576]
> Date: Tue, 18 Jun 2013 15:35:20 -0400
>
> I have reviewed the URL you referenced. Unfortunately it references a
scenario
> with everything running on Unix/Linux and a non-Windows KDC. I have been in
> contact with IBM support (and continue to work with them). They provided me
> with a document for Informix SSO with Windows, but it references a purely
> Windows environment, where IDS is running on a Windows domain member server.
>
> I'm in between those two scenarios :-)
>
> I should mention that this is a lab system - there is no chance of running
> into a problem with max connections :-)
> For reference though, here is the output of the netstat -g ntt:
>
> IBM Informix Dynamic Server Version 11.70.FC6GE -- On-Line -- Up 00:18:22 --> 1951804 Kbytes
>
> global network information:
> #netscb connects read write q-free q-limits q-exceed alloc/max
>
> 9/ 13 1 1 1 2/ 2 275/ 10 0/ 0 2/ 2
>
> Individual thread network information (times):
>
> netscb thread name sid open read write address
>
> 7faeee90dc90 30 15:10:19
>
> 7faef6c45b90 dbWorker2 28 15:10:06
>
> 7faeee8fdc90 dbWorker1 27 15:10:06
>
> 7faeee8e7c90 dbScheduler 26 15:10:06
>
> 7faeee8c3c90 sm_discon 7 15:10:02
>
> 7faeee8bdc90 sm_listen 5 15:10:02
>
> 7faeee8b7c90 soctcplst 4 15:10:02 15:10:19
> myhostname|informixservername|soctcp
>
> 7faef6379cb0 sm_poll 3 15:10:02
>
> 7faeee8b1c90 soctcppoll 2 15:10:19
>
> One other point - this has never worked on this system. This is a new
> configuration that I am putting together, so I could very well be missing
> something.
>
> In the meantime, I've recreated the AD account that my SPN is linked to. IBM
> Windows documentation show that account name is the same as the service name.
> Do you know if that account *has* to be the same as the service name?
>
> Thanks!
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Check server side logs otherwise enable Kerberos event logging on the client
side, see
http://support.microsoft.com/kb/262177
http://technet.microsoft.com/en-us/library/cc738673%28v=ws.10%29.aspx
Pity we cannot get the Windows kerberos client source code and recompile with
our own debugging!
Regards,
David.
On 18 June 2013 at 20:35 PETE MCDONNELL <pete.mcdonnell@ejustsystems.com>
wrote:
> I have reviewed the URL you referenced. Unfortunately it references a
scenario
> with everything running on Unix/Linux and a non-Windows KDC. I have been in
> contact with IBM support (and continue to work with them). They provided me
> with a document for Informix SSO with Windows, but it references a purely
> Windows environment, where IDS is running on a Windows domain member server.
>
> I'm in between those two scenarios :-)
>
> I should mention that this is a lab system - there is no chance of running
> into a problem with max connections :-)
> For reference though, here is the output of the netstat -g ntt:
>
> IBM Informix Dynamic Server Version 11.70.FC6GE -- On-Line -- Up 00:18:22 --> 1951804 Kbytes
>
> global network information:
> #netscb connects read write q-free q-limits q-exceed alloc/max
>
> 9/ 13 1 1 1 2/ 2 275/ 10 0/ 0 2/ 2
>
> Individual thread network information (times):
>
> netscb thread name sid open read write address
>
> 7faeee90dc90 30 15:10:19
>
> 7faef6c45b90 dbWorker2 28 15:10:06
>
> 7faeee8fdc90 dbWorker1 27 15:10:06
>
> 7faeee8e7c90 dbScheduler 26 15:10:06
>
> 7faeee8c3c90 sm_discon 7 15:10:02
>
> 7faeee8bdc90 sm_listen 5 15:10:02
>
> 7faeee8b7c90 soctcplst 4 15:10:02 15:10:19
> myhostname|informixservername|soctcp
>
> 7faef6379cb0 sm_poll 3 15:10:02
>
> 7faeee8b1c90 soctcppoll 2 15:10:19
>
> One other point - this has never worked on this system. This is a new
> configuration that I am putting together, so I could very well be missing
> something.
>
> In the meantime, I've recreated the AD account that my SPN is linked to. IBM
> Windows documentation show that account name is the same as the service name.
> Do you know if that account *has* to be the same as the service name?
>
> Thanks!
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>