Error 951 in IDS 9.4
Posted in 2005
Topics: Installation, Setup & Upgrades, Storage & Space Management, Server Administration, Security, Permissions & Auditing, Logging & Checkpoints, Licensing & Editions, Versions, Editions & End-of-Life
Hi, i work with IDS 9.4 and work right
recently, but now when do oninit say this:
15:40:58 Event alarms enabled. ALARMPROG = '/usr/informix/etc/alarmprogram.sh'
15:40:58 Booting Language <c> from module <>
15:40:58 Loading Module <CNULL>
15:40:58 Booting Language <builtin> from module <>
15:40:58 Loading Module <BUILTINNULL>
15:41:04 Dynamically allocated new virtual shared memory segment (size 8192KB)
15:41:04 IBM Informix Dynamic Server Version 9.40.UC4 Software Serial Number
AAA#B000000
15:41:05 IBM Informix Dynamic Server Initialized -- Shared Memory Initialized.
15:41:05 Physical Recovery Started at Page (1:470).
15:41:05 Physical Recovery Complete: 0 Pages Examined, 0 Pages Restored.
15:41:05 Logical Recovery Started.
15:41:05 10 recovery worker threads will be started.
15:41:08 Logical Recovery has reached the transaction cleanup phase.
15:41:08 Logical Recovery Complete.
0 Committed, 0 Rolled Back, 0 Open, 0 Bad Locks
15:41:09 Dataskip is now OFF for all dbspaces
15:41:09 Checkpoint Completed: duration was 0 seconds.
15:41:09 Checkpoint loguniq 2579, logpos 0x2c1018, timestamp: 78963472
15:41:09 Maximum server connections 0
15:41:09 On-Line Mode
I find what the Maximum server connection is 0 because dead licence or the IDS
have bad configuration.
When i try connect with onmonitor, its say "WARNING: Network Down" Online
and when i try connect with dbacces say this:
951: Incorrect password or user informix is not known on the database server.
and the onstat -m say:
15:44:48 Get Shadow Password for user [informix] failed!
15:44:48 Check for password aging/account lock-out.
15:44:48 listener-thread: err = -951: oserr = 0: errstr = informix: Incorrect
password or user informix is not known on the database server.
The user and password its right, also the network, services, sqlhost and
enviroment variables
How i access the data whit re-install IDS?
Please helpme!
PD: Sorry for my bad english.
--
Open WebMail Project (http://openwebmail.org)
Hi,
are you sure that the password for the user in question
("informix") is in the file /etc/shadow ?
3 possibilities come to my mind:
- you are using Solaris (you don't mention OS and OS version)
and you are running into problem PTS-B 171594 :
If a user who is not known on the system atempts to connect, the
online.log
might show:
11:09:36 WARNING: mt_aio_wait: errno == EINVAL
11:09:36 Get Shadow Password for user [01001358] failed!
11:09:36 Check for password aging/account lock-out.
11:09:36 listener-thread: err = -951: oserr = 0: errstr = 01001358:
Incorrect
password or user 01001358 is not known on the database server.
This is a Solaris problem (so-called "Vendor bug"), which can be solved:
Please see the following email from SUN:
"Yes, it looks like 108993-27 fixed several issues by re-implementing
the
stdio file I/O functions, used by many of the libnsl (Naming Service
library) functions.
The intent is that this change to our implementation should be
transparent to you, so that errno would be set in the same cases where
it was before. However, bug 4915053 indicates that there are
times when
EINVAL is returned erroneously. This bug is fixed in:
Solaris 8 patch 108993-37 and higher
Solaris 9 update 7, patch 113319-18 and higher
Solaris 10 build 46 and higher
So, while it *might* be safe to assume that you can reset any EINVAL
returned from getspnam(), I recommend that you don't change your code.
Instead, it's actually a better idea to update the customer's patches
to
the ones listed above."
- the users password really is not in in /etc/shadow , but you
have deployed a different authentication method that is not
supported by IDS.
IDS natively supports only the generic UNIX password encryption
(using the system call "crypt()"), with the password either being
held in /etc/passwd, /etc/shadow or NIS/NIS+. All other methods
(encryption and/or place to keep encrypted password) are not
natively supported.
With IDS 9.40.xC2 and higher you can use PAM to implement
support for other methods (e.g. MD5 encryption, LDAP, etc.).
- the "oninit" binary ($INFORMIXDIR/bin/oninit) does not have the
correct owner and file access rights settings. This can cause
that oninit is not allowed to open the file /etc/shadow and thus
cannot get the encrypted password from this file.
To set things right, you need to re-run the "RUN_AS_ROOT.server"
script, that you had to run to finish the installation. If the script
no longer exists, the easiest thing probably is to re-install and then
run the script ...
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
forum.subscriber@iiug.org wrote on 02.08.2005 22:56:18:
> Hi, i work with IDS 9.4 and work right recently, but now when do oninit
say this:
>
> 15:40:58 Event alarms enabled. ALARMPROG =
'/usr/informix/etc/alarmprogram.sh'
> 15:40:58 Booting Language <c> from module <>
> 15:40:58 Loading Module <CNULL>
> 15:40:58 Booting Language <builtin> from module <>
> 15:40:58 Loading Module <BUILTINNULL>
> 15:41:04 Dynamically allocated new virtual shared memory segment (size
8192KB)
> 15:41:04 IBM Informix Dynamic Server Version 9.40.UC4 Software
Serial Number AAA#B000000
> 15:41:05 IBM Informix Dynamic Server Initialized -- Shared Memory
Initialized.
>
> 15:41:05 Physical Recovery Started at Page (1:470).
> 15:41:05 Physical Recovery Complete: 0 Pages Examined, 0 Pages
Restored.
> 15:41:05 Logical Recovery Started.
> 15:41:05 10 recovery worker threads will be started.
> 15:41:08 Logical Recovery has reached the transaction cleanup phase.
> 15:41:08 Logical Recovery Complete.
> 0 Committed, 0 Rolled Back, 0 Open, 0 Bad Locks
>
> 15:41:09 Dataskip is now OFF for all dbspaces
> 15:41:09 Checkpoint Completed: duration was 0 seconds.
> 15:41:09 Checkpoint loguniq 2579, logpos 0x2c1018, timestamp: 78963472
>
> 15:41:09 Maximum server connections 0
> 15:41:09 On-Line Mode
>
> I find what the Maximum server connection is 0 because dead licence or
the IDS have bad configuration.
> When i try connect with onmonitor, its say "WARNING: Network Down"
Online
> and when i try connect with dbacces say this:
>
> 951: Incorrect password or user informix is not known on the database
server.>
> and the onstat -m say:
>
> 15:44:48 Get Shadow Password for user [informix] failed!
> 15:44:48 Check for password aging/account lock-out.
> 15:44:48 listener-thread: err = -951: oserr = 0: errstr = informix:
Incorrect password or user informix is not known on the database server.
>
> The user and password its right, also the network, services, sqlhost and
enviroment variables
> How i access the data whit re-install IDS?
>
> Please helpme!
>
> PD: Sorry for my bad english.
>
> --
Thanks Martin!!
Sorry, the OS its the Redhat 9, and the aging of accounts and license its ok.
The problem wos the file permissions, some body change the complete directory
bin permissions with 666!. Now change the oninit to 6754 permission and work.
One last question, the RUN_AS_ROOT.server script, only change the permisions?
Well, thanks for all
Regards
--
Open WebMail Project (http://openwebmail.org)
---------- Original Message -----------
From: Martin Fuerderer <MARTINFU@de.ibm.com>
To: "rguevara" <rguevara@mcanet.com.ar>
Cc: forum.subscriber@iiug.org, ids@iiug.org
Sent: Wed, 3 Aug 2005 11:57:44 +0200
Subject: Re: Error 951 in IDS 9.4 [5535]
> Hi,
>
> are you sure that the password for the user in question
> ("informix") is in the file /etc/shadow ?
>
> 3 possibilities come to my mind:
>
> - you are using Solaris (you don't mention OS and OS version)
> and you are running into problem PTS-B 171594 :
>
> If a user who is not known on the system atempts to connect, the
> online.log
> might show:
>
> 11:09:36 WARNING: mt_aio_wait: errno == EINVAL
> 11:09:36 Get Shadow Password for user [01001358] failed!
> 11:09:36 Check for password aging/account lock-out.
> 11:09:36 listener-thread: err = -951: oserr = 0: errstr = 01001358:
> Incorrect
> password or user 01001358 is not known on the database server.
>
> This is a Solaris problem (so-called "Vendor bug"), which can be solved:
>
> Please see the following email from SUN:
>
> "Yes, it looks like 108993-27 fixed several issues by re-implementing
> the
> stdio file I/O functions, used by many of the libnsl (Naming Service
> library) functions.
>
> The intent is that this change to our implementation should be
> transparent to you, so that errno would be set in the same cases where
> it was before. However, bug 4915053 indicates that there are
> times when
> EINVAL is returned erroneously. This bug is fixed in:
>
> Solaris 8 patch 108993-37 and higher
> Solaris 9 update 7, patch 113319-18 and higher
> Solaris 10 build 46 and higher
>
> So, while it *might* be safe to assume that you can reset any EINVAL
> returned from getspnam(), I recommend that you don't change your code.
>
> Instead, it's actually a better idea to update the customer's patches
> to
> the ones listed above."
>
> - the users password really is not in in /etc/shadow , but you
> have deployed a different authentication method that is not
> supported by IDS.
>
> IDS natively supports only the generic UNIX password encryption
> (using the system call "crypt()"), with the password either being
> held in /etc/passwd, /etc/shadow or NIS/NIS+. All other methods
> (encryption and/or place to keep encrypted password) are not
> natively supported.
>
> With IDS 9.40.xC2 and higher you can use PAM to implement
> support for other methods (e.g. MD5 encryption, LDAP, etc.).
>
> - the "oninit" binary ($INFORMIXDIR/bin/oninit) does not have the
> correct owner and file access rights settings. This can cause
> that oninit is not allowed to open the file /etc/shadow and thus
> cannot get the encrypted password from this file.
>
> To set things right, you need to re-run the "RUN_AS_ROOT.server"
> script, that you had to run to finish the installation. If the script
> no longer exists, the easiest thing probably is to re-install and then
> run the script ...
>
> Regards,
> Martin
> --
> Martin Fuerderer
> IBM Informix Development Munich, Germany
> Information Management
>
> forum.subscriber@iiug.org wrote on 02.08.2005 22:56:18:
> > Hi, i work with IDS 9.4 and work right recently, but now when do oninit
> say this:
> >
> > 15:40:58 Event alarms enabled. ALARMPROG =
> '/usr/informix/etc/alarmprogram.sh'
> > 15:40:58 Booting Language <c> from module <>
> > 15:40:58 Loading Module <CNULL>
> > 15:40:58 Booting Language <builtin> from module <>
> > 15:40:58 Loading Module <BUILTINNULL>
> > 15:41:04 Dynamically allocated new virtual shared memory segment (size
> 8192KB)
> > 15:41:04 IBM Informix Dynamic Server Version 9.40.UC4 Software
> Serial Number AAA#B000000
> > 15:41:05 IBM Informix Dynamic Server Initialized -- Shared Memory
> Initialized.
> >
> > 15:41:05 Physical Recovery Started at Page (1:470).
> > 15:41:05 Physical Recovery Complete: 0 Pages Examined, 0 Pages
> Restored.
> > 15:41:05 Logical Recovery Started.
> > 15:41:05 10 recovery worker threads will be started.
> > 15:41:08 Logical Recovery has reached the transaction cleanup phase.
> > 15:41:08 Logical Recovery Complete.
> > 0 Committed, 0 Rolled Back, 0 Open, 0 Bad Locks
> >
> > 15:41:09 Dataskip is now OFF for all dbspaces
> > 15:41:09 Checkpoint Completed: duration was 0 seconds.
> > 15:41:09 Checkpoint loguniq 2579, logpos 0x2c1018, timestamp: 78963472
> >
> > 15:41:09 Maximum server connections 0
> > 15:41:09 On-Line Mode
> >
> > I find what the Maximum server connection is 0 because dead licence or
> the IDS have bad configuration.
> > When i try connect with onmonitor, its say "WARNING: Network Down"
> Online
> > and when i try connect with dbacces say this:
> >
> > 951: Incorrect password or user informix is not known on the database
> server.> >
> > and the onstat -m say:
> >
> > 15:44:48 Get Shadow Password for user [informix] failed!
> > 15:44:48 Check for password aging/account lock-out.
> > 15:44:48 listener-thread: err = -951: oserr = 0: errstr = informix:
> Incorrect password or user informix is not known on the database server.
> >
> > The user and password its right, also the network, services, sqlhost and
> enviroment variables
> > How i access the data whit re-install IDS?
> >
> > Please helpme!
> >
> > PD: Sorry for my bad english.
> >
> > --
------- End of Original Message -------
Hi,
actually for quite some time I did not check what
exactly the script does ... But certainly it changes owner,
group and access rights of files and directories. Maybe
it also creates a couple of symbolic links if they weren't
done already by the installserver script.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
forum.subscriber@iiug.org wrote on 03.08.2005 15:26:11:
> Thanks Martin!!
> Sorry, the OS its the Redhat 9, and the aging of accounts and license
its ok. The problem wos the file permissions, some body change the
complete directory bin permissions with 666!. Now change the oninit to
6754 permission and work.
>
> One last question, the RUN_AS_ROOT.server script, only change the
permisions?
>
> Well, thanks for all
>
> Regards
>
> --
> Open WebMail Project (http://openwebmail.org)
>
> ---------- Original Message -----------
> From: Martin Fuerderer <MARTINFU@de.ibm.com>
> To: "rguevara" <rguevara@mcanet.com.ar>
> Cc: forum.subscriber@iiug.org, ids@iiug.org
> Sent: Wed, 3 Aug 2005 11:57:44 +0200
> Subject: Re: Error 951 in IDS 9.4 [5535]
>
> > Hi,
> >
> > are you sure that the password for the user in question
> > ("informix") is in the file /etc/shadow ?
> >
> > 3 possibilities come to my mind:
> >
> > - you are using Solaris (you don't mention OS and OS version)
> > and you are running into problem PTS-B 171594 :
> >
> > If a user who is not known on the system atempts to connect, the
> > online.log
> > might show:
> >
> > 11:09:36 WARNING: mt_aio_wait: errno == EINVAL
> > 11:09:36 Get Shadow Password for user [01001358] failed!
> > 11:09:36 Check for password aging/account lock-out.
> > 11:09:36 listener-thread: err = -951: oserr = 0: errstr =
01001358:
> > Incorrect
> > password or user 01001358 is not known on the database server.
> >
> > This is a Solaris problem (so-called "Vendor bug"), which can be
solved:
> >
> > Please see the following email from SUN:
> >
> > "Yes, it looks like 108993-27 fixed several issues by
re-implementing
> > the
> > stdio file I/O functions, used by many of the libnsl (Naming
Service
> > library) functions.
> >
> > The intent is that this change to our implementation should be
> > transparent to you, so that errno would be set in the same cases
where
> > it was before. However, bug 4915053 indicates that there are
> > times when
> > EINVAL is returned erroneously. This bug is fixed in:
> >
> > Solaris 8 patch 108993-37 and higher
> > Solaris 9 update 7, patch 113319-18 and higher
> > Solaris 10 build 46 and higher
> >
> > So, while it *might* be safe to assume that you can reset any
EINVAL
> > returned from getspnam(), I recommend that you don't change your
code.
> >
> > Instead, it's actually a better idea to update the customer's
patches
> > to
> > the ones listed above."
> >
> > - the users password really is not in in /etc/shadow , but you
> > have deployed a different authentication method that is not
> > supported by IDS.
> >
> > IDS natively supports only the generic UNIX password encryption
> > (using the system call "crypt()"), with the password either being
> > held in /etc/passwd, /etc/shadow or NIS/NIS+. All other methods
> > (encryption and/or place to keep encrypted password) are not
> > natively supported.
> >
> > With IDS 9.40.xC2 and higher you can use PAM to implement
> > support for other methods (e.g. MD5 encryption, LDAP, etc.).
> >
> > - the "oninit" binary ($INFORMIXDIR/bin/oninit) does not have the
> > correct owner and file access rights settings. This can cause
> > that oninit is not allowed to open the file /etc/shadow and thus
> > cannot get the encrypted password from this file.
> >
> > To set things right, you need to re-run the "RUN_AS_ROOT.server"
> > script, that you had to run to finish the installation. If the script
> > no longer exists, the easiest thing probably is to re-install and
then
> > run the script ...
> >
> > Regards,
> > Martin
> > --
> > Martin Fuerderer
> > IBM Informix Development Munich, Germany
> > Information Management
> >
> > forum.subscriber@iiug.org wrote on 02.08.2005 22:56:18:
> > > Hi, i work with IDS 9.4 and work right recently, but now when do
oninit
> > say this:> > >
> > > 15:40:58 Event alarms enabled. ALARMPROG =
> > '/usr/informix/etc/alarmprogram.sh'
> > > 15:40:58 Booting Language <c> from module <>
> > > 15:40:58 Loading Module <CNULL>
> > > 15:40:58 Booting Language <builtin> from module <>
> > > 15:40:58 Loading Module <BUILTINNULL>
> > > 15:41:04 Dynamically allocated new virtual shared memory segment
(size
> > 8192KB)
> > > 15:41:04 IBM Informix Dynamic Server Version 9.40.UC4 Software
> > Serial Number AAA#B000000
> > > 15:41:05 IBM Informix Dynamic Server Initialized -- Shared Memory
> > Initialized.
> > >
> > > 15:41:05 Physical Recovery Started at Page (1:470).
> > > 15:41:05 Physical Recovery Complete: 0 Pages Examined, 0 Pages
> > Restored.
> > > 15:41:05 Logical Recovery Started.
> > > 15:41:05 10 recovery worker threads will be started.
> > > 15:41:08 Logical Recovery has reached the transaction cleanup
phase.
> > > 15:41:08 Logical Recovery Complete.
> > > 0 Committed, 0 Rolled Back, 0 Open, 0 Bad Locks
> > >
> > > 15:41:09 Dataskip is now OFF for all dbspaces
> > > 15:41:09 Checkpoint Completed: duration was 0 seconds.
> > > 15:41:09 Checkpoint loguniq 2579, logpos 0x2c1018, timestamp:
78963472
> > >
> > > 15:41:09 Maximum server connections 0
> > > 15:41:09 On-Line Mode
> > >
> > > I find what the Maximum server connection is 0 because dead licence
or
> > the IDS have bad configuration.
> > > When i try connect with onmonitor, its say "WARNING: Network Down"
> > Online
> > > and when i try connect with dbacces say this:
> > >
> > > 951: Incorrect password or user informix is not known on thedatabase
> > server.
> > >
> > > and the onstat -m say:
> > >
> > > 15:44:48 Get Shadow Password for user [informix] failed!
> > > 15:44:48 Check for password aging/account lock-out.
> > > 15:44:48 listener-thread: err = -951: oserr = 0: errstr = informix:
> > Incorrect password or user informix is not known on the database
server.
> > >
> > > The user and password its right, also the network, services, sqlhost
and
> > enviroment variables
> > > How i access the data whit re-install IDS?
> > >
> > > Please helpme!
> > >
> > > PD: Sorry for my bad english.
> > >
> > > --
> ------- End of Original Message -------
>
>
>