Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
Uwe Trefz wanted a SLES 15 app to connect to Informix 12 on Windows 2016 with credentials the domain policy rejects. ke chen advised USERMAPPING=BASIC via onmode -wf, an allowed.surrogates file, onmode -cache surrogates, and CREATE USER test ... PROPERTIES user mapping to an existing OS user. The group id is that user's real group; Uwe will try it.
Auto-generated by Claude from the posts below — may be imperfect; read the full thread.
Uwe Trefz — source: IBM Community (ConnectedCommunity.org) Informix forum
Hi everyone,
I have a question about connecting from an SLES 15 server-where my application is running-to an Informix 12 database on a Windows 2016 server.
The issue is as follows: I log in to the SLES 15 server using the username "test" and the password "test."
My application then passes these credentials on to the database server.
However, the user "test" has a different password on the database server.
The domain policy rejects the password "test" because it does not comply with domain policy requirements.
Consequently, I cannot set up the user "test" with the password "test" on the database server.
Is there any way to establish the database connection using the username and password from the SLES 15 server anyway?
Many thanks for help.
Kind Regards,
Uwe
------------------------------
Uwe Trefz
------------------------------
↪ replying to Uwe Trefz
ke chen — source: IBM Community (ConnectedCommunity.org) Informix forum
Uwe Trefz — source: IBM Community (ConnectedCommunity.org) Informix forum
Hello ke chen, many thanks for the answer.
I understand, that I have to do the setting in onconfig on windows side? Is it then necessary to create a local user "test" on the windows server or will it bypased from the Linux Server?
I have to do following statements in the database for the user test. That is clear. CREATE USER and ALTER USER to register values in appropriate system tables of the SYSUSER database:
------------------------------
Uwe Trefz
------------------------------
↪ replying to Uwe Trefz
ke chen — source: IBM Community (ConnectedCommunity.org) Informix forum
You do not need to create OS level user test at either windows or linux.
On your windows DBMS, you run:
1. onmode -wf USERMAPPING=BASIC
2. create /etc/informix/allowed.surrogates file, as example of:
#Surrogate IDs
#
users:user1
group:18
(user1 is the existing OS user on windows DBMS server).
3. onmode -cache surrogates
4. dbaccess
CREATE USER test WITH PASSWORD "test" PROPERTIES user "user1";
5. dbaccessgrant connect to test;The purpose of using usermapping is to skip creating OS user test, it can be mapped to another existing OS user on Windows.
Have a try, good luck.
------------------------------
ke chen
------------------------------
↪ replying to ke chen
Uwe Trefz — source: IBM Community (ConnectedCommunity.org) Informix forum
Hello ke chen,
many thanks for your help. Now my last question. What does the "group:18" in the file "allowed,surrogates" mean? is this a special informix group? or a group in Linux?
Unfortunately I have no glue.
------------------------------
Uwe Trefz
------------------------------
↪ replying to Uwe Trefz
ke chen — source: IBM Community (ConnectedCommunity.org) Informix forum
group id 18 is the group id of real os user user1.
on windows, I wonder you might be able to assign a random number in
allowed.surrogates.
Have a try.
You might need to try a few workarounds on windows.
------------------------------
ke chen
------------------------------
↪ replying to ke chen
Uwe Trefz — source: IBM Community (ConnectedCommunity.org) Informix forum
Hello ke chen,
many thanks for your help.
I will try and hopefully I'm successfully.
Uwe
------------------------------
Uwe Trefz
------------------------------
Your privacy choices
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.