info about locked out session
Posted in 2006
Topics: Security, Permissions & Auditing
HI, I have the following message in online log, 16:33:02 Password Validation for user [saapmgr] failed! 16:33:02 Check for password aging/account lock-out. 16:33:02 listener-thread: err = -952: oserr = 0: errstr = saapmgr: User (saapmgr)'s password is not correct for the database server. How can I get the information about the locked out process? like, host, process id... Thanks, Frank -- Yunyao "Frank" Qu Computer Sciences Corporation(CSC) NOAA/CLASS, (301)817-4696
Frank, Is this on UNIX ? If so, have an admin start an iptrace session and collect some data and then cross reference it with your online log times. I use AIX and could use: startsrc -s iptrace -a "./mylogfile" Then stopsrc -s iptrace Then use the ipreport utility: ipreport filename > readable file The output can then be inspected for the SRC info ... -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Yunyao (Fra.... Sent: Monday, June 12, 2006 11:36 AM To: ids@iiug.org Subject: info about locked out session [6922] HI, I have the following message in online log, 16:33:02 Password Validation for user [saapmgr] failed! 16:33:02 Check for password aging/account lock-out. 16:33:02 listener-thread: err = -952: oserr = 0: errstr = saapmgr: User (saapmgr)'s password is not correct for the database server. How can I get the information about the locked out process? like, host, process id... Thanks, Frank -- Yunyao "Frank" Qu Computer Sciences Corporation(CSC) NOAA/CLASS, (301)817-4696 ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
I will take a guess that you have recently upgraded (?) or that you have recently installed informix. We had similar issues in our environment. Our users connect to a database and then reverence a database on a different host by using a synonym ( for some of the work they do ) When UNIX times out there passwords they change there password ( but no on the remote machine, ( the user are not savvy enough to know that the other machine exists. ) Starting some where before the release, we use, 9.40UC7 Then on remote servers Informix engine improved its validation routines for remote server ( local server too I believe ) and started checking for "expired" passwords ( from a UNIX perspective ). The Users password is most probably expired, It could also be locked out due to UNIX invalid password attempts. Have a sysadmin check or these things on the machine where the message is showing up in the message log. George -----Original Message----- From: ids-bounces@iiug.org [mailto:ids-bounces@iiug.org] On Behalf Of Yunyao (Fra.... Sent: Monday, June 12, 2006 9:36 AM To: ids@iiug.org Subject: info about locked out session [6922] HI, I have the following message in online log, 16:33:02 Password Validation for user [saapmgr] failed! 16:33:02 Check for password aging/account lock-out. 16:33:02 listener-thread: err = -952: oserr = 0: errstr = saapmgr: User (saapmgr)'s password is not correct for the database server. How can I get the information about the locked out process? like, host, process id... Thanks, Frank -- Yunyao "Frank" Qu Computer Sciences Corporation(CSC) NOAA/CLASS, (301)817-4696 ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.