JDBC Failure encountered during decryption
Posted in 2010
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Networking & sqlhosts Configuration, Java & JDBC Development, Versions, Editions & End-of-Life
We're using IDS 9.40.UC6 on Redhat 7.3 (i386), and are using JDBC driver 3.50.JC5 running on CentOS 5.4 (x86_64) to connect to it. We don't currently have support with IBM for this system. Our java version on the JDBC client side reports: java version "1.6.0" OpenJDK Runtime Environment (build 1.6.0-b09) OpenJDK 64-Bit Server VM (build 1.6.0-b09, mixed mode) Recently we enabled encrypted connections using this setup on the server side: sqlhosts: repl_tcp_ssl onsoctcp * 9089 csm=(ENCCSM) concsm.cfg: ENCCSM("/opt/informix/lib/csm/iencs09a.so", "cipher[allbut:<ecb,des>]") And then on the JDBC client side we add this setting to the Properties: Properties props = new Properties(); props.setProperty("user", db_user); props.setProperty("password", db_pass); props.setProperty("csm", "classname=com.informix.jdbc.Crypto,cipher[all]"); DriverManager.getConnection(str_conn, props); Usually this works fine. However, on occasion, the connection will fail and we'll see this error message: Exception in thread "main" java.sql.SQLException: java.sql.SQLException: System or internal error java.io.IOException: Failure encountered during decryption at com.informix.jdbc.IfxSqliConnect.<init>(IfxSqliConnect.java:1455) at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorI mpl.java:57) at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorA ccessorImpl.java:45) at java.lang.reflect.Constructor.newInstance(Constructor.java:532) at com.informix.jdbc.IfxDriver.connect(IfxDriver.java:254) at java.sql.DriverManager.getConnection(DriverManager.java:620) at java.sql.DriverManager.getConnection(DriverManager.java:169) ... <our code backtrace snipped> ... Caused by: java.sql.SQLException: System or internal error java.io.IOException: Failure encountered during decryption at com.informix.util.IfxErrMsg.getSQLException(IfxErrMsg.java:482) at com.informix.jdbc.IfxSqli.a(IfxSqli.java:9184) at com.informix.jdbc.IfxSqli.receiveMessage(IfxSqli.java:2519) at com.informix.jdbc.IfxSqli.executeProtocols(IfxSqli.java:7700) at com.informix.jdbc.IfxSqliConnect.D(IfxSqliConnect.java:6815) at com.informix.jdbc.IfxSqliConnect.f(IfxSqliConnect.java:3855) at com.informix.jdbc.IfxSqliConnect.<init>(IfxSqliConnect.java:1441) ... 11 more Caused by: java.io.IOException: Failure encountered during decryption at com.informix.csm.IfxCssInputStream.fill_outputStream(IfxCssInputStream.java:186) at com.informix.csm.IfxCssInputStream.read(IfxCssInputStream.java:93) at com.informix.asf.IfxDataInputStream.readFully(IfxDataInputStream.java:146) at com.informix.asf.IfxDataInputStream.readSmallInt(IfxDataInputStream.java:453) at com.informix.jdbc.IfxSqli.receiveMessage(IfxSqli.java:2495) ... 15 more If we change the connection back to non-encrypted, there are no issues and all connections work great. I've searched all over for a solution, but haven't been able to find anyone else with this issue. Anybody else see this? Is there anything I can try to fix it? Thanks, Brian
Mostly this was a defect which was fixed sometime back.... When IDS server and client agrees on some specific cipher (I don't remember that for sure.. but mostly it was des:ofb) .. in that case you will see this error. So, one workaround would be to list all the ciphers except des:ofb (assuming if that was the cipher) Manoj From: "BRIAN WITT" <bwitt@bart.gov> To: ids@iiug.org Date: 01/07/2010 01:55 PM Subject: JDBC Failure encountered during decryption [18620] Sent by: ids-bounces@iiug.org We're using IDS 9.40.UC6 on Redhat 7.3 (i386), and are using JDBC driver 3.50.JC5 running on CentOS 5.4 (x86_64) to connect to it. We don't currently have support with IBM for this system. Our java version on the JDBC client side reports: java version "1.6.0" OpenJDK Runtime Environment (build 1.6.0-b09) OpenJDK 64-Bit Server VM (build 1.6.0-b09, mixed mode) Recently we enabled encrypted connections using this setup on the server side: sqlhosts: repl_tcp_ssl onsoctcp * 9089 csm=(ENCCSM) concsm.cfg: ENCCSM("/opt/informix/lib/csm/iencs09a.so", "cipher[allbut:<ecb,des>]") And then on the JDBC client side we add this setting to the Properties: Properties props = new Properties(); props.setProperty("user", db_user); props.setProperty("password", db_pass); props.setProperty("csm", "classname=com.informix.jdbc.Crypto,cipher[all]"); DriverManager.getConnection(str_conn, props); Usually this works fine. However, on occasion, the connection will fail and we'll see this error message: Exception in thread "main" java.sql.SQLException: java.sql.SQLException: System or internal error java.io.IOException: Failure encountered during decryption at com.informix.jdbc.IfxSqliConnect.<init>(IfxSqliConnect.java:1455) at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorI mpl.java:57) at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorA ccessorImpl.java:45) at java.lang.reflect.Constructor.newInstance(Constructor.java:532) at com.informix.jdbc.IfxDriver.connect(IfxDriver.java:254) at java.sql.DriverManager.getConnection(DriverManager.java:620) at java.sql.DriverManager.getConnection(DriverManager.java:169) .... <our code backtrace snipped> .... Caused by: java.sql.SQLException: System or internal error java.io.IOException: Failure encountered during decryption at com.informix.util.IfxErrMsg.getSQLException(IfxErrMsg.java:482) at com.informix.jdbc.IfxSqli.a(IfxSqli.java:9184) at com.informix.jdbc.IfxSqli.receiveMessage(IfxSqli.java:2519) at com.informix.jdbc.IfxSqli.executeProtocols(IfxSqli.java:7700) at com.informix.jdbc.IfxSqliConnect.D(IfxSqliConnect.java:6815) at com.informix.jdbc.IfxSqliConnect.f(IfxSqliConnect.java:3855) at com.informix.jdbc.IfxSqliConnect.<init>(IfxSqliConnect.java:1441) .... 11 more Caused by: java.io.IOException: Failure encountered during decryption at com.informix.csm.IfxCssInputStream.fill_outputStream(IfxCssInputStream.java:186) at com.informix.csm.IfxCssInputStream.read(IfxCssInputStream.java:93) at com.informix.asf.IfxDataInputStream.readFully(IfxDataInputStream.java:146) at com.informix.asf.IfxDataInputStream.readSmallInt(IfxDataInputStream.java:453) at com.informix.jdbc.IfxSqli.receiveMessage(IfxSqli.java:2495) .... 15 more If we change the connection back to non-encrypted, there are no issues and all connections work great. I've searched all over for a solution, but haven't been able to find anyone else with this issue. Anybody else see this? Is there anything I can try to fix it? Thanks, Brian ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
On Thu, 2010-01-07 at 15:09 -0500, Manoj Mohan wrote: > Mostly this was a defect which was fixed sometime back.... When IDS server > and client agrees on some specific cipher (I don't remember that for > sure.. but mostly it was des:ofb) .. in that case > you will see this error. So, one workaround would be to list all the > ciphers except des:ofb (assuming if that was the cipher) Thanks for the reply. I tried limiting the ciphers to exclude each of the available ciphers one by one (by using the allbut option), and also limiting it to just one, e.g. "cipher[ede:cbc]" on the server side, but it still (randomly) has that failure in each of those configurations. I tried setting it to "cipher[des:ofb]" but it doesn't seem to fail any more often than the others. Do I need to limit on the client side as well? Is there any way to track down exactly what cipher is causing the issue, or find out a version of IDS that doesn't have the issue? I've looked through the release notes and fixed and known defects from most of the releases since, but couldn't find a mention of this. Thanks, Brian