Re: IDS Crashes with LDAP on Solaris 10
Posted in 2006
Topics: Security, Permissions & Auditing, Platform-Specific Issues
After months of struggling (we opened the PMR on 3 January), IBM has _finally_ replicated our crash. Here are the essentials, as I understand them: IDS (9.40 or 10.00) running on Solaris 10. Solaris authenticates via Sun directory server. Solaris communicates with directory server over SSL. *Reverse password lookup prohibited, authentication via BIND only. Given these things (* - not sure if it's required to replicate), IDS will crash on Solaris 10 whenever an LDAP user attempts to connect. Local users still work fine. The crash seems to occur in a Solaris SSL library. The question now is, since the library call works fine on Solaris 8 but not on Solaris 10, is this a bug in Solaris or in IDS? Was IDS simply "getting away with" a bad call on Solaris 8? Or did Sun change something in Solaris 10 that IDS should have, but didn't, account for? Or did Sun simply break something in Solaris 10? Hopefully we'll have answers soon, now that IBM can replicate. Cheers, - TJG
"Thomas J. Girsch" <tgirsch@gmail.com> wrote in message news:Clrjg.65847$P2.45335@tornado.ohiordc.rr.com... > The question now is, since the library call works fine on Solaris 8 but > not on Solaris 10, is this a bug in Solaris or in IDS? Was IDS simply > "getting away with" a bad call on Solaris 8? Or did Sun change something > in Solaris 10 that IDS should have, but didn't, account for? Or did Sun > simply break something in Solaris 10? Ugh! Inter-vendor problems are genrally a nightmare, no mater who the vendors are. We've opened calls with HP and IBM over three years ago because Data Protector introduces a mystery 45-second delay between each logical log during rollforward. If there are hundred of logs (no matter how small) you can imagine that this can add a substantial delay to the recovery process of, potentially, many hours. In the end, after months of stand-off, HP said it was an IBM problem, IBM said it was an HP one, and we just gave up and the problem persists today :-(
Tom Have look out in the sun newsgroup, they are a very helpful lot and might be able to help Cheers Paul Paul Watson Tel: +44 1414161772 Mob: +44 7818003457 GO FURTHER with DB2 GET THERE FASTER with Informix. Attend the IDUG 2006 European Conference. Vienna, Austria. 2-6 October 2006 Visit http://www.iiug.org/conf for more information. > -----Original Message----- > From: Thomas J. Girsch [mailto:tgirsch@gmail.com] > Posted At: 12 June 2006 23:41 > Posted To: comp.databases.informix > Conversation: IDS Crashes with LDAP on Solaris 10 > Subject: Re: IDS Crashes with LDAP on Solaris 10 > > > After months of struggling (we opened the PMR on 3 January), IBM has > _finally_ replicated our crash. Here are the essentials, as I > understand them: > > IDS (9.40 or 10.00) running on Solaris 10. > Solaris authenticates via Sun directory server. > Solaris communicates with directory server over SSL. > *Reverse password lookup prohibited, authentication via BIND only. > > Given these things (* - not sure if it's required to replicate), IDS > will crash on Solaris 10 whenever an LDAP user attempts to connect. > Local users still work fine. The crash seems to occur in a > Solaris SSL > library. > > The question now is, since the library call works fine on > Solaris 8 but > not on Solaris 10, is this a bug in Solaris or in IDS? Was > IDS simply > "getting away with" a bad call on Solaris 8? Or did Sun change > something in Solaris 10 that IDS should have, but didn't, > account for? > Or did Sun simply break something in Solaris 10? > > Hopefully we'll have answers soon, now that IBM can replicate. > > Cheers, > > - TJG
Thomas J. Girsch wrote: > After months of struggling (we opened the PMR on 3 January), IBM has > _finally_ replicated our crash. Here are the essentials, as I > understand them: > > IDS (9.40 or 10.00) running on Solaris 10. > Solaris authenticates via Sun directory server. > Solaris communicates with directory server over SSL. > *Reverse password lookup prohibited, authentication via BIND only. > > Given these things (* - not sure if it's required to replicate), IDS > will crash on Solaris 10 whenever an LDAP user attempts to connect. > Local users still work fine. The crash seems to occur in a Solaris SSL > library. > > The question now is, since the library call works fine on Solaris 8 but > not on Solaris 10, is this a bug in Solaris or in IDS? Was IDS simply > "getting away with" a bad call on Solaris 8? Or did Sun change > something in Solaris 10 that IDS should have, but didn't, account for? > Or did Sun simply break something in Solaris 10? > > Hopefully we'll have answers soon, now that IBM can replicate. > truss -u the process and see where it is crashing. Inside a library call or after the library call completes? Do the values to the last library call before the crash look ok? What is the stack trace? David. > Cheers, > > - TJG