ER: weird behaviour when using s=6 option in sqlhosts
Posted in 2006
Topics: High Availability & Replication, Networking & sqlhosts Configuration
Hello Madison (and the rest). Setting up my test ER/HDR environment I came accross a problem. The environment consists of three instances, each on it own host. Instance A (IDS10.00UC5 on RHEL 4) is primary in ER, Instance B (IDS10.00UC5 on Debian) is target in ER and primary in HDR Instance C (IDS10.00UC4 on Debian) is secondary in HDR. HDR works fine despite the slightly different versions. The problem presented itself when I started using security options in sqlhosts. For every port that participates solely in ER or HDR I included s=6 in options field to prevent any other kind of access to those ports. I defined $INFORMIXDIR/etc/hosts.equiv accordingly. Trusted environment test went successfully. Also, I was able to define both ER servers and cdr list servers output was fine. After that I defined and realized a template on ER primary (instance A) and tried to realize it for target instance also (instance B). The error popped up: -25539: Invalid connection type. OK, so the ER target wasn't able to accept the connection from ER primary although trusted environment was in place. I dropped s=6 option on ER target and put ER primary's hostname in $INFORMIXDIR/.rhosts on target. This time template realization went fine. What this tells me is that cdr realize template run on ER primary for ER targets tries to to connect to suitable ER port on target, but not as a ER connection type, which I think should be the case. I have the workaround but I'd still like to hear what you think about this. Any help is very appreciated. P.S I also have valid Tech Support Contract but I suppose it would take a while to propagate this problem to ER developers.
Davorin Kremenjas wrote: > Hello Madison (and the rest). > > Setting up my test ER/HDR environment I came accross a problem. > The environment consists of three instances, each on it own host. > Instance A (IDS10.00UC5 on RHEL 4) is primary in ER, > Instance B (IDS10.00UC5 on Debian) is target in ER and primary in HDR > Instance C (IDS10.00UC4 on Debian) is secondary in HDR. > HDR works fine despite the slightly different versions. The s=6 option allows only ER connections to connect via the port, it does not allow sql connections. The cdr tool is an ESQL/c program and would need to use an SQL connection to connect to the server. Since part of template realization is to verify that the data is correct, it must connect to those servers. Unfortunately, the CDR CLI knows the servers by the server alias which has the s=6 option. > > The problem presented itself when I started using security options in > sqlhosts. For every port that participates solely in ER or HDR I included > s=6 in options field to prevent any other kind of access to those ports. I > defined $INFORMIXDIR/etc/hosts.equiv accordingly. Trusted environment test > went successfully. Also, I was able to define both ER servers and cdr list > servers output was fine. > After that I defined and realized a template on ER primary (instance A) and > tried to realize it for target instance also (instance B). The error popped > up: -25539: Invalid connection type. > OK, so the ER target wasn't able to accept the connection from ER primary > although trusted environment was in place. > I dropped s=6 option on ER target and put ER primary's hostname in > $INFORMIXDIR/.rhosts on target. This time template realization went fine. > What this tells me is that cdr realize template run on ER primary for ER > targets tries to to connect to suitable ER port on target, but not as a ER > connection type, which I think should be the case. > I have the workaround but I'd still like to hear what you think about this. > Any help is very appreciated. > > P.S I also have valid Tech Support Contract but I suppose it would take a > while to propagate this problem to ER developers. > >