Re: bad password error -951 in Server Studio
Posted in 2012
Already replied you... You can open the PMR, but your installation was NOT
successful.
Something went wrong. Check that you did it as root and if possible tell us
the installation command you used.
Regards.
On Mon, Jul 2, 2012 at 6:03 PM, Laurie Gustin <lgustin@utah.gov> wrote:
>
> Fernando -
> Thanks for the reply - This is a brand new installation. I tried the
> test you suggested and got this output...
>
> [root@psdb01spr infrmx]# ./test_auth informix
> User (from shadow): informix
> Encrypted pwd:
> $6$rcCqdXr7$2my9UOdojIGUEkdsfojeEW03HE12OFkejeFRF5NwUqmjtrm0UeuN87vPI9iJQ3n46yuKNHLUoAWy5MDMS8fmjb01
> UID: 502
> GID: 502
> Real name:
> Home: /home/infrmx
> SHELL: /bin/bash
>
> I will open a PMR.
>
> Thanks
> Laurie
>
> >>> Fernando Nunes <domusonline@gmail.com> 6/28/2012 3:53 PM >>>
>
> I may be missing something obvious, but I'm running out of ideas... I
> recommend you open a PMR... In any case:
>
> ps -ef | grep oninit
> ls -lia $INFORMIXDIR/bin/oninit
>
> Did you copied the installation? Or restored it from a backup or other
> server?
>
> You could try to put the code below in a file called auth_test.c
> and run:
>
> cc -o test_auth test_auth.c
> ./test_auth informix
>
> and see what it returns...
>
>
>
>
> ============================================================================================================
> #include <pwd.h>
> #include <shadow.h>
> #include <stdio.h>
> #include <stdlib.h>
> #include <unistd.h>
> #include <errno.h>
>
> int main(int argc, char *argv[])
> {
> struct passwd *my_pwd;
> struct spwd *my_spwd;
>
> if (argc != 2) {
> fprintf(stderr, "Usage: %s username\\n", argv[0]);
> exit(-1);
> }
> if ((my_pwd=getpwnam(argv[1])) != NULL)
> {
> if ( my_pwd->pw_passwd[0] == 'x' )
> {
> if ((my_spwd=getspnam(argv[1])) != NULL )
> {
> printf("User (from shadow): %s\\nEncrypted pwd: %s\\nUID: %d\\nGID: %d\\nReal
> name: %s\\nHome: %s\\nSHELL: %s\\n",my_pwd->pw_name, my_spwd->sp_pwdp,
> my_pwd->pw_uid, my_pwd->pw_gid,my_pwd->pw_gecos,my_pwd->pw_dir,
> my_pwd->pw_shell);
> }
> else
> {
> perror("getspnam");
> }
> }
> else
> printf("User (from passwd): %s\\nEncrypted pwd: %s\\nUID: %d\\nGID: %d\\nReal
> name: %s\\nHome: %s\\nSHELL: %s\\n",my_pwd->pw_name, my_pwd->pw_passwd,
> my_pwd->pw_uid, my_pwd->pw_gid,my_pwd->pw_gecos,my_pwd->pw_dir,
> my_pwd->pw_shell);
> }
> else
> {
> perror("getpwnam");
> }
> }
>
>
> Apart from this, I'm running out of ideas...
>
>
> ============================================================================================================
>
> On Thu, Jun 28, 2012 at 8:25 PM, Laurie Gustin <lgustin@utah.gov> wrote:
>
>> Fernando -
>> Thanks for the reply - I checked on things and this is what I found.....
>> Are you sure that the local database machine recognizes that user?
>> I can log into the machine just fine... and run dbaccess from the command
>> line. I should note that I also get this error when trying to connect with
>> user informix
>> Are you sure ssh is not authenticating the user against some other
>> mechanism (LDAP for example)?
>> no ldap or other authentication
>>
>>
>> Does the user exist in /etc/passwd? Are you sure that "oninit" can access
>> the file?
>> yes - the user is in /etc/passwd permissions are: -rw-r--r--. 1 root root
>> 1707 Jun 28 09:31 passwd
>>
>> Do you use SE-Linux?
>> se-linux was running. we shut it down but that didnt fix the problem.
>> Is that a regular instance or a "private installation"?
>> this is just a regular vanilla install of IDS 11.7
>> Is oninit running as root/with setuid?
>> most of the oninit processes are running as root, so I would say yes.
>> Any other ideas?
>> Thanks
>> Laurie
>> Laurie Gustin
>> Database Administrator
>> Dept of Technology Services
>> Dept of Public Safety
>> lgustin@utah.gov
>> 801-965-4410
>>
>>
>> >>> Fernando Nunes <domusonline@gmail.com> 6/28/2012 11:27 AM >>>
>>
>> Error -951, seen on the online log has nothing to do with .rhosts and no
>> one should put things in .rhosts if it's not needed.
>> Error -951 (this will not sound right) means the user does not exist. And
>> yes, I've read the ssh test...
>> Are you sure that the local database machine recognizes that user? Are
>> you sure ssh is not authenticationg the user against some other mechanism
>> (LDAP for example)?
>>
>> Does the user exist in /etc/passwd? Are you sure that "oninit" can access
>> the file? Do you use SE-Linux? And do you use ldap? Is that a regular
>> instance or a "private installation"? Is oninit running as root/with setuid?
>>
>> Regards
>>
>>
>> On Thu, Jun 28, 2012 at 6:05 PM, Goldrick, Jim <jgoldrick@judsonu.edu>wrote:
>>
>>> ****
>>>
>>> I think you get that error if you don’t have your .rhosts file setup.
>>> Informix requires the .rhosts to have the remove host name in it. I
>>> generally do it in the user’s home directory/.rhosts file.****
>>>
>>> ****
>>>
>>> Thank you,****
>>>
>>> Jim Goldrick****
>>>
>>> System Admin****
>>>
>>> Judson University****
>>>
>>> 1151 N. State St.
>>> Elgin, IL 60123
>>> (573) 979-9079****
>>>
>>> ****
>>>
>>> Reminder: Judson University IT will never ask for your password or other
>>> personal information over email.****
>>>
>>> ****
>>>
>>> jgoldrick@judsonu.edu <brichardson@judsonu.edu>
>>> [image: cid:84678D8C-A727-4B9C-9ED3-27390449E610@local]****
>>>
>>> ****
>>>
>>> *From:* informix-list-bounces@iiug.org [mailto:
>>> informix-list-bounces@iiug.org] *On Behalf Of *Laurie Gustin
>>> *Sent:* Thursday, June 28, 2012 11:43 AM
>>> *To:* informix-list@iiug.org
>>> *Subject:* bad password error -951 in Server Studio****
>>>
>>> ****
>>>
>>> This seems straight forward... hopefully someone knows a quick answer.**
>>> **
>>>
>>> ****
>>>
>>> IDS 11.7 FC5****
>>>
>>> Red Hat Enterprise Server release 6.3 (Santiago)****
>>>
>>> ****
>>>
>>> Trying to connect through Server Studio.****
>>>
>>> Testing the database connection gets the following errors:****
>>>
>>> ****
>>>
>>> 10:05:06 Get Shadow Password for user [lgustin] failed!
>>> 10:05:06 Check for password aging/account lock-out.
>>> 10:05:06 listener-thread: err = -951: oserr = 0: errstr =
>>> lgustin@111.111.111.111: Incorrect password or user
>>> lgustin@111.111.111.111 is not known on the database server.****
>>>
>>> ****
>>>
>>> The test for the ssh connection goes through fine. Which means the
>>> username and password really are correct.****
>>>
>>> ****
>>>
>>> I'm thinking it has to do with access to the /etc/shadow file which has
>>> permissions 000 (and needs to stay that way). ****
>>>
>>> ****
>>>
>>> Any ideas?****
>>>
>>> ****
>>>
>>> Thanks****
>>>
>>> Laurie****
>>>
>>> ___________________