problem using JDBC proxy as applet
Posted in 1999
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Platform-Specific Issues, Java & JDBC Development
Hello, We are trying to implement an intranet solution which will be accessible as an applet under Netscape 4.5. In order to deal with applet security restrictions, we are attempting to use the Informix JDBC proxy. We have set up the proxy under Apache 1.3.4 under Linux, and tested it succesfully as an ***application*** using both Borland JBuilder client and Linux JDK 1.1.7. However, we have not gotten any client to work yet as an applet. Our problem appears to be security restrictions in either the Netscape VM or Java plug-in. For the Netscape VM, I have made a signed jar file which has a class which calls the "Interval" test. This is supplied by Informix in the JDBC distribution under the directory "demo/basic" in the file Interval.java. As I mentioned, I ran this Interval test successfully as an application. In the signed jar file, I wrote a simple class which calls this Interval main method: [... code fragment --- please e-mail if you would like more details ... ] /*************************************************************************** * Title: Interval.java * * Description: Demo inserting and selecting Informix intervals * * An example of running the program: * * java Interval * 'jdbc:informix-sqli://myhost:1533:informixserver=myserver;user=rdtest;passwor d=test' * * Expected result: * * Inserting and fetching Interval columns test. * * URL = "jdbc:informix-sqli://myhost:1533:informixserver=myserver;user=rdtest;passwor d=test" * * Create a table * Create table rowcount = 0 * * Insert an interval using a String host variable * Insert rowcount = 1 * * Select from intrvl_tab * Select: ym = 102-11 * Select: ds = 5 10:03:55 * * Test End * *************************************************************************** */ import java.sql.*; import java.util.*; import java.lang.*; import java.applet.*; import netscape.security.PrivilegeManager; /* * Connect an existing database test db. Create a table and insert * and fetch an interval value. */ public class IApp2 extends Applet { public void init() { // enable privileges needed by Netscape try { PrivilegeManager.enablePrivilege("UniversalConnect"); } catch (netscape.security.ForbiddenTargetException e) { System.out.println("Error: permission not granted to run this applet."); return; } catch (Exception e) { System.out.println("Unknown exception " + e); return; } init2("jdbc:informix-sqli://infhost:1546:informixserver=infserv;proxy=proxyhost:80"); } public void init2(String arg) { String url = arg; StringTokenizer st = new StringTokenizer(url, ":"); String token; String newUrl = ""; String testName = "Inserting and fetching Interval columns"; [... more code not shown... ] I have tried running this applet in two ways, both with no success: 1. Manually creating a signed jar file from the ifxjdbc.jar file supplied by Informix. I put this file on the CLASSPATH environment variable before starting Netscape. The HTML is as follows: <HTML> <HEAD> <TITLE>Test of Informix JDBC (as applet)</TITLE> </HEAD> <BODY> <H1 ALIGN="CENTER">Test of Informix JDBC (as applet)</H1> <P> <APPLET CODE="IApp2.class" width=200 height=200> </APPLET> </BODY> </HTML> I successfully get the window pop-up to grant "UniversalConnect" permission for the applet, but then the Java Console reports the following: URL = "jdbc:informix-sqli://infhost:1546/testDB:informixserver=infserv;proxy=proxyh ost:80" # Error: Inconsistent files in META-INF directory (-7886) # jar file: /opt/java/signtool/ifxjsign.jar # path: /opt/java/signtool/ifxjsign.jar ERROR: failed to connect: java.sql.SQLException: Message text will be provided in later releases netscape.net.URLConnection 2. Same as 1, but use the usual ifxjdbc.jar, not my manually created signed jar. This also gets the UniversalConnect permission pop-up, but then fails with: URL = "jdbc:informix-sqli://infhost:1546/testDB:informixserver=infserv;proxy=proxyh ost:80" Principal: Internal Error: Unknown principal Permission denied: classes are not signed # Security Exception: checkpropsaccess.key netscape.security.AppletSecurityException: security.checkpropsaccess.key at netscape.security.AppletSecurity.checkPropertyAccess(AppletSecurity.java:481) at java.lang.SecurityManager.checkPropertyAccess(SecurityManager.java:958) at java.lang.System.getProperty(System.java:425) at com.informix.asf.Connection.<init>(Connection.java:266) at com.informix.jdbc.IfxSqliConnect.<init>(IfxSqliConnect.java:437) at com.informix.jdbc.IfxDriver.connect(IfxDriver.java:188) at java.sql.DriverManager.getConnection(DriverManager.java:90) at java.sql.DriverManager.getConnection(DriverManager.java:146) at IApp2.init2(IApp2.java:109) at IApp2.init(IApp2.java:57) at netscape.applet.DerivedAppletFrame$InitAppletEvent.dispatch(DerivedAppletFram e.java:553) at java.awt.EventDispatchThread$EventPump.dispatchEvents(EventDispatchThread.jav a:81) at java.awt.EventDispatchThread.run(EventDispatchThread.java:135) at netscape.applet.DerivedAppletFrame$AppletEventDispatchThread.run(DerivedApple tFrame.java:911) ERROR: failed to connect: java.sql.SQLException: Message text will be provided in later releases security.checkpropsaccess.key We have gotten similar security problems when trying to use the Java 1.2 plug-in under Netscape 4.5. Does anyone have any suggestions on how to get this working? Thanks in advance, Carl Tichler ctichler@millburncorp.com -----------== Posted via Deja News, The Discussion Network ==---------- http://www.dejanews.com/ Search, Read, Discuss, or Start Your Own
ctichler@my-dejanews.com wrote: > Hello, [SNIP] Uhmm, I responded to Carl on the IIUG linux thread and off line. I recommended using serialized objects and doing a 3 tier approach. This way he could see if its the applet, the server app, or the JDBC connection which is causing the problem. IMHO if you are going to do something like this, then you would want to do an applet to a server side application, that connects to the database. Not having Informix's implementation of the JDBC in front of me, I don't know if the "proxy" method is a standard part of the sql interface. Thus I'd be hesitant to use it. Since Informix is here, maybe the author of the JDBC methods could elaborate on the method. Methinks the real problem lies in that the JVM sees the server differently, thus it thinks its a violation of the security rules. (Applets can't connect to any machine except the machine that launched them.) This means bad host file/dns/rdns, etc ... Just out of curiousity, is there anyone who has been certified? Did anyone take the 1.2 test? Anyone go for the developer certification yet? -Mikey