Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver.
Posted in 2009
A user on Windows couldn't connect SQuirreL SQL via the Informix JDBC driver to IDS 11.5 on Debian through an SSH port-forwarded localhost:53260, getting IfxASFException / -908. Replies confirmed the type-4 JDBC driver alone is enough (no CSDK), and suggested testing the tunnel with telnet and enabling SQuirreL's JDBC debug output. A typo in the ssh forwarding command was fixed, but -908 persisted; further ideas (check online.log, bypass the tunnel using port 15260, add client to /etc/hosts, DHCP/reverse-lookup and hosts.equiv issues) were offered. The thread drifts into a rsh/.rhosts argument and records no confirmed fix.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Connectivity: ODBC / JDBC / .NET, Server Administration, Security, Permissions & Auditing, Platform-Specific Issues, Java & JDBC Development
Good day!
I'm presently working a Debian Linux 5.0 development server with IDS
11.5 Developer Edition. My instance and database have successfully
been created and now I'm trying to connect to the Db using SQuirreL
SQL on a windows system. The Informix JDBC driver has been loaded to
the client and it looks okay there. The problem I am having is
connectivity to the database even when I have set up GRANT permission
on the database. "informix" user has been created on the Debian
server. Here is the syntax used for grant permissions.
> GRANT CONNECT TO PUBLIC;
> GRANT CONNECT TO informix;
> GRANT DBA TO informix;
I can connect locally with dbaccess, but unable to connect using
SQuirreL SQL. Do I need the IDS Client SDK even though I have the
Informix JDBC driver loaded and configured? What more do I need to
do? I have been working on this for a few days when time allows and
I'm stumped.
Here is some information about the SQuirrel SQL configuration.
jdbc:informix-sqli://localhost:53260/
morganscrossing:INFORMIXSERVER=vm_ids_115
Error:
vm-debian-5 (vm_ids_115:morganscrossing):
com.informix.asf.IfxASFException: Attempt to connect to database
server (vm_ids_115) failed.
Thank you,
Christopher
Not sure since I don't use JDBC, but IB that if you are using the Informix
JDBC client driver and not the IBM Common Client JDBC driver, that you need
to also install either CSDK or iConnect (the runtime version of CSDK). IB
that the Common Client does not need this.
Art
Art S. Kagel
Oninit (www.oninit.com)
IIUG Board of Directors (art@iiug.org)
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Oninit, the IIUG, nor any other organization
with which I am associated either explicitly or implicitly. Neither do
those opinions reflect those of other individuals affiliated with any entity
with which I am affiliated nor those of the entities themselves.
On Tue, Apr 7, 2009 at 11:48 AM, epsilon <cesmiga@gmail.com> wrote:
> Good day!
>
> I'm presently working a Debian Linux 5.0 development server with IDS
> 11.5 Developer Edition. My instance and database have successfully
> been created and now I'm trying to connect to the Db using SQuirreL
> SQL on a windows system. The Informix JDBC driver has been loaded to
> the client and it looks okay there. The problem I am having is
> connectivity to the database even when I have set up GRANT permission
> on the database. "informix" user has been created on the Debian
> server. Here is the syntax used for grant permissions.
>
> > GRANT CONNECT TO PUBLIC;
> > GRANT CONNECT TO informix;
> > GRANT DBA TO informix;>
> I can connect locally with dbaccess, but unable to connect using
> SQuirreL SQL. Do I need the IDS Client SDK even though I have the
> Informix JDBC driver loaded and configured? What more do I need to
> do? I have been working on this for a few days when time allows and
> I'm stumped.
>
> Here is some information about the SQuirrel SQL configuration.
>
> jdbc:informix-sqli://localhost:53260/
> morganscrossing:INFORMIXSERVER=vm_ids_115
>
> Error:
> vm-debian-5 (vm_ids_115:morganscrossing):
> com.informix.asf.IfxASFException: Attempt to connect to database
> server (vm_ids_115) failed.
>
> Thank you,
> Christopher
>
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
>
If you have Informix JDBC installed, that should be enough. Have you tried connecting to the server using a simple Java/JDBC program? why do you have localhost and not the IP address or hostname for your debian machine that you are trying to connect to in the JDBC URL. Change that and that should probably take care of it. jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ morganscrossing:INFORMIXSERVER=vm_ids_115 VG.
VG, The "localhost" entry is used because I'm port forwarding with "ssh" and "localhost" is used instead of a hostname/ip when port forwarding. Thanks for the suggestions. Christopher VG wrote: > If you have Informix JDBC installed, that should be enough. Have you > tried connecting to the server using a simple Java/JDBC program? > why do you have localhost and not the IP address or hostname for your > debian machine that you are trying to connect to in the JDBC URL. > Change that and that should probably take care of it. > > > jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ > morganscrossing:INFORMIXSERVER=vm_ids_115 > > > VG.
By the way, I appreciate the help and want to thank everyone that contributed some time on this. You all are great and thanks again. If you all have more ideas, please send them over. Thank you, Christopher epsilon wrote: > VG, > > The "localhost" entry is used because I'm port forwarding with "ssh" > and "localhost" is used instead of a hostname/ip when port forwarding. > > Thanks for the suggestions. > > Christopher > > > > > VG wrote: > > If you have Informix JDBC installed, that should be enough. Have you > > tried connecting to the server using a simple Java/JDBC program? > > why do you have localhost and not the IP address or hostname for your > > debian machine that you are trying to connect to in the JDBC URL. > > Change that and that should probably take care of it. > > > > > > jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ > > morganscrossing:INFORMIXSERVER=vm_ids_115 > > > > > > VG.
Hi, do you get a connect when you do a telnet localhost 53260 ? If this connects it proves that at least the tcpip part works... (my guess it that it doesnt) If yes, are you sure vm_ids_115 is the correct instance name? Sounds more like a machine name to me... Cheers, Dirk -- -- -- Dipl.-Math. Dirk Gunsth'vel -- -professional services- -- -- Dirk Gunsth'vel IT Systemanalyse - GunCon -- Hammer Str. 13 -- D-48153 Muenster -- phone: +49 (0) 251 28446- 0 -- fax: +49 (0) 251 28446-55 -- web: http://www.GunCon.de -- email: info@GunCon.de -- UStId: DE 189527667 -- -- 'One now understands why some animals eat their young.' -- (Andrew in 'Bicentennial Man' 1999) "epsilon" <cesmiga@gmail.com> schrieb im Newsbeitrag news:2008e454-1945-429e-b93b-05173e7ea6bf@l25g2000vba.googlegroups.com... > VG, > > The "localhost" entry is used because I'm port forwarding with "ssh" > and "localhost" is used instead of a hostname/ip when port forwarding. > > Thanks for the suggestions. > > Christopher > > > > > VG wrote: >> If you have Informix JDBC installed, that should be enough. Have you >> tried connecting to the server using a simple Java/JDBC program? >> why do you have localhost and not the IP address or hostname for your >> debian machine that you are trying to connect to in the JDBC URL. >> Change that and that should probably take care of it. >> >> >> jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ >> morganscrossing:INFORMIXSERVER=vm_ids_115 >> >> >> VG.
epsilon wrote:
> Good day!
>
> I'm presently working a Debian Linux 5.0 development server with IDS
> 11.5 Developer Edition. My instance and database have successfully
> been created and now I'm trying to connect to the Db using SQuirreL
> SQL on a windows system. The Informix JDBC driver has been loaded to
> the client and it looks okay there. The problem I am having is
> connectivity to the database even when I have set up GRANT permission
> on the database. "informix" user has been created on the Debian
> server. Here is the syntax used for grant permissions.
>
>> GRANT CONNECT TO PUBLIC;
>> GRANT CONNECT TO informix;
>> GRANT DBA TO informix;>
> I can connect locally with dbaccess, but unable to connect using
> SQuirreL SQL. Do I need the IDS Client SDK even though I have the
> Informix JDBC driver loaded and configured? What more do I need to
> do? I have been working on this for a few days when time allows and
> I'm stumped.
>
> Here is some information about the SQuirrel SQL configuration.
>
> jdbc:informix-sqli://localhost:53260/
> morganscrossing:INFORMIXSERVER=vm_ids_115
>
> Error:
> vm-debian-5 (vm_ids_115:morganscrossing):
> com.informix.asf.IfxASFException: Attempt to connect to database
> server (vm_ids_115) failed.
>
> Thank you,
> Christopher
>
Go to Global Preferences -> SQL -> Debug and select JDBC Debug to Output Stream
Then try the connect again. After failure click on the small monitor icon on
the bottom bar.
You should see an error like:
SQLState(08004) vendor code(-908)
If it says "-908" than you have a base tcp connection issue. Either you're not
specifying the correct ports or server name, or your tunneling is not working.
If it's another error than post it here.
JDBC driver is enough. You will not need any Client SDK stuff.
The informix JDBC driver is type 4 meaning it's fully independent:
http://java.sun.com/products/jdbc/driverdesc.html
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Dirk, Listed below shows that I do not have a connection. Hmm. The database is running. Listed below is result of the telnet response. Strange, I wonder what this means outside of communication. $> telnet localhost 53260 Trying 127.0.0.1... telnet: Unable to connect to remote host: Connection refused Christopher Dirk Gunsthövel wrote: > Hi, > > do you get a connect when you do a > telnet localhost 53260 > ? > > If this connects it proves that at least the tcpip part > works... (my guess it that it doesnt) > > If yes, are you sure vm_ids_115 is the correct instance > name? Sounds more like a machine name to me... > > Cheers, > Dirk > > -- > -- > -- Dipl.-Math. Dirk Gunsth'vel > -- -professional services- > -- > -- Dirk Gunsth'vel IT Systemanalyse - GunCon > -- Hammer Str. 13 > -- D-48153 Muenster > -- phone: +49 (0) 251 28446- 0 > -- fax: +49 (0) 251 28446-55 > -- web: http://www.GunCon.de > -- email: info@GunCon.de > -- UStId: DE 189527667 > -- > -- 'One now understands why some animals eat their young.' > -- (Andrew in 'Bicentennial Man' 1999) > > > "epsilon" <cesmiga@gmail.com> schrieb im Newsbeitrag > news:2008e454-1945-429e-b93b-05173e7ea6bf@l25g2000vba.googlegroups.com... > > VG, > > > > The "localhost" entry is used because I'm port forwarding with "ssh" > > and "localhost" is used instead of a hostname/ip when port forwarding. > > > > Thanks for the suggestions. > > > > Christopher > > > > > > > > > > VG wrote: > >> If you have Informix JDBC installed, that should be enough. Have you > >> tried connecting to the server using a simple Java/JDBC program? > >> why do you have localhost and not the IP address or hostname for your > >> debian machine that you are trying to connect to in the JDBC URL. > >> Change that and that should probably take care of it. > >> > >> > >> jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ > >> morganscrossing:INFORMIXSERVER=vm_ids_115 > >> > >> > >> VG.
epsilon wrote: > VG, > > The "localhost" entry is used because I'm port forwarding with "ssh" > and "localhost" is used instead of a hostname/ip when port forwarding. > > Thanks for the suggestions. > > Christopher > > > > > VG wrote: >> If you have Informix JDBC installed, that should be enough. Have you >> tried connecting to the server using a simple Java/JDBC program? >> why do you have localhost and not the IP address or hostname for your >> debian machine that you are trying to connect to in the JDBC URL. >> Change that and that should probably take care of it. >> >> >> jdbc:informix-sqli://<hostname of the debian LINUX BOX>:53260/ >> morganscrossing:INFORMIXSERVER=vm_ids_115 >> >> >> VG. From this and the test with telnet I believe it's safe to assume your port forwarding is broken... right? -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
VG
Oops! A blasted operator error on my part with port forwarding. I
had a typo in the "ssh" port syntax I was trying to use. This has
been corrected as listed below, and now I see the -908 error you
mentioned as a possibility.
$> telnet localhost 53260
Trying 127.0.0.1...
Connected to BOOBOO.bcgssbd.doodles.com.
Escape character is '^]'.
Connection closed by foreign host.
Went to Global Preferences -> SQL -> Debug and select JDBC Debug to
Output Stream.
Then I tried to connect again. After the failure I clicked on the
small monitor icon at the bottom bar and saw the error:
SQLState(08004) vendor code(-908)
java.sql.SQLException: com.informix.asf.IfxASFException: Attempt to
connect to database server (vm_ids_115) failed.
http://www.oninit.com/errorcode/index.php (Oninit States)
-908 Attempt to connect to database server (servername) failed.
The program or application is trying to access another database server
but has failed. Note the server name in the current statement.
The desired database server is unavailable, or the network is down or
is congested. Ask your DBA and system administrator to verify that the
server and network are operational. If the network is congested, use
the environment variables INFORMIXCONTIME and INFORMIXCONRETRY to tune
connection timing. For information on setting these environment
variables, see the IBM Informix Guide to SQL: Reference.
-----
Linux ENV Settings
-----
INFORMIXCONRETRY=3
INFORMIXCONTIME=120
INFORMIXDIR=/opt/IBM/informix
INFORMIXSERVER=vm_ids_115
INFORMIXSQLHOSTS=/opt/IBM/informix/etc/sqlhosts.vm_ids_115
$ cat /opt/IBM/informix/etc/sqlhosts.vm_ids_115
#==============================================================
#DBSERVER PROTOCOL HOSTNAME SERVICE
#==============================================================
vm_ids_115 onsoctcp vm-debian-5 15260
vm_ids_115_drda drsoctcp vm-debian-5 15261
vm_ids_115_shm onipcshm vm-debian-5 dummy
vm_ids_115_str onipcstr vm-debian-5 dummy
Thank you,
Christopher
Fernando Nunes wrote:
> epsilon wrote:
> > Good day!
> >
> > I'm presently working a Debian Linux 5.0 development server with IDS
> > 11.5 Developer Edition. My instance and database have successfully
> > been created and now I'm trying to connect to the Db using SQuirreL
> > SQL on a windows system. The Informix JDBC driver has been loaded to
> > the client and it looks okay there. The problem I am having is
> > connectivity to the database even when I have set up GRANT permission
> > on the database. "informix" user has been created on the Debian
> > server. Here is the syntax used for grant permissions.
> >
> >> GRANT CONNECT TO PUBLIC;
> >> GRANT CONNECT TO informix;
> >> GRANT DBA TO informix;> >
> > I can connect locally with dbaccess, but unable to connect using
> > SQuirreL SQL. Do I need the IDS Client SDK even though I have the
> > Informix JDBC driver loaded and configured? What more do I need to
> > do? I have been working on this for a few days when time allows and
> > I'm stumped.
> >
> > Here is some information about the SQuirrel SQL configuration.
> >
> > jdbc:informix-sqli://localhost:53260/
> > morganscrossing:INFORMIXSERVER=vm_ids_115
> >
> > Error:
> > vm-debian-5 (vm_ids_115:morganscrossing):
> > com.informix.asf.IfxASFException: Attempt to connect to database
> > server (vm_ids_115) failed.
> >
> > Thank you,
> > Christopher
> >
>
> Go to Global Preferences -> SQL -> Debug and select JDBC Debug to Output Stream
> Then try the connect again. After failure click on the small monitor icon on
> the bottom bar.
> You should see an error like:
>
> SQLState(08004) vendor code(-908)
>
> If it says "-908" than you have a base tcp connection issue. Either you're not
> specifying the correct ports or server name, or your tunneling is not working.
> If it's another error than post it here.
>
> JDBC driver is enough. You will not need any Client SDK stuff.
> The informix JDBC driver is type 4 meaning it's fully independent:
>
> http://java.sun.com/products/jdbc/driverdesc.html
>
> Regards.
>
> --
> Fernando Nunes
> Portugal
>
> http://informix-technology.blogspot.com
> My email works... but I don't check it frequently...
epsilon wrote:
> VG
>
> Oops! A blasted operator error on my part with port forwarding. I
> had a typo in the "ssh" port syntax I was trying to use. This has
> been corrected as listed below, and now I see the -908 error you
> mentioned as a possibility.
>
> $> telnet localhost 53260
> Trying 127.0.0.1...
> Connected to BOOBOO.bcgssbd.doodles.com.
> Escape character is '^]'.
> Connection closed by foreign host.
>
> Went to Global Preferences -> SQL -> Debug and select JDBC Debug to
> Output Stream.
> Then I tried to connect again. After the failure I clicked on the
> small monitor icon at the bottom bar and saw the error:
>
> SQLState(08004) vendor code(-908)
> java.sql.SQLException: com.informix.asf.IfxASFException: Attempt to
> connect to database server (vm_ids_115) failed.
>
> http://www.oninit.com/errorcode/index.php (Oninit States)
>
> -908 Attempt to connect to database server (servername) failed.
>
> The program or application is trying to access another database server
> but has failed. Note the server name in the current statement.
>
> The desired database server is unavailable, or the network is down or
> is congested. Ask your DBA and system administrator to verify that the
> server and network are operational. If the network is congested, use
> the environment variables INFORMIXCONTIME and INFORMIXCONRETRY to tune
> connection timing. For information on setting these environment
> variables, see the IBM Informix Guide to SQL: Reference.
>
> -----
> Linux ENV Settings
> -----
> INFORMIXCONRETRY=3
> INFORMIXCONTIME=120
> INFORMIXDIR=/opt/IBM/informix
> INFORMIXSERVER=vm_ids_115
> INFORMIXSQLHOSTS=/opt/IBM/informix/etc/sqlhosts.vm_ids_115
>
> $ cat /opt/IBM/informix/etc/sqlhosts.vm_ids_115>
> #==============================================================
> #DBSERVER PROTOCOL HOSTNAME SERVICE
> #==============================================================
> vm_ids_115 onsoctcp vm-debian-5 15260
> vm_ids_115_drda drsoctcp vm-debian-5 15261
> vm_ids_115_shm onipcshm vm-debian-5 dummy
> vm_ids_115_str onipcstr vm-debian-5 dummy>
>
> Thank you,
> Christopher
>
>
>
>
>
>
>
>
> Fernando Nunes wrote:
>> epsilon wrote:
>>> Good day!
>>>
>>> I'm presently working a Debian Linux 5.0 development server with IDS
>>> 11.5 Developer Edition. My instance and database have successfully
>>> been created and now I'm trying to connect to the Db using SQuirreL
>>> SQL on a windows system. The Informix JDBC driver has been loaded to
>>> the client and it looks okay there. The problem I am having is
>>> connectivity to the database even when I have set up GRANT permission
>>> on the database. "informix" user has been created on the Debian
>>> server. Here is the syntax used for grant permissions.
>>>
>>>> GRANT CONNECT TO PUBLIC;
>>>> GRANT CONNECT TO informix;
>>>> GRANT DBA TO informix;>>> I can connect locally with dbaccess, but unable to connect using
>>> SQuirreL SQL. Do I need the IDS Client SDK even though I have the
>>> Informix JDBC driver loaded and configured? What more do I need to
>>> do? I have been working on this for a few days when time allows and
>>> I'm stumped.
>>>
>>> Here is some information about the SQuirrel SQL configuration.
>>>
>>> jdbc:informix-sqli://localhost:53260/
>>> morganscrossing:INFORMIXSERVER=vm_ids_115
>>>
>>> Error:
>>> vm-debian-5 (vm_ids_115:morganscrossing):
>>> com.informix.asf.IfxASFException: Attempt to connect to database
>>> server (vm_ids_115) failed.
>>>
>>> Thank you,
>>> Christopher
>>>
>> Go to Global Preferences -> SQL -> Debug and select JDBC Debug to Output Stream
>> Then try the connect again. After failure click on the small monitor icon on
>> the bottom bar.
>> You should see an error like:
>>
>> SQLState(08004) vendor code(-908)
>>
>> If it says "-908" than you have a base tcp connection issue. Either you're not
>> specifying the correct ports or server name, or your tunneling is not working.
>> If it's another error than post it here.
>>
>> JDBC driver is enough. You will not need any Client SDK stuff.
>> The informix JDBC driver is type 4 meaning it's fully independent:
>>
>> http://java.sun.com/products/jdbc/driverdesc.html
>>
>> Regards.
>>
>> --
>> Fernando Nunes
>> Portugal
>>
>> http://informix-technology.blogspot.com
>> My email works... but I don't check it frequently...
Weird... Can you check the online.log of your instance at the time you did the
connect using telnet? Does it show any message like "invalid message received
from sqlexec"?
-908 is an error that happens when something is wrong at the lower layer (TCP).
It has nothing to do with permissions, grants, passwords etc.
I'm still not convinced your port forwarding is working ok... Can you confirm
the port numbers and host names? Also, can you confirm it didn't close the
tunnel when telnet exited?
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Like Fernando says, I believe something else is wrong... can you bypass ssh port forwarding and see if the direct connect works (modifying the URL to use port 15260 instead)? VG.
VG I will try that idea and get back with you all. Thank you, Christopher VG wrote: > Like Fernando says, I believe something else is wrong... can you > bypass ssh port forwarding and see if the direct connect works > (modifying the URL to use port 15260 instead)? > > VG.
epsilon wrote: > VG > > Oops! A blasted operator error on my part with port forwarding. I > had a typo in the "ssh" port syntax I was trying to use. This has > been corrected as listed below, and now I see the -908 error you > mentioned as a possibility. > > $> telnet localhost 53260 > Trying 127.0.0.1... > Connected to BOOBOO.bcgssbd.doodles.com. > Escape character is '^]'. > Connection closed by foreign host. > > Went to Global Preferences -> SQL -> Debug and select JDBC Debug to > Output Stream. > Then I tried to connect again. After the failure I clicked on the > small monitor icon at the bottom bar and saw the error: > > SQLState(08004) vendor code(-908) > java.sql.SQLException: com.informix.asf.IfxASFException: Attempt to > connect to database server (vm_ids_115) failed. > > http://www.oninit.com/errorcode/index.php (Oninit States) > > -908 Attempt to connect to database server (servername) failed. > I've seen 908 arise from the fact that the server couldn't verify the client's address. Is you client obtaining its address by DHCP? If so does the DHCP server provide a DNS service and does the database server use that as a name server? If the client address is fixed does the database server have it in /etc/hosts? If the client is using DHCP it may be best to reserve the address on the DHCP server and then set this up in the database server's host file. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Ian, Thanks for the tip. I added the host entry to the ids server and the results were the same as mentioned earlier. Our IDS DBA is out this week and I'll chat with him since he has his SQuirreL Client working. If/when I get this working, I'll update the forum. Again, I want to thank everyone for their time and effort with this. I know the answer is out there, I just need to keep hammering on it. Thanks again, Christopher Ian Goddard wrote: > epsilon wrote: > > VG > > > > Oops! A blasted operator error on my part with port forwarding. I > > had a typo in the "ssh" port syntax I was trying to use. This has > > been corrected as listed below, and now I see the -908 error you > > mentioned as a possibility. > > > > $> telnet localhost 53260 > > Trying 127.0.0.1... > > Connected to BOOBOO.bcgssbd.doodles.com. > > Escape character is '^]'. > > Connection closed by foreign host. > > > > Went to Global Preferences -> SQL -> Debug and select JDBC Debug to > > Output Stream. > > Then I tried to connect again. After the failure I clicked on the > > small monitor icon at the bottom bar and saw the error: > > > > SQLState(08004) vendor code(-908) > > java.sql.SQLException: com.informix.asf.IfxASFException: Attempt to > > connect to database server (vm_ids_115) failed. > > > > http://www.oninit.com/errorcode/index.php (Oninit States) > > > > -908 Attempt to connect to database server (servername) failed. > > > > I've seen 908 arise from the fact that the server couldn't verify the > client's address. Is you client obtaining its address by DHCP? If so > does the DHCP server provide a DNS service and does the database server > use that as a name server? If the client address is fixed does the > database server have it in /etc/hosts? If the client is using DHCP it > may be best to reserve the address on the DHCP server and then set this > up in the database server's host file. > > -- > Ian > > Hotmail is for spammers. Real mail address is igoddard > at nildram co uk
Ian Goddard wrote: > epsilon wrote: >> VG >> >> Oops! A blasted operator error on my part with port forwarding. I >> had a typo in the "ssh" port syntax I was trying to use. This has >> been corrected as listed below, and now I see the -908 error you >> mentioned as a possibility. >> >> $> telnet localhost 53260 >> Trying 127.0.0.1... >> Connected to BOOBOO.bcgssbd.doodles.com. >> Escape character is '^]'. >> Connection closed by foreign host. >> >> Went to Global Preferences -> SQL -> Debug and select JDBC Debug to >> Output Stream. >> Then I tried to connect again. After the failure I clicked on the >> small monitor icon at the bottom bar and saw the error: >> >> SQLState(08004) vendor code(-908) >> java.sql.SQLException: com.informix.asf.IfxASFException: Attempt to >> connect to database server (vm_ids_115) failed. >> >> http://www.oninit.com/errorcode/index.php (Oninit States) >> >> -908 Attempt to connect to database server (servername) failed. >> > > I've seen 908 arise from the fact that the server couldn't verify the > client's address. Is you client obtaining its address by DHCP? If so > does the DHCP server provide a DNS service and does the database server > use that as a name server? If the client address is fixed does the > database server have it in /etc/hosts? If the client is using DHCP it > may be best to reserve the address on the DHCP server and then set this > up in the database server's host file. > Uhu? 908 because of a failed reverse DNS? Weird... Nevertheless, it doesn't apply here... The "host" that IDS will see is the same machine as the one running the engine, because of the port forwarding... Nice way to connect without password and trusts :) Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Fernando Nunes wrote:
> Uhu? 908 because of a failed reverse DNS? Weird...
Yup. After switching from Centos (as per my earler thread) to Ubuntu
rsh prompted for a password despite setting up hosts.equiv *and* rhosts
and dbaccess returned 908 to a client obtaining its IP on DHCP. The
initial fix was to put a + in hosts.equiv instead of the client name -
in other words accept any host.
This makes sense when you think about it. The server receives a
connection attempt from an IP address - how does can it compare this
with a name in hosts.equiv? It needs to do a reverse lookup. If IDS is
using the same mechanism then it has the same problem.
Notwithstanding your tutorial on using PAM this is a badly documented
area. For instance Informix docs mention testing the connection with
rsh. Google reveals that if anyone failing to get rsh to work posts a
query on a forum they are almost invariably answered by a know-all
telling them to use ssh instead.
--
Ian
Hotmail is for spammers. Real mail address is igoddard
at nildram co uk
> Date: Thu, 9 Apr 2009 08:15:51 +0100
> From: goddai01@hotmail.co.uk
> Subject: Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver.
> To: informix-list@iiug.org
>
> Fernando Nunes wrote:
> > Uhu? 908 because of a failed reverse DNS? Weird...
>
> Yup. After switching from Centos (as per my earler thread) to Ubuntu
> rsh prompted for a password despite setting up hosts.equiv *and* rhosts
> and dbaccess returned 908 to a client obtaining its IP on DHCP. The
> initial fix was to put a + in hosts.equiv instead of the client name -
> in other words accept any host.
>
First, no duh! What you said above will never work!
With respect of putting a + or dynamic IP'd machine in any of your hosts.equiv entries... uhm very bad idea. If this was a production machine, your sysadmin would bitch slap you and probably demand that you get fired for gross incompetence. While it sounds like this is a test machine, you should still act like its a production machine.
With respect to your problem as stated above...
Let me get this straight. You have a client that gets its IP address from DHCP. Ok, so how then is the server supposed to know who the machine is? TRY SETTING UP THE CLIENT WITH A STATIC IP ADDRESS.
Oh and DO NOT USE .rhosts !!! Anyone who does this is a pathetic moron/git/imbicile/ brain dead idiot and should be fired for incompetence.
THIS IS WORSE THAN TRYING TO RUN INFORMIX CHUNKS ON A RAID 5 DISK ARRAY!
Look, here's the skinny. (Caveat, I'm going from memory so take it for what its worth...)
You have a machine name that is tied to a dynamic address. How does your server resolve that name to a *trusted* known machine? The answer is that it can't. Now there are companies that offer services where they'll let you dynamically update your IP address to resolve to a name, but thats a different beast.
You can't authenticate xxx.xxx.xxx.yyy as a specific machine.
In your hosts.equiv, you can enter either an ip address or a hostname.
If you're using dynamic IPs how do you expect your server to resolve the hostname to an IP, therefore your hosts.equiv will not work. You can input an IP address, however, because you're using dynamic IPs you don't have the guarantee that the IP in the file is going to match your pc.
As luck would have it, you could assign a static IP address to your pc and put the IP address in your hosts.equiv. However, I would really, really recommend that you don't do it. Is your PC equivelent to your server? ;-)
HTH
-Mikey
> This makes sense when you think about it. The server receives a
> connection attempt from an IP address - how does can it compare this
> with a name in hosts.equiv? It needs to do a reverse lookup. If IDS is
> using the same mechanism then it has the same problem.
>
> Notwithstanding your tutorial on using PAM this is a badly documented
> area. For instance Informix docs mention testing the connection with
> rsh. Google reveals that if anyone failing to get rsh to work posts a
> query on a forum they are almost invariably answered by a know-all
> telling them to use ssh instead.
>
> --
> Ian
>
> Hotmail is for spammers. Real mail address is igoddard
> at nildram co uk
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
_________________________________________________________________
Windows Live™: Keep your life in sync.
http://windowslive.com/explore?ocid=TXT_TAGLM_WL_allup_1a_explore_042009
Ian Michael Gumby wrote:
>
>
> > Date: Thu, 9 Apr 2009 08:15:51 +0100
> > From: goddai01@hotmail.co.uk
> > Subject: Re: Trouble connecting to IDS 11.5 development server using
> SQuirrel SQL with IDS JDBC driver.
> > To: informix-list@iiug.org
> >
> > Fernando Nunes wrote:
> > > Uhu? 908 because of a failed reverse DNS? Weird...
> >
> > Yup. After switching from Centos (as per my earler thread) to Ubuntu
> > rsh prompted for a password despite setting up hosts.equiv *and* rhosts
> > and dbaccess returned 908 to a client obtaining its IP on DHCP. The
> > initial fix was to put a + in hosts.equiv instead of the client name -
> > in other words accept any host.
> >
>
> First, no duh! What you said above will never work!
This sounds rather like the bumblebee. According to theory the bee
cannot possibly fly. Unfortunately nobody told the bee and it flies
quite happily. And nobody told my setup it couldn't work either. But
read on.
> With respect of putting a + or dynamic IP'd machine in any of your
> hosts.equiv entries... uhm very bad idea. If this was a production
> machine, your sysadmin would bitch slap you and probably demand that you
> get fired for gross incompetence. While it sounds like this is a test
> machine, you should still act like its a production machine.
My words were "initial fix". This confirmed that reverse lookup was the
problem.
> With respect to your problem as stated above...
>
> Let me get this straight. You have a client that gets its IP address
> from DHCP. Ok, so how then is the server supposed to know who the
> machine is? TRY SETTING UP THE CLIENT WITH A STATIC IP ADDRESS.
And the longer term fix is to *reserve* an IP address on the DHCP
server. The client is a laptop and as laptops are liable to be used in
other locations a static IP address is not a good idea. A reserved
address on the DHCP server has the same effect, namely that the database
server can be given the appropriate name/IP pair.
> Oh and DO NOT USE .rhosts !!! Anyone who does this is a pathetic
> moron/git/imbicile/ brain dead idiot and should be fired for incompetence.
Well, that's Bill Joy told off; AFAIK the entire remote access stuff was
written by him. But what does he know?
Oh, by the way, the correct spelling is imbecile.
--
Ian
Hotmail is for spammers. Real mail address is igoddard
at nildram co uk
Ian Goddard wrote: > > This sounds rather like the bumblebee. According to theory the bee > cannot possibly fly. Unfortunately nobody told the bee and it flies > quite happily. http://en.wikipedia.org/wiki/Bumblebee#Bumblebee_myths -- RGB
Sigh.
Back in the 80's when a lot of the .rhosts and host.equiv stuff came out, there wasn't a lot of thought to security risks. This was when the internet was mainly a couple of tech companies and most of the networks on the net were universities. If you were lucky, you might be able to piggy back via dialup UUCP to get mail and Usenet. You could easily get a full class C block assigned to you permenently, or two. Canter and Siegel were not even an issue yet, and most people on the 'net followed the rules of ettiquette.
Morris changed that when he borrowed some of his dad's work and launched his worm. One of the vectors that Morris used was to gain access to a compromised machine and then compromise machines that were in /etc/hosts.equiv and .rhosts files. Note: He had gained root access because of a buffer overflow attack that worked on Sun and I think Vaxen. I believe it was Gene Spafford at Purdue that set up CERT and lead the work on reverse engineering the worm. We were lucky that we had a different brand of servers acting as our gateway so they were immune to the attack. Unfortunately, the pharmacology department got hit. They were out of our control and since the network was segmented, we got lucky and shut them down while we backed up all of our servers just in case.
Lessons learned was that .rhosts were a bad thing. Its something that sysadmins can't control and its a possible attack vector for worms and potentially other malicious code.
/etc/hosts.equiv isn't inherently bad, but it is dangerous. It is controlled by root access so it limits some exposure.
If you use it properly, its a good thing when you want to implement ER. It's also a good thing if you've got a private network segment between your database server and your web server. Essentially if you've got a secondary network connection that is private to only machines in your machine room that you know you can trust.
With respect to DHCP... I'm no expert so I've never seen where you can reserve an IP address for a specific machine that isn't a static IP address. In one of my clients, I have a sales office where there are between 75 - 125 laptops (and growing) on and off the network each day. There are a handfull of desktop and act as 'servers' that are tethered via a gigabit switch. Everything else is wireless. So I use a static IP address for the desktop machines and I use a wide range of addresses under DHCP. Even here, when connecting to the office printer/fax/scanner machine, they are set up via TCP/IP address and not name. So you can mix static and non-static IP addresses in the office.
On some of the wireless set ups, I believe you can set up individual profiles on laptops so that when you connect to a different network, you can specify if you want to use a specific static address or dhcp.
I'm sure if you spoke with Bill Joy lately, he'll tell you that yes, don't use .rhosts and be careful of hosts.equiv because of the potential dangers.
I understand that the audience here is mainly DBAs but any sysadmin who's worth their weight in <insert your own precious metal here>, they will go ballistic if you tell them that you need to use .rhosts or /etc/host.equiv when it comes to pc's on your network.
If you want to see someone go ballistic, go up to Art Kagel and tell him that you're running your servers on Raid 5 and you recommend that to all of your clients. ;-)
What pisses me off is that Morris happened in '88 or so. It took 5+ years to fix their Sun-OS / Solaris operating system to close their buffer overflow problems. (SCO and others didn't fix it until much later.) Now you know why the letter 'n' is important in C. (strcopy()should be strncopy() ... ); We're now 20+ years later and people still don't understand the simple things they need to do to protect their machines. Its not rocket science and its a trivial fix.
> Date: Thu, 9 Apr 2009 15:31:53 +0100
> From: goddai01@hotmail.co.uk
> Subject: Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver.
> To: informix-list@iiug.org
>
> Ian Michael Gumby wrote:
> >
> >
> > > Date: Thu, 9 Apr 2009 08:15:51 +0100
> > > From: goddai01@hotmail.co.uk
> > > Subject: Re: Trouble connecting to IDS 11.5 development server using
> > SQuirrel SQL with IDS JDBC driver.
> > > To: informix-list@iiug.org
> > >
> > > Fernando Nunes wrote:
> > > > Uhu? 908 because of a failed reverse DNS? Weird...
> > >
> > > Yup. After switching from Centos (as per my earler thread) to Ubuntu
> > > rsh prompted for a password despite setting up hosts.equiv *and* rhosts
> > > and dbaccess returned 908 to a client obtaining its IP on DHCP. The
> > > initial fix was to put a + in hosts.equiv instead of the client name -
> > > in other words accept any host.
> > >
> >
> > First, no duh! What you said above will never work!
>
> This sounds rather like the bumblebee. According to theory the bee
> cannot possibly fly. Unfortunately nobody told the bee and it flies
> quite happily. And nobody told my setup it couldn't work either. But
> read on.
>
> > With respect of putting a + or dynamic IP'd machine in any of your
> > hosts.equiv entries... uhm very bad idea. If this was a production
> > machine, your sysadmin would bitch slap you and probably demand that you
> > get fired for gross incompetence. While it sounds like this is a test
> > machine, you should still act like its a production machine.
>
> My words were "initial fix". This confirmed that reverse lookup was the
> problem.
>
> > With respect to your problem as stated above...
> >
> > Let me get this straight. You have a client that gets its IP address
> > from DHCP. Ok, so how then is the server supposed to know who the
> > machine is? TRY SETTING UP THE CLIENT WITH A STATIC IP ADDRESS.
>
> And the longer term fix is to *reserve* an IP address on the DHCP
> server. The client is a laptop and as laptops are liable to be used in
> other locations a static IP address is not a good idea. A reserved
> address on the DHCP server has the same effect, namely that the database
> server can be given the appropriate name/IP pair.
>
> > Oh and DO NOT USE .rhosts !!! Anyone who does this is a pathetic
> > moron/git/imbicile/ brain dead idiot and should be fired for incompetence.
>
> Well, that's Bill Joy told off; AFAIK the entire remote access stuff was
> written by him. But what does he know?
>
> Oh, by the way, the correct spelling is imbecile.
>
> --
> Ian
>
> Hotmail is for spammers. Real mail address is igoddard
> at nildram co uk
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
_________________________________________________________________
Quick access to your favorite MSN content and Windows Live with Internet Explorer 8.
http://ie8.msn.com/microsoft/internet-explorer-8/en-us/ie8.aspx?ocid=B037MSN55C0701A
> Date: Thu, 9 Apr 2009 15:54:20 +0100 > From: RedGrittyBrick@spamweary.invalid > Subject: Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver. > To: informix-list@iiug.org > > > Ian Goddard wrote: > > > > This sounds rather like the bumblebee. According to theory the bee > > cannot possibly fly. Unfortunately nobody told the bee and it flies > > quite happily. > > http://en.wikipedia.org/wiki/Bumblebee#Bumblebee_myths > Well look at it this way... his fix is to essentially set up his server such that anyone can connect to it as a trusted machine. Its essentially like walking to the center of Time Square in NY dropping your pants, spreading your legs standing next to a sign saying "Bugger me! Please!" Is that a graphic enough picture? Seriously just because you can do it, doesn't mean you should. Unfortunately, the Oracle DBAs are not much smarter. Here's a link to a blog post made this past February... http://neworacledba.blogspot.com/2009/02/etchostsequiv-file-security-threat.html (Hint: This has been a known security issue for the past 20+ years!!!) Of course IBM still doesn't grok security. From an IDS 10 online manual: http://publib.boulder.ibm.com/infocenter/idshelp/v10/index.jsp?topic=/com.ibm.admin.doc/admin151.htm [HINT: THIS SHOULD BE UPDATED] At least HP provides some better docs and some warnings. Gee I wonder why they would have a command parameter that limits the use of .rhosts to only root? You can read their man page here: http://docs.hp.com/en/B9106-90011/hosts.equiv.4.html I could go on ... and here are just two quick links to older user group forums where this topic has come up before: http://www.dbforums.com/informix/1208113-security-client-server-connection-informix-10-without-rhosts-hosts-equiv.html http://lists.samba.org/archive/samba/2003-August/071956.html Oh and if you think that Apple gets it straight... : http://www.juniper.net/security/auto/vulnerabilities/vuln31708.html But hey! What do I know? ;-) _________________________________________________________________ Quick access to your favorite MSN content and Windows Live with Internet Explorer 8. http://ie8.msn.com/microsoft/internet-explorer-8/en-us/ie8.aspx?ocid=B037MSN55C0701A
Ian Goddard wrote:
> Fernando Nunes wrote:
>> Uhu? 908 because of a failed reverse DNS? Weird...
>
> Yup. After switching from Centos (as per my earler thread) to Ubuntu
> rsh prompted for a password despite setting up hosts.equiv *and* rhosts
> and dbaccess returned 908 to a client obtaining its IP on DHCP. The
> initial fix was to put a + in hosts.equiv instead of the client name -
> in other words accept any host.
>
> This makes sense when you think about it. The server receives a
> connection attempt from an IP address - how does can it compare this
> with a name in hosts.equiv? It needs to do a reverse lookup. If IDS is
> using the same mechanism then it has the same problem.
>
> Notwithstanding your tutorial on using PAM this is a badly documented
> area. For instance Informix docs mention testing the connection with
> rsh. Google reveals that if anyone failing to get rsh to work posts a
> query on a forum they are almost invariably answered by a know-all
> telling them to use ssh instead.
>
I'll gladly accept suggestions for posts on this area... Just make me a list of
doubts/topics...
I may miss some "dirty" details that only R&D can provide, but I'll do my best.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
Ian Michael Gumby wrote: > > > > Date: Thu, 9 Apr 2009 15:54:20 +0100 > > From: RedGrittyBrick@spamweary.invalid > > Subject: Re: Trouble connecting to IDS 11.5 development server using > SQuirrel SQL with IDS JDBC driver. > > To: informix-list@iiug.org > > > > > > Ian Goddard wrote: > > > > > > This sounds rather like the bumblebee. According to theory the bee > > > cannot possibly fly. Unfortunately nobody told the bee and it flies > > > quite happily. > > > > http://en.wikipedia.org/wiki/Bumblebee#Bumblebee_myths > > > > Well look at it this way... his fix is to essentially set up his server > such that anyone can connect to it as a trusted machine. > Its essentially like walking to the center of Time Square in NY dropping > your pants, spreading your legs standing next to a sign saying "Bugger > me! Please!" > > Is that a graphic enough picture? > > Seriously just because you can do it, doesn't mean you should. > > Unfortunately, the Oracle DBAs are not much smarter. Here's a link to a > blog post made this past February... > http://neworacledba.blogspot.com/2009/02/etchostsequiv-file-security-threat.html > (Hint: This has been a known security issue for the past 20+ years!!!) > > > Of course IBM still doesn't grok security. From an IDS 10 online manual: > http://publib.boulder.ibm.com/infocenter/idshelp/v10/index.jsp?topic=/com.ibm.admin.doc/admin151.htm > [HINT: THIS SHOULD BE UPDATED] > > At least HP provides some better docs and some warnings. Gee I wonder > why they would have a command parameter that limits the use of .rhosts > to only root? You can read their man page here: > http://docs.hp.com/en/B9106-90011/hosts.equiv.4.html > > I could go on ... and here are just two quick links to older user group > forums where this topic has come up before: > http://www.dbforums.com/informix/1208113-security-client-server-connection-informix-10-without-rhosts-hosts-equiv.html > http://lists.samba.org/archive/samba/2003-August/071956.html > > Oh and if you think that Apple gets it straight... : > http://www.juniper.net/security/auto/vulnerabilities/vuln31708.html > > But hey! What do I know? ;-) > > > > ------------------------------------------------------------------------ > Quick access to your favorite MSN content and Windows Live with Internet > Explorer 8. Download FREE now! > <http://ie8.msn.com/microsoft/internet-explorer-8/en-us/ie8.aspx?ocid=B037MSN55C0701A> Once again I write... The files are not the main issue. Just close the services... If anyone wants to make a request for IDS stop using these files (like it'ts already possible for HDR setup) I'll put myself on the head of the line... But, again: IDS DOES NOT need the "r" services running... it just looks at the files (and not exactly the same way as the "r" commands). Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Ian Michael Gumby wrote: > Sigh. Sigh indeed > > /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is > controlled by root access so it limits some exposure. Read this and see if you recognise it: Informix requires a hosts.equiv file for its default authentication policy. Read it again: Informix requires a hosts.equiv file for its default authentication policy. Was there any part of that you didn't understand? Where does that come from? It comes from p3.12 of the IDS 11.50 IDS administrator's guide. Let's just say it again in case you missed it. Informix requires a hosts.equiv file for its default authentication policy. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Ian Michael Gumby wrote: > > > > Date: Thu, 9 Apr 2009 15:54:20 +0100 > > From: RedGrittyBrick@spamweary.invalid > > Subject: Re: Trouble connecting to IDS 11.5 development server using > SQuirrel SQL with IDS JDBC driver. > > To: informix-list@iiug.org > > > > > > Ian Goddard wrote: > > > > > > This sounds rather like the bumblebee. According to theory the bee > > > cannot possibly fly. Unfortunately nobody told the bee and it flies > > > quite happily. > > > > http://en.wikipedia.org/wiki/Bumblebee#Bumblebee_myths > > > > Well look at it this way... his fix is to essentially set up his server > such that anyone can connect to it as a trusted machine. Read my post again. This time read it properly. Find where I said that we're dealing with a box exposed to the internet. Find where I said that hosts.equiv was left open. You didn't find either did you? If you have a problem connecting and opening hosts.equiv as a temporary measure fixes it then you know you have a problem authenticating the client. Having done that you can close hosts.equiv and look for the source of your problem. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Ian Goddard wrote: > Ian Michael Gumby wrote: >> Sigh. > > Sigh indeed > >> >> /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is >> controlled by root access so it limits some exposure. > > Read this and see if you recognise it: > > Informix requires a hosts.equiv file for its default authentication policy. > > Read it again: > > > Informix requires a hosts.equiv file for its default authentication policy. > > Was there any part of that you didn't understand? > > Where does that come from? > > It comes from p3.12 of the IDS 11.50 IDS administrator's guide. > > Let's just say it again in case you missed it. > > Informix requires a hosts.equiv file for its default authentication policy. > > Please... whenever you say that, add that it DOESN'T need the "r" services running. Also add that you can control if it checks /etc/hosts.equiv or .rhosts or both or none. Also add that this happens ONLY if you want to use trusted connections (you can use other ways of authentication). Also add that it is NOT needed for distributed queries (just configure PAM). (you can also add that this is a touchy subject for me, but I believe people will not care about that ;) ) Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Fernando Nunes wrote: > Ian Goddard wrote: >> Ian Michael Gumby wrote: >>> Sigh. >> >> Sigh indeed >> >>> >>> /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is >>> controlled by root access so it limits some exposure. >> >> Read this and see if you recognise it: >> >> Informix requires a hosts.equiv file for its default authentication >> policy. >> >> Read it again: >> >> >> Informix requires a hosts.equiv file for its default authentication >> policy. >> >> Was there any part of that you didn't understand? >> >> Where does that come from? >> >> It comes from p3.12 of the IDS 11.50 IDS administrator's guide. >> >> Let's just say it again in case you missed it. >> >> Informix requires a hosts.equiv file for its default authentication >> policy. >> >> > > Please... whenever you say that, add that it DOESN'T need the "r" > services running. You'll need to speak to the folks who write the manuals because it goes on to suggest testing with rlogin > Also add that you can control if it checks /etc/hosts.equiv or .rhosts or both or none. I'm coming to the conclusion that Gumby can only take in small amounts of information at a time and that might be overload. -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
Ian Goddard wrote: > Fernando Nunes wrote: >> Ian Goddard wrote: >>> Ian Michael Gumby wrote: >>>> Sigh. >>> >>> Sigh indeed >>> >>>> >>>> /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is >>>> controlled by root access so it limits some exposure. >>> >>> Read this and see if you recognise it: >>> >>> Informix requires a hosts.equiv file for its default authentication >>> policy. >>> >>> Read it again: >>> >>> >>> Informix requires a hosts.equiv file for its default authentication >>> policy. >>> >>> Was there any part of that you didn't understand? >>> >>> Where does that come from? >>> >>> It comes from p3.12 of the IDS 11.50 IDS administrator's guide. >>> >>> Let's just say it again in case you missed it. >>> >>> Informix requires a hosts.equiv file for its default authentication >>> policy. >>> >>> >> >> Please... whenever you say that, add that it DOESN'T need the "r" >> services running. > > You'll need to speak to the folks who write the manuals because it goes > on to suggest testing with rlogin True... Of course, if it works with rlogin it should work with IDS ;) That should be fixed. I agree. > I'm coming to the conclusion that Gumby can only take in small amounts > of information at a time and that might be overload. > Most probably that's also true :) Well... I'll probably post something soon about this... I'll try to take the opportunity to do it before xC4 comes out. Than I'll have other subjects to cover ;) Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
> Date: Thu, 9 Apr 2009 22:16:00 +0100 > From: goddai01@hotmail.co.uk > Subject: Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver. > To: informix-list@iiug.org > > Ian Michael Gumby wrote: > > Sigh. > > Sigh indeed > > > > > /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is > > controlled by root access so it limits some exposure. > > Read this and see if you recognise it: > > Informix requires a hosts.equiv file for its default authentication policy. > > Read it again: > > > Informix requires a hosts.equiv file for its default authentication policy. > > Was there any part of that you didn't understand? > > Where does that come from? > > It comes from p3.12 of the IDS 11.50 IDS administrator's guide. > > Let's just say it again in case you missed it. > > Informix requires a hosts.equiv file for its default authentication policy. > > Authentication policy for what exactly? Java? Web apps? .Net and ODBC? Or just 4GL apps... Which would mean that there's an issue with the csdk and Informix's cli. I can understand that you would use /etc/hosts.equiv when you're setting up ER, but not for a client. And btw, I don't have pcs set up in etc/hosts.equiv and I can connect java apps (swing), Web apps from glassfish both without a problem. I'd try esql/c but I don't have a c compiler on my pc because I'm too cheap to buy one and too lazy to download gnu's C compiler .... I'll say it again and again. YOU DO NOT WANT TO USE .rhosts and be very careful with /etc/hosts.equiv. Period, end of story. As for Informix's connection authentication, it uses the underlying OS to authenticate users. If you have PAM or LDAP set up you can use that too. _________________________________________________________________ Rediscover Hotmail®: Get e-mail storage that grows with you. http://windowslive.com/RediscoverHotmail?ocid=TXT_TAGLM_WL_HM_Rediscover_Storage1_042009
> From: domusonline@gmail.com > > Informix requires a hosts.equiv file for its default authentication policy. > > > > > > Please... whenever you say that, add that it DOESN'T need the "r" services > running. Also add that you can control if it checks /etc/hosts.equiv or .rhosts > or both or none. Also add that this happens ONLY if you want to use trusted > connections (you can use other ways of authentication). Also add that it is NOT > needed for distributed queries (just configure PAM). > > (you can also add that this is a touchy subject for me, but I believe people > will not care about that ;) ) > > Regards. Geez! Ok, lets clear the air. Are you talking about a *trusted* server that is running Informix so you can *do* distributed queries? If so, then your server should have a static IP address and you should use /etc/hosts.equiv, but never .rhosts. You have PAM which is a little bit more than just for authentication services, and you could use LDAP which is an authentication service. I do agree that Informix's PAM documentation is a tad *lame* and back when 10.x was released, it was pretty much non-existent. If you're talking about a client to host connection. /etc/hosts.equiv is not an issue. If you're a bank/thrift and you're using .rhosts, you would probably fail an OTS IT audit. (Depending on the auditor.) If you use /etc/hosts.equiv, you'll have to document and justify why. Informix has done some brain dead things in the past... (NewEra anyone?) so it doesn't come as a shock that they would screw something else up... But hey! Like I said, it took IBM, SUN, SCO, and a couple of other vendors many. many years to put a little letter n in their strcopy and memcopy function calls... _________________________________________________________________ Rediscover Hotmail®: Get e-mail storage that grows with you. http://windowslive.com/RediscoverHotmail?ocid=TXT_TAGLM_WL_HM_Rediscover_Storage1_042009
> Date: Thu, 9 Apr 2009 22:34:46 +0100 > From: goddai01@hotmail.co.uk > > Also add that you can control if it checks /etc/hosts.equiv or .rhosts or both or none. > > I'm coming to the conclusion that Gumby can only take in small amounts > of information at a time and that might be overload. > > -- > Ian > No, I can take in a lot of information at a time. It seems that you can't grasp the potential damage you can do if you use .rhosts and /etc/host.equiv improperly. I'm not the one who can't get my connections to work, am I? Ok, I *did* have trouble with getting IDS to work on Sun's glassfish and webservers using Netbean's wizards. But that wasn't my fault that the documentation provided by Sun was wrong. ;-) (Yeah, I'll admit I was brain dead because while I was scratching my head, I totally ignored the fact that I had the java docs for Informix's jdbc on my machine. But that's another friggin story.) I will say this. Until you live through a firefight drill and spend 36 hours straight in panic mode, you don't appreciate how fixing a small thing can make your life easy. This is why I have tried to beat some sense in to you. Of course it doesn't help when the brain dead morons who wrote Informix's documentation don't grok proper sys admin security. _________________________________________________________________ Rediscover Hotmail®: Now available on your iPhone or BlackBerry http://windowslive.com/RediscoverHotmail?ocid=TXT_TAGLM_WL_HM_Rediscover_Mobile1_042009
Ian Michael Gumby wrote: > > > > Date: Thu, 9 Apr 2009 22:16:00 +0100 > > From: goddai01@hotmail.co.uk > > Subject: Re: Trouble connecting to IDS 11.5 development server using > SQuirrel SQL with IDS JDBC driver. > > To: informix-list@iiug.org > > > > Ian Michael Gumby wrote: > > > Sigh. > > > > Sigh indeed > > > > > > > > /etc/hosts.equiv isn't inherently bad, but it is dangerous. It is > > > controlled by root access so it limits some exposure. > > > > Read this and see if you recognise it: > > > > Informix requires a hosts.equiv file for its default authentication > policy. > > > > Read it again: > > > > > > Informix requires a hosts.equiv file for its default authentication > policy. > > > > Was there any part of that you didn't understand? > > > > Where does that come from? > > > > It comes from p3.12 of the IDS 11.50 IDS administrator's guide. > > > > Let's just say it again in case you missed it. > > > > Informix requires a hosts.equiv file for its default authentication > policy. > > > > > Authentication policy for what exactly? > Java? > Web apps? > > .Net and ODBC? > > Or just 4GL apps... > > Which would mean that there's an issue with the csdk and Informix's cli. > > I can understand that you would use /etc/hosts.equiv when you're setting > up ER, but not for a client. Exactly what part of the phrase "p3.12 of the IDS 11.50 IDS administrator's guide" did you not understand? -- Ian Hotmail is for spammers. Real mail address is igoddard at nildram co uk
> Date: Tue, 14 Apr 2009 08:43:07 +0100 > From: goddai01@hotmail.co.uk > Subject: Re: Trouble connecting to IDS 11.5 development server using SQuirrel SQL with IDS JDBC driver. > > Exactly what part of the phrase "p3.12 of the IDS 11.50 IDS > administrator's guide" did you not understand? > Uhm... NETRC? Or did you mean the basic information that starts on 3.11 talking about Network Security Files? And if you bothered to read, they're giving you a basic understanding of how Linux/Unix security is set up. They are not giving you a system administrator's look at the security risks around using these files. I *can* read, can you? Also in reading the subject line, we're talking about JDBC which has nothing to do with this because you don't need to use /etc/hosts.equiv with JDBC. _________________________________________________________________ Windows Live™: Keep your life in sync. http://windowslive.com/explore?ocid=TXT_TAGLM_WL_allup_1a_explore_042009
Related threads
- Connection break during waiting for resultset - how to deal with?
- Oracle ?
- EGL Licensing
- Max Locks Forever
- Re: Function for nth bit set?