RE: dbcopy over secure/encrypted line
Posted in 2008
Topics: Backup & Restore, Performance & Tuning, Server Administration, Security, Permissions & Auditing, Migration, Import/Export & Data Conversion
(sorry for the top-post)
Yeah, I can run the dbcopy in normal mode. We cannot use the -P or -U
options, because we run under privileged accts for which we do not have
the passwords (effectively, we sudo to the accts). The piece that is
missing is to be able to use a secure/encrypted connection between the
two boxes, such as using ssh. I have the keys set up between them, but
AFAIK, the data sent via dbcopy does NOT by default travel over an ssh
connection. Am I wrong? I tried to set up ssh port forwarding, but
that just seemed to hose things up when I tried to use dbcopy via
that/those ports. Maybe I just set it up wrong - dunno. That's why I
was asking if anyone had already done this.
I got some very useful suggestions re HPL & named-pipes & ssh, and will
definitely take a serious look at that route. But I'm comfortable with
and like dbcopy, and was just hoping for a simple solution using that
tool.
Thanks,
Paul M.
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
This message may contain confidential and/or privileged information. If
you are not the addressee
or authorized to receive this for the addressee, you must not use, copy,
disclose, or take any action
based on this message or any information herein. If you have received
this message in error,
please advise the sender immediately by reply e-mail and delete this
message.
Thank you for your cooperation.
<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
From: informix-list-bounces@iiug.org
[mailto:informix-list-bounces@iiug.org] On Behalf Of Art Kagel
Sent: Thursday, September 18, 2008 3:30 PM
To: Informix list
Subject: Fwd: dbcopy over secure/encrypted line
IMG: Um, that's EXACTLY what dbcopy does and it already exists. The
problem Paul is having is using dbcopy between servers that don't trust
each other and require an ssh communications.
Paul: What version of dbcopy.ec do you have? The -P & -U options to
pass in username and password for the connections were added in October
of 2004 in v1.43. It does use the same username and password on both
connections, so if you need different ones for each server, it would be
a new feature. For now you could make sure that the same username is
available on both machines, and that the password is the same on both
during the copy operation. Can the two machines ping each other? Can
you open a remote dbaccess session from one machine to a DB on the
other? If so, dbcopy should be able to do it also.
Art
On Thu, Sep 18, 2008 at 1:03 PM, Ian Michael Gumby
<im_gumby@hotmail.com> wrote:
Why not write a simple python script that has two database connections.
One to the old database and one to the new database?
In short, you select data from one table, insert row in to new table on
second box.
If you want better performance, then create multiple threads and do a
table per thread.
This will move your data over, never having to stage it on disk.
> Subject: RE: dbcopy over secure/encrypted line
> Date: Thu, 18 Sep 2008 11:46:07 -0500
> From: mosserp@wellsfargo.com
> To: curtis@crowson1.com; informix-list@iiug.org
>
> > -----Original Message-----
> > From: informix-list-bounces@iiug.org [mailto:informix-list-
> > bounces@iiug.org] On Behalf Of bozon
> > Sent: Thursday, September 18, 2008 8:44 AM
> > To: informix-list@iiug.org
> > Subject: Re: dbcopy over secure/encrypted line
> >
> > On Sep 17, 5:50 pm, <moss...@wellsfargo.com> wrote:
> > > Anyone have an ideas on how to use Art K.'s "dbcopy" utility over
a
> > > secure/encrypted line? I tried to set up port forwarding under
ssh,
> > but
> > > am not having any luck. Anyone made this to work?
> > >
> > > TIA,
> > > Paul M.
> >
> > Are you using a later version of informix because HPL is now much
> > nicer. The onpladm command works great. This may take the place of
> > using dbcopy. Can you just use HPL to unload the data and then sftp
to
> > the other box? Also in 10 you can redirect ontape through the ssh I
> > have an example of doing this that might work for you.
> >
> > just type onpladm for help
> >
> > onpladm
> > usage : onpladm <command>
> > create job <jobname> {options}>
> << clipped >>
>
> Thanks for the suggestion. HPL might be an option, but we were hoping
> to bypass having to put the data to flat files at all, thus the desire
> to use dbcopy. And ontape is not an option for us, as we are migrating
> to different boxes (HP => Linux), and different IDS versions (9.40 =>
> 10.00).
>
> A co-worker (former Informix employee) and I were experimenting, and
> there might be a way to use named pipes, ssh, and unload / load, to
get
> the data across and loaded. Anyone already done something like that??
>
> TIA (again),
> Paul M.
>
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org
> http://www.iiug.org/mailman/listinfo/informix-list
_____
Get more out of the Web. Learn 10 hidden secrets of Windows Live. Learn
Now
<http://windowslive.com/connect/post/jamiethomson.spaces.live.com-Blog-c
ns%21550F681DAD532637%215295.entry?ocid=TXT_TAGLM_WL_getmore_092008>
_______________________________________________
Informix-list mailing list
Informix-list@iiug.org
http://www.iiug.org/mailman/listinfo/informix-list
--
Art S. Kagel
Oninit (www.oninit.com)
IIUG Board of Directors (art@iiug.org)
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Oninit, the IIUG, nor any other
organization with which I am associated either explicitly or implicitly.
Neither do those opinions reflect those of other individuals affiliated
with any entity with which I am affiliated nor those of the entities
themselves.
--
Art S. Kagel
Oninit (www.oninit.com)
IIUG Board of Directors (art@iiug.org)
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Oninit, the IIUG, nor any other
organization with which I am associated either explicitly or implicitly.
Neither do those opinions reflect those of other individuals affiliated
with any entity with which I am affiliated nor those of the entities
themselves.
mosserp@wellsfargo.com wrote:
> (sorry for the top-post)
>
>
>
> Yeah, I can run the dbcopy in normal mode. We cannot use the 'P or 'U
> options, because we run under privileged accts for which we do not have
> the passwords (effectively, we sudo to the accts). The piece that is
> missing is to be able to use a secure/encrypted connection between the
> two boxes, such as using ssh. I have the keys set up between them, but
> AFAIK, the data sent via dbcopy does NOT by default travel over an ssh
> connection. Am I wrong? I tried to set up ssh port forwarding, but
> that just seemed to hose things up when I tried to use dbcopy via
> that/those ports. Maybe I just set it up wrong ' dunno. That's why I
> was asking if anyone had already done this.
>
>
>
> I got some very useful suggestions re HPL & named-pipes & ssh, and will
> definitely take a serious look at that route. But I'm comfortable with
> and like dbcopy, and was just hoping for a simple solution using that tool.
>
>
>
> Thanks,
> Paul M.
> /<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>/
> /This message may contain confidential and/or privileged information.
> If you are not the addressee
> or authorized to receive this for the// //addressee, you must not use,
> copy, disclose, or take any action
> based on this message or any information herein. If you have received
> this message in error,
> please advise the sender immediately by reply e-mail and delete this
> message.
> Thank you for your cooperation.//
> //<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>/
>
> *From:* informix-list-bounces@iiug.org
> [mailto:informix-list-bounces@iiug.org] *On Behalf Of *Art Kagel
> *Sent:* Thursday, September 18, 2008 3:30 PM
> *To:* Informix list
> *Subject:* Fwd: dbcopy over secure/encrypted line
>
>
>
>
>
> IMG: Um, that's EXACTLY what dbcopy does and it already exists. The
> problem Paul is having is using dbcopy between servers that don't trust
> each other and require an ssh communications.
>
> Paul: What version of dbcopy.ec <http://dbcopy.ec> do you have? The -P
> & -U options to pass in username and password for the connections were
> added in October of 2004 in v1.43. It does use the same username and
> password on both connections, so if you need different ones for each
> server, it would be a new feature. For now you could make sure that the
> same username is available on both machines, and that the password is
> the same on both during the copy operation. Can the two machines ping
> each other? Can you open a remote dbaccess session from one machine to
> a DB on the other? If so, dbcopy should be able to do it also.
>
> Art
>
> On Thu, Sep 18, 2008 at 1:03 PM, Ian Michael Gumby <im_gumby@hotmail.com
> <mailto:im_gumby@hotmail.com>> wrote:
>
> Why not write a simple python script that has two database connections.
> One to the old database and one to the new database?
>
> In short, you select data from one table, insert row in to new table on
> second box.
>
> If you want better performance, then create multiple threads and do a
> table per thread.
>
> This will move your data over, never having to stage it on disk.
>
>
>
>
> > Subject: RE: dbcopy over secure/encrypted line
> > Date: Thu, 18 Sep 2008 11:46:07 -0500
> > From: mosserp@wellsfargo.com <mailto:mosserp@wellsfargo.com>
> > To: curtis@crowson1.com <mailto:curtis@crowson1.com>;
> informix-list@iiug.org <mailto:informix-list@iiug.org>
>
>
> >
> > > -----Original Message-----
> > > From: informix-list-bounces@iiug.org
> <mailto:informix-list-bounces@iiug.org> [mailto:informix-list-
> <mailto:informix-list->
> > > bounces@iiug.org <mailto:bounces@iiug.org>] On Behalf Of bozon
> > > Sent: Thursday, September 18, 2008 8:44 AM
> > > To: informix-list@iiug.org <mailto:informix-list@iiug.org>
> > > Subject: Re: dbcopy over secure/encrypted line
> > >
> > > On Sep 17, 5:50 pm, <moss...@wellsfargo.com
> <mailto:moss...@wellsfargo.com>> wrote:
> > > > Anyone have an ideas on how to use Art K.'s "dbcopy" utility over a
> > > > secure/encrypted line? I tried to set up port forwarding under ssh,
> > > but
> > > > am not having any luck. Anyone made this to work?
> > > >
> > > > TIA,
> > > > Paul M.
> > >
> > > Are you using a later version of informix because HPL is now much
> > > nicer. The onpladm command works great. This may take the place of
> > > using dbcopy. Can you just use HPL to unload the data and then sftp to
> > > the other box? Also in 10 you can redirect ontape through the ssh I
> > > have an example of doing this that might work for you.
> > >
> > > just type onpladm for help
> > >
> > > onpladm
> > > usage : onpladm <command>
> > > create job <jobname> {options}> >
> > << clipped >>
> >
> > Thanks for the suggestion. HPL might be an option, but we were hoping
> > to bypass having to put the data to flat files at all, thus the desire
> > to use dbcopy. And ontape is not an option for us, as we are migrating
> > to different boxes (HP => Linux), and different IDS versions (9.40 =>
> > 10.00).
> >
> > A co-worker (former Informix employee) and I were experimenting, and
> > there might be a way to use named pipes, ssh, and unload / load, to get
> > the data across and loaded. Anyone already done something like that??
> >
> > TIA (again),
> > Paul M.
> >
> > _______________________________________________
> > Informix-list mailing list
> > Informix-list@iiug.org <mailto:Informix-list@iiug.org>
> > http://www.iiug.org/mailman/listinfo/informix-list
>
> ------------------------------------------------------------------------
>
> Get more out of the Web. Learn 10 hidden secrets of Windows Live. Learn
> Now
> <http://windowslive.com/connect/post/jamiethomson.spaces.live.com-Blog-cns%21550F681DAD532637%215295.entry?ocid=TXT_TAGLM_WL_getmore_092008>
>
>
> _______________________________________________
> Informix-list mailing list
> Informix-list@iiug.org <mailto:Informix-list@iiug.org>
> http://www.iiug.org/mailman/listinfo/informix-list
>
>
>
>
> --
> Art S. Kagel
> Oninit (www.oninit.com <http://www.oninit.com>)
> IIUG Board of Directors (art@iiug.org <mailto:art@iiug.org>)
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Oninit, the IIUG, nor any other
> organization with which I am associated either explicitly or implicitly.
> Neither do those opinions reflect those of other individuals affiliated
> with any entity with which I am affiliated nor those of the entities
> themselves.
>
>
>
>
> --
> Art S. Kagel
> Oninit (www.oninit.com <http://www.oninit.com>)
> IIUG Board of Directors (art@iiug.org <mailto:art@iiug.org>)
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Oninit, the IIUG, nor any other
> organization with which I am associated either explicitly or implicitly.
> Neither do those opinions