Setting password for database user on Linux
Posted in 2000
A user on Informix for Linux could connect as informix but got "password is not correct for this user in the database server" (error 952) when CONNECTing as another user. The cause: the engine's authentication isn't PAM-aware and can't read shadowed and/or MD5-hashed passwords (oninit calls getpwnam, then fails opening /etc/shadow). Workarounds offered: revert to unshadowed /etc/passwd with standard DES crypt (remove md5 from /etc/pam.d/passwd and reset passwords). Informix cited bug 125608, fixed in IIF.2000 9.21 (patch via support for 9.20), but not addressed in 7.30.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues
Informix on Linux
I'm having difficulty with something that seems like it should be pretty
basic.
Using dbaccess, I can connect to the stores7 database and run select style
queries etc. without any problem. However, if I try to use the "connect"
option and specify a different user besides the "informix" user, I get
prompted for a password, I enter the password for that user and it says
"the password is not correct for this user in the database server".
What em I missing? How do I set the password for this use so that it is
known by the database server?
Thanks for any pointers that you can provide.
jb
Known problem if you are using the shadow password file or PAM. You
have to back down to /etc/passwd and connection with a username and
password will work again. The method was posted here in the last 4
months a few times and I believe it is somewhere on the Informix site
as well.
Art S. Kagel
John Brock wrote:
>
> Informix on Linux
>
> I'm having difficulty with something that seems like it should be pretty
> basic.
>
> Using dbaccess, I can connect to the stores7 database and run select style
> queries etc. without any problem. However, if I try to use the "connect"
> option and specify a different user besides the "informix" user, I get
> prompted for a password, I enter the password for that user and it says
> "the password is not correct for this user in the database server".
>
> What em I missing? How do I set the password for this use so that it is
> known by the database server?
>
> Thanks for any pointers that you can provide.
>
> jb
I've been looking for a solution to this problem like crazy. After
speaking to the Informix techsupport I was informed that "they had heard
of a workaround" that involved the removal of "md5" from the passwd file
in /etc/pam.d directory. I tried it and it didn't work. They also
informed me that this problem WILL NOT BE ADDRESSED BY INFORMIX. I've
not been able to find a description of the method that was posted during
the last 4 months anywhere (including Informix). Could someone who saw
the solution please repost?
/m
"Art S. Kagel" wrote:
>
> Known problem if you are using the shadow password file or PAM. You
> have to back down to /etc/passwd and connection with a username and
> password will work again. The method was posted here in the last 4
> months a few times and I believe it is somewhere on the Informix site
> as well.
>
> Art S. Kagel
>
> John Brock wrote:
> >
> > Informix on Linux
> >
> > I'm having difficulty with something that seems like it should be pretty
> > basic.
> >
> > Using dbaccess, I can connect to the stores7 database and run select style
> > queries etc. without any problem. However, if I try to use the "connect"
> > option and specify a different user besides the "informix" user, I get
> > prompted for a password, I enter the password for that user and it says
> > "the password is not correct for this user in the database server".
> >
> > What em I missing? How do I set the password for this use so that it is
> > known by the database server?
> >
> > Thanks for any pointers that you can provide.
> >
> > jb
Here is the response I got from Informix when I questioned them about this bug (I use IIF.2000 9.20): From: Anabella James <anabella.james@informix.com> Subject: RE: Fix for the shadow password bug in IIF.2000 To: "Ivan Raikov" <ivan@faxnet.com> Cc: Anabella James <anabella.james@informix.com> Date: Wed, 19 Jul 2000 16:25:08 -0500 Hello Ivan, Thank you for contacting Informix. My apologies for the late response. The bug you are referring to is: bug# 125608 ON LINUX (KERNEL 2.2.5) USER CANNOT CONNECT (ERROR 952, WRONG PASSWORD) WHEN PASSWORD SHADOWING (PWCONV) AND NIS IS ENABLED I'm not sure what version you have of IIF.2000 but this bug has been fixed with version 9.21. If you are not using the combination of password shadowing and NIS, you shouldn't have a problem with 9.20. If you do have version 9.20 you can get patches only through support. Please call them at 1-800-274-8184, if you are internationally located, please contact your local sales office. Please go to the sales office website to find the office nearest you: http://www.informix.com/informix/contact/offices Best regards, Anabella James -- Ivan Raikov 800 Fowler Street, Atlanta, Georgia 30313-2554 Phone: 404-892-6579 x. 106 Email: raikov@cc.gatech.edu
Ivan Raikov <raikov@cc.gatech.edu> writes: > I'm not sure what version you have of IIF.2000 but this bug has been fixed > with version 9.21. If you are not using the combination of password > shadowing and NIS, you shouldn't have a problem with 9.20. That translates to: "If you're not interested in securing your system in a production environment, you shouldn't have a problem". Is 9.21 out for Linux? If so, has anyone tested to verify that PAM works with it? -- Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 President, CEO Fax: (760) 499-9152 My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B
It seems to have been fixed for IIF2K - but not for 7.30. My problem lies in the fact that I have to use 7.3. (due to project constraints). I've got it working now but I had remove any use of encrypted passwords. /m In article <m38zuw7ktr.fsf@fkth15.eastnet.gatech.edu>, Ivan Raikov <raikov@cc.gatech.edu> wrote: > > Here is the response I got from Informix when I questioned them about > this bug (I use IIF.2000 9.20): > > From: Anabella James <anabella.james@informix.com> > Subject: RE: Fix for the shadow password bug in IIF.2000 > To: "Ivan Raikov" <ivan@faxnet.com> > Cc: Anabella James <anabella.james@informix.com> > Date: Wed, 19 Jul 2000 16:25:08 -0500 > > Hello Ivan, > Thank you for contacting Informix. My apologies for the late response. > > The bug you are referring to is: bug# 125608 > ON LINUX (KERNEL 2.2.5) USER CANNOT CONNECT (ERROR 952, WRONG PASSWORD) > WHEN PASSWORD SHADOWING (PWCONV) AND NIS IS ENABLED > > I'm not sure what version you have of IIF.2000 but this bug has been fixed > with version 9.21. If you are not using the combination of password > shadowing and NIS, you shouldn't have a problem with 9.20. > > If you do have version 9.20 you can get patches only through support. Please > call them at 1-800-274-8184, if you are internationally located, please > contact your local sales office. Please go to the sales office website to > find the office nearest you: > http://www.informix.com/informix/contact/offices > > Best regards, > Anabella James > > -- > Ivan Raikov > 800 Fowler Street, Atlanta, Georgia 30313-2554 > Phone: 404-892-6579 x. 106 > Email: raikov@cc.gatech.edu > Sent via Deja.com http://www.deja.com/ Before you buy.
Here's what I found on the Informix TechInfo site, regarding this problem on 7.30: Product: Informix ONLINE Reported: 10/22/1999 ONLINE 7.30.UC7 FOR LINUX: CONNECTION AUTHENTICATION NOT PAM AWARE; WILL FAIL IF NONSTANDARD DES CRYPT ENCRYPTION USED FOR PASSWORD AUTHENTICATION. I helped troubleshoot an authentication problem with 7.30.UC7 for linux. What was happening was that connection attempts to the engine would always fail with a "952: User's password is not correct for the database server" error. Of course, we could log into the system fine. What we found out was that it seems that our executables are not pam (pluggable authentication method) aware, and John was using md5 as an encryption method, instead of the standard DES crypt. Here is what John's /etc/pam.d/passwd authentication configuration was set to: [informix@zappa bin]$ cat /etc/pam.d/passwd #%PAM-1.0 auth required /lib/security/pam_pwdb.so shadow nullok account required /lib/security/pam_pwdb.so password required /lib/security/pam_cracklib.so retry=3 password required /lib/security/pam_pwdb.so use_authtok md5 nullok shadow When we changed the passwd config by eliminating the md5 and after changing user passwords, we could now successfully connect to the 7.30.UC7 server. This is a Redhat 6.1 system, which during installation allows the selection of md5 as an encryption method. It seems that Informix should become more pam compliant, especially since Redhat has been pam enabled since 4.0. the_bwana@my-deja.com writes: > It seems to have been fixed for IIF2K - but not for 7.30. My problem > lies in the fact that I have to use 7.3. (due to project constraints). > I've got it working now but I had remove any use of encrypted passwords. > /m > -- Ivan Raikov 800 Fowler Street, Atlanta, Georgia 30313-2554 Phone: 404-892-6579 x. 106 Email: raikov@cc.gatech.edu
the_bwana@my-deja.com writes: > It seems to have been fixed for IIF2K - but not for 7.30. My problem > lies in the fact that I have to use 7.3. (due to project constraints). > I've got it working now but I had remove any use of encrypted passwords. Actually, they are still encrypted (with DES), but not shadowed. -- Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412 Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142 President, CEO Fax: (760) 499-9152 My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B
Ivan Raikov <gte085h@prism.gatech.edu> writes:
> What we found out was that it seems that our executables are not pam
> (pluggable authentication method) aware, and John was using md5 as an
> encryption method, instead of the standard DES crypt.
Yes, to use 7.30, you must be using unshadowed, DES passwords.
Could someone running IDS-9.2[01] on RedHat 6.x be so kind as to run
this command:
$ for i in $INFORMIXDIR/bin/*; do ldd $i | grep libpam; done
and tell me if libpam.so.0 and libpam_misc.so.0 are present in the
output? Thanks!
--
Forte International, P.O. Box 1412, Ridgecrest, CA 93556-1412
Ronald Cole <ronald@forte-intl.com> Phone: (760) 499-9142
President, CEO Fax: (760) 499-9152
My GPG fingerprint: C3AF 4BE9 BEA6 F1C2 B084 4A88 8851 E6C8 69E3 B00B
No, IDS 9.20 does not seem to be using libpam*; I think that was
established earlier. I just ran ldd on my Mandrake system, to verify
that.
By the way, an ltrace/strace on oninit (with shadowed passwords) shows
that it's calling getpwnam (3) and that's opening '/etc/passwd'
reading the first entry, then trying to open '/etc/shadow' and failing
(obviously) because the process does not have permission to open this
file.
Ivan Raikov
Ronald Cole <ronald@forte-intl.com> writes:
>
> Yes, to use 7.30, you must be using unshadowed, DES passwords.
>
> Could someone running IDS-9.2[01] on RedHat 6.x be so kind as to run
> this command:
>
> $ for i in $INFORMIXDIR/bin/*; do ldd $i | grep libpam; done>
> and tell me if libpam.so.0 and libpam_misc.so.0 are present in the
> output? Thanks!
>
--
Ivan Raikov
800 Fowler Street, Atlanta, Georgia 30313-2554
Phone: 404-892-6579 x. 106
Email: raikov@cc.gatech.edu