Re: likely database privilege problem
Posted in 2011
Hi TJ,
Here is the information to capture DRDA trace output from IDS server:
1) Open an IDS Command windows
2) Cleanup DUMPDIR output
cd $DUMPDIR
delete all files at $DUMPDIR
FYI: By default the DUMPDIR may be set to $INFORMIXDIR\\\\tmp
You can find this by scanning the onconfig file for the IDS server inst=
ance
located at ($INFORMIXDIR\\\\etc)
3) To start the DRDA trace at the computer where IDS server is running.=
onmode -p +1 drda_dbg
4) From client computer try establishing connection to IDS by using
DB2 .NET provider.
Since it is a DRDA connection, it must have generated a trace file at
$DUMPDIR
5) Please send the generated trace output file to me.
Regards,
Satyan
Software Engineer
R&D - IBM Information Management Division
11200 Lakeview, Lenexa, KS 66219
Tel: 913 599 8792 (T/L: 337-8792)
|------------>
| From: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Sathyanesh Krishnan/Lenexa/IBM@IBMUS =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| To: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|"Throstur Jonsson" <tj@rational-network.com> =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Cc: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Ardeshir Jamshidi/Oakland/IBM@IBMUS, ids@iiug.org, classics-bounces@=
iiug.org, informix-list@iiug.org, dotNet Runtime Team =
|
|<dotNet_Runtime_Team%IBMUS@us.ibm.com> =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Date: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|01/26/2011 11:35 PM =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Subject: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Re: likely database privilege problem =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Sent by: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|informix-list-bounces@iiug.org =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
Hi TJ,
The instruction you followed to setup the DRDA listening port on IDS se=
rver
is the right one.
I would like to take a look on trace output captured from client and ID=
S
server.
I will soon send you the information to capture the DRDA trace output f=
rom
IDS server.
Meanwhile can you please capture the trace output from the client and s=
end
it to me.
Information to take trace output from client:
1) Open a DB2 Command window at client computer
Then issue the following command to start capturing the trace.
db2trc on -i 16m -m "*.*.84.*.*" -t
2) Then run the client application connecting to IDS.
3) Dump the trace output to a file.
db2trc dmp db2trcout.dmp
4) Please send the output to me.
FYI:You can get more information about DB2TRC by going through the URL.=
http://www.ibm.com/developerworks/db2/library/techarticle/dm-0409melnyk=
/
The step3 of the testconn is trying to establish a connection.
To simplify the trace output we can use an application that try to
establish connection and close.
Please use the fooling source to build an application that try to estab=
lish
to server and close the connection.
static void Main(string[] args)
{
String ConnStr =3D "User
ID=3Dinformix;Password=3Dxxxxxx;Database=3Deloxnet;Server=3D192.168.57.=
72:9091";
DB2Connection Conn =3D new DB2Connection(ConnStr);
try
{
Conn.Open();
Console.WriteLine("Open Sucess");
}
catch (Exception e)
{
Console.WriteLine(e.ToString());
}
Conn.Close();
Console.WriteLine("Closed!");
}
Regards,
Satyan
Software Engineer
R&D - IBM Information Management Division
11200 Lakeview, Lenexa, KS 66219
Tel: 913 599 8792 (T/L: 337-8792)
Inactive hide details for "Throstur Jonsson" ---01/26/2011 03:47:13 AM-=
--Hi
Satyan, First of all those where the grant commands"Throstur Jonsson"
---01/26/2011 03:47:13 AM---Hi Satyan, First of all those where the gra=
nt
commands I ran against the database:
=
=
From: "Throstur Jonsson" <tj@rational-network.com> =
=
=
To: Sathyanesh Krishnan/Lenexa/IBM@IBMUS =
=
=
Cc: Ardeshir Jamshidi/Oakland/IBM@IBMUS, <classics-bounces@iiug.org=
>,
"dotNet Runtime Team" <dotNet_Runtime_Team%IBMUS@us.ibm.com>, =
<ids@iiug.org>, <informix-list@iiug.org> =
=
=
Date: 01/26/2011 03:47 AM =
=
=
Subjec Re: likely database privilege problem =
t: =
=
Hi Satyan,
First of all those where the grant commands I ran against the database:=
grant connect to public;
grant resource to public;Where there any more to run?
Yes the DRDA port is 9091, otherwise the same testconn40.exe command wo=
uld
not work when run from the local IDS server. But it does work there. It=
is
only when run from another machine on the Local Area Network that it fa=
ils,
as described in my previous post. Please note that the IBM .Net provide=
r is
correctly configured on that client machine. This is an IDS security
problem when trying to access the IDS over LAN via the DRDA. I can with=
out
problems access the same IDS from the same client computer using Server=
Studio or ODBC. It is only the DRDA connection that is giving me this
security issue.
There is no firewall running at the IDS server, so that is not the prob=
lem
either.
Actualy I configured the DRDA following my