enhaced secury problems
Posted in 2005
Topics: Versions, Editions & End-of-Life
hello I'm trying to log in into an Informix db IDS 7.3, I have just update the security from base to enhanced on my tru64 server. the db replays to me the -952 error, what can I do ??
On 11/21/05, FAUSTO CHIA.... <fausto_chiaretti@hotmail.com> wrote: > > hello I'm trying to log in into an Informix db IDS 7.3, I have just update > the security from base to enhanced on my tru64 server. > the db replays to me the -952 error, what can I do ?? Be more precise about the version of IDS 7.31 (or is it 7.30?) that you are using. Be more precise about the version of HP/DEC Tru64 Unix that you're using. Explain what the enhanced security option does - but I'd suspect that it changes the password system from the classic Unix /etc/passwd and /etc/shadow system to some fancier and more secure system. The chances are, IDS 7.3x does not know how to cope. The simplest solution is the obvious one - revert to the base security system. Alternatively, can you upgrade to IDS 9.40 or IDS 10.00 and use the PAM authentication modules? Is there a PAM module available that would work? -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
Hi,
I guess, that the security change on your system from "base" to
"enhanced" affected the password stuff on the machine.
You have to figure out, what has changed with the passwords.
There are several possibilities. For an idea what to look for I
currently can think of these:
- password encryption method has changed.
IDS supports (i.e. uses) only basic UNIX encryption as
implemented by the UNIX "crypt()" system call. Anything else
(like MD5 encryption method) is not supported.
- location of passwords has changed, e.g. from /etc/passwd file
to /etc/shadow file.
IDS can work with passwords in /etc/shadow , however, as that
file is readable only by user "root", file ownership and access
rights for binary "oninit" must be set correctly. (With passwords
in /etc/passwd and that file readable by anyone, IDS would also
work with improper access rights for binary "oninit".)
IDS usually will not work with location of passwords anywhere else
except from /etc/passwd , /etc/shadow , NIS/NIS+.
- password expiration (policy) has changed in a way that IDS thinks
the passwords are no longer valid.
Usually this would mean that you also can't (UNIX) login anymore,
as your password is expired. However, there's been a bug with this
in an old IDS version (I don't recall exact IDS version number, it was
maybe 3-5 years ago and has been fixed since) that made IDS think
that the password was expired even though it was not (yet) expired.
Regards,
Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
forum.subscriber@iiug.org wrote on 21.11.2005 16:28:04:
> hello I'm trying to log in into an Informix db IDS 7.3, I have just
update the security
> from base to enhanced on my tru64 server.
> the db replays to me the -952 error, what can I do ??
Changing to enhanced security will expire all passwords. If you are attempting to use the previous password the login will fail. I also experienced a problem with Informix 9.2 where it was impossible to connect via a net connection to Tru64 with enhanced security. Don't know if this also affects 7.x The problem hasn't appeared in 9.3. Simon Coyne Infrastructure Specialist DLA Piper Rudnick Gray Cary LLP
How
would I clean up these WARNINGS? I was told to 'ignore' them, but I
would rather the oncheck be 'clean'....
Thanks,
Wz
oncheck -cc -q -yWARNING:No sysdepend record for TBLspace gim2usr.sysdbspaces.
Ignore the warning if view is on table(s) external to current database.
WARNING:No syssyntable records found.
WARNING:No sysdepend record for TBLspace gim2usr.sysdbspaces.
Ignore the warning if view is on table(s) external to current database.
WARNING:No syssyntable records found.
WARNING:No syssyntable records found.
WARNING:No syssyntable records found.
WARNING:No syssyntable records found.
WARNING:No sysdepend record for TBLspace gim2usr.sysdbspaces.
Ignore the warning if view is on table(s) external to current database.
WARNING:No syssyntable records found.
WARNING:No syssyntable records found.
Please do not transmit orders or instructions regarding a UBS account by
e-mail. The information provided in this e-mail or any attachments is not an
official transaction confirmation or account statement. For your protection,
do not include account numbers, Social Security numbers, credit card
numbers, passwords or other non-public information in your e-mail. Because
the information contained in this message may be privileged, confidential,
proprietary or otherwise protected from disclosure, please notify us
immediately by replying to this message and deleting it from your computer
if you have received this communication in error. Thank you.
UBS Financial Services Inc.
UBS International Inc.