SPWDCSM gives error -5009
Posted in 2009
A user on IDS 10.00.FC9 / SLES 10.1 tried to enable the password-encryption CSM (SPWDCSM) via sqlhosts (csm=(SPWDCSM)) and concsm.cfg, but every connection attempt from dbaccess or Python informixdb failed with error -5009 and "Password Validation for user failed" in the online log. Respondents asked about CSDK version (a 3.50 SPWDCSM bug fixed in 3.50.xC3), PAM usage, and suggested testing a non-CSM DBSERVERALIAS and trying p=0. Trusted connections without user/password worked; connecting with username and password did not. No fix was found in the thread; the poster said he would contact IBM support.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration
Hello,
I'm trying to get an existing infromix 10.00-FC9 (on SLES 10.1) wo
work with SPWDCSM, configured like this:
"""
vittel:/opt/informix/etc # cat sqlhosts
olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
vittel:/opt/informix/etc # cat concsm.cfg
SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
"""
Alas, we had no luck with connecting to the db either through dbaccess
or the python informixdb on the same machine. The documentation
http://www.redbooks.ibm.com/redbooks/SG247556/5-3-3.htm
hints that I'd need an extra line in the concsm.cfg for client
access, but I wouldn't know where to put it in the sqlhosts. I tried
copying the sqlhosts to use with the client configuration provided by
the docu, but that didn't help either.
Every which way I tried, I keep getting a -5009 error, the informix
log stating:
"""
11:34:30 Password Validation for user [xxx] failed!
11:34:30 Check for password aging/account lock-out.
"""
I've rechecked the password for the user, and I can still log in
through ssh as this user on the machine, so that shouldn't be the
problem.
Can anyone help me out with this one? TIA,
Felix Schäfer
Hi Felix:
Which version of CSDK are you using? There is a bug in 3.50 related to SPWDSM
and the bug was fixed in 3.50.xC3.
Regards,
-Ping
--- On Mon, 5/4/09, Felix Schäfer <schaefer@cypres-it.com> wrote:
> From: Felix Schäfer <schaefer@cypres-it.com>
> Subject: SPWDCSM gives error -5009 [15660]
> To: ids@iiug.org
> Date: Monday, May 4, 2009, 5:04 AM
> Hello,
>
> I'm trying to get an existing infromix 10.00-FC9 (on SLES
> 10.1) wo
> work with SPWDCSM, configured like this:
> """
> vittel:/opt/informix/etc # cat sqlhosts
> olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
> vittel:/opt/informix/etc # cat concsm.cfg
> SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
> """
>
> Alas, we had no luck with connecting to the db either
> through dbaccess
> or the python informixdb on the same machine. The
> documentation
> http://www.redbooks.ibm.com/redbooks/SG247556/5-3-3.htm
>
> hints that I'd need an extra line in the concsm.cfg for
> client
> access, but I wouldn't know where to put it in the
> sqlhosts. I tried
> copying the sqlhosts to use with the client configuration
> provided by
> the docu, but that didn't help either.
>
> Every which way I tried, I keep getting a -5009 error, the
> informix
> log stating:
> """
> 11:34:30 Password Validation for user [xxx] failed!
> 11:34:30 Check for password aging/account lock-out.
> """
> I've rechecked the password for the user, and I can still
> log in
> through ssh as this user on the machine, so that shouldn't
> be the
> problem.
>
> Can anyone help me out with this one? TIA,
>
> Felix Schäfer
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
Hello Ping, Am 04.05.2009 um 14:51 schrieb PING TANG: > Which version of CSDK are you using? There is a bug in 3.50 related > to SPWDSM > and the bug was fixed in 3.50.xC3. Well, it's the version bundled with ids 10.00-FC9, which according to yast is iconnect 2.90.FC4R1. BR, Felix
Are you using SPWDCSM with PAM? Can you give your sqlhosts entry and concsm.cfg entry please? Manoj = "Felix Sch=E4fer" = <schaefer@cypres- = it.com> = To Sent by: ids@iiug.org = ids-bounces@iiug. = cc org = Subj= ect Re: SPWDCSM gives error -5009 = 05/04/2009 08:10 [15662] = AM = = = Please respond to = ids@iiug.org = = = Hello Ping, Am 04.05.2009 um 14:51 schrieb PING TANG: > Which version of CSDK are you using? There is a bug in 3.50 related > to SPWDSM > and the bug was fixed in 3.50.xC3. Well, it's the version bundled with ids 10.00-FC9, which according to yast is iconnect 2.90.FC4R1. BR, Felix ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. =
Hello,
Am 04.05.2009 um 17:02 schrieb Manoj Mohan:
> Are you using SPWDCSM with PAM? Can you give your sqlhosts entry and
> concsm.cfg entry please?
I'm trying to use it with PAM, yes. I already posted the contents of
these files in the original mai, but here they are again anyway:
"""
vittel:/opt/informix/etc # cat sqlhosts
olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
vittel:/opt/informix/etc # cat concsm.cfg
SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
"""
Note that I put the "p=1" there according to the documentation, but
when I tested it, I even wasn't able to connect from the local machine
from an authorized user by calling 'dbaccess DATABASENAME', I had to
remove the "p=1" part to make that work.
BR,
Felix
Hi,
Sorry, I did not realize that you had already given the info earlier..
I don't see pam options specified in your sqlhosts entry..
So, you are getting -5009 with just SPWDCSM, without using PAM?
Regards,
Manoj
=
"Felix Sch=E4fer" =
<schaefer@cypres- =
it.com> =
To
Sent by: ids@iiug.org =
ids-bounces@iiug. =
cc
org =
Subj=
ect
Re: SPWDCSM gives error -5009 =
05/04/2009 03:33 [15666] =
PM =
=
=
Please respond to =
ids@iiug.org =
=
=
Hello,
Am 04.05.2009 um 17:02 schrieb Manoj Mohan:
> Are you using SPWDCSM with PAM? Can you give your sqlhosts entry and
> concsm.cfg entry please?
I'm trying to use it with PAM, yes. I already posted the contents of
these files in the original mai, but here they are again anyway:
"""
vittel:/opt/informix/etc # cat sqlhosts
olvittel onsoctcp vittel sqlexec csm=3D(SPWDCSM)
vittel:/opt/informix/etc # cat concsm.cfg
SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=3D1")
"""
Note that I put the "p=3D1" there according to the documentation, but
when I tested it, I even wasn't able to connect from the local machine
from an authorized user by calling 'dbaccess DATABASENAME', I had to
remove the "p=3D1" part to make that work.
BR,
Felix
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=
Am 04.05.2009 um 22:48 schrieb Manoj Mohan: > So, you are getting -5009 with just SPWDCSM, without using PAM? Oh, I thought you meant the standard "system user in informix group" authentification scheme, I wasn't even aware of the possibility to explicitely connect IDS to PAM. To get back to your question: yes, I am getting -5009 with SPWDCSM only, no PAM explicitely involved. BR, Felix
Felix,
1.
set p=0, connect as trusted user (no username and no password)?
2.
set p=0, connect with user name and password.
Are you able to connect by using dbaccess in both steps?
--- On Mon, 5/4/09, Felix Schäfer <schaefer@cypres-it.com> wrote:
> From: Felix Schäfer <schaefer@cypres-it.com>
> Subject: Re: SPWDCSM gives error -5009 [15666]
> To: ids@iiug.org
> Date: Monday, May 4, 2009, 3:33 PM
> Hello,
>
> Am 04.05.2009 um 17:02 schrieb Manoj Mohan:
>
> > Are you using SPWDCSM with PAM? Can you give your
> sqlhosts entry and
> > concsm.cfg entry please?
>
> I'm trying to use it with PAM, yes. I already posted the
> contents of
> these files in the original mai, but here they are again
> anyway:
> """
> vittel:/opt/informix/etc # cat sqlhosts
> olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
> vittel:/opt/informix/etc # cat concsm.cfg
> SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
> """
>
> Note that I put the "p=1" there according to the
> documentation, but
> when I tested it, I even wasn't able to connect from the
> local machine
> from an authorized user by calling 'dbaccess DATABASENAME',
> I had to
> remove the "p=1" part to make that work.
>
> BR,
>
> Felix
>
>
>
*******************************************************************************
>
> Forum Note: Use "Reply" to post a response in the
> discussion forum.
>
>
Hi Felix,
Sorry to be late to the party, but if you eliminate SWPCSM from the equation,
can you still connect to the database, or are your getting an error there. ssh
is not a guaranteed way to test this. However if you can setup a DBSERVERALIAS
in the SQLHOSTS file that doesn't use CSM, but connects fine, then you
eliminate authentication as an issue.
Again, I apologize if this test/request has already been asked.
________________________________
From: Felix Schäfer <schaefer@cypres-it.com>
To: ids@iiug.org
Sent: Monday, May 4, 2009 5:04:51 AM
Subject: SPWDCSM gives error -5009 [15660]
Hello,
I'm trying to get an existing infromix 10.00-FC9 (on SLES 10.1) wo
work with SPWDCSM, configured like this:
"""
vittel:/opt/informix/etc # cat sqlhosts
olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
vittel:/opt/informix/etc # cat concsm.cfg
SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
"""
Alas, we had no luck with connecting to the db either through dbaccess
or the python informixdb on the same machine. The documentation
http://www.redbooks.ibm.com/redbooks/SG247556/5-3-3.htm
hints that I'd need an extra line in the concsm.cfg for client
access, but I wouldn't know where to put it in the sqlhosts. I tried
copying the sqlhosts to use with the client configuration provided by
the docu, but that didn't help either.
Every which way I tried, I keep getting a -5009 error, the informix
log stating:
"""
11:34:30 Password Validation for user [xxx] failed!
11:34:30 Check for password aging/account lock-out.
"""
I've rechecked the password for the user, and I can still log in
through ssh as this user on the machine, so that shouldn't be the
problem.
Can anyone help me out with this one? TIA,
Felix Schäfer
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Hello,
Took me quite some time to get back to this one, but here it goes:
Am 04.05.2009 um 23:13 schrieb PING TANG:
> 1.
> set p=0, connect as trusted user (no username and no password)?
>
> 2.
> set p=0, connect with user name and password.
>
> Are you able to connect by using dbaccess in both steps?
Case 1. works, case 2. doesn't. Anyway, I'm have the feeling I've gone
through all the permutations I could think of (no "p=?" at all, "p=0"
and "p=1"), so I'll contact the hotline.
Thanks for your help,
Felix Schäfer
> --- On Mon, 5/4/09, Felix Schäfer <schaefer@cypres-it.com> wrote:
>
>> From: Felix Schäfer <schaefer@cypres-it.com>
>> Subject: Re: SPWDCSM gives error -5009 [15666]
>> To: ids@iiug.org
>> Date: Monday, May 4, 2009, 3:33 PM
>> Hello,
>>
>> Am 04.05.2009 um 17:02 schrieb Manoj Mohan:
>>
>>> Are you using SPWDCSM with PAM? Can you give your
>> sqlhosts entry and
>>> concsm.cfg entry please?
>>
>> I'm trying to use it with PAM, yes. I already posted the
>> contents of
>> these files in the original mai, but here they are again
>> anyway:
>> """
>> vittel:/opt/informix/etc # cat sqlhosts
>> olvittel onsoctcp vittel sqlexec csm=(SPWDCSM)
>> vittel:/opt/informix/etc # cat concsm.cfg
>> SPWDCSM("/opt/informix/lib/csm/libixspw.so","","p=1")
>> """
>>
>> Note that I put the "p=1" there according to the
>> documentation, but
>> when I tested it, I even wasn't able to connect from the
>> local machine
>> from an authorized user by calling 'dbaccess DATABASENAME',
>> I had to
>> remove the "p=1" part to make that work.
>>
>> BR,
>>
>> Felix
>>
>>
>>
>
*******************************************************************************
>>
>> Forum Note: Use "Reply" to post a response in the
>> discussion forum.
>>
>>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>