RE: Can't connect to database - Unknown error message 84
Posted in 2009
A user couldn't connect to IDS after changing his Active Directory password, getting "unknown error message 84"; OS logins worked with the new password, but database connections (ODBC, JDBC, dbaccess) only succeeded with a password he had set three months earlier. Suggestions included a stale cache, a changed password encryption algorithm, PAM/LDAP authentication configured in sqlhosts (he said none was active), and a locale issue — Jonathan Leffler noted error 84 is EILSEQ, "illegal byte sequence", on Linux. Ideas to test another password change or a new user were raised, but the thread ends with no resolution recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Internationalization & Character Sets
> From: domusonline@gmail.com > Subject: Re: Can't connect to database - Unknown error message 84 > > I can login to the server with the new password just fine, it's just > > the database connection that is not working. Strangely, all my ODBC and > > JDBC connections configured on various Windows clients that have the old > > password stored do still work! But as soon as I touch any one of them and > > change the stored password to the new one, they fail with the above error. > > Moreover, after that they don't even work when I try the old password again. > > My password's don't contain any irregular characters, only letters and > > numbers, so I can exclude any character set problems. > > > > Any idea about the cause, and a solution? > > > > Regards, Richard > > > > Did you change the password encryption algorithm? > This looks familiar to situations where this have happened... > He said that his old password still works when he connects via his applications. Can you say stale cache? _________________________________________________________________ Windows Live™ Hotmail®:…more than just e-mail. http://windowslive.com/online/hotmail?ocid=TXT_TAGLM_WL_HM_more_042009
Ian Michael Gumby <im_gumby@hotmail.com> schrieb: >> Did you change the password encryption algorithm? >> This looks familiar to situations where this have happened... >> > >He said that his old password still works when he connects via his applications. >Can you say stale cache? Stale cache was my first thought, too. However, the problem persists even after a reboot of the server, so all caches should have been reset. Disabling nscd on the server didn't make any difference either. And since I can logon to the OS successfully with my new password, there is no indication that the password encryption algorithm has changed. I just sniffered a successful database connection via ODBC from one of my applications. To my great surprise, this connection was still using my second last password! Seems like I didn't change all my ODBC and JDBC password settings after I had changed the AD password over three months ago and had completely forgotten about it. So I can connect again, using that old password. However, the underlying problem remains unsolved: Where does IDS cache that old password? To logon to the OS, I have to use my new password! I always thought that IDS uses the underlying OS's mechanisms for password verification. Any idea what that "unknown error message 84" means? Regards, Richard
On Thu, Apr 30, 2009 at 01:17, Richard Spitz wrote: > Any idea what that "unknown error message 84" means? According to /usr/include/bits/errno.h on a recent Linux platform (Ubuntu 9.04, I think): /usr/include/bits/errno.h:# define EILSEQ 84 /* Illegal byte sequence. */ What is your locale set to? -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2008.0513 -- http://dbi.perl.org/ "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." NB: Please do not use this email for correspondence. I don't necessarily read it every week, even. Albert Einstein - "Only two things are infinite, the universe and human stupidity, and I'm not sure about the f... - http://www.brainyquote.com/quotes/authors/a/albert_einstein.html
> From: Richard.Spitz@med.uni-muenchen.de > Subject: Re: Can't connect to database - Unknown error message 84 > Date: Thu, 30 Apr 2009 10:17:49 +0200 > To: informix-list@iiug.org > > Ian Michael Gumby <im_gumby@hotmail.com> schrieb: > > >> Did you change the password encryption algorithm? > >> This looks familiar to situations where this have happened... > >> > > > >He said that his old password still works when he connects via his applications. > >Can you say stale cache? > > Stale cache was my first thought, too. However, the problem persists even > after a reboot of the server, so all caches should have been reset. Disabling > nscd on the server didn't make any difference either. And since I can logon > to the OS successfully with my new password, there is no indication that > the password encryption algorithm has changed. > > I just sniffered a successful database connection via ODBC from one of my > applications. To my great surprise, this connection was still using my > second last password! Seems like I didn't change all my ODBC and JDBC > password settings after I had changed the AD password over three months > ago and had completely forgotten about it. > > So I can connect again, using that old password. However, the underlying > problem remains unsolved: Where does IDS cache that old password? To logon > to the OS, I have to use my new password! I always thought that IDS uses > the underlying OS's mechanisms for password verification. > This is weird in that Informix does use the local machine's authentication methods, unless you tell it to use a specific authentication method via $INFORMIXDIR/etc/sqlhosts. An example is LDAP or PAM. What does your sqlhosts file look like? My thought is that you may have set up IDS to authenticate against an LDAP server that didn't get the latest password update. But that's just a SWAG since I don't know your machine nor your network configuration. HTH _________________________________________________________________ Rediscover Hotmail®: Get quick friend updates right in your inbox. http://windowslive.com/RediscoverHotmail?ocid=TXT_TAGLM_WL_HM_Rediscover_Updates2_042009
Jonathan Leffler <jleffler.iiug@gmail.com> schrieb:
>/usr/include/bits/errno.h:# define EILSEQ 84 /* Illegal byte sequence. */
Correct, same on my system (SLES 10 SP1)
>What is your locale set to?
Which one? Client or server?
The problem happens no matter what locale I set in the ODBC datasource
(from I-Connect 3.00). It also happens when using dbaccess's "Connect"
feature from another or even the same Linux machine. I cannot connect
to IDS using my current password, only the old password from over 3
months ago.
Where could IDS store password information?
Regards, Richard
Ian Michael Gumby <im_gumby@hotmail.com> schrieb: >This is weird in that Informix does use the local machine's authentication methods, >unless you tell it to use a specific authentication method via $INFORMIXDIR/etc/sqlhosts. >An example is LDAP or PAM. > >What does your sqlhosts file look like? We had experimented with PAM/LDAP in the beginning, but that gave us problems with OLEDB connections. The Informix OLEDB provider does not support PAM. See my postings in thread "OLEDB connection and AD Windows" from April 2008. There are currently no active LDAP/PAM configurations in my sqlhost files on any of the machines. I'm completely puzzled about this! Regards, Richard
On Apr 30, 11:43 am, Richard Spitz <Richard.Sp...@med.uni-muenchen.de> wrote: > Ian Michael Gumby <im_gu...@hotmail.com> schrieb: > > >This is weird in that Informix does use the local machine's authentication methods, > >unless you tell it to use a specific authentication method via $INFORMIXDIR/etc/sqlhosts. > >An example is LDAP or PAM. > > >What does your sqlhosts file look like? > > We had experimented with PAM/LDAP in the beginning, but that gave us problems > with OLEDB connections. The Informix OLEDB provider does not support PAM. See > my postings in thread "OLEDB connection and AD Windows" from April 2008. > > There are currently no active LDAP/PAM configurations in my sqlhost files > on any of the machines. > > I'm completely puzzled about this! > > Regards, Richard To the best of my knowledge Informix doesn't cache anything in terms of passwords. It will use whatever authentication methods you have set up on your machine. The fact that your previous password works for Informix but your new password connects to your server is interesting. Are you the sysadmin on the server? Can you see if you have an outdated entry that is local to the server? Its weird but it seems like Informix may be authenticating against one file while your server is authenticating against another. What happens if you change your password again? Or create a new test user?