Re: likely database privilege problem
Posted in 2011
Hi TJ,
The instruction you followed to setup the DRDA listening port on IDS se=
rver
is the right one.
I would like to take a look on trace output captured from client and I=
DS
server.
I will soon send you the information to capture the DRDA trace output f=
rom
IDS server.
Meanwhile can you please capture the trace output from the client and s=
end
it to me.
Information to take trace output from client:
1) Open a DB2 Command window at client computer
Then issue the following command to start capturing the trace.
db2trc on -i 16m -m "*.*.84.*.*" -t
2) Then run the client application connecting to IDS.
3) Dump the trace output to a file.
db2trc dmp db2trcout.dmp
4) Please send the output to me.
FYI:You can get more information about DB2TRC by going through the URL.=
http://www.ibm.com/developerworks/db2/library/techarticle/dm-0409melnyk=
/
The step3 of the testconn is trying to establish a connection.
To simplify the trace output we can use an application that try to
establish connection and close.
Please use the fooling source to build an application that try to estab=
lish
to server and close the connection.
static void Main(string[] args)
{
String ConnStr =3D "User
ID=3Dinformix;Password=3Dxxxxxx;Database=3Deloxnet;Server=3D192.168.57.=
72:9091";
DB2Connection Conn =3D new DB2Connection(ConnStr);
try
{
Conn.Open();
Console.WriteLine("Open Sucess");
}
catch (Exception e)
{
Console.WriteLine(e.ToString());
}
Conn.Close();
Console.WriteLine("Closed!");
}
Regards,
Satyan
Software Engineer
R&D - IBM Information Management Division
11200 Lakeview, Lenexa, KS 66219
Tel: 913 599 8792 (T/L: 337-8792)
|------------>
| From: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|"Throstur Jonsson" <tj@rational-network.com> =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| To: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Sathyanesh Krishnan/Lenexa/IBM@IBMUS =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Cc: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Ardeshir Jamshidi/Oakland/IBM@IBMUS, <classics-bounces@iiug.org>, "d=
otNet Runtime Team" <dotNet_Runtime_Team%IBMUS@us.ibm.com>, <ids@iiug.o=
rg>, |
|<informix-list@iiug.org> =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Date: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|01/26/2011 03:47 AM =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|------------>
| Subject: |
|------------>
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
|Re: likely database privilege problem =
=
|
>--------------------------------------------------------------------=
-----------------------------------------------------------------------=
-------|
Hi Satyan,
First of all those where the grant commands I ran against the database:=
grant connect to public;
grant resource to public;Where there any more to run?
Yes the DRDA port is 9091, otherwise the same testconn40.exe command wo=
uld
not work when run from the local IDS server. But it does work there. It=
is
only when run from another machine on the Local Area Network that it fa=
ils,
as described in my previous post. Please note that the IBM .Net provide=
r is
correctly configured on that client machine. This is an IDS security
problem when trying to access the IDS over LAN via the DRDA. I can with=
out
problems access the same IDS from the same client computer using Server=
Studio or ODBC. It is only the DRDA connection that is giving me this
security issue.
There is no firewall running at the IDS server, so that is not the prob=
lem
either.
Actualy I configured the DRDA following my own guidance that I created =
last
summer as it was pritty difficult finding out from the IBM documentatio=
n.
Find the guidance attached.
To assure the DRDA is correctly setup, is there any standard method oth=
er
than using the testconn40.exe?
At least here is a result run from the IDS server to gurantee that the =
port
is there open and working (connected with Visual Studio installed on th=
e
local IDS server)
C:\\\\Program Files\\\\Informix\\\\Client-SDK>netstat -an | findstr 9091
TCP 0.0.0.0:9091 0.0.0.0:0 LISTENING
TCP 192.168.57.72:1143 192.168.57.72:9091 ESTABLISHED
TCP 192.168.57.72:9091 192.168.57.72:1143 ESTABLISHED
If I disconnect Visual Studio on the Iocal IDS server I get:
C:\\\\Program Files\\\\Informix\\\\Client-SDK>netstat -an | findstr 9091
TCP 0.0.0.0:9091 0.0.0.0:0 LISTENING
TCP 192.168.57.72:1143 192.168.57.72:9091 TIME_WAIT
So it seems to be the correct DRDA port and working properly.
Hope this helps you helping me :-)
Regards
TJ
----- Original Message -----
From: Sathyanesh Krishnan
To: Throstur Jonsson
Cc: Ardeshir Jamshidi ; classics-bounces@iiug.org ; dotNet Runtime Tea=
m ;
ids@iiug.org ; informix-list@iiug.org
Sent: Tuesday, January 25, 2011 7:59 PM
Subject: Re: likely database privilege problem
Hi TJ,
Unfortunately the reason code 25 of the error doesn't give much clue,
IDS server support multiple protocols (SQLI and DRDA).
This .NET provider uses DRDA protocol to connect to IDS database.
Can you please verify the port number you are using (9091) is configur=
ed
at IDS to use DRDA protocol.
Regards,
Satyan
Software Engineer
R&D - IBM Information Management Division
11200 Lakeview, Lenexa, KS 66219
Tel: 913 599 8792 (T/L: 337-8792)
Inactive hide details for "Throstur Jonsson" ---01/25/2011 01:02:04
PM---Hi Sathyanesh, This helped me on the local server, the"Throstur
Jonsson" ---01/25/2011 01:02:04 PM---Hi Sathyanesh, This helped me on =
the
local server, the testconn40.exe now finish with success. Howev
@@NL