RE: IDS 11.70.FC4 - two questions: encrypted backu
Posted in 2012
Topics: High Availability & Replication, Backup & Restore, Security, Permissions & Auditing, Migration, Import/Export & Data Conversion
I know that both of the issues listed in the Subject have been discussed
before, but I can't find my notes; and we are just moving to 11.70 and want to
try these.
1) What is the easiest method, using ontape, to perform encryption during a
tape backup (and also the reverse for unencrypting and restoring)?
2) I have never tried to restore an ontape backup of an instance to a
different instance on the same server. What are the procedures? Also, to take
it one step further, is it possible to do an archive and restore through
STDIO, instantaneously without using other media between instances on the same
server?
3) Finally, with reference to number 2 above, can you use the direct method,
through STDIO, for copying just a single database from one instance to replace
a single database on another instance of the same server? (or maybe something
similar to setting up HDR using STDIO - dbexport -ss -d instance1:database1 -t
STDIO -F | rsh instance2:database1 dbimport_restore.ksh)
Thank you.
Larry
See below:
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Fri, Jan 20, 2012 at 11:09 AM, LARRY SORENSEN <lsorensen25@msn.com>wrote:
> I know that both of the issues listed in the Subject have been discussed
> before, but I can't find my notes; and we are just moving to 11.70 and
> want to
> try these.
>
> 1) What is the easiest method, using ontape, to perform encryption during a
> tape backup (and also the reverse for unencrypting and restoring)?
>
Use the BACKUP_FILTER and RESTORE_FILTER environment variables to name an
encryption filter program to use for backups and restores respectively.
>
> 2) I have never tried to restore an ontape backup of an instance to a
> different instance on the same server. What are the procedures? Also, to
> take
>
You just set up an onconfig file for the new server with a new ROOTDBS and
other important parameters matching the source server then do a redirected
restore where you specify (either on the commandline or in a mapping file)
where to write the data from each of the original chunk paths (including
the root path).
> it one step further, is it possible to do an archive and restore through
> STDIO, instantaneously without using other media between instances on the
> same
> server?
>
Yes. Use "-t STDIO" on the ontape commandline and pipe the ontape -s... -t
STDIO output to ontape -r -t STDIO.
>
> 3) Finally, with reference to number 2 above, can you use the direct
> method,
> through STDIO, for copying just a single database from one instance to
> replace
> a single database on another instance of the same server? (or maybe
> something
>
No. However, you can use the archecker to read an archive file and restore
the table data from the archive to any database anywhere as long as the
table to receive the data exists. So dbschema/myschema to get the schema,
create the target database, then use archecker to copy the data from the
archive. Of course you could just use dbexport & dbimport to export the
database from one server instance and reload the database to another server
instance or you can use my dbcopy utility to copy the data directly from
one server to the other (my utils4_ak package contains an AWK script that
will read dbschema or myschema output and generate a script to copy an
entire database using dbcopy - another will do the same using SELECT FROM
... INSERT INTO ... ).
> similar to setting up HDR using STDIO - dbexport -ss -d
> instance1:database1 -t
> STDIO -F | rsh instance2:database1 dbimport_restore.ksh)
>
You can also use the new ifxclone utility to clone an entire server onto
another instance with a single commandline.
>
> Thank you.
>
> Larry
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--e89a8f839c1bb7754a04b6f81033
Thank you for the good information.
First, do you have any manuals on your utils4_ak package usage including the
dbcopy?
I have never heard of ifxclone. Is it an Informix product or a third party
prooduct? Is there documentation on that somewhere?
Thank you again.
Larry
> To: ids@iiug.org
> From: art.kagel@gmail.com
> Subject: Re: IDS 11.70.FC4 - two questions: encrypted b.... [25988]
> Date: Fri, 20 Jan 2012 11:21:04 -0500
>
> See below:
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> other organization with which I am associated either explicitly,
> implicitly, or by inference. Neither do those opinions reflect those of
> other individuals affiliated with any entity with which I am affiliated nor
> those of the entities themselves.
>
> On Fri, Jan 20, 2012 at 11:09 AM, LARRY SORENSEN <lsorensen25@msn.com>wrote:
>
> > I know that both of the issues listed in the Subject have been discussed
> > before, but I can't find my notes; and we are just moving to 11.70 and
> > want to
> > try these.
> >
> > 1) What is the easiest method, using ontape, to perform encryption during a
> > tape backup (and also the reverse for unencrypting and restoring)?
> >
>
> Use the BACKUP_FILTER and RESTORE_FILTER environment variables to name an
> encryption filter program to use for backups and restores respectively.
>
> >
> > 2) I have never tried to restore an ontape backup of an instance to a
> > different instance on the same server. What are the procedures? Also, to
> > take
> >
>
> You just set up an onconfig file for the new server with a new ROOTDBS and
> other important parameters matching the source server then do a redirected
> restore where you specify (either on the commandline or in a mapping file)
> where to write the data from each of the original chunk paths (including
> the root path).
>
> > it one step further, is it possible to do an archive and restore through
> > STDIO, instantaneously without using other media between instances on the
> > same
> > server?
> >
>
> Yes. Use "-t STDIO" on the ontape commandline and pipe the ontape -s... -t
> STDIO output to ontape -r -t STDIO.
>
> >
> > 3) Finally, with reference to number 2 above, can you use the direct
> > method,
> > through STDIO, for copying just a single database from one instance to
> > replace
> > a single database on another instance of the same server? (or maybe
> > something
> >
>
> No. However, you can use the archecker to read an archive file and restore
> the table data from the archive to any database anywhere as long as the
> table to receive the data exists. So dbschema/myschema to get the schema,
> create the target database, then use archecker to copy the data from the
> archive. Of course you could just use dbexport & dbimport to export the
> database from one server instance and reload the database to another server
> instance or you can use my dbcopy utility to copy the data directly from
> one server to the other (my utils4_ak package contains an AWK script that
> will read dbschema or myschema output and generate a script to copy an
> entire database using dbcopy - another will do the same using SELECT FROM
> .... INSERT INTO ... ).
>
> > similar to setting up HDR using STDIO - dbexport -ss -d
> > instance1:database1 -t
> > STDIO -F | rsh instance2:database1 dbimport_restore.ksh)
> >
>
> You can also use the new ifxclone utility to clone an entire server onto
> another instance with a single commandline.
>
> >
> > Thank you.
> >
> > Larry
> >
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --e89a8f839c1bb7754a04b6f81033
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
ifxclone is part of 11.70 and makes it possible to do a 'one-step' cloning
of a server.
From: "LARRY SORENSEN" <lsorensen25@msn.com>
To: ids@iiug.org
Date: 01/20/2012 10:54 AM
Subject: RE: IDS 11.70.FC4 - two questions: encrypted b.... [25990]
Sent by: ids-bounces@iiug.org
Thank you for the good information.
First, do you have any manuals on your utils4_ak package usage including
the
dbcopy?
I have never heard of ifxclone. Is it an Informix product or a third party
prooduct? Is there documentation on that somewhere?
Thank you again.
Larry
> To: ids@iiug.org
> From: art.kagel@gmail.com
> Subject: Re: IDS 11.70.FC4 - two questions: encrypted b.... [25988]
> Date: Fri, 20 Jan 2012 11:21:04 -0500
>
> See below:
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> other organization with which I am associated either explicitly,
> implicitly, or by inference. Neither do those opinions reflect those of
> other individuals affiliated with any entity with which I am affiliated
nor
> those of the entities themselves.
>
> On Fri, Jan 20, 2012 at 11:09 AM, LARRY SORENSEN
<lsorensen25@msn.com>wrote:
>
> > I know that both of the issues listed in the Subject have been
discussed
> > before, but I can't find my notes; and we are just moving to 11.70 and
> > want to
> > try these.
> >
> > 1) What is the easiest method, using ontape, to perform encryption
during
a
> > tape backup (and also the reverse for unencrypting and restoring)?
> >
>
> Use the BACKUP_FILTER and RESTORE_FILTER environment variables to name an
> encryption filter program to use for backups and restores respectively.
>
> >
> > 2) I have never tried to restore an ontape backup of an instance to a
> > different instance on the same server. What are the procedures? Also,
to
> > take
> >
>
> You just set up an onconfig file for the new server with a new ROOTDBS
and
> other important parameters matching the source server then do a
redirected
> restore where you specify (either on the commandline or in a mapping
file)
> where to write the data from each of the original chunk paths (including
> the root path).
>
> > it one step further, is it possible to do an archive and restore
through
> > STDIO, instantaneously without using other media between instances on
the
> > same
> > server?
> >
>
> Yes. Use "-t STDIO" on the ontape commandline and pipe the ontape -s...
-t
> STDIO output to ontape -r -t STDIO.
>
> >
> > 3) Finally, with reference to number 2 above, can you use the direct
> > method,
> > through STDIO, for copying just a single database from one instance to
> > replace
> > a single database on another instance of the same server? (or maybe
> > something
> >
>
> No. However, you can use the archecker to read an archive file and
restore
> the table data from the archive to any database anywhere as long as the
> table to receive the data exists. So dbschema/myschema to get the schema,
> create the target database, then use archecker to copy the data from the
> archive. Of course you could just use dbexport & dbimport to export the
> database from one server instance and reload the database to another
server
> instance or you can use my dbcopy utility to copy the data directly from
> one server to the other (my utils4_ak package contains an AWK script that
> will read dbschema or myschema output and generate a script to copy an
> entire database using dbcopy - another will do the same using SELECT FROM
> .... INSERT INTO ... ).
>
> > similar to setting up HDR using STDIO - dbexport -ss -d
> > instance1:database1 -t
> > STDIO -F | rsh instance2:database1 dbimport_restore.ksh)
> >
>
> You can also use the new ifxclone utility to clone an entire server onto
> another instance with a single commandline.
>
> >
> > Thank you.
> >
> > Larry
> >
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --e89a8f839c1bb7754a04b6f81033
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
*******************************************************************************
Forum Note: Use "Reply" to post a response in the discussion forum.
Larry:
The utils4_ak package is just a set of sample AWK scripts you can use or
modify to create SQL or shell scripts to perform operations on an entire
database by post processing the output from dbschema or myschema (from
utils2_ak).
Once you build dbcopy it prints its own usage manual if you execute it with
no arguments or with -? (all of my utilities at least do the latter even if
no args is a reasonable default run mode). There are many options and I
know it can get confusing. The most common way to run dbcopy, however, is:
dbcopy -h source_server -H target_server -d source_database -D
target_database -t source_table -T target_table -F -f 10000 -l error.log -i
100 -w 10
Copy all data from table source_database@source_server:source_table to
target_database@target_server:target_table (at least one of the server
aliases must be a network connection as dbcopy uses two simultaneous
connections and shared memory only supports a single connection). The -F
means flush only when the communication buffer it full (default buffers
size is 32K - see -b) and -f 10000 means commit and report every 10,000
rows (approximately - see the notes on -f). The -i 100 options says to
ignore the first 100 errors and the -l option logs rows that cannot be
written to the target to the file error.log in delimited (UNLOAD) format
from where you can manually correct the data and reload it using dbaccess
or dbload.
This is basically the command that the mkdbcopy.awk script in utils4_ak
writes into the ksh script that it outputs when you run it like this:
dbschema -d mydatabase | awk -f mkdbcopy.awk >dbcopy_mydatabase.ksh
If you run the output script, dbcopy_mydatabase.ksh (or whatever you name
it) it will print its own usage as well.
The ifxclone utility was introduced in the later releases of Informix
11.70. It resides in $INFORMIXDIR/bin and if you run it with no args it
also produces a usage printout. Ifxclone is documented in the
Administrator's Reference manual in chapter 18 where it says:
*Chapter 18. The ifxclone utility
You use the ifxclone utility to create a snapshot of a database server.
*
It is meant for manual use, however, it is also used internally by the new
11.70 rolling upgrade feature to perform the physical restore step of
upgrading an HDR or RSS secondary server.
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other organization with which I am associated either explicitly,
implicitly, or by inference. Neither do those opinions reflect those of
other individuals affiliated with any entity with which I am affiliated nor
those of the entities themselves.
On Fri, Jan 20, 2012 at 11:31 AM, LARRY SORENSEN <lsorensen25@msn.com>wrote:
> Thank you for the good information.
>
> First, do you have any manuals on your utils4_ak package usage including
> the
> dbcopy?
>
> I have never heard of ifxclone. Is it an Informix product or a third party
> prooduct? Is there documentation on that somewhere?
>
> Thank you again.
>
> Larry
>
> > To: ids@iiug.org
> > From: art.kagel@gmail.com
> > Subject: Re: IDS 11.70.FC4 - two questions: encrypted b.... [25988]
> > Date: Fri, 20 Jan 2012 11:21:04 -0500
> >
> > See below:
> >
> > Art
> >
> > Art S. Kagel
> > Advanced DataTools (www.advancedatatools.com)
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own opinions
> > and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> > other organization with which I am associated either explicitly,
> > implicitly, or by inference. Neither do those opinions reflect those of
> > other individuals affiliated with any entity with which I am affiliated
> nor
> > those of the entities themselves.
> >
> > On Fri, Jan 20, 2012 at 11:09 AM, LARRY SORENSEN <lsorensen25@msn.com
> >wrote:
> >
> > > I know that both of the issues listed in the Subject have been
> discussed
> > > before, but I can't find my notes; and we are just moving to 11.70 and
> > > want to
> > > try these.
> > >
> > > 1) What is the easiest method, using ontape, to perform encryption
> during
> a
> > > tape backup (and also the reverse for unencrypting and restoring)?
> > >
> >
> > Use the BACKUP_FILTER and RESTORE_FILTER environment variables to name an
> > encryption filter program to use for backups and restores respectively.
> >
> > >
> > > 2) I have never tried to restore an ontape backup of an instance to a
> > > different instance on the same server. What are the procedures? Also,
> to
> > > take
> > >
> >
> > You just set up an onconfig file for the new server with a new ROOTDBS
> and
> > other important parameters matching the source server then do a
> redirected
> > restore where you specify (either on the commandline or in a mapping
> file)
> > where to write the data from each of the original chunk paths (including
> > the root path).
> >
> > > it one step further, is it possible to do an archive and restore
> through
> > > STDIO, instantaneously without using other media between instances on
> the
> > > same
> > > server?
> > >
> >
> > Yes. Use "-t STDIO" on the ontape commandline and pipe the ontape -s...
> -t
> > STDIO output to ontape -r -t STDIO.
> >
> > >
> > > 3) Finally, with reference to number 2 above, can you use the direct
> > > method,
> > > through STDIO, for copying just a single database from one instance to
> > > replace
> > > a single database on another instance of the same server? (or maybe
> > > something
> > >
> >
> > No. However, you can use the archecker to read an archive file and
> restore
> > the table data from the archive to any database anywhere as long as the
> > table to receive the data exists. So dbschema/myschema to get the schema,
> > create the target database, then use archecker to copy the data from the
> > archive. Of course you could just use dbexport & dbimport to export the
> > database from one server instance and reload the database to another
> server
> > instance or you can use my dbcopy utility to copy the data directly from
> > one server to the other (my utils4_ak package contains an AWK script that
> > will read dbschema or myschema output and generate a script to copy an
> > entire database using dbcopy - another will do the same using SELECT FROM
> > .... INSERT INTO ... ).
> >
> > > similar to setting up HDR using STDIO - dbexport -ss -d
> > > instance1:database1 -t
> > > STDIO -F | rsh instance2:database1 dbimport_restore.ksh)
> > >
> >
> > You can also use the new ifxclone utility to clone an entire server onto
> > another instance with a single commandline.
> >
> > >
> > > Thank you.
> > >
> > > Larry
> > >
> > >
> > >
> > >
> >
>
>
*******************************************************************************
> > > Forum Note: U