-952 oddity
Posted in 2012
Topics: Connectivity: ODBC / JDBC / .NET, Platform-Specific Issues
We're running 11.70 FC5 on Solaris 10 u10 x86. And we're getting a -952 error (cannot authenticate) for a bunch of new users. During troubleshooting, we noticed some strange behavior. I can access the database with these accounts using a native IDS driver on Linux, but I cannot access them over ODBC from Windows or Linux or using PDO on Linux. All of these connections are from different computers, not locally. Any ideas? Or anything in FC6 that would fix this sort of problem?
Are the users trying to connect with or without login and password? Often the Windows accounts start with upper case while UNIX/Linux accounts normally are all lower case. This will get you a -952 if the user is trying to authenticate with the Windows username rather than using their Linux login id. Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Fri, Nov 30, 2012 at 9:02 AM, LUKE SIMMONS <luke.simmons@vgregion.se>wrote: > We're running 11.70 FC5 on Solaris 10 u10 x86. > > And we're getting a -952 error (cannot authenticate) for a bunch of new > users. > During troubleshooting, we noticed some strange behavior. > > I can access the database with these accounts using a native IDS driver on > Linux, but I cannot access them over ODBC from Windows or Linux or using > PDO > on Linux. All of these connections are from different computers, not > locally. > > Any ideas? Or anything in FC6 that would fix this sort of problem? > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --14dae93411851806ff04cfb6f545
No Art...
If the OP is mentioning -952 he must be looking at the error in the server
side, because the error on client side will always be -951.
And on the server side, a non existent user will raise -951. A wrong
password will raise -952.
I would say it's impossible to have a -952 from a client and a working
login from another client unless there was a bug... But assuming this is
what the OP is seeing please:
- Confirm that you're getting this error in the online.log
- Turn off the user caching (NS_CACHE ... user=0). This can be changed
dynamically with onmode -wm/wf
- Tell us if you're using some sort of external authentication... are some
of your users local to the machine and others remote (LDAP?)
- Are you using PAM at the OS level?
- Do your clients have different versions, if so which ones?
- Do those users have passwords greater than 8 characters? If yes, can you
temporarly reduce the password length for test purposes?
Regards
On Fri, Nov 30, 2012 at 2:10 PM, Art Kagel <art.kagel@gmail.com> wrote:
> Are the users trying to connect with or without login and password? Often
> the Windows accounts start with upper case while UNIX/Linux accounts
> normally are all lower case. This will get you a -952 if the user is
> trying to authenticate with the Windows username rather than using their
> Linux login id.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
> and do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> other organization with which I am associated either explicitly,
> implicitly, or by inference. Neither do those opinions reflect those of
> other individuals affiliated with any entity with which I am affiliated nor
> those of the entities themselves.
>
> On Fri, Nov 30, 2012 at 9:02 AM, LUKE SIMMONS <luke.simmons@vgregion.se
> >wrote:
>
> > We're running 11.70 FC5 on Solaris 10 u10 x86.
> >
> > And we're getting a -952 error (cannot authenticate) for a bunch of new
> > users.
> > During troubleshooting, we noticed some strange behavior.
> >
> > I can access the database with these accounts using a native IDS driver
> on
> > Linux, but I cannot access them over ODBC from Windows or Linux or using
> > PDO
> > on Linux. All of these connections are from different computers, not
> > locally.
> >
> > Any ideas? Or anything in FC6 that would fix this sort of problem?
> >
> >
> >
> >
>
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --14dae93411851806ff04cfb6f545
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--002354790f4469939304cfb740c3
This seems to be fixed. We turned off the NS_CACHE as mentioned earlier, moved a user over to passwd and voila, it worked. We could change the password for 4 different users and log in. We had moved a bunch of users from passwd to NIS before this happened and this seemed to have affected this. Those users that had the same password in passwd and NIS couldn't change their password, even when they didn't have an account anymore in passwd. Odd... but thanks for the help!! Very much appreciated!!
Confusing... the ability to change the password or not does not have anything to do with Informix. Regarding NS_CACHE... if you have it active, and change a user password, the new password will raise -952 for a while... You can "flush" it... "user=0" and then re-activate it again. Regards. On Fri, Nov 30, 2012 at 3:29 PM, LUKE SIMMONS <luke.simmons@vgregion.se>wrote: > This seems to be fixed. > > We turned off the NS_CACHE as mentioned earlier, moved a user over to > passwd > and voila, it worked. We could change the password for 4 different users > and > log in. > > We had moved a bunch of users from passwd to NIS before this happened and > this > seemed to have affected this. Those users that had the same password in > passwd > and NIS couldn't change their password, even when they didn't have an > account > anymore in passwd. > > Odd... but thanks for the help!! Very much appreciated!! > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... --20cf302ef93c4b5e2704cfb8aa2a