Informix Error -5013: CSM: cannot obtain credential: authentication error.
Cause and resolution
CSM: cannot obtain credential: authentication error.
A CSM (Communications Support Module), in the database server or in the client, cannot obtain a credential to proceed in an authentication exchange. For example, a user did not provide a password, or a credential request to an external authentication service returned an error. This error can only occur during context setup (that is, at connection time).
The connection establishment fails.
When a CSM is configured to require a password for authentication, a valid password must be provided. Do not configure the database server to use CSM in such a way that password input is required when you first bring up the database server. Bring the database server up and let it build system tables. Bring the database server down, and reconfigure it to use the CSM as you desire.
Provide the password credential, or perform the operations that the external authentication service provider requires in advance (for example, Kerberos klogin).
Oninit® Troubleshooting Guidance
Reasons / Common Causes
-5013 fires when a CSM (Communications Support Module) can't obtain a credential to proceed with an authentication exchange — per the official guidance, this can only occur during context setup (connection time), and always fails the connection establishment.
- A user didn't provide a password, per the official guidance — a named example.
- A credential request to an external authentication service returned an error, per the official guidance — a named example.
Solutions / Resolution
- Provide the password credential, per the official guidance, or
- Perform the operations the external authentication service provider requires in
advance (for example, Kerberos
klogin), per the official guidance. - Don't configure the database server to require password input when first bringing it up, per the official guidance — bring it up, let it build system tables, bring it down, then reconfigure it to use the CSM as desired.
Examples
N/A
No specific triggering statement is documented beyond a missing password or a failed external credential request.
Diagnostic Checks
- Check whether a password was supplied, and whether any required external
authentication step (e.g. Kerberos
klogin) was performed beforehand.
Related Errors / Related Topics
- -5009 — "CSM: authentication error." A related, more general authentication failure, about a supplied credential being rejected rather than one being unobtainable at all.
A CSM couldn't obtain a credential for authentication — supply the password, or perform the required external authentication step first.