Informix Error -960: The connection failed because the user failed the security check set by the SECURITY_LOCALCONNECTION configuration parameter.
Cause and resolution
The connection failed because the user failed the security check set by the SECURITY_LOCALCONNECTION configuration parameter.
The ID of the local user running the client program is not the same ID of the user trying to access the database. The server checks the user IDs when the SECURITY_LOCALCONNECTION configuration parameter is set to a nonzero value.
See the IBM Informix Administrator's Reference manual for more information.
Oninit® Troubleshooting Guidance
Reasons / Common Causes
-960 fires when SECURITY_LOCALCONNECTION is set to a nonzero value and the local OS user ID
running the client program doesn't match the user ID attempting to access the database — per the
official guidance, this parameter specifically enables that check.
- The client program running as one OS user, while the database connection attempts to authenticate as a different user, per the official guidance — the direct, only cause when this check is enabled.
SECURITY_LOCALCONNECTIONenabled without every client application's user-ID handling being reviewed against it, if this parameter was turned on after applications were already in production use with a different assumption.
Solutions / Resolution
- Ensure the connecting user ID matches the local OS user ID running the client program,
per the official guidance's underlying requirement, if
SECURITY_LOCALCONNECTIONneeds to stay enabled. - Check the current
SECURITY_LOCALCONNECTIONsetting, per the official guidance:grep SECURITY_LOCALCONNECTION "$ONCONFIG" - If this check isn't appropriate for the application's design (for instance, a service process connecting as a different database user than its own OS identity), work with the administrator to reconsider the parameter's setting — changing a security parameter is an administrative decision, not a client-side workaround.
Examples
Checking the current setting
$ grep SECURITY_LOCALCONNECTION "$ONCONFIG"
SECURITY_LOCALCONNECTION 1
A nonzero value confirms this check is active.
Diagnostic Checks
- Check
SECURITY_LOCALCONNECTION's current value in$ONCONFIG. - Compare the OS user ID running the client program against the database user ID it's authenticating as.
Related Errors / Related Topics
No closely related error codes are cross-referenced for -960 in this set yet.
Confirm SECURITY_LOCALCONNECTION's setting and whether the OS user and database user IDs are
expected to match — reconsider the parameter with the administrator if the application's design
doesn't fit that assumption.