SQL*Net over IPC fails for normal users

When normal users try to use SQL*Net to log on to a local
database on a Linux box, they get the message "ORA-12546:
TNS:permission denied". An example of this would be the command:
sqlplus scott/tiger@MG8
The oracle unix account can execute the above without problems
and when a normal user sets ORACLE_SID and omits the SQL*Net
connect string it works fine.
Oddly, this is only a problem for connections using the IPC
protocol. If I omit the IPC section from my listener.ora
(leaving only the TCP section), non-privileged users can log on
to local databases through SQL*Net without problems.
I suppose it's not a big deal (there's not that much overhead
going through the TCP loopback port on Linux), but I'm wondering
what's wrong. SQL*Net over IPC certainly works on Solaris.
This is on a S.u.S.E 5.3 distribution of Linux.
null

Mark Gleaves (guest) wrote:
: When normal users try to use SQL*Net to log on to a local
: database on a Linux box, they get the message "ORA-12546:
: TNS:permission denied". An example of this would be the
: command
: sqlplus scott/tiger@MG8
: The oracle unix account can execute the above without problems
: and when a normal user sets ORACLE_SID and omits the SQL*Net
: connect string it works fine.
Check that your oracle executable is SUID oracle and SGID dba?
I'd have thought that would cause problems with bequeath
connections, so perhaps not.
Wierd error. You might try running an strace on the sqlplus to
see what system call fails.
-michael
null

Similar Messages

  • ALSA won't work for normal user [solved]

    hello archers!
    alsa on my arch box doesn't work for normal user, just for root. when i attempt to run ogle, it gives this error:
    ALSA lib pcm_dmix.c:1102:(_snd_pcm_dmix_open) The field ipc_gid must be a valid group (create group audio)
    ERROR[ogle_audio]: Opening alsa pcm device 'default': Invalid argument
    FATAL[ogle_audio]: failed opening the alsa audio driver at default
    error in the first line accurs even when i attempt to open audio tab in winecfg. googling this error didn't help me. xmms with alsa output doesn't seem to work too giving the same error, it works just with oss output.
    hmm, and YES i DO HAVE audio group, and my user IS member of this group.
    [root@otovo /]# ls -l /dev/sound/
    total 0
    crw-rw---- 1 root audio 14, 12 2006-03-09 01:37 adsp
    crw-rw---- 1 root audio 14, 4 2006-03-09 01:37 audio
    crw-rw---- 1 root audio 14, 20 2006-03-09 01:37 audio1
    crw-rw---- 1 root audio 14, 3 2006-03-09 01:37 dsp
    crw-rw---- 1 root audio 14, 19 2006-03-09 01:37 dsp1
    crw-rw---- 1 root audio 14, 0 2006-03-09 01:37 mixer
    crw-rw---- 1 root audio 14, 16 2006-03-09 01:37 mixer1
    crw-rw---- 1 root audio 14, 1 2006-03-09 01:37 sequencer
    crw-rw---- 1 root audio 14, 8 2006-03-09 01:37 sequencer2
    can anyone help me? or should i provide more information?
    thanx & greetings
    ota

    I've found it!
    groups run under user gave just gids of groups, whilst under root it gave proper names. so i took look at /etc/group and here is the problem :shock:
    [root@otovo etc]# ls -l group
    -rw------- 1 root root 427 2006-03-09 01:32 group
    i've changed permissions to a+r and it's working.
    thanks Gandalf, you've helped to save the Middleearth again .
    ota

  • Tacacs authentication fails for one user account for only one switch

    Hi,
    I am having an scenario, where as Tacacs authentication fails for one user account for only one switch.
    The same user account works well for other devices.
    The AAA configs are same on every devices in the network.
    Heres the show tacacs output from the switch where only one user account fails;
                  Socket opens:        157
                 Socket closes:        156
                 Socket aborts:        303
                 Socket errors:          1
               Socket Timeouts:          2
       Failed Connect Attempts:          0
            Total Packets Sent:       1703
            Total Packets Recv:       1243
              Expected Replies:          0
    What could be the reason ?
    No errors on ACS server; same rights had been given to the user account.
    Thanks to advise.
    Prasey

    Hi there,
    Does the user get authenticated in the ACS logs?
    reports and activity----> failed attempts
    ro
    reports and activity----->  passed authentications
    That will help narrow it down.
    Brad

  • Fingerprint utility is not working for normal users - Tecra M11

    Hi All,
    I installed windows 7 pro in Tecra M11 laptop and the Toshiba finger print utility is not working for normal users.
    It is working only for domain administrators. The TFPU is not working for, normal domain users, local users, local administrators. If we run the utility it will ask to enter the windows password and once we applied the password then the message saying "entered password is not valid" will prompt even if we are trying to use the utility first time.
    If we try with a domain admin account it will work without any problem. Can somebody help me to trouble shoot this issue?
    Thanks.

    People nowadays experienced that no matter How many times we glide our finger it have no response.In this instance, you might be very afraid of Windows password lost by reason that there is a plenty of important data on your PC.
    Then what should you do? One choose is fix the Fingerprint scanners, but this method will cost a lot of money. The other is use the Windows password function to solve the problem. Certainly, this is a very safer, faster and easier to use method for you.
    According my personal experience, you can try these three ways to re-access to your PC:
    Method 1: Login with the default administrator account
    * Step 1: Start Windows PC
    * Step 2: When you can see the Windows login screen, press ctrl+alt+del keys Twice and it'll show Classic Login box
    * Step 3: Type Administrator as Username and leave the password field blank
    * Step 4: Press the Enter Key and then you can be able to login the default windows administrator account which is it created by default when install windows.
    *Note:* This trick is only work for Windows XP. And when you input the key combination Please don't put the cursor on any account. And if you change the name or password before, you cannot login by this way.
    Method 2: Use the previous password reset disk
    This method describes how to create and use a password reset disk for a computer that is a member of a domain. You can use a Windows password reset disk to gain access to your Microsoft Windows Professional-based computer if you forget your Windows password. Please click here to learn more.
    Method 3: Using Windows Password Unlocker
    Using Windows password remove software is could be the fastest and easiest way for you to reset your Windows password while you didn't create a password reset disk before.
    There are 2 options for you: recover Windows password with a bootable CD/DVD or recover Windows password with a USB flash drive.
    Before starting, a bootable CD/DVD or USB flash drive and a computer with CD drive are required. (Internal CD drive and external CD drive are both OK.
    Option 1: Recover Windows password by burning a bootable CD/DVD
    Option 2: Recover Windows password by burning a USB flash drive
    The whole Windows password recovery process can be divided to 3 big steps:
    * >> Step 1: Burn a USB flash drive to remove lost Windows password
    * >> Step 2: Set your target computer to boot from USB
    * >> Step 3: Recover forgotten Windows password with the burned USB flash drive
    In fact, all you need is a *Windows Password Unlocker www.passwordunlocker.com/windows-password-recovery.html which can help you directly reset your windows xp password, and then you can login your XP without a password required. Of course, there are also some other ways to do it, but this way may be most convenient one.

  • MAC address display for normal user

    Hi ,
    Any one can share, which command will display MAC address for normal user. I can't get exact result from arp command.
    Regards,
    Siva

    hmm, arp should work, odd.
    Aynway, you can also find it from prtconf, which requires some parsing if you have more than one interfaces;
    prtconf -vp|grep -i mac-address
    .7/M.

  • Over Quota warning for deleted user

    We keep getting, "over quota" warnings for a users that no longer has an account on the mail server. The user has been deleted from the Workgroup and her mailboxes were deleted via command line, but we keep getting over quota warnings. Anyone every seen this? Or know how to make it stop? We're runnning OS 10.4.9.
    Connie

    Matt,
    The problem is that this is not being initiated from a task, but form our nightly maintenance job. These users are falling off because of AD updates outside of our system.
    If a DN is deleted from AD, it's already been removed from the groups in AD, but the privileges in our Identity Store haven't synced yet. If we strip all privileges before the entry is deleted, and the DN is no longer valid, the event task will bomb because it is trying to remove a user that doesn't exist anymore.
    I'm thinking of just trapping it in the jobs with a script that checks that the user DN is not null. If it is, just skip the entry.
    And yes, I will be at TechEd.
    Thanks,
    Jared

  • [All Platforms][Playlists] Feature for normal user to customize playlist cover

    Hello spotfiy commuity!  I saw a post about this a cople of years back, but I feel like its time to revisit the subject.  I have always wanted a feature that enabled me to choose a custom playlist cover photo. This would make my playlist even more personal. I always wonder why this wasn't a feature, I thought that it could be legal issues with the pictures, but just resently spotify released the "Discover weekly" that is absolutely amazing! On the playlist they use your facebook picture as the playlist cover. So it can't be legal issues? One can use anything as a facebook photo (No copy rights needed).  I know this is a feature for records companys or larger playlist and so on. I can understand that its limited to partners, but I don't think it would do any harm to add this feature for regular users aswell?  All I really want is an reason why this isn't a feature for normal users :)   

    Updated: 2015-08-03Hi and thanks for your contribution! Any announcements about this potential feature will be announced in this thread:
    https://community.spotify.com/t5/Live-Ideas/Customization-of-playlists-cover-and-description-box/idi-p/211048
    Add your kudos and comments there please!

  • Sql Server 2012 Login Failed for user "NT Authority\System"

    I have installed SQL Server on a new server. I have been getting the following error on each of the database in it.
    Login failed for user 'NT AUTHORITY\SYSTEM'. Reason: Failed to open the explicitly specified database 'ABC'. [CLIENT: xxx.xxx.xxx.xxx]
    Here is some information on the instance:
    1) Default instance
    2) SQL Server, Sql Server Agent, Sql Server Reporting services are running / log on using a domain service account.
    3) Sql Server Browser is disabled.
    4) SQL Server VSS Writer is running / log on as Local Service.
    5) NT AUTHORITY\SYSTEM does exists in Login with just public server roles.
    I ran a trace on login failed and I get:
    ApplicationName: Microsoft Windows Script Host
    and it runs every 15 minutes.
    Help please?

    Hi,
    The error was thrown when the SCOM components connected to the backend SCOM databases.
     You can specify a domain account, grant it the sysadmin role and the error should be gone.
    Also, see the replies in your previous thread:
    http://social.technet.microsoft.com/Forums/en-US/23f6b6cb-ec41-4117-8613-26d24c948827/login-failed-for-user-username-reason-failed-to-open-the-explicitly-specified-database
    Thanks.
    Tracy Cai
    TechNet Community Support

  • ODBC--connection to 'SQL Serverservername' failed for one user but not another

    In Win7, we're linking tables in an MS Access 2010 db to tables in a SQL Server 2008 R2 db. The driver user by the File dsn is SQL Server version 6.01.7601.17514 & we're using SQL Server Authentication.
    For some reason, one user gets the msg "ODBC--connection to 'SQL Serverservername' failed" before they're even asked for a password, but for other users, the prompt comes up and when they uncheck the Windows Auth box, they enter their password
    and connect successfully to the SQL Server db.  Both users have db_datareader access to the SQL Server db.
    I had the user that gets the error msg log onto my PC and they get the same error (yet it works for me.)
    This user was, however, able to successfully relink the tables, but then when we closed the access db and opened it again, the user got the "ODBC--connection..." error agin.
    I'm stumped as to why this is happening for one user.

    Hello Knellen,
    Please help to collect more log information regarding this issue, such as windows event log, SQL Sever log information. They are helpful for us to troubleshoot it.
    Regards,
    Elvis Long
    TechNet Community Support

  • SQL Error Log: Login Failed for User ''

    Hi B1 experts,
    currently i have a little problem with our SAP System or better SQL Server. Everytime when a SAP client is started, the SQL Server get the following warning message:
    Login failed for user ''. Fehler bei der Anmeldung mit der SQL Authentifizierung. Der Server ist nur für die Windows-Authentifizierung konfiguriert. Client: IP
    Fehler 18456, Schweregrad 14, Status 58.
    The same message occurs when i log into sap. The funktionality of SAP is not impaired.
    I have checked the server authentification mode and the sql server is SQL and Windows Authentification configured.
    SQL Server: 2008 R2
    SAP System: SAP B1 8.8 PL19
    Client System: Windows 7
    Someone any ideas?
    Regards,
    Sabine

    Hi Rahul, Hi Julie,
    thanks for your replys
    @Rahul:
    all named pipes are aktiv. the services are all on automatic mode
    @Julie
    Our Server is running with SQL authentication. We do not use trusted connection generally - security risk.
    Further i have disables all Addon. the error occurs again.
    We do not use the SBO Mailer, he isn't installed.
    Regards,
    Sabine

  • SQL Server Log: Login failed for user ''

    We've found in SQL Server Log many records:
    Date
    3/22/2013 11:13:03 AM
    Log
    Windows NT (Application)
    Source
    MSSQLSERVER
    Category
    Logon
    Event
    3221243928
    Computer
    SBO05
    Message
    Login failed for user ''. Reason: An attempt to login using SQL authentication failed. Server is configured for Windows authentication only. [CLIENT: <local machine>]
    The server autentification is set to "SQL Server and Windows Autentification mode". But when we open SAP, before entering login/password, we see this message in log. But we still could work in SAP.
    How could we solve this?
    Kind regards,
    Anna Shevchenko

    Hi Joseph,
    It doesn't help. The same things i've already done.
    But when I change Mixed Autentification to Windows, i see another error:
    Date
    3/22/2013 11:04:26 AM
    Log
    SQL Server (Current - 3/22/2013 12:33:00 PM)
    Source
    Logon
    Message
    Login failed for user 'sa'. Reason: Failed to open the explicitly specified database. [CLIENT: 192.168.0.145]
    Do you know why?
    Kind regards,
    Anna Shevchenko

  • Forms 10.1.2.3 app. OK when connected as admin, FAIL when 'normal' user

    Hi All,
    I have patched our app. server to 10.1.2.3. When I run our application from a Vista SP1 client as Administrator using the Java Plug-in 1.6.0_05, all is OK including webutil/jacob functionality. For example when I want to view a PDF file, the file is opened correctly and displayed as expected. When I connect to the same client PC as a 'normal' user, I get the following error when trying exactly the same :
    ERROR>WUH-407 [Host.getProcessOutput()] OutputSink is null
    Has any of of you experienced the same and/or would you know how to resolve this ?
    Kind regards,
    Gerrit Breebaart

    Hi All,
    I have patched our app. server to 10.1.2.3. When I run our application from a Vista SP1 client as Administrator using the Java Plug-in 1.6.0_05, all is OK including webutil/jacob functionality. For example when I want to view a PDF file, the file is opened correctly and displayed as expected. When I connect to the same client PC as a 'normal' user, I get the following error when trying exactly the same :
    ERROR>WUH-407 [Host.getProcessOutput()] OutputSink is null
    Has any of of you experienced the same and/or would you know how to resolve this ?
    Kind regards,
    Gerrit Breebaart

  • How to secure SQL*Net over firewall?

    A client application is in an insecure network. It has to connect via SQL*Net to a database server in a DMZ behind a firewall. The client application uses a database user with read-only permissions.
    What measures are available, to restrict the client permissions?
    It shall not be possible to authenticate as DBA from the insecure client.
    Any suggestions?
    Regards,
    D.

    Depending on what it is you are trying to secure, you can use Oracle Advanced Security to encrypt all the traffic to and from the database, so no one can evesdrop on the traffic to the client machine. To get through the DMZ, you would probably need to install and configure Oracle Connection Manager. Some firewalls will proxy the Oracle connection through the firewall, as well.
    Can you connect as sysdba from machines other than the database server today? I don't believe there is a way to restrict connections from a particular user to coming from a particular set of machines, though you can lock down a database so that only local connections can be made AS SYSDBA.
    Justin
    Distributed Database Consulting, Inc.
    http://www.ddbcinc.com/askDDBC

  • ALSA device busy for normal user (not root) after systemd [resolved]

    I'm not able to get audio when using a normal user (device or resource busy) but root works just fine. I think I've messed something up since I just removed consolekit and switched to systemd.
    Here's what my .xinitrc looks like
    #!/bin/sh
    # ~/.xinitrc
    # Executed by startx (run your window manager from here)
    if [ -d /etc/X11/xinit/xinitrc.d ]; then
    for f in /etc/X11/xinit/xinitrc.d/*; do
    [ -x "$f" ] && . "$f"
    done
    unset f
    fi
    #exec gnome-session
    #exec startkde
    #exec startxfce4
    #exec enlightenment_start
    # ...or the Window Manager of your choice
    #exec ck-launch-session startlxde
    exec dbus-launch startlxde
    I use LightDM via systemd service and LXDE. My devices in /dev/snd aren't actually busy. Nobody is using them and they work fine for root.
    Where else should I be looking for trouble? Anyone have a similar experience?
    Last edited by royallthefourth (2013-06-12 17:32:20)

    It says I'm in the audio group. Here's the permission on the audio devices:
    crw-rw----+ 1 root audio 116, 6 Jun 12 03:45 controlC0
    crw-rw----+ 1 root audio 116, 9 Jun 12 03:45 controlC1
    crw-rw----+ 1 root audio 116, 11 Jun 12 03:45 controlC2
    crw-rw----+ 1 root audio 116, 8 Jun 12 03:45 hwC1D0
    crw-rw----+ 1 root audio 116, 5 Jun 12 03:45 pcmC0D0c
    crw-rw----+ 1 root audio 116, 4 Jun 12 03:45 pcmC0D0p
    crw-rw----+ 1 root audio 116, 3 Jun 12 03:45 pcmC0D1c
    crw-rw----+ 1 root audio 116, 2 Jun 12 03:45 pcmC0D1p
    crw-rw----+ 1 root audio 116, 7 Jun 12 03:45 pcmC1D3p
    crw-rw----+ 1 root audio 116, 10 Jun 12 03:45 pcmC2D0c
    crw-rw----+ 1 root audio 116, 1 Jun 12 03:45 seq
    crw-rw----+ 1 root audio 116, 33 Jun 12 03:45 timer
    I ought to have access to these, right?

  • MAC authentication failed for Wired Users

    Hi,
    I tried to configure MAC authentication for registed users by ACS. But failed. Need help.

    ok ok..i got ur point....please correct me the config steps:
    1. Added switch as aaa client into acs
    2. entered machine mac address into acs user-setup as both usename & password.
    3. in 64,65 & 81 (in bother group & user setup) choosed 64=vlan; 65=802; 81=authenticated_vlan_id
    4. in switch
    aaa new-model
    aaa authentication dot1x default group radius
    radius-server host acs_ip auth-port 1645 acct-port 1646 key ****
    dot1x system-auth-control
    int fa0/1
    switchport mode access
    dot1x mac-auth-bypass
    dot1x port-control auto
    dot1x reauthentication
    dot1x pae authenticator
    dot1x guest-vlan 900
    Note: Whenever i issue the command "port-control auto" the line protocol of the port goes down.
    5. in end machine disable ieee 802.1x authentication.
    I will try this setting tomorrow & update you accordingly.

Maybe you are looking for

  • Best practice for presenting different storage vendors arrays..?

    Hi, can't seem to find a specific answer in writing on this. Typical FlexPod already deployed, with different vsans on different n5ks. Uplinks from UCS / NetApp are FCoE. So I now want to present some normal FC (not FCoE, nexsan) storage to the same

  • How can I add a third e-mail address to a submit button?

    Right now it's only limited to two addresses. The form in question is here: http://www.ucmexus.ucr.edu/resources/Final_Narrative_Report_CONACYT.pdf I need to add a third person to the existing addresses in the submit button. Using Acrobat X Pro.

  • My experience migrating Kodo 3.4 to 4.1

    Hello Stefan, I struggled with Kodo 4.0 and gave it up. Kodo 4.1 seems to be a much better release. I migrated my app in a day. First I managed to run it against 3.4 metadata with some property file changes (migration docs are not very good and miss

  • EP60 SP2 Portal Component Support

    Hi EP Experts,    We are using EP60 SP2 and we are using Universal worklist to look at the workitems in the workflow inbox.    Current UWL portal component supports only SAP file types while attaching a document to the work item. When i try to attach

  • Edits to photos do not save

    After I make edits (of any kind, be it cropping, enhancing, etc.) and hit "Done" the edits and changes do not save. The edited version disappears and the photo reverts to original. I've had this Mac for over a year and never experienced this with any