db-derby-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Knut Anders Hatlen (Commented) (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (DERBY-5651) Protocol error when connecting to db with NATIVE authentication using strong password substitution
Date Thu, 15 Mar 2012 08:29:37 GMT

    [ https://issues.apache.org/jira/browse/DERBY-5651?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13229985#comment-13229985

Knut Anders Hatlen commented on DERBY-5651:

> FYI: I am able to reproduce the BUILTIN behavior only if I specify password substitution
with an invalid user name.

Yes, I failed to mention that I had defined the user in a database property, not in a system
property. Strong password substitution is still supported for users defined in system properties
(because the server knows the cleartext password for those users). When the user is defined
in a database property, BUILTIN fails with the above message also when valid credentials are
> Protocol error when connecting to db with NATIVE authentication using strong password
> --------------------------------------------------------------------------------------------------
>                 Key: DERBY-5651
>                 URL: https://issues.apache.org/jira/browse/DERBY-5651
>             Project: Derby
>          Issue Type: Bug
>          Components: Network Server, Services
>    Affects Versions:
>            Reporter: Knut Anders Hatlen
> If you connect to a db with native authentication using strong password substitution
to protect the password, you'll get a protocol error:
> ij(CONNECTION2)> connect 'jdbc:derby://localhost/db;user=app;password=papp;securityMechanism=8';
> ERROR 08006: A network protocol error was encountered and the connection has been terminated:
A PROTOCOL Data Stream Syntax Error was detected.  Reason: 0x18. Plaintext connection attempt
to an SSL enabled server?
> I don't think strong password substitution is intended to work with NATIVE, but it should
probably fail more gracefully. With BUILTIN, you'll get a more helpful error message:
> ij(CONNECTION5)> connect 'jdbc:derby://localhost/db2;user=app;password=papp;securityMechanism=8';
> ERROR 08004: DERBY SQL error: SQLCODE: -1, SQLSTATE: 08004, SQLERRMC: Connection authentication
failure occurred. Either the supplied credentials were invalid, or the database uses a password
encryption scheme not compatible with the strong password substitution security mechanism.
If this error started after upgrade, refer to the release note for DERBY-4483 for options.

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira


View raw message