Configuring a Data Source on Linux
The ODBC driver (libogodbc.so) provided by oGRAC can be used once it is configured into a data source. Configuring a data source requires setting up two configuration files, odbc.ini and odbcinst.ini (generated when compiling and installing unixODBC and placed in the /usr/local/etc directory by default), and performing configuration on the server.
Procedure
Obtain the unixODBC source package.
The unixODBC version must be 2.3.6 or later. Taking unixODBC-2.3.6 as an example, you can download it directly: unixODBC-2.3.6.tar.gz.
Install unixODBC. If an earlier version of unixODBC is already installed on the machine, uninstall it first or directly overwrite the existing installation.
Taking unixODBC-2.3.6 as an example, run the following commands on the client to install unixODBC. By default, it is installed to the
/usr/localdirectory, the data source files are generated in the/usr/local/etcdirectory, and the library files are generated in the/usr/local/libdirectory.shelltar zxvf unixODBC-2.3.6.tar.gz cd unixODBC-2.3.6 ./configure --enable-gui=no make # The installation may require root privileges. make installReplace the client ODBC driver.
Copy the ODBC driver (libogodbc.so) provided by oGRAC to the
/usr/local/libdirectory, and verify its integrity.shellldd /usr/local/lib/libogodbc.soConfigure the data source.
Configure the ODBC driver file.
Append the following content to the
/usr/local/etc/odbcinst.inifile.shell[OgracMPP] Driver64=/usr/local/lib/libogodbc.so setup=/usr/local/lib/libogodbc.soTable 1 describes the configuration parameters in the
odbcinst.inifile.Table 1 Configuration parameters in the
odbcinst.inifileDriver name, which corresponds to the driver name in the data source DSN.
Driver installation path, which must be the dynamic library path specified in Driver64.
Configure the data source file.
Append the following content to the
/usr/local/etc/odbc.inifile.shell[OgracDB] Driver=OgracMPP Servername=127.0.0.1 Port=1611 Username=test Password=test123Table 2 describes the
odbc.inifile configuration parameters.Table 2
odbc.inifile configuration parametersFor details about the allowed values of the
sslmodeoptions, see the following table:Table 3
sslmodeoptions
Use SSL mode.
Generate the server certificate.
Perform the following operations on the server where the database is installed:
shell# Generate the CA certificate ca.crt and private key ca.key on the host. openssl req -newkey rsa:3072 -passout pass:12345678 -keyout ca.key -x509 -days 365 -out ca.crt -subj "/C=CN/ST=BJ/O=huawei/OU=huawei/CN=CA/emailAddress=123456@xxx.com" # Generate the private key mes.key and certificate request mes.csr on the host. openssl req -newkey rsa:3072 -nodes -keyout mes.key -out mes.csr -subj "/C=CN/ST=BJ/L=BJ/O=huawei/OU=huawei/CN=Server/emailAddress=123456@xxx.com" # Generate the certificate mes.crt on the host. openssl x509 -req -days 365 -in mes.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out mes.crtConfigure server parameters.
Create a directory
/opt/ograc/dataon the server where the database is installed, place the generated certificatesca.crt,ca.key,ca.srl,mes.crt,mes.csr, andmes.keyinto this directory, and modify the permissions on the folder and certificates:shell# Modify the folder permissions, where ogracdba is the database installation user. chmod 700 /opt/ograc/data chown ogracdba:ogracdba /opt/ograc/data # Modify the certificate permissions. chmod 400 /opt/ograc/data/* chown ogracdba:ogracdba /opt/ograc/data/*Add SSL parameters to enable SSL mode for the database.
shell# Log in to the database. ogsql test/test123@127.0.0.1:1611 -q # Execute the following SQL statements to add parameters. alter system set SSL_CA = '/opt/ograc/data/ca.crt'; alter system set SSL_CERT = '/opt/ograc/data/mes.crt'; alter system set SSL_KEY='/opt/ograc/data/mes.key'; # Restart the database. cms res -stop db cms res -start dbAfter the restart, execute the SQL command:
show parameter ssl. If the query result shows that the value ofHAVE_SSLisTRUE, SSL has been successfully enabled.Configure an SSL connection on the ODBC client.
Create an arbitrary directory
/usr/test/certificateon the client where ODBC is located, and use scp to transfer theca.crtfile generated on the server to the client where ODBC is located. Then perform the following operations:shellmkdir -p /usr/test/certificate cd /usr/test/certificate scp root@xxx.xxx.xx.xx:/opt/ograc/data/ca.crt .Generate the private key
client.keyand the certificate requestclient.csron the client:shellopenssl req -newkey rsa:3072 -nodes -keyout client.key -out client.csr -subj "/C=CN/ST=BJ/L=BJ/O=huawei/OU=huawei/CN=Server/emailAddress=123456@xxx.com"Use scp to transfer
client.csrto the/opt/ograc/datadirectory on the server where the database is located:shellscp client.csr root@xxx.xxx.xx.xx:/opt/ograc/data/Generate the client certificate.
Generate the certificate
client.crtin the/opt/ograc/datadirectory on the server where the database is located, and transfer it to the client:shellcd /opt/ograc/data openssl x509 -req -days 365 -in client.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out client.crtTransfer the certificate to the client.
Transfer the generated certificate
client.crtto the client:shellcd /usr/test/certificate scp root@xxx.xxx.xx.xx:/opt/ograc/data/client.crt .Configure ODBC parameters on the client.
Grant permissions to the certificate:
shellchmod 400 /usr/test/certificate/*Add the following parameters in the
odbc.inifile:shellsslca=/usr/test/certificate/ca.crt sslcert=/usr/test/certificate/client.crt sslkey=/usr/test/certificate/client.key sslmode = VERIFY_CA
Configure environment variables on the client.
shellvim ~/.bashrcAppend the following content to the configuration file:
shellexport PATH=/usr/local/bin:$PATH export LD_LIBRARY_PATH=/usr/local/lib:$LD_LIBRARY_PATHRun the following command to apply the settings:
shellsource ~/.bashrcRegister the driver.
shellodbcinst -i -d -f /usr/local/etc/odbcinst.ini
Testing the Data Source Configuration
After installation, run the isql command to verify the connection, that is, isql OgracDB -v test test123.
If the following information is displayed, the configuration is correct and the connection is successful.
shell+---------------------------------------+ | Connected! | | | | sql-statement | | help [tablename] | | quit | | | +---------------------------------------+ SQL>If
ERRORinformation is displayed, a configuration error exists. Check whether the above configuration is correct.