HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 144

Configuring a Gateway Server Without Enabling Remote, Authentication

Page 144 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines Before configuring a Gateway Server machine, you must do the following: • Configure a DCE cell that includes DFS. • Configure each machine that is to become a Gateway Server as a DFS client and an NFS server. • Ensure proper synchronization among the system clocks on machines that are to become Gateway Servers, machines configured as NFS clients that are to contact the Gateway Servers, and machines in the DCE cell to be contacted. You must keep the system clocks on these machines synchronized at all times. Once you have met these prerequisites, you can configure your Gateway Server machines. Configuring a Gateway Server Without Enabling Remote Authentication Perform the steps in this section to enable DCE authentication from a Gateway Server machine without enabling it from NFS clients that contact the Gateway Server. Users can authenticate only by issuing the dfsgw add command on the Gateway Server machine (or by having a system administrator issue the command for them, if administrators control authentication to the DCE cell). To allow users of NFS clients to authenticate to DCE from the Gateway Server machine but not from NFS clients that contact the Gateway Server, perform the following steps on the machine to be configured as a Gateway Server: 1 Log in as the local root user on the machine. 2 Install the binary file for the dfsgw command suite in the directory dcelocal/bin/ on the machine. The dfsgw command suite provides a local interface to the authentication table maintained on the Gateway Server machine. Commands in the dfsgw suite can be used to add, delete, and view mappings in the authentication table. (See the sections from "Authenticating to DCE from a Gateway Server Machine" through "Displaying Information About All Users Who Are Authenticated to DCE" for information about using these commands.) 144

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

144
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
Before configuring a Gateway Server machine, you must do the following:
Configure a DCE cell that includes DFS.
Configure each machine that is to become a Gateway Server as a DFS client and
an NFS server.
Ensure proper synchronization among the system clocks on machines that are to
become Gateway Servers, machines configured as NFS clients that are to contact
the Gateway Servers, and machines in the DCE cell to be contacted.
You must
keep the system clocks on these machines synchronized at all times.
Once you have met these prerequisites, you can configure your Gateway
Server machines.
Configuring a Gateway Server Without Enabling Remote
Authentication
Perform the steps in this section to enable DCE authentication from a
Gateway Server machine without enabling it from NFS clients that contact
the Gateway Server. Users can authenticate only by issuing the
dfsgw add
command on the Gateway Server machine (or by having a system
administrator issue the command for them, if administrators control
authentication to the DCE cell).
To allow users of NFS clients to authenticate to DCE from the Gateway
Server machine but not from NFS clients that contact the Gateway Server,
perform the following steps on the machine to be configured as a Gateway
Server:
1
Log in as the local
root
user on the machine.
2
Install the binary file for the
dfsgw
command suite in the directory
dcelocal/bin/
on the machine. The
dfsgw
command suite provides a local
interface to the authentication table maintained on the Gateway Server
machine. Commands in the
dfsgw
suite can be used to add, delete, and view
mappings in the authentication table. (See the sections from “Authenticating
to DCE from a Gateway Server Machine” through “Displaying Information
About All Users Who Are Authenticated to DCE” for information about
using these commands.)