HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 146

Configuring the BOS Server Process

Page 146 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines Configuring the BOS Server Process To configure the BOS Server (bosserver) process, perform the following steps on the machine to be configured as a Gateway Server. In all cases, hostname is the hostname of the local machine. (Note that you may need to install the bosserver binary file on themachine if it is not already present. See your vendor's installation and configuration documentation for information about installing the binary file.) 1 Authenticate to DCE as a principal who has the following ACL permissions on entries in the registry database: • The i permission on the directory hosts/hostname. • The m, a, u, g, and c permissions on the principal hosts/hostname/dfsserver. The principal is created during the configuration steps. • The t and M permissions on the group subsys/dce/dfs-admin. • The R, t, and M permissions on the organization none. • The r permission on the registry Policy object for the DCE cell. This requirement is most easily met by authenticating to a privileged DCE identity (for example, cell_admin or a principal who is a member of the group acct-admin). 2 Create the principal hosts/hostname/dfs-server, and create an account for the principal. Use the following dcecp commands to create the principal and account in the registry database. In the commands, password is the password of the DCE identity to which you are authenticated. $ dcecp dcecp> principal create hosts/hostname/ dcecp> account create hosts/hostname/dfs_server -group \ > sbsys/dce/dfs-admin -org none \ > -password password -mypwd password 3 Grant the group subsys/dce/dfs-admin the appropriate permissions on the ACL for the hosts/hostname/dfs-server principal in the registry database: dcecp> acl mod /.:/sec/principal/hosts/hostname/dfs-server \ > -add {group subsys/dce/dfs-admin rcDnfmag} dcecp> exit 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

146
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
Configuring the BOS Server Process
To configure the BOS Server (
bosserver
) process, perform the following
steps on the machine to be configured as a Gateway Server. In all cases,
hostname
is the hostname of the local machine. (Note that you may need to
install the
bosserver
binary file on themachine if it is not already present.
See your vendor’s installation and configuration documentation for
information about installing the binary file.)
1
Authenticate to DCE as a principal who has the following ACL permissions
on entries in the registry database:
The
i
permission on the directory
hosts/
hostname
.
The
m
,
a
,
u
,
g
, and
c
permissions on the principal
hosts/
hostname
/
dfs-
server
. The principal is created during the configuration steps.
The
t
and
M
permissions on the group
subsys/dce/dfs-admin
.
The
R
,
t
, and
M
permissions on the organization
none
.
The
r
permission on the registry Policy object for the DCE cell.
This requirement is most easily met by authenticating to a privileged DCE
identity (for example,
cell_admin
or a principal who is a member of the
group
acct-admin
).
2
Create the principal
hosts/
hostname
/
dfs-server
, and create an account for the
principal. Use the following
dcecp
commands to create the principal and
account in the registry database. In the commands,
password
is the password
of the DCE identity to which you are authenticated.
$
dcecp
dcecp>
principal create hosts/
hostname
/
dcecp>
account create hosts/
hostname
/
dfs_server -group
\
>
sbsys/dce/dfs-admin
-org none
\
> -password
password
-mypwd
password
3
Grant the group
subsys/dce/dfs-admin
the appropriate permissions on the
ACL for the
hosts/
hostname
/
dfs-server
principal in the registry database:
dcecp>
acl mod /.:/sec/principal/hosts/
hostname
/
dfs-server
\
>
-add {group subsys/dce/dfs-admin rcDnfmag}
dcecp>
exit