HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 147

The BOS Server process is now fully con d on the machine.

Page 147 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines 4 Use the su command to become the local root user on the machine: $ su Password: root_password 5 Add a server key for the hosts/hostname/dfs-server principal to the /krb5/v5srvtab keytab file on the machine. The dced process recognizes the keytab file by the entry name self. The command creates the keytab file if the file does not already exist. In the commands, password is the password of the DCE identity to which you were authenticated when you created the principal. # dcecp dcecp> keytab add self -member hosts/hostname/dfs-server \ > -key password dcecp> keytab add self -member hosts/hostname/dfs-server \ > -random -registry dcecp> exit 6 Remove the BosConfig file and any administrative lists that may exist from a previous configuration of the BOS Server on the machine: # rm -f dcelocal/var/dfs/BostConfig # rm -f dcelocal/var/dfs/admin.* 7 Start the bosserver process with DFS authorization checking disabled. The process creates a new BosConfig file and a newadmin.bos file, which is the administrative list for the BOS Server. # dcelocal/bin/bosserver -noauth & 8 Add the group subsys/dce/dfs-admin to the admin.bos file: # dcelocal/bin/bos addadmin -server /.:/hosts/hostname \ > -adminlist admin.bos \ > -group subsys/dce/dfs-admin 9 Enable DFS authorization checking by the BOS Server: # dcelocal/bin/bos addadmin -server /.:/hosts/hostname \ > -authchecking on 10 Configure the bosserver process to start automatically when the system is rebooted by removing the two # (number signs) from the following line of the /etc/rc.dfs file (or its equivalent): ##daemonrunning $DCELOCAL/bin/bosserver The BOS Server process is now fully configured on the machine. 147

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

147
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
4
Use the
su
command to become the local
root
user on the machine:
$
su
Password:
root_password
5
Add a server key for the
hosts/
hostname
/
dfs-server
principal to the
/krb5/v5srvtab
keytab file on the machine. The
dced
process recognizes the
keytab file by the entry name
self
. The command creates the keytab file if the
file does not already exist. In the commands,
password
is the password of the
DCE identity to which you were authenticated when you created the
principal.
# dcecp
dcecp>
keytab add self -member hosts/
hostname
/
dfs-server
\
>
-key
password
dcecp>
keytab add self -member hosts/
hostname
/
dfs-server
\
>
-random -registry
dcecp>
exit
6
Remove the
BosConfig
file and any administrative lists that may exist from
a previous configuration of the BOS Server on the machine:
# rm -f
dcelocal
/
var/dfs/BostConfig
# rm -f
dcelocal
/
var/dfs/admin.*
7
Start the
bosserver
process with DFS authorization checking disabled.
The
process creates a new
BosConfig
file and a
newadmin.bos
file, which is the
administrative list for the BOS Server.
#
dcelocal
/
bin/bosserver -noauth &
8
Add the group
subsys/dce/dfs-admin
to the
admin.bos
file:
#
dcelocal
/bin/bos addadmin -server /.:/hosts/
hostname
\
>
-adminlist admin.bos
\
>
-group subsys/dce/dfs-admin
9
Enable DFS authorization checking by the BOS Server:
#
dcelocal
/bin/bos addadmin -server /.:/hosts/
hostname
\
>
-authchecking on
10
Configure the
bosserver
process to start automatically when the system is
rebooted by removing the two
#
(number signs) from the following line of the
/etc/rc.dfs
file (or its equivalent):
##daemonrunning $DCELOCAL/bin/bosserver
The BOS Server process is now fully configured on the machine.