HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 149

The DFS/NFS Secure Gateway

Page 149 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines 5 Authenticate to DCE as a principal who has the following ACL permissions on entries in the registry database: • The i permission on the directory hosts/hostname. • For the first Gateway Server process, the i permission on the directory subsy/dce. • The m, a, u, and g permissions on the principal hosts/hostname/dfsgw-server. The principal is created during the configuration steps. • The t and M permissions on the group subsys/dce/dfsgw-admin. The group is created during the configuration steps. • The R, t, and M permissions on the organization none. • The r permission on the registry Policy object for the DCE cell. This requirement is most easily met by authenticating to a privileged DCE identity (for example, cell_admin or a principal who is a member of the group acct-admin). 6 Invoke the dcecp command: $ dcep 7 For the first Gateway Server process, create the group subsys/dce/dfsgw-admin in the registry database. Use the following dcecp command to create the group: dcecp> group create subsys/dce/dfsgw-admin 8 Create the principal hosts/hostname/dfsgw-server, and create an account for the principal. The Gateway Server process communicates as the principal hosts/hostname/dfsgw-server. Use the following dcecp commands to create the principal and account in the registry database. In the commands, password is the password of the DCE identity to which you are authenticated. dcecp> principal create hosts/hostnamedfsgw-server dcecp> account create hosts/hostname/dfsgw-server \ > -group susbsys/dce/dfsgw-admin -org none \ > -password password -mypwd password dcecp> exit 9 Use the su command to become the local root user on the machine: $ su Password: root_password 149

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

149
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
5
Authenticate to DCE as a principal who has the following ACL permissions
on entries in the registry database:
The
i
permission on the directory
hosts/
hostname
.
For the first Gateway Server process
, the
i
permission on the directory
subsy/dce
.
The
m
,
a
,
u
, and
g
permissions on the principal
hosts/
hostname
/
dfsgw-server
. The principal is created during the
configuration steps.
The
t
and
M
permissions on the group
subsys/dce/dfsgw-admin
. The
group is created during the configuration steps.
The
R
,
t
, and
M
permissions on the organization
none
.
The
r
permission on the registry Policy object for the DCE cell.
This requirement is most easily met by authenticating to a privileged DCE
identity (for example,
cell_admin
or a principal who is a member of the
group
acct-admin
).
6
Invoke the
dcecp
command:
$
dcep
7
For the first Gateway Server process
, create the group
subsys/dce/dfsgw-admin
in the registry database. Use the following
dcecp
command to create the group:
dcecp>
group create subsys/dce/dfsgw-admin
8
Create the principal
hosts/
hostname
/
dfsgw-server
, and create an account for
the principal. The Gateway Server process communicates as the principal
hosts/
hostname
/dfsgw-server
. Use the following
dcecp
commands to create
the principal and account in the registry database. In the commands,
password
is the password of the DCE identity to which you are authenticated.
dcecp>
principal create hosts/
hostname
dfsgw-server
dcecp>
account create hosts/
hostname
/dfsgw-server
\
>
-group susbsys/dce/dfsgw-admin -org none
\
>
-password
password
-mypwd
password
dcecp>
exit
9
Use the
su
command to become the local
root
user on the machine:
$
su
Password:
root_password