HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 150

Configuring NFS Clients to Access DFS

Page 150 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines 10 Add a server key for the hosts/hostname/dfsgw-server principal to the /krb5/v5srvtab keytab file on the machine. The dced process recognizes the keytab file by the entry name self. In the commands, password is the password of the DCE identity to which you were authenticated when you created the principal. # dcecp dcecp> keytab add self -member hosts/hostname/dfsgw-server \ > key password dcecp> keytab add self -member hosts/hostname/dfsgw-server \ > -random -registry dcecp> exit 11 Log out as root to return to your authenticated DCE identity. 12 If your current DCE identity is not included in the dcelocal/var/dfs/admin.bos file on the machine, either add the identity to the file or authenticate to DCE as a principal who is included in the file. You can use the bos lsadmin command to list the principals and groups included in the admin.bos file: $ dcelocal/bin/bos lasdmin -server /.:/hosts/hostname \ > -adminlist admin.bos 13 Create a simple BOS Server process named dfsgw to run the dfsgwd server process: $ dcelocal/bin/bos lsadmin -server /.:/hostshostname -process dfsgw \ -type simple cmd dcelocal/bin/dfsgwd The Gateway Server process is now fully configured on the machine. Configuring NFS Clients to Access DFS Once you have configured at least one Gateway Server machine according to the instructions in "Configuring Gateway Server Machines," you can configure your NFS clients to provide access to the DFS filespace. Users who have DCE accounts can then authenticate to DCE for authenticated access to DFS from the NFS clients. Authenticating to DCE provides these users with the privileges and permissions associated with their DCE identities. 150

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

150
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
10
Add a server key for the
hosts
/
hostname
/
dfsgw-server
principal to the
/krb5/v5srvtab
keytab file on the machine. The
dced
process recognizes the
keytab file by the entry name
self
. In the commands,
password
is the
password of the DCE identity to which you were authenticated when you
created the principal.
# dcecp
dcecp>
keytab add self -member hosts/
hostname
/dfsgw-server
\
>
key
password
dcecp>
keytab add self -member hosts/
hostname
/dfsgw-server
\
>
-random -registry
dcecp>
exit
11
Log out as
root
to return to your authenticated DCE identity.
12
If your current DCE identity is not included in the
dcelocal
/var/dfs/admin.bos
file on the machine, either add the identity to the
file or authenticate to DCE as a principal who is included in the file. You can
use the
bos lsadmin
command to list the principals and groups included in
the
admin.bos
file:
$
dcelocal
/bin/bos lasdmin -server /.:/hosts/hostname
\
>
-adminlist admin.bos
13
Create a
simple
BOS Server process named
dfsgw
to run the
dfsgwd
server
process:
$
dcelocal
/bin/bos lsadmin -server /.:/hosts
hostname
-process dfsgw
\
-type simple cmd
dcelocal
/bin/dfsgwd
The Gateway Server process is now fully configured on the machine.
Configuring NFS Clients to Access DFS
Once you have configured at least one Gateway Server machine according to
the instructions in “Configuring Gateway Server Machines,” you can
configure your NFS clients to provide access to the DFS filespace. Users
who have DCE accounts can then authenticate to DCE for authenticated
access to DFS from the NFS clients. Authenticating to DCE provides these
users with the privileges and permissions associated with their DCE
identities.