HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 45

Restricting RPC Addresses

Page 45 highlights

Installing and Configuring Enhanced DFS 3.0 Restricting RPC Addresses Restricting RPC Addresses Enhanced DFS 3.0 includes restricting RPC addresses with the use of the environment variable, RPC_SUPPORTED_NETADDRS. The format of the RPC_SUPPORTED_NETADDRS string is as follows: RPC_SUPPORTED_NETADDRS=protseq:netaddr For example, assuming that host myhost is located at IP address 10.3.2.1, the Korn shell statements: export RPC_SUPPORTED_NETADDRS=ip:myhost or export RPC_SUPPORTED_NETADDRS=ip:10.3.2.1 forces any servers started in the current shell to support only the addresses associated with the name myhost and the network address 10.3.2.1 Since both DCE and DFS respond to RPC_SUPPORTED_NETADDRS, it may be best to set it in a file that is sourced by both /sbin/init.d/dce and /sbin/init.d/dfs. For example, the Korn shell statement above could be placed in the file /etc/rc.config.d/rpc_supported_netaddrs, and the lines such as if [ -r ${OS_DCE_ETC}/rpc_supported_netaddrs ] then . . ${OS_DCE_ETC}/rpc_supported_netaddrs fi could be included in both /sbin/init.d/dce and /sbin/init.d/dfs. You may use the RPC_SUPPORTED_NETADDRS environment variable to restrict DFS/DCE/EFS interfaces to a single interface, but you may not specify any entries for the CN protocol sequence, nor may you specify more than a single network address. The RPC_SUPPORTED_NETADDRS environment variable should be consistent between all DCE and all DFS/EFS processes. 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

45
Installing and Configuring Enhanced DFS 3.0
Restricting RPC Addresses
Restricting RPC Addresses
Enhanced DFS 3.0 includes restricting RPC addresses with the use of the
environment variable, RPC_SUPPORTED_NETADDRS.
The format of the RPC_SUPPORTED_NETADDRS string is as follows:
RPC_SUPPORTED_NETADDRS=protseq:netaddr
For example, assuming that host myhost is located at IP address 10.3.2.1, the
Korn shell statements:
export RPC_SUPPORTED_NETADDRS=ip:myhost
or
export RPC_SUPPORTED_NETADDRS=ip:10.3.2.1
forces any servers started in the current shell to support only the addresses
associated with the name myhost and the network address 10.3.2.1
Since both DCE and DFS respond to RPC_SUPPORTED_NETADDRS, it
may be best to set it in a file that is sourced by both
/sbin/init.d/dce
and
/sbin/init.d/dfs
. For example, the Korn shell statement above could be
placed in the file
/etc/rc.config.d/rpc_supported_netaddrs
, and the lines
such as
if [ -r ${OS_DCE_ETC}/rpc_supported_netaddrs ]
then
. . ${OS_DCE_ETC}/rpc_supported_netaddrs
fi
could be included in both
/sbin/init.d/dce
and
/sbin/init.d/dfs
.
You may use the RPC_SUPPORTED_NETADDRS environment variable to
restrict DFS/DCE/EFS interfaces to a single interface, but you may not
specify any entries for the CN protocol sequence, nor may you specify more
than a single network address. The RPC_SUPPORTED_NETADDRS
environment variable should be consistent between all DCE and all
DFS/EFS processes.