Re: [OpenAFS] controlling access to backup volumes

2007-03-20 Thread anne salemme
Adam Megacz wrote: So, is there any way to make a backup volume less accessible than its rw? If not, then it means that reducing access to any backed-up file always has to wait until the next backup... if you're in a big hurry, you can do a 'vos backup' manually, no need to wait for the n

Re: [OpenAFS] Re: unix owner/group of files in AFS

2007-03-20 Thread FB
Hi, On Mon, Mar 19, 2007 at 07:13:21PM -0700, Adam Megacz wrote: > > Derrick J Brashear <[EMAIL PROTECTED]> writes: > > someone had nss_pts. that's the right idea. > > http://tarna.oit.unc.edu/~utoddl/nss_pts_0.2.tgz > > Hey neat, the output of 'ls' shows pts names. Based on nss_pts, i wrote n

Re: [OpenAFS] Hijacking a PAG

2007-03-20 Thread Derek Atkins
I think the KeyRing/PAG design is specifically so you CANT do what you're trying to do. Different sessions should have different PAGs. -derek Andreas Haupt <[EMAIL PROTECTED]> writes: > Hi, > > I'm working on the SGE / AFS integration under SL5. With the latest > OpenAFS (1.4.3) the way PAGs a

Re: [OpenAFS] Hijacking a PAG

2007-03-20 Thread chas williams - CONTRACTOR
In message <[EMAIL PROTECTED]>,Andreas Haupt write s: >I can have full access to the PAG environment SGE has created. How can I >"transfer" the PAG now to a second "virgin" environment. As an example I >have two sessions and I want the second session to be in the same PAG as >the first session:

[OpenAFS] Initial server setup

2007-03-20 Thread Martin Lütken
I tried for a couple of weeks now to set up an openAFS server. I read through the IBM documentation and surfed the net. It seems the IBM documentation is somewhat outdated or ? Should I still use 'kasserver' . Sometimes I find statement saying not to but IBM documentation use that. I know I shooul

Re: [OpenAFS] Re: unix owner/group of files in AFS

2007-03-20 Thread Derrick J Brashear
On Mon, 19 Mar 2007, Adam Megacz wrote: Derrick J Brashear <[EMAIL PROTECTED]> writes: Hey neat, the output of 'ls' shows pts names. i actually did this years ago, before there was nss, and let it drop. but, the issue when you have not coordinated local uids and pts ids is when do you do an

Re: [OpenAFS] Initial server setup

2007-03-20 Thread Christopher D. Clausen
Martin Lütken <[EMAIL PROTECTED]> wrote: > I tried for a couple of weeks now to set up an openAFS server. > I read through the IBM documentation and surfed the net. > It seems the IBM documentation is somewhat outdated or ? > Should I still use 'kasserver' . Sometimes I find statement saying not >

Re: [OpenAFS] Initial server setup

2007-03-20 Thread david l goodrich
> I tried for a couple of weeks now to set up an openAFS server. > I read through the IBM documentation and surfed the net. > It seems the IBM documentation is somewhat outdated or ? > Should I still use 'kasserver' . Sometimes I find statement saying not > to but IBM documentation use that. Don't

Re: [OpenAFS] Hijacking a PAG

2007-03-20 Thread Andreas Haupt
Hi Derek, hi Chas, On Tue, 20 Mar 2007, chas williams - CONTRACTOR wrote: In message <[EMAIL PROTECTED]>,Andreas Haupt write s: I can have full access to the PAG environment SGE has created. How can I "transfer" the PAG now to a second "virgin" environment. As an example I have two sessions an

Re: [OpenAFS] Initial server setup

2007-03-20 Thread Martin Lütken
Christopher D. Clausen wrote: Martin Lütken <[EMAIL PROTECTED]> wrote: I tried for a couple of weeks now to set up an openAFS server. I read through the IBM documentation and surfed the net. It seems the IBM documentation is somewhat outdated or ? Should I still use 'kasserver' .

Re: [OpenAFS] Re: unix owner/group of files in AFS

2007-03-20 Thread Christopher D. Clausen
FB <[EMAIL PROTECTED]> wrote: > Hi, > > On Mon, Mar 19, 2007 at 07:13:21PM -0700, Adam Megacz wrote: >> >> Derrick J Brashear <[EMAIL PROTECTED]> writes: >>> someone had nss_pts. that's the right idea. >> >> http://tarna.oit.unc.edu/~utoddl/nss_pts_0.2.tgz >> >> Hey neat, the output of 'ls' shows p

Re: [OpenAFS] Hijacking a PAG

2007-03-20 Thread Christof Hanke
Hi, just one (or three) question(s) out of curiosity : Why don't you operate on the krb5-ticket-level? Wouldn't that be easier (and more portable to other systems) ? Any specific reason for that ? Christof Andreas Haupt wrote: > Hi Derek, hi Chas, > > On Tue, 20 Mar 2007, chas williams - CON

Re: [OpenAFS] Initial server setup

2007-03-20 Thread Martin Lütken
ted creedon wrote: Stick to SuSe 10.2, it works fine here. (8.x, 9.x, 10.0, 10.1 10.2). When you reinstall SUSE, intall the krb5 package but leave all the afs rpm's out, including the krb-afs, the afs module, etc. Set up stock krb5.ini, if you can wait a few days I'll add in the scripts I

Re: [OpenAFS] Server encryption keys

2007-03-20 Thread Ken Hornstein
>On a test cell, I've been able to change the encryption key as >follows: I change the afs password using kadmin and export it >to the KeyFile. I then have to kill the bos process and all >server processes on all servers, since my old admin tokens >don't work any more, nor do new ones when I reaut

Re: [OpenAFS] Re: unix owner/group of files in AFS

2007-03-20 Thread FB
Hi, On Tue, Mar 20, 2007 at 10:56:23AM -0500, Christopher D. Clausen wrote: > FB <[EMAIL PROTECTED]> wrote: [snip] > > Based on nss_pts, i wrote nss-ptdb which provides some more features: > > * fake homedirectory information from ptdb > > ( homedir= /afs/$cellname/user/$username ) > > *

Re: [OpenAFS] Hijacking a PAG

2007-03-20 Thread Andreas Haupt
Hi, On Tue, 20 Mar 2007, Christof Hanke wrote: Hi, just one (or three) question(s) out of curiosity : Why don't you operate on the krb5-ticket-level? Wouldn't that be easier (and more portable to other systems) ? Any specific reason for that ? it's actually working on the Krb5-Level. Beside