[OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Lars Schimmer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi! As the other thread is more about limits, I switched to a new thread. We need a distributed filestorage for 20-200 organizations EU wide. I think about setting up a single OpenAFS cell with a central krb5 server and 3 db servers (managed by the

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Harald Barth
You may want to think through how you manage the pts entries, how you add and subtract users / groups. If you need or have another infrastructure for that anyway, you could easily push to that data to pts. And then it does not matter if you push it to one or 20 cells. (or not pushing but with a

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Anders Magnusson
Lars Schimmer wrote: Right now I see the limit of 20 groups per ACL in a directory as a problem - but thats a point we could work araound, somehow. You should use as few ACL entries as possible and instead put users/groups in groups on the directories. IMHO something is setup wrong if you

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Lars Schimmer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 *sry* send the first one only to harald. Harald Barth wrote: You may want to think through how you manage the pts entries, how you add and subtract users / groups. If you need or have another infrastructure for that anyway, you could easily push

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Davor Ocelic
On Wed, 27 Jan 2010 10:26:04 +0100 Lars Schimmer l.schim...@cgv.tugraz.at wrote: You need to do some preconfigured shipping anyway, if you automate the generate boot CD process it does not matter much if you need to add a new cellname and security KeyFile in that process. A complete

[OpenAFS] Re: New Cell setup - ideas?

2010-01-27 Thread Andrew Deason
On Wed, 27 Jan 2010 09:22:38 +0100 Lars Schimmer l.schim...@cgv.tugraz.at wrote: One cell per organization could be done, to - but it needs far more admin overhead at the organizations (which are NOT technical organizations and admin alike, which means lots of training and kinda thats to much

Re: [OpenAFS] Linux kernel modules - symlinks instead of rebuilds?

2010-01-27 Thread Derek Atkins
Simon Wilkinson s...@inf.ed.ac.uk writes: On 26 Jan 2010, at 17:11, Derrick Brashear wrote: It's not without risk. You're probably ok (and assuming the symbol versioning works correctly you shouldn't lose if the module does load) but we don't want to rely on it. RedHat already do this with

Re: [OpenAFS] Re: Cron Jobs for Regular Users

2010-01-27 Thread Holger Rauch
Hi Andrew (and all the other list members), ok, first I like to admit that this is actually rather Kerberos- than OpenAFS-related. Sorry for that, but I want to be able to issue cron jobs as an OpenAFS user without having to create both new, dedicated user_name/cron princs and the associated new

Re: [OpenAFS] Re: Cron Jobs for Regular Users

2010-01-27 Thread Thomas Kula
On Wed, Jan 27, 2010 at 04:27:59PM +0100, Holger Rauch wrote: I tried to follow your suggestion. I had come accross this mail: http://www.mail-archive.com/kerbe...@mit.edu/msg03229.html However, when following the steps described in there, I get the following error message after having

[OpenAFS] Re: Cron Jobs for Regular Users

2010-01-27 Thread Andrew Deason
On Wed, 27 Jan 2010 16:27:59 +0100 Holger Rauch holger.ra...@empic.de wrote: - Could it be that the kvno doesn't match? - What's the default kvno for princs that are created interactively from within kadmin using the addprinc command? - In case I want to reuse a regular user princ from

[OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Adam Megacz
Derrick Brashear sha...@gmail.com writes: I might be able to try that, but it will take a few days. if true, you should see output in cmdebug now Okay, I just caught it red-handed. Can anybody help with reading the tea leaves here? meg...@quine:~$cmdebug localhost Lock afs_xvcache

[OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Derrick Brashear
On Wed, Jan 27, 2010 at 12:10 PM, Adam Megacz a...@megacz.com wrote: Derrick Brashear sha...@gmail.com writes: I might be able to try that, but it will take a few days. if true, you should see output in cmdebug now Okay, I just caught it red-handed.  Can anybody help with reading the tea

Re: [OpenAFS] Re: Cron Jobs for Regular Users

2010-01-27 Thread Russ Allbery
Thomas Kula k...@tproa.net writes: On Wed, Jan 27, 2010 at 04:27:59PM +0100, Holger Rauch wrote: - What's the default kvno for princs that are created interactively from within kadmin using the addprinc command? When I just created one, I got a kvno of 1. If you create a principal in MIT

[OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Adam Megacz
Derrick Brashear sha...@gmail.com writes:  Lock afs_xvcache status: (none_waiting, write_locked(pid:11013 at:335)) Ah, so I am to interpret the thing after the comma as the name of a function somewhere within the openafs source code. Knowing that helps a lot! assuming you're not running

Re: [OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Simon Wilkinson
On 27 Jan 2010, at 21:30, Adam Megacz wrote: Derrick Brashear sha...@gmail.com writes: Lock afs_xvcache status: (none_waiting, write_locked(pid:11013 at:335)) Ah, so I am to interpret the thing after the comma as the name of a function somewhere within the openafs source code. Knowing

Re: [OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Derrick Brashear
On Wed, Jan 27, 2010 at 4:30 PM, Adam Megacz a...@megacz.com wrote: Derrick Brashear sha...@gmail.com writes:  Lock afs_xvcache status: (none_waiting, write_locked(pid:11013 at:335)) Ah, so I am to interpret the thing after the comma as the name of a function somewhere within the openafs

[OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Adam Megacz
Derrick Brashear sha...@gmail.com writes: You don't. You can ask the vlserver, which is how the CM found out anyhow: vos listaddrs -printuuid -noresolve Yikes, that list is full of incorrect addresses. How on earth is the list compiled? - a ___

Re: [OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Steven Jenkins
On Wed, Jan 27, 2010 at 5:22 PM, Adam Megacz a...@megacz.com wrote: Derrick Brashear sha...@gmail.com writes: You don't. You can ask the vlserver, which is how the CM found out anyhow: vos listaddrs -printuuid -noresolve Yikes, that list is full of incorrect addresses.  How on earth is the

Re: [OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Derrick Brashear
On Wed, Jan 27, 2010 at 5:22 PM, Adam Megacz a...@megacz.com wrote: Derrick Brashear sha...@gmail.com writes: You don't. You can ask the vlserver, which is how the CM found out anyhow: vos listaddrs -printuuid -noresolve Yikes, that list is full of incorrect addresses.  How on earth is the

Re: [OpenAFS] Re: advice on troubleshooting blocked cache manager on MacOS?

2010-01-27 Thread Rich Sudlow
Steven Jenkins wrote: On Wed, Jan 27, 2010 at 5:22 PM, Adam Megacz a...@megacz.com wrote: Derrick Brashear sha...@gmail.com writes: You don't. You can ask the vlserver, which is how the CM found out anyhow: vos listaddrs -printuuid -noresolve Yikes, that list is full of incorrect addresses.

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Jason Edgecombe
Lars Schimmer wrote: *sry* send the first one only to harald. Harald Barth wrote: You may want to think through how you manage the pts entries, how you add and subtract users / groups. If you need or have another infrastructure for that anyway, you could easily push to that data to pts. And

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Tom Keiser
On Wed, Jan 27, 2010 at 3:22 AM, Lars Schimmer l.schim...@cgv.tugraz.at wrote: - -no single user (person) should be identified accessing that data by sharing organization (to see which department is fine, but not the single persons of the accessing department) The AFS-3 security model

Re: [OpenAFS] New Cell setup - ideas?

2010-01-27 Thread Derrick Brashear
On Wed, Jan 27, 2010 at 11:17 PM, Tom Keiser tkei...@sinenomine.net wrote: On Wed, Jan 27, 2010 at 3:22 AM, Lars Schimmer l.schim...@cgv.tugraz.at wrote: - -no single user (person) should be identified accessing that data by sharing organization (to see which department is fine, but not the