[OpenAFS] Announcing OpenAFS E&O Insurance Covering Code Contributions

2018-01-24 Thread Dave Botsch
All, On behalf of the OpenAFS Foundation Board of Directors, I am pleased to announce that the OpenAFS initiative including any paid or volunteer software development is now covered by Errors and Omissions insurance. This is a big step forward and now allows contributions of code without major fea

[OpenAFS] afs db failover testing for lowest IP

2018-01-24 Thread John Sopko
I need to upgrade our afs db servers. It has been sometime so I setup a test cell with 3 servers to see how things react when the lowest IP server is down. When the lowest IP db server is down udebug shows the second lowest IP becomes the sync site. But, I cannot do certain commands that time out

[OpenAFS] Re: afs db failover testing for lowest IP

2018-01-24 Thread John Sopko
I did not have the secondary db machines in /usr/vice/etc/CellServDB. All is good :) On Wed, Jan 24, 2018 at 9:57 AM, John Sopko wrote: > I need to upgrade our afs db servers. It has been sometime so I setup > a test cell with 3 servers to see how things react when the lowest IP > server is down.

[OpenAFS] Is member of a machine group honored as system:authuser?

2018-01-24 Thread Ximeng Guan
Hello, I am trying to make some effective use of machine groups in AFS to accommodate certain requirement of licensed software. I read about the feature, and noticed that in the 1998 edition of the book "Managing AFS, The Andrew File System" by Richard Campbell, the following text appeared in C

[OpenAFS] Re: Re: afs db failover testing for lowest IP

2018-01-24 Thread Stephen Joyce
Hey, John. Let me know if you have more problems, or just need to bounce any ideas around. I went through something similar last summer, but I actually changed IP addresses (moved to a different VLAN). I decided to bite the bullet and virtualize my DB servers at the same time. You may want t

Re: [OpenAFS] Re: Re: afs db failover testing for lowest IP

2018-01-24 Thread Stephen Joyce
That was intended to be addressed only to John. Mea culpa. On Wed, 24 Jan 2018, Stephen Joyce wrote: Hey, John. Let me know if you have more problems, or just need to bounce any ideas around. I went through something similar last summer, but I actually changed IP addresses (moved to a differe

Re: [OpenAFS] Re: Re: afs db failover testing for lowest IP

2018-01-24 Thread John Sopko
Were all friends, good to let the group know some of our issues! In my case I built openafs 1.6.22.1 For Redhat 6.9 since there are no binaries. When I updated it nuked the /usr/vice/etc/CellServDB.local on my working cell so the clients did not know about about the secondary servers anymore. We us

Re: [OpenAFS] Is member of a machine group honored as system:authuser?

2018-01-24 Thread Garance A Drosehn
On 24 Jan 2018, at 14:31, Ximeng Guan wrote: I would expect that a local user on 10.12.8.31, even without an AFS token, would be able to "cd" into the top directory of the cell. But in reality that does not happen. An unauthenticated user is denied of access. When I explicitly put "machinegr

Re: [OpenAFS] Is member of a machine group honored as system:authuser?

2018-01-24 Thread Benjamin Kaduk
On Wed, Jan 24, 2018 at 07:31:51PM +, Ximeng Guan wrote: [snip] > Did I miss anything here? I don't think so. It's probably best to think of system:authuser as a shorthand for "all entities that can authenticate to the protection server", users and keytab-based credentials. The machine/IP