Re: [OpenAFS] Setup a new OpenAFS cell on Debian bullseye v11

2022-05-02 Thread Andreas Ladanyi
Hi Jose, we rekeyed our cell years ago. Maybe this help you. https://www.openafs.org/pages/security/how-to-rekey.txt https://www.openafs.org/pages/security/install-rxkad-k5-1.6.txt regards, Andreas Am 02.05.22 um 16:18 schrieb Jose M Calhariz: I am helping my intern to setup a new OpenAFS

Re: [OpenAFS] Migrating away from single DES

2020-09-14 Thread Andreas Ladanyi
Hi Stefano, Rekey your AFS Server(s). Have a look at this document: https://www.openafs.org/pages/security/how-to-rekey.txt An interesting discussion about "how-to-rekey.txt": https://openafs-info.openafs.narkive.com/PVFdhGZD/afs-principal-rekeying-instructions-may-be-incomplete regards,

Re: [OpenAFS] AFS client hanged

2019-12-18 Thread Andreas Ladanyi
Hi, >> kernel-2.6.32-696.20.1.el6.x86_64. After we upgrade to the new linux >> kernel and install the default openafs client version using yum(the version >> we used listed in the following), we have the hang issue. That's why I >> suspect the version compatibility. >> >> AFS

Re: [OpenAFS] AFS client hanged

2019-12-16 Thread Andreas Ladanyi
Hi , > Dear all, > > Recently, I'm stuck with some AFS issues. > > AFS client hanged with the following log message. In this case, > the AFS instance blocked and jobs failed to access any files > located in AFS. I have to reboot the work node to recover service. > > Dec  6 

Re: [OpenAFS] Windows 10 Pro and openafs client : cannot obtain token

2019-06-17 Thread Andreas Ladanyi
t; > Thanks in advance. > Laurent > -- Karlsruher Institut für Technologie (KIT) Fakultät für Informatik ATIS – Abteilung Technische Infrastruktur Dipl.-Ing. Andreas Ladanyi - Systemadministrator - Am Fasanengarten 5, Gebäude 50.34, Raum 013 76131 Karlsruhe Telefon: +49 721 608 - 4

Re: [OpenAFS] AFS 1.8.2, afsd errors on FreeBSD

2019-04-29 Thread Andreas Ladanyi
Hi, > On Tue, Apr 16, 2019 at 03:02:16PM +0200, Andreas Ladanyi wrote: >> Hi, >> >> afsd -debug tells me: >> >> SScall(339, 28, 6601376)=-1 (78, Function not implemented) >> SScall(339, 28, -18944)=-1 (78, Function not implemented) >> SScall(339, 28,

[OpenAFS] AFS 1.8.2, afsd errors on FreeBSD

2019-04-16 Thread Andreas Ladanyi
Hi, afsd -debug tells me: SScall(339, 28, 6601376)=-1 (78, Function not implemented) SScall(339, 28, -18944)=-1 (78, Function not implemented) SScall(339, 28, 1)=-1 (78, Function not implemented) afsd: Forking rx listener daemon. afsd: Forking rx callback listener. SScall(339, 28, 15050)=-1 (78,

Re: [OpenAFS] AFS 1.8.2 , bus error on FreeBSD

2019-04-08 Thread Andreas Ladanyi
ompile the "bos" binary could start without "bus error" ? Am 07.04.19 um 20:44 schrieb Benjamin Kaduk: I don't think that's a requirement, no. (Were the crashes with a gcc-compiled version?) -Ben On Sun, Apr 07, 2019 at 08:17:44PM +0200, Andreas Ladanyi wrote: Ok so i hav

Re: [OpenAFS] AFS 1.8.2 , bus error on FreeBSD

2019-04-07 Thread Andreas Ladanyi
Ok so i have to compile OpenAFS 1.8 with clang instead of gcc at FreeBSD ? Am 06.04.19 um 04:33 schrieb Benjamin Kaduk: On Fri, Apr 05, 2019 at 08:39:23AM +0200, Andreas Ladanyi wrote: Hi, i compiled afs 1.8.2 on freebsd 11.2. When i want to execute bos command it shows me a "Bus

[OpenAFS] AFS 1.8.2 , bus error on FreeBSD

2019-04-05 Thread Andreas Ladanyi
Hi, i compiled afs 1.8.2 on freebsd 11.2. When i want to execute bos command it shows me a "Bus Error".  If i understand the problem correctly the problem is that bos wants to access memory which CPU physically cant access. Do i have to set some flags at configure time, before make ?

Re: [OpenAFS] AFS fails to build on FreeBSD

2019-03-27 Thread Andreas Ladanyi
Hi, > Hi, > >>> I don't have it in front of me right now, but at least on 1.8.x (I haven't >>> tried 1.6.x), it's necessary to create that file based on the FreeBSD 11.1 >>> version and add a systype for 11.2 into some other file(s) (a grep for fbsd >>> should help). It was actually pretty

Re: [OpenAFS] AFS fails to build on FreeBSD

2019-03-20 Thread Andreas Ladanyi
Hi, >> I don't have it in front of me right now, but at least on 1.8.x (I haven't >> tried 1.6.x), it's necessary to create that file based on the FreeBSD 11.1 >> version and add a systype for 11.2 into some other file(s) (a grep for fbsd >> should help). It was actually pretty

[OpenAFS] AFS fails to build on FreeBSD

2019-03-15 Thread Andreas Ladanyi
Hi, AFS 1.6.23 fails to build on FreeBSD 11.2 make tells me: dont know how to make ./param.amd64_fbsd_112.h. Stop Could somebody assist me, please ? thanks, Andreas ___ OpenAFS-info mailing list OpenAFS-info@openafs.org

Re: [OpenAFS] AFS Performance / ZFS

2019-03-07 Thread Andreas Ladanyi
Hi Jeffrey, >> Hi, >> >> iam testing a box with FreeNAS  (BSD) and ZFS. On this box i use >> virtualized byhve guest as afs server. >> [...] >> Any ideas why afs speed is only about 25 MByte/s ? Maybe i have to >> adjust another afs server parameter ? > There are performance bottlenecks in the

[OpenAFS] AFS Performance / ZFS

2019-03-07 Thread Andreas Ladanyi
Hi, iam testing a box with FreeNAS  (BSD) and ZFS. On this box i use virtualized byhve guest as afs server. The box includes SAS drives (12G/s) on HBA (12G/s). I created some vice partitions for the afs server guest and connect them with ahci. If For ZFS pool which contains the vice partitions:

[OpenAFS] rxperf

2019-03-07 Thread Andreas Ladanyi
Hi, i want to test rx performance with rxperf. Where can i get rxperf ? I cant find it in the openafs packages on ubuntu / centos. rxdebug ist available. regards, Andreas ___ OpenAFS-info mailing list OpenAFS-info@openafs.org

[OpenAFS] server crash / moving volumes without vos move

2018-12-17 Thread Andreas Ladanyi
? regards, Andreas -- Karlsruher Institut für Technologie (KIT) Fakultät für Informatik ATIS – Abteilung Technische Infrastruktur Dipl.-Ing. Andreas Ladanyi - Systemadministrator - Am Fasanengarten 5, Gebäude 50.34, Raum 013 76131 Karlsruhe Telefon: +49 721 608 - 4 3663 Fax: +49 721 608 - 4 6

[OpenAFS] cache manager timeout

2018-11-26 Thread Andreas Ladanyi
Hi, is it possible to adjust the timeout of the cache manager when asking the next CellServDB or afsdb entry when a server listed in CellServDB / afsdb is offline so for example the users dont get a long waiting for ssh login ? regards, Andreas

Re: [OpenAFS] automatic replication of ro volumes

2018-11-12 Thread Andreas Ladanyi
Hi Jeffrey, it is common an openafs admin has to sync an ro volume after something is added to rw volume. This is done by the vos release command. I think its the only way. Are there automatic sync functions in the vol / fs server. The risk of automated volume releases is that the automated

[OpenAFS] automatic replication of ro volumes

2018-11-09 Thread Andreas Ladanyi
Hi, it is common an openafs admin has to sync an ro volume after something is added to rw volume. This is done by the vos release command. I think its the only way. Are there automatic sync functions in the vol / fs server. Andreas ___ OpenAFS-info

Re: [OpenAFS] disk cache read error in CacheItems

2018-10-23 Thread Andreas Ladanyi
Hi Martin, > > Hi ! > > In the last few days we've observed an increasing number of Nodes, > which are no longer be reached and have to be rebooted > > In the /var/log/messages we see a lot of lines with e.g. > > Oct 22 18:48:26 bird858 kernel: afs: disk cache read error in > CacheItems slot 25254

Re: [OpenAFS] OpenAFS Security Releases 1.8.2, 1.6.23 available

2018-10-13 Thread Andreas Ladanyi
Hi Brian, For any other folks using Red Hat – what are you doing for deploying OpenAFS?  Are there any repos out there equivalent to the Ubuntu PPA? https://copr.fedorainfracloud.org/coprs/jsbillings/openafs/packages/ regards, Andy

Re: [OpenAFS] problems with ubuntu 18.04 client

2018-10-05 Thread Andreas Ladanyi
> You need to update your apparmor policy to allow rw access to > /var/cache/openafs/**; accesses are performed by the kernel cache manager > on behalf of all processes and apparmor's view of the credentials do not > line up. MIT's configuration does this as of >

Re: [OpenAFS] problems with ubuntu 18.04 client

2018-10-04 Thread Andreas Ladanyi
Hi, > if i login into the same Computer, the tree /afs/desy.de/user is also > missing for me ... > Does a reboot solve the issue ? Did you use ubuntu 18.04 and afs 1.6 before switching to afs 1.8 ? Are there issues from volumes in the salvager log  ? regards, Andy

Re: [OpenAFS] problems with ubuntu 18.04 client

2018-10-04 Thread Andreas Ladanyi
Hi Martin, > > Hi, again ! > > Shortly after i send this mail to the list, one of the user report > back ... same problemes like before ... :-( > > In an old  terminal (where afs was running well) everyhing seems to be > ok, create files,folder, pwd... etc) but for  every new one terminal > or

Re: [OpenAFS] problems with ubuntu 18.04 client

2018-10-02 Thread Andreas Ladanyi
> We were probably just lucky, or the packages from the 1.8 ppa > http://ppa.launchpad.net/openafs/stable/ubuntu never had the problem. Did you use 1.8.0 from ppa for the clients in the past or did you start at 1.8.2 when switching from 1.6 release ? > > > Greetings, > Gaja Peters > cheers,

Re: [OpenAFS] problems with ubuntu 18.04 client

2018-10-02 Thread Andreas Ladanyi
AFS-info mailing list > OpenAFS-info@openafs.org > https://lists.openafs.org/mailman/listinfo/openafs-info -- Karlsruher Institut für Technologie (KIT) Fakultät für Informatik ATIS – Abteilung Technische Infrastruktur Dipl.-Ing. Andreas Ladanyi - Systemadministrator - Am Fasanengarten

Re: [OpenAFS] volume could not be attached

2018-09-13 Thread Andreas Ladanyi
/09.09:19:45) >> backupDate = 1536512433 (2018/09/09.19:00:33), expirationDate = 0 >> (1970/01/01.01:00:00) >> accessDate = 1536568099 (2018/09/10.10:28:19), updateDate = 1536568099 >> (2018/09/10.10:28:19) >> owner = 29724, accountNumber = 0 >> dayUse = 9473; week

Re: [OpenAFS] volume could not be attached

2018-09-11 Thread Andreas Ladanyi
568099 > (2018/09/10.10:28:19) > owner = 29724, accountNumber = 0 > dayUse = 9473; week = (20149, 14021, 403285, 46815, 88402, 59592, > 32594), dayUseDate = 1536530400 (2018/09/10.00:00:00) > volUpdateCounter = 161079 > > > Andreas > > ______

[OpenAFS] volume could not be attached

2018-09-10 Thread Andreas Ladanyi
Hi, one volume could not be attached. This is not a new created volume. OpenAFS 1.6.22.2 (dafs) / Ubuntu 18.04 vos exa user.name: Volume 536875101 is busy     RWrite: 536875101 Backup: 536875103     number of sites -> 1    server ... partition /vicepa RW Site vos online /

Re: [OpenAFS] Obtaining tokens at login on Ubuntu 18.04

2018-08-17 Thread Andreas Ladanyi
Hi, try to remove the dbus-user-session package and look if it works. Have a look at https://github.com/systemd/systemd/issues/7261 regards, Andy Am 17.08.2018 um 02:41 schrieb Prasad K. Dharmasena: I've installed OpenAFS and pam-afs-session on Ubuntu 18.04 (bionic) via (a) vendor supplied

[OpenAFS] fs newcell / clients CellServDB / adding new db server

2018-06-26 Thread Andreas Ladanyi
Hi Jeffrey, i want to give a little feedback. We finished the job. We bos added and then restarted / startet the pt/vl servers beginning with lowest ip. The new ubik election and syncing works great. We distributed the CellServDB to clients and the execution of "fs newcell"  with ansible. This

Re: [OpenAFS] fs newcell / clients CellServDB / adding new db server

2018-06-18 Thread Andreas Ladanyi
> > The ubik clients do not rank servers based upon IP address. What they > do is: ok. Then maybe i misunderstood the documentation (http://docs.openafs.org/QuickStartUnix/HDRWQ114.html) which tells me the machine with lowest ip is "usually"  elected as the ubik coordinator. I followed the

Re: [OpenAFS] fs newcell / clients CellServDB / adding new db server

2018-06-15 Thread Andreas Ladanyi
Hi Jeffrey, >>> i understand that a change in CellServDB on client does have no effect >>> until reboot. >> The OpenAFS unix cache manager populates the list of location servers >> (vlservers) at startup. The loaded server list can be adjusted via the >> "fs newcell" command at runtime. >> >>

Re: [OpenAFS] Windows 10, KDC not reachable / AFS integrated login failed

2018-06-14 Thread Andreas Ladanyi
Hi Gaja, you are great. Thank you. It works. Andi > Am 30.01.2018 um 14:09 schrieb Andreas Ladanyi: > >> Windows 10 Pro , Auristor AFS client package >> >> When starting the device and before login screen appears the messages >> appears: [snip] >> >>

[OpenAFS] fs newcell / clients CellServDB / adding new db server

2018-06-14 Thread Andreas Ladanyi
> On 6/13/2018 8:06 AM, Andreas Ladanyi wrote: >> Hi, >> >> by reading >> >> http://docs.openafs.org/QuickStartUnix/HDRWQ114.html >> >> and >> >> http://docs.openafs.org/Reference/1/fs_newcell.html >> >> i understand that

[OpenAFS] fs newcell / clients CellServDB / adding new db server

2018-06-13 Thread Andreas Ladanyi
Hi, by reading http://docs.openafs.org/QuickStartUnix/HDRWQ114.html and http://docs.openafs.org/Reference/1/fs_newcell.html i understand that a change in CellServDB on client does have no effect until reboot. So i copied the CellServDB which contain a new db server (and the old db servers)

[OpenAFS] FreeNAS/ZFS and OpenAFS

2018-05-17 Thread Andreas Ladanyi
Hi, i want to ask you if there is an experience of a setup with FreeNAS/ZFS storage and OpenAFS. Do  i need two server boxes. One FreeNAS storage box and one for the OpenAFS daemons and connect them with iscsi ? Is it possible to run the OpenAFS server services in FreeNAS ? (maybe this

[OpenAFS] Windows 10, KDC not reachable / AFS integrated login failed

2018-01-30 Thread Andreas Ladanyi
Hi, Windows 10 Pro , Auristor AFS client package When starting the device and before login screen appears the messages appears: Integrated login failed - unable to reach any KDC in realm ... or AFS integrated login failed before it is possible to enter credentials at windows login box

Re: [OpenAFS] Windows 10, OpenAFS 1.7, heimdal 7.4 kerberos enctype issue

2018-01-22 Thread Andreas Ladanyi
Hi Dirk, > Am 19.01.2018 um 09:28 schrieb Andreas Ladanyi: > >> i try so setup windows 10, heimdal kerberos for windows and network >> idendity manager. > > You don't need all this anymore nowadays. The Auristor installer > <https://www.auristor.com/openafs/client

[OpenAFS] Windows 10, OpenAFS 1.7, heimdal 7.4 kerberos enctype issue

2018-01-19 Thread Andreas Ladanyi
Hi, i try so setup windows 10, heimdal kerberos for windows and network idendity manager. The network idendity manager log tells me this kerberos error code -1765328370 which tells me that enctype is not supported. It seems that i get a kerberos 5 tgt at network idendity manager, but i never

Re: [OpenAFS] Windows 10 Pro and OpenAFS Client

2017-12-11 Thread Andreas Ladanyi
Hi Anders, i dont know enough about driver signing / driver verification at windows and i dont know how you tested. Did you set the system date to some timestamp in the future at 2018 or later ? Is there some other driver verification magic which we couldnt test for failing today ? Andreas >

Re: [OpenAFS] Windows 10 Pro and OpenAFS Client

2017-12-09 Thread Andreas Ladanyi
Hi, On 2017-12-08 13:20, Anders Nordin wrote: Hello, What does this mean exactly? Will it be possible to install the OpenAFS-client after 31.12.2017? Is it just an academic problem? We set a computers BIOS to the future and, installed the OS (non-networked) and then installed the client

Re: [OpenAFS] Windows 10 Pro and OpenAFS Client

2017-12-05 Thread Andreas Ladanyi
Hi, > > But take care, depending on the setup of your windows (secure boot,etc.) > OpenAFS will no more work on windows after 31.12.2017, as the kernel > module has no more a valid signature (in the def. of MS). if i understand the facts correctly i have two options: 1. I use the windows client

Re: [OpenAFS] Windows 10 Pro and OpenAFS Client

2017-11-30 Thread Andreas Ladanyi
Hi Lars, > On 2017-11-29 17:02, Andreas Ladanyi wrote: >> Hi, >> >> what is your experience with Windows 10 Pro and the latest package >> OpenAFS for Windows ? >> >> Is there any special what i have to consider at OpenAFS for Windows >> setup and at

[OpenAFS] Windows 10 Pro and OpenAFS Client

2017-11-29 Thread Andreas Ladanyi
Hi, what is your experience with Windows 10 Pro and the latest package OpenAFS for Windows ? Is there any special what i have to consider at OpenAFS for Windows setup and at daily operating on the client ? Regards, Andreas ___ OpenAFS-info mailing

Re: [OpenAFS] mod_waklog question

2017-07-24 Thread Andreas Ladanyi
Hi Jason, i want to feedback that i found the issue in the past. The problem was that not all subdirectories were set with the AFS apache username and rl permission because i was using "fs sa " instead "find -type d -exec fs sa ". So now it seems to work :-) thanks and regards,

Re: [OpenAFS] mod_waklog question

2017-07-13 Thread Andreas Ladanyi
Hi Jason, i tried out your systemd config as below. I have a CentOS 7 box. k5start and Apache starts. pstree: k5start───httpd───10*[httpd───2*[{httpd}]] less /proc/fs/openafs/unixusers: === UID/PAG Refs States Cell ViceID Tok Set Tok Begin

Re: [OpenAFS] mod_waklog question

2017-07-12 Thread Andreas Ladanyi
Hi Ben, now i only enabled the module in Apache without any directory / location directive which points to the afs filesystem path. For testing. I have a look at error_log and mod_waklog renew the token sometimes a day. > I am far from an expert on mod_waklog (mostly, I just sat through a >

Re: [OpenAFS] mod_waklog question

2017-07-11 Thread Andreas Ladanyi
Hi Jason, > Hi Andreas, > > Getting systemd, apache, and kstart to play nice took a little bit of > work. I have included a sanitized copy of my Apache systemd unit file. > Be sure to modify the ExecStart line to have the correct keytab > location and principal name. > > I have NOT tested this in

Re: [OpenAFS] mod_waklog question

2017-07-11 Thread Andreas Ladanyi
> ​mod_waklog is meant to be used as an .htaccess-style mechanism​ to > let users supply credentials via a web browser so that apache can use > those credentials to access user files. In this case, the apache > process switches between multiple AFS users and the tokens only need > to live for the

[OpenAFS] mod_waklog question

2017-07-03 Thread Andreas Ladanyi
Hi, I test Apache2 with mod_waklog. When will waklog autorenew the ticket/token ? After a duration of time apache is running i get error messages in the apache log that apache cant write to afs path. Maybe this could be because the ticket/token is invalid. I would expect that waklog will renew

Re: [OpenAFS] 1.6.20 pam_afs_session bug ?

2017-04-10 Thread Andreas Ladanyi
Hi, just for info. The suggestion of Dirk for working around the problem by removing the dbus-user-session package removes the issue for first test. Andreas > On Thu, Apr 06, 2017 at 10:05:19AM +0200, Andreas Ladanyi wrote: >> Am 31.03.2017 um 22:18 schrieb Benjamin Kaduk: >>&

Re: [OpenAFS] 1.6.20 pam_afs_session bug ?

2017-04-10 Thread Andreas Ladanyi
Am 07.04.2017 um 05:41 schrieb Benjamin Kaduk: > Hmm, this feels more like systemd fallout, the more I think about > it. (Ubuntu 16.10 is on systemd now, right?) yes. > It seems like a usetul debugging step would be to determin the > process hierarchy when the screensaver is calling into >

Re: [OpenAFS] 1.6.20 pam_afs_session bug ?

2017-04-07 Thread Andreas Ladanyi
Am 07.04.2017 um 06:26 schrieb Dirk Heinrichs: > On 07.04.2017 05:41, Benjamin Kaduk wrote: > >> Hmm, this feels more like systemd fallout, the more I think about >> it. (Ubuntu 16.10 is on systemd now, right?) > > Now that you mention it: I've also had some problem with lost tokens > on Debian

Re: [OpenAFS] 1.6.20 pam_afs_session bug ?

2017-04-06 Thread Andreas Ladanyi
Am 31.03.2017 um 22:18 schrieb Benjamin Kaduk: > On Thu, Mar 30, 2017 at 03:53:24PM +0200, Andreas Ladanyi wrote: >> Hi guys, >> >> i tested: >> >> Ubuntu 16.10, Gnome, Kernel 4.8 >> >> current OpenAFS 1.6.20 from ppa. >> >> After relogin

Re: [OpenAFS] 1.6.20 pam_afs_session bug ?

2017-03-31 Thread Andreas Ladanyi
n Thu, Mar 30, 2017 at 03:53:24PM +0200, Andreas Ladanyi wrote: >> Hi guys, >> >> i tested: >> >> Ubuntu 16.10, Gnome, Kernel 4.8 >> >> current OpenAFS 1.6.20 from ppa. >> >> After relogin from screensaver dialog the kerberos

[OpenAFS] 1.6.20 pam_afs_session bug ?

2017-03-30 Thread Andreas Ladanyi
Hi guys, i tested: Ubuntu 16.10, Gnome, Kernel 4.8 current OpenAFS 1.6.20 from ppa. After relogin from screensaver dialog the kerberos tgt and afs service ticket are renewed but the afs token isnt renewed. There is no "always_aklog" flag at pam_afs_session.so line in pam common-auth file. If

Re: [OpenAFS] Connection timed out - problem with cache manager?

2016-11-30 Thread Andreas Ladanyi
Iam not sure. I dont know your kernel version. Maybe the reason is the old afs client module version. There was a problem with the splice kernel function since kernel 4.4 and backports. We are using the openafs ppa repository (https://launchpad.net/~openafs/+archive/ubuntu/stable) on Ubuntu

Re: [OpenAFS] Moving volumes between different cell and different realm names

2016-10-11 Thread Andreas Ladanyi
Am 10.10.2016 um 17:24 schrieb Jeffrey Altman: >>> And you need to install the keys from Cell B onto the fileserver. >> The old afs server doesnt support rxkad, only single des. >> The new afs server works with rxkad. >> >> Is this a problem ? > I believe you meant to say the new afs server uses

Re: [OpenAFS] Moving volumes between different cell and different realm names

2016-10-10 Thread Andreas Ladanyi
Am 07.10.2016 um 22:58 schrieb Jeffrey Altman: > >> >> I read the thread: >> https://lists.openafs.org/pipermail/openafs-info/2009-March/031004.html >> >> So if i understand the thread and man pages correctly i could do the >> following steps: > Step 0. Shutdown all of the AFS services on the

Re: [OpenAFS] /afs is empty

2016-10-08 Thread Andreas Ladanyi
On 7 Oct 2016, at 9:48, Andreas Ladanyi wrote: Hi, my problem on one afs client is that /afs is empty. Ubuntu 12.04: 3.2.0-109-generic, OpenAFS 1.6.18.3-1 from PPA openafs-client restart doesnt help. ps ax | grep afsd: 1232 pts/0S+ 0:00 grep afsd 27942 ?Ss 0:00 /sbin

Re: [OpenAFS] /afs is empty

2016-10-07 Thread Andreas Ladanyi
Hi, i rebooted this system and now kernel 3.2.0-110-generic is running. Same issue. Andreas Hi, my problem on one afs client is that /afs is empty. Ubuntu 12.04: 3.2.0-109-generic, OpenAFS 1.6.18.3-1 from PPA openafs-client restart doesnt help. ps ax | grep afsd: 1232 pts/0S+

Re: [OpenAFS] /afs is empty

2016-10-07 Thread Andreas Ladanyi
Am 07.10.2016 um 15:56 schrieb Stephan Wiesand: On 7 Oct 2016, at 15:48, Andreas Ladanyi <andreas.lada...@kit.edu> wrote: my problem on one afs client is that /afs is empty. Is AFS actually mounted on /afs ? - Stephan mount: AFS on /afs type a

Re: [OpenAFS] Problem restore / mount volume

2016-06-27 Thread Andreas Ladanyi
Hi, i want to thank you for answer and feedback that restoring and mounting works at another system Ubuntu 12.04 , kernel 3.2.0, afs-client 1.6.17. regards, Andreas smime.p7s Description: S/MIME Cryptographic Signature

Re: [OpenAFS] Problem restore / mount volume

2016-06-21 Thread Andreas Ladanyi
Hi Kostas, > Hi, > > On my site, such behaviour by ls was the result of client AFSd cache > being trashed, eg by cache partition running out of space. Maybe worth > checking it out. fs getcacheparms AFS using 1187 of the cache's available 10 1K byte blocks. Andreas smime.p7s Description:

Re: [OpenAFS] Problem restore / mount volume

2016-06-21 Thread Andreas Ladanyi
Hi, > By any chance was the mount point created before the "user.test" volume > was restored or was the volume restored, removed, and restored again? No. > > I'm thinking the client might have cached a volume id for "user.test" > that is no longer valid. If that is the case, try > > fs

Re: [OpenAFS] Problem restore / mount volume

2016-06-21 Thread Andreas Ladanyi
> What does the log of the afs fileserver tell you, on which the volume > resist? On afs server: FileLog: fssync: breaking all call backs for volume 536875364 VolserLog: Volser: CreateVolume: volume 536875364 (user.test) created > Looks like the user.test volume is not online. vos examine

Re: [OpenAFS] Problem restore / mount volume

2016-06-21 Thread Andreas Ladanyi
> Try to salvage that volume/partition. Ok. No change. smime.p7s Description: S/MIME Cryptographic Signature

[OpenAFS] Problem restore / mount volume

2016-06-21 Thread Andreas Ladanyi
Hi, vos restore -server xyz -partition a -name user.test -file /san/xyz_full_backup_volume vos listvldb user.test: user.test RWrite: 536875364 number of sites -> 1 server .. partition /vicepa RW Site "fs mkmount -dir user.test -vol user.test" in my directory in afs rw path.

Re: [OpenAFS] failed to write to cache items off

2016-05-19 Thread Andreas Ladanyi
> What filesystem is used for the disk cache? We use a diskcache on ext4 filesystem on SSD drive. > > -Ben > > On Wed, 18 May 2016, Andreas Ladanyi wrote: > >> Hi, >> >> i found this error in syslog of an ubuntu 14.04.4 client, openafs-client >> fr

[OpenAFS] failed to write to cache items off

2016-05-18 Thread Andreas Ladanyi
Hi, i found this error in syslog of an ubuntu 14.04.4 client, openafs-client from ppa archive: afs: failed to write to CacheItems off 1997620 code -4/80 openafs: assertion failed: afs_WriteDCache(tdc, 1) == 0, file:

Re: [OpenAFS] Support for Mac OSX 10.10 ( El capitan )

2016-04-11 Thread Andreas Ladanyi
Hi, > Hi all, > > since I cannot find a release of openAFS for El Capitan, even not for > Yosemite. I was wondering whether OS/X is still supported or is it > abandoned. > Can someone give some more insight in this, since it gives some doubt > in our present idea of transferring the company file

Re: [OpenAFS] openafs client crashs after ubuntu kernel update

2016-04-07 Thread Andreas Ladanyi
Hi Ben, > On Tue, 5 Apr 2016, Andreas Ladanyi wrote: > >> Hi, >> >> openafs client tells me unable to create file / connection timeout >> messages. >> >> It seems that this behavior appear when installing the latest kernel >> version of Ubuntu 15.10

[OpenAFS] openafs client crashs after ubuntu kernel update

2016-04-05 Thread Andreas Ladanyi
Hi, openafs client tells me unable to create file / connection timeout messages. It seems that this behavior appear when installing the latest kernel version of Ubuntu 15.10 and 14.04 LTS and maybe soon in 12.04 LTS (which i didnt upgrade yet). This problem is for example with ubuntu kernel

Re: [OpenAFS] Migrating Kerberos/LDAP to Samba DC

2015-11-13 Thread Andreas Ladanyi
Hi Dirk, you have to install some software packages on windows to get windows working as an AFS client. You should read this webpage. I think this will answer your questions for windows and AFS. http://openafs.org/windows.html I know that it is possible to get AFS working with an MS AD

Re: [OpenAFS] Apache2 and OpenAFS

2015-10-12 Thread Andreas Ladanyi
Am 10.10.2015 um 02:26 schrieb Måns Nilsson: > Subject: Re: [OpenAFS] Apache2 and OpenAFS Date: Thu, Oct 08, 2015 at > 04:49:16PM +0200 Quoting Andreas Ladanyi (andreas.lada...@kit.edu): >> I found the possibility in Apache 2 to work with the mod_waklog module >> which does

Re: [OpenAFS] Apache2 and OpenAFS

2015-10-08 Thread Andreas Ladanyi
I found the possibility in Apache 2 to work with the mod_waklog module which does the kinit / aklog magic: http://www.modwaklog.org/ Following the instructions on the following blog works: https://blog.inf.ed.ac.uk/toby/2009/02/04/serving-afs-space-using-apache-and-mod_waklog regards, Andreas

Re: [OpenAFS] Apache2 and OpenAFS

2015-10-08 Thread Andreas Ladanyi
Hi Harald, thank you for your details. We use MIT kerberos in FreeIPA. The kinit doesnt have a --afslog option. > We run our web server authenticated from a keytab. The keytab contains > > # /usr/heimdal/sbin/ktutil --keytab=/etc/krb5.keytab.web-daemon list > Vno Type

[OpenAFS] Apache2 and OpenAFS

2015-10-07 Thread Andreas Ladanyi
Hi, i have OpenAFS volumes / mounts which contains Apache web content. My question is which is the easiest way to get tgt/token/PAG for the apache user so the apache could access to the web content in the AFS volume. I read that one way is to use pagsh to get an authentification object (pag)

Re: [OpenAFS] CellServDB priority of entries

2015-08-12 Thread Andreas Ladanyi
Hi Stephan, On 11 Aug 2015, at 09:02, Andreas Ladanyi andreas.lada...@kit.edu wrote: i dont know if i remember correctly, but think i red something about priorities for DB server entries listed in the file CellServDB in the past. I couldnt find something in the manpage cellservdb. I think

[OpenAFS] CellServDB priority of entries

2015-08-11 Thread Andreas Ladanyi
Hi, i dont know if i remember correctly, but think i red something about priorities for DB server entries listed in the file CellServDB in the past. I couldnt find something in the manpage cellservdb. I think the priority is given by the ip adress, isnt it ? cheers, Andy smime.p7s

Re: [OpenAFS] afsd: Error calling AFSOP_CACHEINODE: not configured

2015-07-02 Thread Andreas Ladanyi
and the openafs kernel module or the cache ? Now i could see my cell in /afs and could create volumes and set file system rights. Thanks to all, Andy On Thu, 2015-07-02 at 15:42 +0200, Andreas Ladanyi wrote: fs la /afs/ fs: Invalid argument; it is possible that /afs/ is not in AFS. fs mkmount /afs

[OpenAFS] afsd: Error calling AFSOP_CACHEINODE: not configured

2015-07-01 Thread Andreas Ladanyi
Hi, openafs 1.6.11.1 / Centos 7 SELinux=permissive iptables is empty bos server runs by systemd script. bos status server: Instance vlserver, currently running normally. Instance ptserver, currently running normally. Instance dafs, currently running normally. Auxiliary status is: file server

Re: [OpenAFS] bos server instances doesnt come up

2015-06-29 Thread Andreas Ladanyi
, Andreas Ladanyi wrote: PtLog: ptserver: file not found when processing dbase Ubik init failed ptserver: running unauthenticated VLLog: = vlserver: Ubik init failed: file not found when processing dbase The database file cannot be created or opened. How was OpenAFS installed

Re: [OpenAFS] bos server instances doesnt come up

2015-06-29 Thread Andreas Ladanyi
Please answer Jeffrey's questions, and we may be able to help. I answered Jeffreys questions: How was OpenAFS installed and on which OS/version? I use the openafs 1.6.11.1 srpm package from the openafs website. I built my own binary rpms from this srpm package and installed it. The OS is

Re: [OpenAFS] Uninstall OpenAFS after make install

2015-06-29 Thread Andreas Ladanyi
On Centos 7: yum-builddep openafs.spec works. rpmbuild -ba openafs.spec exits with 0. I got my rpm packages. On Fedora 20: I add a yum repository file which points to the 1.6.10 rpm Fedora 20 packages at openafs.org yum install produce the following output with some errors and bad exit:

Re: [OpenAFS] bos server instances doesnt come up

2015-06-25 Thread Andreas Ladanyi
, Andreas Ladanyi wrote: PtLog: ptserver: file not found when processing dbase Ubik init failed ptserver: running unauthenticated VLLog: = vlserver: Ubik init failed: file not found when processing dbase The database file cannot be created or opened. How was OpenAFS installed

Re: [OpenAFS] bos server instances doesnt come up

2015-06-25 Thread Andreas Ladanyi
? regards, Andy -- Karlsruher Institut für Technologie (KIT) Fakultät für Informatik ATIS – Abteilung Technische Infrastruktur Dipl.-Ing. Andreas Ladanyi - Systemadministrator - Am Fasanengarten 5, Gebäude 50.34, Raum 013 76131 Karlsruhe Telefon: +49 721 608 - 4 3663 Fax: +49 721 608 - 4 6699 E

[OpenAFS] bos server instances doesnt come up

2015-06-25 Thread Andreas Ladanyi
Hi, i installed Openafs 1.6.11.1. The pt / vl / bu instances dont come up. bos status FQDN server -noauth bos: running unauthenticated Instance buserver, temporarily disabled, stopped for too many errors, currently starting up. Instance ptserver, temporarily disabled, stopped for too many

Re: [OpenAFS] Uninstall OpenAFS after make install

2015-06-22 Thread Andreas Ladanyi
On Fedora 20: I add a yum repository file which points to the 1.6.10 rpm Fedora 20 packages at openafs.org yum install produce the following output with some errors and bad exit: 1.6.10 is too old for that kernel, you need at least 1.6.11. NB F20 is EOL. ok. Thank you. Iam wondering

Re: [OpenAFS] Uninstall OpenAFS after make install

2015-06-22 Thread Andreas Ladanyi
Hi Ben, iam using Centos 7 and openafs 1.6.11.1 from source tarball. In general when a packaged version of something is available, it should be preferred over a source build, since the packaging system tracks which files are installed by the package and should allow for cleaner uninstalls.

[OpenAFS] Uninstall OpenAFS after make install

2015-06-18 Thread Andreas Ladanyi
Hi, i cant see a make uninstall / remove target to uninstall OpenAFS after make install procedure. Is there a script or something other secret how the removing of installed files is possible ? iam using Centos 7 and openafs 1.6.11.1 from source tarball. Andy

[OpenAFS] vos syncvldb

2015-05-13 Thread Andreas Ladanyi
Hi, if i call the command on server a (a which isnt the fileserver with the volumes) as root: vos syncvldb server b (b which is the filesserver with volumes) i get the following messages. There are a lot of more volumes listed but the list was too long so i cut the message text: Could not

Re: [OpenAFS] Re: AFS + CrossRealm + FreeIPA + Migration

2014-11-18 Thread Andreas Ladanyi
Hi, thank you for your efforts. In none of the above cases the afs service ticket work correctly although In the 1. case i have a des-cbc-crc key. I cant access my user directory in afs. I get a permission denied error. Yes, and that is expected. I suppose I have not been clear; you have two

Re: [OpenAFS] Re: AFS + CrossRealm + FreeIPA + Migration

2014-11-17 Thread Andreas Ladanyi
On Tue, 11 Nov 2014 09:28:35 +0100 Andreas Ladanyi andreas.lada...@kit.edu wrote: No the token from aklog doesnt work fine. I could only list the user directories (name of the users). I could not enter the user directories. I couldnt enter my own directory. The AFS ID of the token is ok

Re: [OpenAFS] Re: AFS + CrossRealm + FreeIPA + Migration

2014-11-11 Thread Andreas Ladanyi
On Mon, 10 Nov 2014 10:09:54 +0100 Andreas Ladanyi andreas.lada...@kit.edu wrote: Now aklog works and i can get a AFS token. Why are all this keys important for aklog ? Or which key exeptly the DES key is important ? That is indeed a bit puzzling; it's possible ipa-getkeytab does something

Re: [OpenAFS] Re: AFS + CrossRealm + FreeIPA + Migration

2014-11-11 Thread Andreas Ladanyi
old server: MIT Kerberos 5 - Realm A What version? Version 1.9.2 from OpenCSW new server: FreeIPA 3.3 I don't suppose you know what version of MIT krb5 this is based on? Version : 1.11.5 Release : 11.fc20 Service principals: afs/FQDN of the old Server with

Re: [OpenAFS] Re: AFS + CrossRealm + FreeIPA + Migration

2014-11-10 Thread Andreas Ladanyi
Hi, On Fri, 07 Nov 2014 16:05:11 +0100 Andreas Ladanyi andreas.lada...@kit.edu wrote: sorry i didnt told that. In FreeIPA you must enable the DES salttype. I enabled the des-cbc-crc:normal and des-cbc-crc:v4. I'm not too familiar with FreeIPA, but usually you need to enable weak enctypes

[OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Andreas Ladanyi
Hi, i want to migrate my old Server System to a new environment. The Posix Users+Groups are migrated from the old LDAP system to the new FreeIPA LDAP system. I have the following situation: old server: MIT Kerberos 5 - Realm A OpenLDAP without Kerberos schemata OpenAFS Server 1.6 -

  1   2   >