23.07.2014 Views

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11.2 <strong>Lustre</strong> Setup with Kerberos<br />

Setting up <strong>Lustre</strong> with Kerberos can provide advanced security protections for the<br />

<strong>Lustre</strong> network. Broadly, Kerberos offers three types of benefit:<br />

■<br />

■<br />

■<br />

Allows <strong>Lustre</strong> connection peers (MDS, OSS and clients) to authenticate one<br />

another.<br />

Protects the integrity of the PTLRPC message from being modified during<br />

network transfer.<br />

Protects the privacy of the PTLRPC message from being eavesdropped during<br />

network transfer.<br />

Kerberos uses the “kernel keyring” client upcall mechanism.<br />

11.2.1 Configuring Kerberos for <strong>Lustre</strong><br />

This section describes supported Kerberos distributions and how to set up and<br />

configure Kerberos on <strong>Lustre</strong>.<br />

11.2.1.1 Kerberos Distributions Supported on <strong>Lustre</strong><br />

<strong>Lustre</strong> supports the following Kerberos distributions:<br />

■<br />

■<br />

■<br />

■<br />

MIT Kerberos 1.3.x<br />

MIT Kerberos 1.4.x<br />

MIT Kerberos 1.5.x<br />

MIT Kerberos <strong>1.6</strong> (not yet verified)<br />

On a number of operating systems, the Kerberos RPMs are installed when the<br />

operating system is first installed. To determine if Kerberos RPMs are installed on<br />

your OS, run:<br />

# rpm -qa | grep krb<br />

If Kerberos is installed, the command returns a list like this:<br />

krb5-devel-1.4.3-5.1<br />

krb5-libs-1.4.3-5.1<br />

krb5-workstation-1.4.3-5.1<br />

pam_krb5-2.2.6-2.2<br />

11-2 <strong>Lustre</strong> <strong>1.6</strong> <strong>Operations</strong> <strong>Manual</strong> • September 2008

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!