23.07.2014 Views

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

General Installation Notes<br />

■<br />

■<br />

■<br />

The host.domain should be the FQDN in your network. Otherwise, the server may<br />

not recognize any GSS request.<br />

To install a keytab entry on a node, use the ktutil 1 utility.<br />

<strong>Lustre</strong> supports these encryption types for MIT Kerberos 5, v1.4 and higher:<br />

■<br />

■<br />

■<br />

■<br />

■<br />

des-cbc-crc<br />

des-cbc-md5<br />

des3-hmac-sha1<br />

aes128-cts<br />

aes256-cts<br />

■ arcfour-hmac-md5<br />

For MIT Kerberos 1.3.x, only des-cbc-md5 works because of a known issue<br />

between libgssapi and the Kerberos library.<br />

Note – The encryption type (or enctype) is an identifier specifying the encryption,<br />

mode and hash algorithms. Each Kerberos key has an associated enctype that<br />

identifies the cryptographic algorithm and mode used when performing<br />

cryptographic operations with the key. It is important that the enctypes requested by<br />

the client are actually supported on the system hosting the client. This is the case if<br />

the defaults that control enctypes are not overridden.<br />

1. Kerberos keytab file maintenance utility.<br />

Chapter 11 Kerberos 11-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!