23.07.2014 Views

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

Lustre 1.6 Operations Manual

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11.2.2.7 Authenticating Normal Users<br />

On client nodes, non-root users must use kinit to access <strong>Lustre</strong> (just like other<br />

Kerberized applications). kinit is used to obtain and cache Kerberos ticket-granting<br />

tickets. Two requirements to authenticating users:<br />

■<br />

■<br />

Before kinit is run, the user must be registered as a principal with the Kerberos<br />

server (the Key Distribution Center or KDC). In KDC, the username is noted as<br />

username@REALM.<br />

The client and MDT nodes should have the same user database.<br />

To destroy the established security contexts before logging out, run lfs flushctx:<br />

# lfs flushctx [-k]<br />

Here -k also means destroy the on-disk Kerberos credential cache. It is equivalent to<br />

kdestroy. Otherwise, it only destroys established contexts in the <strong>Lustre</strong> kernel.<br />

11-16 <strong>Lustre</strong> <strong>1.6</strong> <strong>Operations</strong> <strong>Manual</strong> • September 2008

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!