10.07.2015 Views

Expert Oracle Exadata - Parent Directory

Expert Oracle Exadata - Parent Directory

Expert Oracle Exadata - Parent Directory

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 14 STORAGE LAYOUTby the ASM instance. In the earlier example Customer-A’s environment coulduse database-scoped security to separate database environments from oneanother within its half rack configuration.Cell Security TerminologyBefore we get too far along, let’s take a look at some of the new terminology specific to <strong>Exadata</strong>’s cellsecurity.Storage Realm: Grid disks that share a common security domain are referred toas a storage realm.Security Key: A security key is used to authenticate ASM and database clients tothe storage realm. It is also used for securing messages sent between the storagecells and the ASM and database clients. The security key is created using theCellCLI command create key. The key is then assigned to grid disks using theCellCLI assign key command.cellkey.ora: The cellkey.ora file is stored on the database servers. Onecellkey.ora file is created for ASM-scoped security and another cellkey.orafile is created for each database requiring database-scoped security. Thecellkey.ora files are used to identify security keys, the storage realm, and theunique name of the ASM cluster or database.Table 14-7 shows the definitions for the fields in the cellkey.ora file.Table 14-7. The Contents of the Cellkey.ora FileFieldkeyasmrealmDescriptionThis is the security key generated at the storage cell with the create key command. This keyis used to authenticate the ASM cluster and database to the storage realm.For ASM-scoped security, this value must match the key assigned to the ASM cluster usingthe assign key command.For database-scoped security this value must match the security key assigned to thedatabase using the assign key command.This is the unique name of the ASM cluster found in the DB_UNIQUE_NAME parameter of theASM instance. It is used to associate the ASM cluster with the availableTo attribute of thegrid disks in the storage realm. Grid disks are assigned this value using the CellCLI creategriddisk and alter grid disk commands.This field is optional. If used, the value must match the realmName attribute assigned to thestorage cells using the CellCLI command alter cell realmName.488

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!