29.01.2013 Views

GPFS: Administration and Programming Reference - IRA Home

GPFS: Administration and Programming Reference - IRA Home

GPFS: Administration and Programming Reference - IRA Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

mmauth Comm<strong>and</strong><br />

Name<br />

mmauth – Manages secure access to <strong>GPFS</strong> file systems.<br />

Synopsis<br />

mmauth genkey {new | commit}<br />

Or,<br />

mmauth add RemoteClusterName -k KeyFile -l CipherList<br />

Or,<br />

mmauth update RemoteClusterName -C NewClusterName -k KeyFile [-l CipherList]<br />

Or,<br />

mmauth delete {RemoteClusterName | all }<br />

Or,<br />

mmauth grant {RemoteClusterName | all } -f { Device | all } [-a {rw | ro} ] [-r {uid:gid | no}]<br />

Or,<br />

mmauth deny {RemoteClusterName | all } -f { Device | all }<br />

Or,<br />

mmauth show [RemoteClusterName | all]<br />

Description<br />

The mmauth comm<strong>and</strong> prepares a cluster to grant secure access to file systems owned locally. The<br />

mmauth comm<strong>and</strong> also prepares a cluster to receive secure access to file systems owned by another<br />

cluster. Use the mmauth comm<strong>and</strong> to generate a public/private key pair for the local cluster. A<br />

public/private key pair must be generated on both the cluster owning the file system <strong>and</strong> the cluster<br />

desiring access to the file system. The administrators of the clusters are responsible for exchanging the<br />

public portion of the public/private key pair. Use the mmauth comm<strong>and</strong> to add or delete permission for a<br />

cluster to mount file systems owned by the local cluster.<br />

When a cluster generates a new public/private key pair, administrators of clusters participating in remote<br />

file system mounts are responsible for exchanging their respective public key file /var/mmfs/ssl/<br />

id_rsa.pub generated by this comm<strong>and</strong>.<br />

The administrator of a cluster desiring to mount a file system from another cluster must provide the<br />

received key file as input to the mmremotecluster comm<strong>and</strong>. The administrator of a cluster allowing<br />

another cluster to mount a file system must provide the received key file to the mmauth comm<strong>and</strong>.<br />

The keyword appearing after mmauth determines which action is performed:<br />

add Adds a cluster <strong>and</strong> its associated public key to the list of clusters authorized to connect to this<br />

cluster for the purpose of mounting file systems owned by this cluster.<br />

Chapter 8. <strong>GPFS</strong> comm<strong>and</strong>s 73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!