<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.old.lustre.org/index.php?action=history&amp;feed=atom&amp;title=GSS_%2F_Kerberos</id>
	<title>GSS / Kerberos - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.old.lustre.org/index.php?action=history&amp;feed=atom&amp;title=GSS_%2F_Kerberos"/>
	<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;action=history"/>
	<updated>2026-04-09T00:37:10Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.7</generator>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=13218&amp;oldid=prev</id>
		<title>Adilger: Undo revision 12284 by Delphia Mulcahey (talk)</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=13218&amp;oldid=prev"/>
		<updated>2013-04-12T16:26:46Z</updated>

		<summary type="html">&lt;p&gt;Undo revision 12284 by &lt;a href=&quot;/index.php?title=Special:Contributions/Delphia_Mulcahey&quot; title=&quot;Special:Contributions/Delphia Mulcahey&quot;&gt;Delphia Mulcahey&lt;/a&gt; (&lt;a href=&quot;/index.php?title=User_talk:Delphia_Mulcahey&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;User talk:Delphia Mulcahey (page does not exist)&quot;&gt;talk&lt;/a&gt;)&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 09:26, 12 April 2013&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l43&quot;&gt;Line 43:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 43:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; addprinc -randkey lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; addprinc -randkey lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Install the keytab on the MDS node. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; [http://www.slow-computer-solutions.org/  fix my slow computer]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Install the keytab on the MDS node.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3. Configure OSS node:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3. Configure OSS node:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Adilger</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=12284&amp;oldid=prev</id>
		<title>Delphia Mulcahey: /* Configuration */</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=12284&amp;oldid=prev"/>
		<updated>2011-04-06T13:33:02Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Configuration&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 06:33, 6 April 2011&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l43&quot;&gt;Line 43:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 43:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; addprinc -randkey lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; addprinc -randkey lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_mds/mds_host.domain@REALM&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Install the keytab on the MDS node.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Install the keytab on the MDS node. &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; [http://www.slow-computer-solutions.org/  fix my slow computer]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3. Configure OSS node:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3. Configure OSS node:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Delphia Mulcahey</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=12261&amp;oldid=prev</id>
		<title>Sbarthel: /* Secure MGC - MGS connection */</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=12261&amp;oldid=prev"/>
		<updated>2011-01-20T18:41:13Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Secure MGC - MGS connection&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:41, 20 January 2011&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l187&quot;&gt;Line 187:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 187:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;By default, MGS accept RPCs with any flavor. But sysad can configure MGS to only accept certain flavor from certain network. The syntax is similar but with target as a special &amp;quot;_mgs&amp;quot;:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;By default, MGS accept RPCs with any flavor. But sysad can configure MGS to only accept certain flavor from certain network. The syntax is similar but with target as a special &amp;quot;_mgs&amp;quot;:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  mgs&amp;gt; lctl conf_param _mgs.srpc.flavor.&amp;lt;network&amp;gt;=flavor&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  mgs&amp;gt; lctl conf_param _mgs.srpc.flavor.&amp;lt;network&amp;gt;=flavor&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;NOTE: apply inappropriate flavor may lead to a node never be able to communicate with MGS until restart. So use it carefully.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;#039;&amp;#039;&amp;#039;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;NOTE:&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;#039;&amp;#039;&amp;#039; &lt;/ins&gt;apply inappropriate flavor may lead to a node never be able to communicate with MGS until restart. So use it carefully.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Cross-Realms Authentication ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Cross-Realms Authentication ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Due to idmap functionality is missing, we don&amp;#039;t support cross-realm authentication currently.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Due to idmap functionality is missing, we don&amp;#039;t support cross-realm authentication currently.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sbarthel</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11860&amp;oldid=prev</id>
		<title>Ericm: /* Setting Security Flavors */</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11860&amp;oldid=prev"/>
		<updated>2010-09-07T21:39:32Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Setting Security Flavors&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 14:39, 7 September 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l133&quot;&gt;Line 133:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 133:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If there a existing rule of &amp;lt;spec&amp;gt; part, it will overwritten.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;If there a existing rule of &amp;lt;spec&amp;gt; part, it will overwritten.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;To delete a rule&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, just leave &amp;lt;flavor&amp;gt; part be empty&lt;/del&gt;:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;To delete a rule:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  mgs&amp;gt; lctl conf_param &amp;lt;spec&amp;gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  mgs&amp;gt; lctl conf_param &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-d &lt;/ins&gt;&amp;lt;spec&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Current rule set could be obtained by:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Current rule set could be obtained by:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ericm</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11782&amp;oldid=prev</id>
		<title>Sbarthel: /* required packages */</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11782&amp;oldid=prev"/>
		<updated>2010-06-09T18:13:54Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;required packages&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:13, 9 June 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l68&quot;&gt;Line 68:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 68:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*For MIT Kerberos 1.3.x, only &amp;#039;&amp;#039;des-cbc-md5&amp;#039;&amp;#039; works because a known issue between libgssapi and Kerberos library.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*For MIT Kerberos 1.3.x, only &amp;#039;&amp;#039;des-cbc-md5&amp;#039;&amp;#039; works because a known issue between libgssapi and Kerberos library.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;required &lt;/del&gt;packages ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Required &lt;/ins&gt;packages ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Every node should have follow packages installed:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Every node should have follow packages installed:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;libgssapi&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; version 0.10 or higher. Some newer Linux distributions already come with it. If not, build &amp;amp; install from source: http://www.citi.umich.edu/projects/nfsv4/linux/libgssapi/libgssapi-0.11.tar.gz&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;libgssapi&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; version 0.10 or higher. Some newer Linux distributions already come with it. If not, build &amp;amp; install from source: http://www.citi.umich.edu/projects/nfsv4/linux/libgssapi/libgssapi-0.11.tar.gz&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sbarthel</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11781&amp;oldid=prev</id>
		<title>Sbarthel at 18:11, 9 June 2010</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11781&amp;oldid=prev"/>
		<updated>2010-06-09T18:11:09Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 11:11, 9 June 2010&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Note: &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;only &lt;/del&gt;HEAD branch &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;support &lt;/del&gt;GSS/Kerberos functionality&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, and it&amp;#039;s &lt;/del&gt;subject to changes at any time, backward compatibility is NOT guaranteed.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;#039;&amp;#039;&amp;#039;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Note:&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;#039;&amp;#039;&amp;#039; Only the &lt;/ins&gt;HEAD branch &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;supports &lt;/ins&gt;GSS/Kerberos functionality&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;. It is &lt;/ins&gt;subject to changes at any time, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and &lt;/ins&gt;backward compatibility is NOT guaranteed.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Kerberos Lustre Setup =&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;= Kerberos Lustre Setup =&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Sbarthel</name></author>
	</entry>
	<entry>
		<id>http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11780&amp;oldid=prev</id>
		<title>Sbarthel: Created page with &#039;&#039;&#039;&#039;Note: only HEAD branch support GSS/Kerberos functionality, and it&#039;s subject to changes at any time, backward compatibility is NOT guaranteed.&#039;&#039;&#039;  = Kerberos Lustre Setup =  ==...&#039;</title>
		<link rel="alternate" type="text/html" href="http://wiki.old.lustre.org/index.php?title=GSS_/_Kerberos&amp;diff=11780&amp;oldid=prev"/>
		<updated>2010-06-09T18:10:26Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;#039;&amp;#039;&amp;#039;&amp;#039;Note: only HEAD branch support GSS/Kerberos functionality, and it&amp;#039;s subject to changes at any time, backward compatibility is NOT guaranteed.&amp;#039;&amp;#039;&amp;#039;  = Kerberos Lustre Setup =  ==...&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Note: only HEAD branch support GSS/Kerberos functionality, and it&amp;#039;s subject to changes at any time, backward compatibility is NOT guaranteed.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
= Kerberos Lustre Setup =&lt;br /&gt;
&lt;br /&gt;
== Security Flavor ==&lt;br /&gt;
A security flavor is a string to describe what kind authentication and data transformation be performed upon a PTLRPC connection. It covers both RPC message and BULK data.&lt;br /&gt;
&lt;br /&gt;
The support flavors are described in following table:&lt;br /&gt;
&lt;br /&gt;
{|border=1 cellspacing=0&lt;br /&gt;
|bgcolor=#E6E6E6| Base Flavor||bgcolor= 	#E6E6E6|Authentication||bgcolor=#E6E6E6|RPC Message Protection||bgcolor=#E6E6E6|Bulk Data Protection||bgcolor=#E6E6E6|Notes&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;null&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||N/A ||N/A ||N/A &amp;#039;&amp;#039;&amp;#039;[*]&amp;#039;&amp;#039;&amp;#039; ||Almost no performance overhead. The on-wire rpc format is compatible with old versions (1.4.x, 1.6.x, 1.8.x).&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;plain&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||N/A ||N/A ||checksum||(obsolete)&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;krb5n&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||GSS/Kerberos5 ||null||checksum (adler32)||No protection of rpc message, adler32 checksum protection of bulk data, light performance overhead.&lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;krb5a&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||GSS/Kerberos5 ||partly integrity (krb5)||checksum (adler32)||Only header of rpc message is integrity protected, adler32 checksum protection of bulk data, more performance overhead compare to krb5n. &lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;krb5i&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||GSS/Kerberos5 ||integrity (krb5)||integrity (krb5)||transformation algorithm is determined by actual Kerberos algorithms in use; Heavy performance penalty. &lt;br /&gt;
|-&lt;br /&gt;
|&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;krb5p&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;||GSS/Kerberos5 ||privacy (krb5)||privacy (krb5)||transformation privacy protection algorithm is determined by actual Kerberos algorithms in use; The heaviest performance penalty.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;[*]&amp;#039;&amp;#039;&amp;#039; In Lustre 1.4 and 1.6 it is possible to enable bulk data checksumming to provide integrity checking using CRC32.  In 1.6.5 this is expected to be the default behaviour, using the Adler32 mechanism by default (lower CPU overhead than CRC32).&lt;br /&gt;
&lt;br /&gt;
In the future, we may want to support customize flavor to some extend. For example, allow set different flavors for RPC message and bulk data.&lt;br /&gt;
&lt;br /&gt;
== Kerberos Setup ==&lt;br /&gt;
=== Distribution ===&lt;br /&gt;
* We only support MIT Kerberos 5, version from 1.3.x to latest 1.6.x.&lt;br /&gt;
&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
1. Configure client nodes:&lt;br /&gt;
*For each client node, create a lustre_root principal and generate keytab.&lt;br /&gt;
   kadmin&amp;gt; addprinc -randkey lustre_root/client_host.domain@REALM&lt;br /&gt;
   kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_root/client_host.domain@REALM &lt;br /&gt;
*Install the keytab on the client node.&lt;br /&gt;
&lt;br /&gt;
2. Configure MDS node:&lt;br /&gt;
*For each MDS node, create a lustre_mds principal and generate keytab.&lt;br /&gt;
  kadmin&amp;gt; addprinc -randkey lustre_mds/mds_host.domain@REALM&lt;br /&gt;
  kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_mds/mds_host.domain@REALM&lt;br /&gt;
*Install the keytab on the MDS node.&lt;br /&gt;
&lt;br /&gt;
3. Configure OSS node:&lt;br /&gt;
*For each OSS node, create a lustre_oss principal and generate keytab.&lt;br /&gt;
  kadmin&amp;gt; addprinc -randkey lustre_oss/oss_host.domain@REALM&lt;br /&gt;
  kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_oss/oss_host.domain@REALM&lt;br /&gt;
*Install the keytab on the OSS node.&lt;br /&gt;
&lt;br /&gt;
NOTES:&lt;br /&gt;
*The &amp;#039;&amp;#039;host.domain&amp;#039;&amp;#039; should be the FQDN in your network, otherwise server might not recognize any GSS request.&lt;br /&gt;
&lt;br /&gt;
*As an alternative of the client keytab, if you want to save the trouble of assigning unique keytab for each client node, you can create a general lustre_root principal and its keytab, and install the same keytab on as many client nodes as you want. &amp;#039;&amp;#039;&amp;#039;But be aware that in this way one compromised client means all clients are insecure&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
      kadmin&amp;gt; addprinc -randkey lustre_root@REALM&lt;br /&gt;
      kadmin&amp;gt; ktadd -e aes128-cts:normal lustre_root@REALM&lt;br /&gt;
&lt;br /&gt;
*To merge keytab files, you need the tool &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;ktutil&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;, for more details please refers to manual of ktutil.&lt;br /&gt;
&lt;br /&gt;
*Lustre support following &amp;#039;&amp;#039;enctypes&amp;#039;&amp;#039; for MIT Kerberos 5 version 1.4 or higher:&lt;br /&gt;
**&amp;lt;u&amp;gt;&amp;#039;&amp;#039;des-cbc-md5&amp;#039;&amp;#039;&amp;lt;/u&amp;gt;&lt;br /&gt;
**&amp;lt;u&amp;gt;&amp;#039;&amp;#039;des3-hmac-sha1&amp;#039;&amp;#039;&amp;lt;/u&amp;gt;&lt;br /&gt;
**&amp;lt;u&amp;gt;&amp;#039;&amp;#039;aes128-cts&amp;#039;&amp;#039;&amp;lt;/u&amp;gt;&lt;br /&gt;
**&amp;lt;u&amp;gt;&amp;#039;&amp;#039;aes256-cts&amp;#039;&amp;#039;&amp;lt;/u&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*For MIT Kerberos 1.3.x, only &amp;#039;&amp;#039;des-cbc-md5&amp;#039;&amp;#039; works because a known issue between libgssapi and Kerberos library.&lt;br /&gt;
&lt;br /&gt;
== required packages ==&lt;br /&gt;
Every node should have follow packages installed:&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;libgssapi&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; version 0.10 or higher. Some newer Linux distributions already come with it. If not, build &amp;amp; install from source: http://www.citi.umich.edu/projects/nfsv4/linux/libgssapi/libgssapi-0.11.tar.gz&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;keyutils&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Kernel &amp;amp; Environment ==&lt;br /&gt;
* System wide configuration:&lt;br /&gt;
On Each node (MDT, OST, Client) following line should be added into /etc/fstab to be automatically mounted&lt;br /&gt;
   nfsd         /proc/fs/nfsd            nfsd            defaults   0 0 &lt;br /&gt;
Each MDT and Client node add following line into /etc/request-key.conf:&lt;br /&gt;
   create lgssc * * /usr/sbin/lgss_keyring %o %k %t %d %c %u %g %T %P %S&lt;br /&gt;
Note you might need to replace &amp;#039;&amp;#039;&amp;#039;/usr/sbin/lgss_keyring&amp;#039;&amp;#039;&amp;#039; in above line to the actual path to lgss_keyring binary in your setting.&lt;br /&gt;
&lt;br /&gt;
* Networking:&lt;br /&gt;
If you are using network which is &amp;#039;&amp;#039;&amp;#039;NOT&amp;#039;&amp;#039;&amp;#039; TCP or Infiniband (e.g. Quadrics Elan, Myrinet, etc), you need configure a &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;/etc/lustre/nid2hostname&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; on &amp;#039;&amp;#039;&amp;#039;each&amp;#039;&amp;#039;&amp;#039; server node (MDT &amp;amp; OST), which is a simple script to translate NID into hostname. Following is sample on a Elan cluster:&lt;br /&gt;
&lt;br /&gt;
   #!/bin/bash&lt;br /&gt;
   set -x&lt;br /&gt;
   exec 2&amp;gt;/tmp/$(basename $0).debug&lt;br /&gt;
    &lt;br /&gt;
   # convert a NID for a LND to a hostname, for GSS for example&lt;br /&gt;
    &lt;br /&gt;
   # called with thre arguments: lnd netid nid&lt;br /&gt;
   #   $lnd will be string &amp;quot;QSWLND&amp;quot;, &amp;quot;GMLND&amp;quot;, etc.&lt;br /&gt;
   #   $netid will be number in hex string format, like &amp;quot;0x16&amp;quot;, etc.&lt;br /&gt;
   #   $nid has the same format as $netid&lt;br /&gt;
   # output the corresponding hostname, or error message leaded by a &amp;#039;@&amp;#039; for error logging.&lt;br /&gt;
    &lt;br /&gt;
   lnd=$1&lt;br /&gt;
   netid=$2&lt;br /&gt;
   nid=$3&lt;br /&gt;
     &lt;br /&gt;
   # uppercase the hex&lt;br /&gt;
   nid=$(echo $nid | tr &amp;#039;[abcdef]&amp;#039; &amp;#039;[ABCDEF]&amp;#039;)&lt;br /&gt;
   # and convert to decimal&lt;br /&gt;
   nid=$(echo -e &amp;quot;ibase=16\n${nid/#0x}&amp;quot; | bc)&lt;br /&gt;
   case $lnd in&lt;br /&gt;
        QSWLND)   # simply stick &amp;quot;mtn&amp;quot; on the front&lt;br /&gt;
                  echo &amp;quot;mtn$nid&amp;quot;&lt;br /&gt;
                  ;;&lt;br /&gt;
        *)        echo &amp;quot;@unknown LND: $lnd&amp;quot;&lt;br /&gt;
                  ;;&lt;br /&gt;
   esac&lt;br /&gt;
&lt;br /&gt;
== Build Lustre ==&lt;br /&gt;
Enable GSS during configuration:&lt;br /&gt;
&lt;br /&gt;
 ./configure --enable-gss --other-options&lt;br /&gt;
&lt;br /&gt;
== Running ==&lt;br /&gt;
=== GSS Daemons ===&lt;br /&gt;
Make sure start the daemon process &amp;#039;&amp;#039;&amp;#039;lsvcgssd&amp;#039;&amp;#039;&amp;#039; on each OST and MDT node before starting Lustre. The command syntax is:&lt;br /&gt;
 lsvcgssd [-f] [-v]&lt;br /&gt;
* &amp;#039;&amp;#039;-f&amp;#039;&amp;#039;: running at foreground instead of as daemon, thus output error/warning messages to front console instead of system log.&lt;br /&gt;
* &amp;#039;&amp;#039;-v&amp;#039;&amp;#039;: increase verbosity by 1. The default is 0, maximum is 4.&lt;br /&gt;
&lt;br /&gt;
=== Setting Security Flavors ===&lt;br /&gt;
Note: If nothing specified, by default all RPC connections will use &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;null&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
On MGS there&amp;#039;s a persistent sptlrpc rule database, by specifying set of rules you can change security flavors between nodes. A rule is in form of:&lt;br /&gt;
 &amp;lt;spec&amp;gt;=&amp;lt;flavor&amp;gt;&lt;br /&gt;
Rules can be manipulated on MGS node. To add a rule:&lt;br /&gt;
 mgs&amp;gt; lctl conf_param &amp;lt;spec&amp;gt;=&amp;lt;flavor&amp;gt;&lt;br /&gt;
If there a existing rule of &amp;lt;spec&amp;gt; part, it will overwritten.&lt;br /&gt;
&lt;br /&gt;
To delete a rule, just leave &amp;lt;flavor&amp;gt; part be empty:&lt;br /&gt;
 mgs&amp;gt; lctl conf_param &amp;lt;spec&amp;gt;=&lt;br /&gt;
&lt;br /&gt;
Current rule set could be obtained by:&lt;br /&gt;
 msg&amp;gt; cat /proc/fs/lustre/mgs/&amp;lt;mgs-name&amp;gt;/live/&amp;lt;fs-name&amp;gt; | grep &amp;quot;srpc.flavor&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
* Rules have persistent storage on MGS, so it applied across re-mount.&lt;br /&gt;
* It doesn&amp;#039;t matter in which order you add a set of rules, lustre keep rules in certain order or priority.&lt;br /&gt;
* After you changed a rule, usually it will take the system within 1 minutes to apply the new rules to all nodes, depend on system load.&lt;br /&gt;
* Before you change a rule, make sure affected nodes are ready for the new security flavor. E.g. you changed flavor from &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;null&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; to &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;krb5p&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; but GSS/Kerberos env is not properly configured on affected nodes, those nodes might be evicted because they can&amp;#039;t communicate with others.&lt;br /&gt;
* You can also specify rules via device on-disk parameters, by mke2fs.lustre or tune2fs.lustre. The syntax is the same, and the rule only applied to connections to this specific target (MDT/OST).&lt;br /&gt;
&lt;br /&gt;
=== Rules Syntax &amp;amp; Examples ===&lt;br /&gt;
The general syntax is:&lt;br /&gt;
 &amp;lt;target&amp;gt;.srpc.flavor.&amp;lt;network&amp;gt;[.&amp;lt;direction&amp;gt;]=flavor&lt;br /&gt;
&lt;br /&gt;
* &amp;lt;target&amp;gt;: could be filesystem name, or specific MDT/OST device name. For example, &amp;#039;&amp;#039;lustre&amp;#039;&amp;#039;, &amp;#039;&amp;#039;lustre-MDT0000&amp;#039;&amp;#039;, &amp;#039;&amp;#039;lustre-OST0001&amp;#039;&amp;#039;, etc.&lt;br /&gt;
* &amp;lt;network&amp;gt;: LNET network name of the RPC initiator. For example, &amp;#039;&amp;#039;tcp0&amp;#039;&amp;#039;, &amp;#039;&amp;#039;elan1&amp;#039;&amp;#039;, &amp;#039;&amp;#039;o2ib0&amp;#039;&amp;#039;.&lt;br /&gt;
* &amp;lt;direction&amp;gt;: could be one of &amp;#039;&amp;#039;cli2mdt&amp;#039;&amp;#039;, &amp;#039;&amp;#039;cli2ost&amp;#039;&amp;#039;, &amp;#039;&amp;#039;mdt2mdt&amp;#039;&amp;#039;, &amp;#039;&amp;#039;mdt2ost&amp;#039;&amp;#039;. In most cases you don&amp;#039;t need to specify &amp;lt;direction&amp;gt; part.&lt;br /&gt;
&lt;br /&gt;
Examples:&lt;br /&gt;
* Apply &amp;#039;&amp;#039;krb5i&amp;#039;&amp;#039; on &amp;#039;&amp;#039;&amp;#039;ALL&amp;#039;&amp;#039;&amp;#039; connections:&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default=krb5i&lt;br /&gt;
&lt;br /&gt;
* Nodes in network &amp;#039;&amp;#039;tcp0&amp;#039;&amp;#039; use &amp;#039;&amp;#039;krb5p&amp;#039;&amp;#039;; All other nodes use &amp;#039;&amp;#039;null&amp;#039;&amp;#039;&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.tcp0=krb5p&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default=null&lt;br /&gt;
&lt;br /&gt;
* Nodes in network &amp;#039;&amp;#039;tcp0&amp;#039;&amp;#039; use &amp;#039;&amp;#039;krb5p&amp;#039;&amp;#039;; Nodes in &amp;#039;&amp;#039;elan1&amp;#039;&amp;#039; use &amp;#039;&amp;#039;plain&amp;#039;&amp;#039;; Amount other nodes, clients use &amp;#039;&amp;#039;krb5i&amp;#039;&amp;#039; to MDT/OST, MDT use &amp;#039;&amp;#039;null&amp;#039;&amp;#039; to other MDTs, MDT use &amp;#039;&amp;#039;plain&amp;#039;&amp;#039; to OSTs.&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.tcp0=krb5p&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.elan1=plain&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default.cli2mdt=krb5i&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default.cli2ost=krb5i&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default.mdt2mdt=null&lt;br /&gt;
  mgs&amp;gt; lctl conf_param lustre.srpc.flavor.default.mdt2ost=plain&lt;br /&gt;
&lt;br /&gt;
=== Authenticate Normal Users ===&lt;br /&gt;
On client nodes, a non-root user need &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;kinit&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; before accessing Lustre, just like other Kerberized applications.&lt;br /&gt;
* Required by kerberos, the user&amp;#039;s principal (&amp;#039;&amp;#039;username@REALM&amp;#039;&amp;#039;) should be added into KDC.&lt;br /&gt;
* Client and MDT nodes should have the same user database, i.e. the user name and uid/gid translation.&lt;br /&gt;
A use could destroy the established security contexts before logout, by &amp;quot;lfs flushctx&amp;quot;:&lt;br /&gt;
&lt;br /&gt;
 lfs flushctx [-k]&lt;br /&gt;
&lt;br /&gt;
Here &amp;quot;-k&amp;quot; means also destroy the on-disk kerberos credential cache, equals to &amp;quot;kdestroy&amp;quot;, otherwise it only destroy established contexts in Lustre kernel memory.&lt;br /&gt;
&lt;br /&gt;
== Secure MGC - MGS connection ==&lt;br /&gt;
Each node can specify what flavor to use to connect to MGS, by option &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;mgssec=flavor&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; upon mounting a target device or client. By default &amp;#039;&amp;#039;null&amp;#039;&amp;#039; is chosen. Once a flavor is chosen, it can&amp;#039;t be changed until umount.&lt;br /&gt;
&lt;br /&gt;
Because each node has only one connection to MGS, so if there&amp;#039;s more than one target device or client on a single node, all the &amp;quot;mgssec=&amp;quot; specification must be the same. Or simply missing option &amp;quot;mgssec=&amp;quot; means &amp;quot;using currently chosen flavor.&lt;br /&gt;
&lt;br /&gt;
By default, MGS accept RPCs with any flavor. But sysad can configure MGS to only accept certain flavor from certain network. The syntax is similar but with target as a special &amp;quot;_mgs&amp;quot;:&lt;br /&gt;
 mgs&amp;gt; lctl conf_param _mgs.srpc.flavor.&amp;lt;network&amp;gt;=flavor&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;NOTE: apply inappropriate flavor may lead to a node never be able to communicate with MGS until restart. So use it carefully.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== Cross-Realms Authentication ==&lt;br /&gt;
Due to idmap functionality is missing, we don&amp;#039;t support cross-realm authentication currently.&lt;/div&gt;</summary>
		<author><name>Sbarthel</name></author>
	</entry>
</feed>