<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HP9000 system containers in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5525973#M521599</link>
    <description>&lt;P&gt;Trusted mode is supported only with HP 9000 classic containers. As you have discovered this model is less cleaner compared to system model as regards to file system and services isolation from the host OS environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HP 9000 Containers are built using HP-UX Containers (SRP) and utilize the features/capabilities provided by SRP for name space virtualization. Since trusted mode is deprecated on HP-UX 11i v3, SRP does not provide any name space virtualization capabilities for trusted mode security. Thus HP 9000 system containers do not support trusted mode. Alternative for trusted mode on HP-UX 11i v3 is SMSE (standard mode security extensions) which works with Integrity native HP-UX system containers. However, we cannot use SMSE for HP 9000 Containers built with HP-UX environments prior to HP-UX 11i v2. Furthermore, security infrastructure is invoked through the login process, thus plugging SMSE with older HP-UX environments inside HP 9000 system containers would be difficult to architect implement and likely to be error prone. Lack of trusted mode support inside HP 9000 system containers is not due to ARIES emulation inside contaienrs. ARIES passes down emulated application stystem calls to host OS kernel which lacks the name space virtualization capabilities for trusted mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If trusted mode with HP 9000 system containers is a critical business requirement in your case, please submit the issue/enhancement request to HP support center. Alternatively, you can use standalone ARIES mode without containers provided you can prepare application inventory (libraries, executables, config files etc) and dependencies for copying over to Integrity server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your comment about suggesting the client to port to AIX - if porting is an option, you can do so with comparatively lesser effort to HP-UX 11i v3 on HP Integrity servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Rajesh&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2012 05:59:58 GMT</pubDate>
    <dc:creator>Rajesh K Chaurasia</dc:creator>
    <dc:date>2012-02-02T05:59:58Z</dc:date>
    <item>
      <title>HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5516107#M521597</link>
      <description>&lt;P&gt;Hi everybody, long time no posts (from me),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am designing a solution for a customer who is looking to migrate off their old HP9000 PA-RISC kit.&lt;/P&gt;&lt;P&gt;They don't want to migrate any software to 11iv3 but do realise that they must get off the old hardware, so I am proposing a move to HP9000 system containers as a short-medium term solution, while they think about how to replace or upgrade their apps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the limitations of these containers is that they don't support trusted mode security (/tcb etc).&amp;nbsp; I think that this may be a consequence of emulated authentication.&lt;/P&gt;&lt;P&gt;Does anybody know if support for trusted mode security is planned in a future release of HP9000 system containers?&amp;nbsp; It could be a show-stopper because the customer's security standards include password history and all the old boxes use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation suggests that classic containers would be the only solution for this.&amp;nbsp; However from what I can glean from the documentation it seems like a mess because it would entail a lot more work re-configuring the software;&amp;nbsp; the system would be half in the container and half in the host VM; there would be a shared /etc and shared /var; half of the old o/s utilities won't work; I am not sure if classic containers would support 11.11.&amp;nbsp; I think I would rather tell them to port to AIX.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other issue I have is that they still have some old kit running HP-UX 10.20.&amp;nbsp; Hopefully the old software will run happily within a HP9000 system&amp;nbsp; container running at an upgrade to 11.11, within a VM at 11iv3, within a VM host at 11iv3, on an Integrity blade, within an enclosure running VC / flex-10 and VC for FC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2012 15:31:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5516107#M521597</guid>
      <dc:creator>Steve Lewis</dc:creator>
      <dc:date>2012-02-01T15:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5516281#M521598</link>
      <description>&lt;P&gt;&amp;gt;Does anybody know if support for trusted mode security is planned in a future release of HP9000 system containers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps not since trusted mode is deprecated on 11.31.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2012 18:37:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5516281#M521598</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2012-02-01T18:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5525973#M521599</link>
      <description>&lt;P&gt;Trusted mode is supported only with HP 9000 classic containers. As you have discovered this model is less cleaner compared to system model as regards to file system and services isolation from the host OS environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HP 9000 Containers are built using HP-UX Containers (SRP) and utilize the features/capabilities provided by SRP for name space virtualization. Since trusted mode is deprecated on HP-UX 11i v3, SRP does not provide any name space virtualization capabilities for trusted mode security. Thus HP 9000 system containers do not support trusted mode. Alternative for trusted mode on HP-UX 11i v3 is SMSE (standard mode security extensions) which works with Integrity native HP-UX system containers. However, we cannot use SMSE for HP 9000 Containers built with HP-UX environments prior to HP-UX 11i v2. Furthermore, security infrastructure is invoked through the login process, thus plugging SMSE with older HP-UX environments inside HP 9000 system containers would be difficult to architect implement and likely to be error prone. Lack of trusted mode support inside HP 9000 system containers is not due to ARIES emulation inside contaienrs. ARIES passes down emulated application stystem calls to host OS kernel which lacks the name space virtualization capabilities for trusted mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If trusted mode with HP 9000 system containers is a critical business requirement in your case, please submit the issue/enhancement request to HP support center. Alternatively, you can use standalone ARIES mode without containers provided you can prepare application inventory (libraries, executables, config files etc) and dependencies for copying over to Integrity server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your comment about suggesting the client to port to AIX - if porting is an option, you can do so with comparatively lesser effort to HP-UX 11i v3 on HP Integrity servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Rajesh&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2012 05:59:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5525973#M521599</guid>
      <dc:creator>Rajesh K Chaurasia</dc:creator>
      <dc:date>2012-02-02T05:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5526515#M521600</link>
      <description>Thanks for that comprehensive reply Rajesh.</description>
      <pubDate>Thu, 02 Feb 2012 14:25:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5526515#M521600</guid>
      <dc:creator>Steve Lewis</dc:creator>
      <dc:date>2012-02-02T14:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 containers: Can v11.0 run in a "System" Container</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5871457#M521601</link>
      <description>&lt;P&gt;Docs state "Classic" containers have been known to run 10.x and 11.0 environments.... Also states 10.x are not known to work in "System" Container.&amp;nbsp; Can 11.0 run in a "System" container? Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2012 20:54:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5871457#M521601</guid>
      <dc:creator>Bob Sobey</dc:creator>
      <dc:date>2012-11-19T20:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 containers: Can v11.0 run in a "System" Container</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5874109#M521602</link>
      <description>&lt;P&gt;There have been several instances of successful PoC projects and production deployments of HP-UX 10.20 / 11.0 legacy environments with HP 9000 system containers. This configuration is known to work but not supported. Please refer to more recent documentation on HP 9000 Containers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://h21007.www2.hp.com/portal/download/files/prot/files/hp9000/HP9000_Containers_Admin_Guide.pdf" target="_blank"&gt;http://h21007.www2.hp.com/portal/download/files/prot/files/hp9000/HP9000_Containers_Admin_Guide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most recent product update to HP 9000 Containers (A.03.01.04) released during 10/2012 enables support for trusted mode environments with HP 9000 system containers. For software access, visit HP software depot home.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HP9000-Containers" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HP9000-Containers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Rajesh&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2012 06:34:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/5874109#M521602</guid>
      <dc:creator>Rajesh K Chaurasia</dc:creator>
      <dc:date>2012-11-21T06:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6049581#M521603</link>
      <description>&lt;P&gt;Recently My company accepted a support contract to move an 11.0 box into our datacenter emulated under Aries and Containers. I'd read through the Admin Guide and had a rough idea of how the system works. I'd also seen on the web site that there was training available.&lt;/P&gt;&lt;P&gt;We now have the new system to execute this and I tried to sign up for the training.&lt;/P&gt;&lt;P&gt;Well the Dates link took me to a "Call this number"&lt;/P&gt;&lt;P&gt;I did and was told they have no dates planned for the future.&lt;/P&gt;&lt;P&gt;The Admin Guide is not all inclusively written.(In fact it is lame on points of Vpar Npar and application integration.&lt;/P&gt;&lt;P&gt;I can't get training that Hop said was there on the website.&lt;/P&gt;&lt;P&gt;I don't see much user activity here in the Forums like ITRC used to have. (This environment is difficult to use)&lt;/P&gt;&lt;P&gt;I guess all that is available to be for help on this proprietary emulator is RTFM (Read The Freaking Manual) and buying professional services to do that that were not in the original budget.&lt;/P&gt;&lt;P&gt;I'm highly skilled all I really needed was to see a sample deployment in a class like was advertised on the web page.&lt;/P&gt;&lt;P&gt;Is there any other help Learning this product since it appears HP has simply resorted to RTFM?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:28:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6049581#M521603</guid>
      <dc:creator>JoyOrton</dc:creator>
      <dc:date>2013-05-02T17:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6049585#M521604</link>
      <description>&lt;P&gt;Thanks for responses. I've since - successfully - POC two 11.0&amp;nbsp;environments&amp;nbsp;in Containers - SAP no less!&amp;nbsp; Both on same server, but only can bring up one at a time due to kernel constraints I believe.&amp;nbsp; Thanks again -&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 17:38:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6049585#M521604</guid>
      <dc:creator>Bob Sobey</dc:creator>
      <dc:date>2013-05-02T17:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: HP9000 system containers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6067521#M521605</link>
      <description>vpars and npars are not a issue with containers since the container runs in the Vpar, NPAR or VM operating system so the vpar,npar or vm only determines how much cpu and memory is available to the OS which the containers run in. THen you specify how much resources each container gets.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HP 9000 containers are to port a PA RISC environment to a itanium box unmodified. You restore a PA RISC backup into a directory like /9000 then you create the hp9000 container and reference that directory.&lt;BR /&gt;&lt;BR /&gt;This is my cookbook&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;download and install PHSS_41099 (no reboot)&lt;BR /&gt;download and install compartments (part of SRP install)&lt;BR /&gt;download and install SRP first (reboot needed) prerequisite.&lt;BR /&gt;download and install HP9000 containers (no reboot)&lt;BR /&gt;&lt;BR /&gt;mkdir /home/9000&lt;BR /&gt;cd 9000&lt;BR /&gt;frecover -r -X -f ../srp/hpmdd78.backup&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;add user oinstall:&lt;BR /&gt;&lt;BR /&gt;oinstall::110:&lt;BR /&gt;&lt;BR /&gt;in /home/down2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;useradd -u 120 -g oinstall -m oracle&lt;BR /&gt;&lt;BR /&gt;chown -R oracle:oinstall /Apps/*&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ln -s /home/down2 /9000&lt;BR /&gt;&lt;BR /&gt;srp_sys -setup take defaults&lt;BR /&gt;&lt;BR /&gt;srp -add HP9000&lt;BR /&gt;&lt;BR /&gt;services - default&lt;BR /&gt;unix names for administrator - default&lt;BR /&gt;List of UNIX user names for login: root,oracle&lt;BR /&gt;unix group names: adm,oinstall&lt;BR /&gt;PRM all default&lt;BR /&gt;IP address 10.10.67.9 (or whatever)&lt;BR /&gt;network interface name: lan1:5&lt;BR /&gt;gateway: default&lt;BR /&gt;autostart&lt;BR /&gt;&lt;BR /&gt;srp -add HP9000 -t sshd -b&lt;BR /&gt;srp -start HP9000&lt;BR /&gt;srp_ps HP9000 -ef | grep sshd&lt;BR /&gt;&lt;BR /&gt;srp -add HP9000 -t hp9000&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 May 2013 19:16:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp9000-system-containers/m-p/6067521#M521605</guid>
      <dc:creator>Emil Velez_2</dc:creator>
      <dc:date>2013-05-14T19:16:19Z</dc:date>
    </item>
  </channel>
</rss>

