<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cmclconfd - security token exchange? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775394#M698145</link>
    <description>These messages could imply that there is a problem talking to identd. What messages are logged into syslog at the time the messages are reported by cmapplyconf? Can you verify that identd is setup and working correctly?&lt;BR /&gt;&lt;BR /&gt;If identd appears to be working correctly and syslog gives no further clues then it would probably be necessary to turn on logging to determine what is causing this.</description>
    <pubDate>Fri, 21 Apr 2006 04:08:19 GMT</pubDate>
    <dc:creator>John Bigg</dc:creator>
    <dc:date>2006-04-21T04:08:19Z</dc:date>
    <item>
      <title>cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775389#M698140</link>
      <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;I've noticed my cmviewcl, cmgetconf, cmquerycl commands are taking a while (1-2 minutes) to return. I've got a 7 node cluster with 36 packages. All nodes have dedicated heartbeat LANs.&lt;BR /&gt;&lt;BR /&gt;As I'm adding a new package, I got the message below:&lt;BR /&gt;&lt;BR /&gt;# cmapplyconf -v -P /etc/cmcluster/packages/stcards/stcards.conf&lt;BR /&gt;&lt;BR /&gt;Checking existing configuration ... Done&lt;BR /&gt;Gathering configuration information ... Done&lt;BR /&gt;Parsing package file: /etc/cmcluster/packages/stcards/stcards.conf.&lt;BR /&gt;Attempting to add package stcards.&lt;BR /&gt;(this took a while to come back too)&lt;BR /&gt;Maximum configured packages parameter is 70.&lt;BR /&gt;Configuring 36 package(s).&lt;BR /&gt;34 package(s) can be added to this cluster.&lt;BR /&gt;198 access policies can be added to this cluster.&lt;BR /&gt;&lt;BR /&gt;Modify the package configuration ([y]/n)? y&lt;BR /&gt;Adding the package configuration for package stcards.&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node hods01&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node drds04&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node drds02&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node hods04&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node hods02&lt;BR /&gt;Unable to perform the security token exchange with cmclconfd on node drds06&lt;BR /&gt;Completed the cluster update.&lt;BR /&gt;&lt;BR /&gt;I can startup the new package ok.&lt;BR /&gt;&lt;BR /&gt;Questions:&lt;BR /&gt;1. What is that security token exchange thing?&lt;BR /&gt;2. Why is it taking longer for cmviewcl, cmgetconf, cmquerycl to return?&lt;BR /&gt;&lt;BR /&gt;Any help would be greatly appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Many thanks.&lt;BR /&gt;&lt;BR /&gt;Tung</description>
      <pubDate>Fri, 21 Apr 2006 02:57:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775389#M698140</guid>
      <dc:creator>support_5</dc:creator>
      <dc:date>2006-04-21T02:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775390#M698141</link>
      <description>The mesaages about access configuration makes me think that this is latest version of SG. (At least 11.16?) &lt;BR /&gt;What version SG?&lt;BR /&gt;&lt;BR /&gt;Did you think about applying it with -k option? I think (not sure though) security token messages are on account of existing access policies.</description>
      <pubDate>Fri, 21 Apr 2006 03:08:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775390#M698141</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2006-04-21T03:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775391#M698142</link>
      <description>Whoops, silly me. All nodes running HP-UX 11.23, SG 11.16.&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestion, RAC, but no go, I tried cmquerycl with the -k option, it was a bit faster, but it took a while "Gathering configuration information...", but the warnings and errors below worries me.&lt;BR /&gt;&lt;BR /&gt;Warning: Not probing node drds06 as it is currently unreachable.&lt;BR /&gt; This may cause network partitions to be reported.&lt;BR /&gt;Warning: Not probing node hods02 as it is currently unreachable.&lt;BR /&gt; This may cause network partitions to be reported.&lt;BR /&gt;&lt;BR /&gt;Error: Cannot connect to configuration daemon (cmclconfd) on node drds06&lt;BR /&gt;Error: Cannot connect to configuration daemon (cmclconfd) on node hods02&lt;BR /&gt;&lt;BR /&gt;cmclconfd is running on both drds06 and hods02, I can ping both servers from hods01. It was not always like this, the latest change was adding drds06 into the cluster.&lt;BR /&gt;&lt;BR /&gt;More question:&lt;BR /&gt;3. Why is it complaining it cannot connect to configuration daemon cmclconfd?&lt;BR /&gt;&lt;BR /&gt;Hmmm...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Many thanks.&lt;BR /&gt;&lt;BR /&gt;Tung</description>
      <pubDate>Fri, 21 Apr 2006 03:26:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775391#M698142</guid>
      <dc:creator>support_5</dc:creator>
      <dc:date>2006-04-21T03:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775392#M698143</link>
      <description>From those two hosts, Can you do cmviewcl on any of the packages running on another hosts?&lt;BR /&gt;&lt;BR /&gt;Are you up to date on patches?</description>
      <pubDate>Fri, 21 Apr 2006 03:35:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775392#M698143</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2006-04-21T03:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775393#M698144</link>
      <description>Yup, I was able to run cmviewcl -p PACKAGE_NAME successfully from the two hosts, still slower to return, though. As for patches, a set of ServiceGuard 11.16 patches were applied from Sep 2005. &lt;BR /&gt;&lt;BR /&gt;We also moved our DNS and Sendmail server, but not sure if that could have affected it?&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Apr 2006 04:01:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775393#M698144</guid>
      <dc:creator>support_5</dc:creator>
      <dc:date>2006-04-21T04:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775394#M698145</link>
      <description>These messages could imply that there is a problem talking to identd. What messages are logged into syslog at the time the messages are reported by cmapplyconf? Can you verify that identd is setup and working correctly?&lt;BR /&gt;&lt;BR /&gt;If identd appears to be working correctly and syslog gives no further clues then it would probably be necessary to turn on logging to determine what is causing this.</description>
      <pubDate>Fri, 21 Apr 2006 04:08:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775394#M698145</guid>
      <dc:creator>John Bigg</dc:creator>
      <dc:date>2006-04-21T04:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775395#M698146</link>
      <description>If your servers rely on identd for Serviceguard, insure:&lt;BR /&gt;1) identd (sendmail) is at version 8.9.3.1 and patched &lt;BR /&gt;&lt;BR /&gt;2) /etc/nsswitch.conf =&lt;BR /&gt;hosts:  files  dns&lt;BR /&gt;&lt;BR /&gt;3) /etc/hosts contains a list of every IP-bearing NIC on each cluster node&lt;BR /&gt;&lt;BR /&gt;4) nslookup and "who -Rm" shows the correct hostname&lt;BR /&gt;&lt;BR /&gt;5) Port 113 is not denied in /var/adm/inetd.sec&lt;BR /&gt;&lt;BR /&gt;6) Internode HB connection is not done by a router, and if done by switch, no filtering of hacl ports or identd port numbers&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Apr 2006 08:16:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775395#M698146</guid>
      <dc:creator>Stephen Doud</dc:creator>
      <dc:date>2006-04-21T08:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: cmclconfd - security token exchange?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775396#M698147</link>
      <description>Sorry for the late reply, guys. identd is not used, commented out in /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;Anyway, the problem went away after a restart of inetd daemon. It seems to have played up after our redundant core switch died? We restarted inetd because our Control-M agents were playing up too, complaining about inetd. cmviewcl and cmgetconf runs great now.&lt;BR /&gt;&lt;BR /&gt;Is this normal behaviour? Strange that it should complain about some security token exchange?&lt;BR /&gt;&lt;BR /&gt;Thanks again for your help, guys.</description>
      <pubDate>Wed, 10 May 2006 01:26:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cmclconfd-security-token-exchange/m-p/3775396#M698147</guid>
      <dc:creator>support_5</dc:creator>
      <dc:date>2006-05-10T01:26:21Z</dc:date>
    </item>
  </channel>
</rss>

