<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DECNET in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033865#M54134</link>
    <description>add net$examine to the username you are using.&lt;BR /&gt;</description>
    <pubDate>Wed, 14 Mar 2007 08:50:15 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2007-03-14T08:50:15Z</dc:date>
    <item>
      <title>DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033852#M54121</link>
      <description>How do I make unrestricted access between nodes,&lt;BR /&gt;eg. at the moment I can do the following :&lt;BR /&gt;DIR NODE"user pass"::DISK:[dir] but I need to be able to DIR NODE::DISK:[dir], when I try I get a message saying no priv. or object prot. violation.&lt;BR /&gt;I have read the manual I think I need to alter the defaults that were setup when I created the three node network, but which and how.&lt;BR /&gt;Thanks for any help.</description>
      <pubDate>Wed, 14 Mar 2007 04:49:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033852#M54121</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T04:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033853#M54122</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;you need to set up DECnet PROXIES to allow access to the other nodes without specifying username and password.&lt;BR /&gt;&lt;BR /&gt;Assuming you are logged in on NODE1 as USER1 and want to access files on NODE2 with the same username (USER1). You need to create a proxy on NODE2:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE1::USER1 USER1/DEFAULT &lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 14 Mar 2007 05:02:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033853#M54122</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2007-03-14T05:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033854#M54123</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;if you just want to skip the user/pass string, you can setup proxies between the nodes for specific users (MCR AUTHORIZE ADD/PROX).&lt;BR /&gt;&lt;BR /&gt;Or if you want to setup an all accessible directory you can configure decnet to use a default access (using NET$CONFIGURE). This is done via object FAL, which normally runs under an username of FAL$SERVER, so the user FAL$SERVER should have access to DISK:[DIR].&lt;BR /&gt;&lt;BR /&gt;You can check for FAL with:&lt;BR /&gt;- DECNet IV: MC NCP SHO OBJ FAL &lt;BR /&gt;- DECnet V: MC NCL SHO SESS CON APPL FAL ALL ATTR&lt;BR /&gt;&lt;BR /&gt;regards Kalle</description>
      <pubDate>Wed, 14 Mar 2007 05:03:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033854#M54123</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2007-03-14T05:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033855#M54124</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;When configuring this type of access, please consider with care the security implications. Enabling global access via DECnet to all users is, at least potentially, the same as removing all file protections throughout the system.&lt;BR /&gt;&lt;BR /&gt;Proxies are a fine way to achieve the functionality within limits. You will find a full description of the security implications in the Guide to System Security (available in the online documentation set at &lt;A href="http://www.hp.com/go/openvms" target="_blank"&gt;http://www.hp.com/go/openvms&lt;/A&gt; ).&lt;BR /&gt;&lt;BR /&gt;If the three nodes comprise an OpenVMS cluster, then mounting devices clusterwide is the better option.&lt;BR /&gt;&lt;BR /&gt;I hope that the above is helpful.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Wed, 14 Mar 2007 05:27:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033855#M54124</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2007-03-14T05:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033856#M54125</link>
      <description>Or consider SSH which avoids security risks.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 14 Mar 2007 05:46:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033856#M54125</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-14T05:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033857#M54126</link>
      <description>Hi Guys,&lt;BR /&gt;thanks for quick response, I have tried the proxy approach first as it seemed the quicker method, so I have made proxies on all nodes, uaf no error, but it still doesn't work, except I can now dir node1:: while being on node1 which was not possible before. On my eldest node where decnet was already setup I found the FAl$server.exe but on the other nodes which I setup the command gave an error, I have an bad feeling I have not set up the decnet correctly, but I can set host and dir (user pass) works.</description>
      <pubDate>Wed, 14 Mar 2007 05:51:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033857#M54126</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T05:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033858#M54127</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;you need to provide more details about VMS and DECnet versions (Phase IV or Phase V), which command you tried and what the error message was...&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 14 Mar 2007 05:55:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033858#M54127</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2007-03-14T05:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033859#M54128</link>
      <description>There are three nodes an old one which I am phasing out. Old node vms7.2-2 decnet 7.2-1, show net gives full listing idents, status etc.. net type DNA V, the two newer nodes run VMS 7.3-2 and decnet 7.3-2 net type DNA V, but when I show net/full decnet I get header detail but only errors after that, such as CMLSENFAILED, ACCESSDENIED and EMAAPROB .... error returned from vms ema agent.&lt;BR /&gt;These nodes I set up decnet with net$configure and as local, its supposed to run over tcpip, its looking more and more that I have not configured correctly, I thought net$configure did it all?</description>
      <pubDate>Wed, 14 Mar 2007 07:04:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033859#M54128</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T07:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033860#M54129</link>
      <description>When I remove BYPASS from my privs and do show net/fu, I also get ACCESSDENIED and the other messages. &lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 14 Mar 2007 07:09:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033860#M54129</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-14T07:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033861#M54130</link>
      <description>But not when I'm logged in as SYSTEM without bypass. My previous test was done with [7,3] where maxsysgroup is 7.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 14 Mar 2007 07:12:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033861#M54130</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-14T07:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033862#M54131</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;you need privs or the following identifier:&lt;BR /&gt;&lt;BR /&gt;NET$EXAMINE - Permits display of the attributes of an entity&lt;BR /&gt;&lt;BR /&gt;Trying to set up proxies with DECnet-over-IP can get tricky, especially if the underlying DECnet configuration has not been properly verified to work.&lt;BR /&gt;&lt;BR /&gt;Consider enabling security alarms on the destination nodes and interpret the alarms you'll get, if the remote access does not work.&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 14 Mar 2007 07:14:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033862#M54131</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2007-03-14T07:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033863#M54132</link>
      <description>You need identifier net$examine but because I use bypass, I don't need it. System had it.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 14 Mar 2007 07:19:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033863#M54132</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2007-03-14T07:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033864#M54133</link>
      <description>I assume I add the identifier net$examine to user decnet or to the user i am trying to work with? In fact the user decnet does not exist on one of my nodes, so is it created by the net$configure ?</description>
      <pubDate>Wed, 14 Mar 2007 08:15:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033864#M54133</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T08:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033865#M54134</link>
      <description>add net$examine to the username you are using.&lt;BR /&gt;</description>
      <pubDate>Wed, 14 Mar 2007 08:50:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033865#M54134</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2007-03-14T08:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033866#M54135</link>
      <description>Sorry, I have added the ident. but I do not see how this helps me, I have the same problems as before. I am getting desperate.</description>
      <pubDate>Wed, 14 Mar 2007 09:07:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033866#M54135</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T09:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033867#M54136</link>
      <description>I have tried to set logging, I get ncp-w-sysmgt - system specific management not supported, so how can I monitor the node.</description>
      <pubDate>Wed, 14 Mar 2007 09:44:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033867#M54136</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-14T09:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033868#M54137</link>
      <description>Using AUTHORIZE in your SYSUAF, establish the following DECnet proxies:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY remnode::remuser localuser /DEFAULT&lt;BR /&gt;&lt;BR /&gt;Assuming no cluster, you'll need this on each node that will receive an incoming connection,   and the localuser is the username with sufficient access to allow access.  You can wildcard the remuser, if you trust the remote node.&lt;BR /&gt;&lt;BR /&gt;If you have a cluster, mount the disks and go direct.&lt;BR /&gt;&lt;BR /&gt;The most common failure with the DECnet proxy processing involve omitting the /DEFAULT, or with a node that does not have the name of the incoming node configured in its local database.&lt;BR /&gt;&lt;BR /&gt;In the case of the latter, you can see what nodename or node number is used by issuing a valid username and password string in an access such as the following:&lt;BR /&gt;&lt;BR /&gt;DIRECTORY remnode"user pwd"::&lt;BR /&gt;&lt;BR /&gt;And then looking in the NET*SERVER.LOG file that gets created on remnode::.  If you see numbers or such, or a name that does not match what you expect, you can use the DECNET_REGISTER tool to register the node name on DECnet-Plus (Phase V, DECnet/OSI), and you can use the NCP commands SET and then DEFINE NODE x.y NAME nodnam.  On each node.&lt;BR /&gt;&lt;BR /&gt;Also make sure you're on the right end of the connection when you're configuring stuff, or looking for a log file.  The DECnet proxies and log files are on the node that is receiving the connection, for instance.  This can easily get confusing.&lt;BR /&gt;&lt;BR /&gt;And whenever there's a cluster involved, also ensure that all members of the cluster have the same username and password for the incoming usernames in DECnet and the DECnet proxy database, and ensure that the SYSUAF, RIGHTSLIST, NETPROXY, NET$PROXY, and the other twenty files (see SYLOGICALS.TEMPLATE) are configured and correctly shared across all nodes.  But again, if there's a cluster involved, just mount the disks and go directly.&lt;BR /&gt;&lt;BR /&gt;To troubleshoot the privilege-related errors, ensure security auditing or security alarms are enabled, and look in the audit file with ANALYZE/AUDIT or use REPLY/ENABLE to look at the alarms.  The audit or alarm will be on the node receiving the incoming connection, and will typically indicate details of failed and triggered the NOPRIV error, and usually why.&lt;BR /&gt;&lt;BR /&gt;Stephen Hoffman&lt;BR /&gt;HoffmanLabs&lt;BR /&gt;</description>
      <pubDate>Wed, 14 Mar 2007 11:43:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033868#M54137</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2007-03-14T11:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033869#M54138</link>
      <description>As a quick hack only to prove that proxy processing is working you could set up proxies on each node as follows:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY *::TIM TIM /DEFAULT&lt;BR /&gt;&lt;BR /&gt;Because we're using wildcard here that gets past some of the Phase IV / Phase V differences in name lookups - it's ause ful test, but not a good solution because it's not very secure (much worse is *::SYSTEM SYSTEM/DEFAULT!).&lt;BR /&gt;&lt;BR /&gt;If that works, then you can tighten them up to:&lt;BR /&gt;&lt;BR /&gt;on Node1:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE2::TIM TIM /DEFAULT&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE3::TIM TIM /DEFAULT&lt;BR /&gt;&lt;BR /&gt;on Node2:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE1::TIM TIM /DEFAULT&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE3::TIM TIM /DEFAULT&lt;BR /&gt;&lt;BR /&gt;on Node3:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE1::TIM TIM /DEFAULT&lt;BR /&gt;UAF&amp;gt; ADD/PROXY NODE2::TIM TIM /DEFAULT&lt;BR /&gt;&lt;BR /&gt;Assuming that it's Phase V (which it looks like), then to erase any naming wierdness it's worth flushing the naming caches on each node with NCL&amp;gt; FLUSH SESSION CONTROL NAMING CACHE ENTRY "*".&lt;BR /&gt;&lt;BR /&gt;It's also worth checking that FAL (File Access Listener) has proxy access enabled (NCL&amp;gt; SHOW SESSION CONTROL APPLICATION FAL ALL, OR NCP SHOW OBJECT FAL, or something like that - I'm in a hotel and working from memory at the moment).&lt;BR /&gt;&lt;BR /&gt;All of the above will apply whether it's a cluster or not, except that in a cluster you would usually have a single common UAF / RIGHTSLIST and so on.&lt;BR /&gt;&lt;BR /&gt;If you're wrestling with Phase V and have time for some background reading then you might find this useful: &lt;A href="http://h71000.www7.hp.com/openvms/journal/v5/decnet.pdf" target="_blank"&gt;http://h71000.www7.hp.com/openvms/journal/v5/decnet.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Come to the "bootcamp" in May if you can: &lt;A href="http://h71000.www7.hp.com/symposium/index.html?jumpid=symposium" target="_blank"&gt;http://h71000.www7.hp.com/symposium/index.html?jumpid=symposium&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers, Colin (&lt;A href="http://www.xdelta.co.uk)." target="_blank"&gt;www.xdelta.co.uk).&lt;/A&gt;</description>
      <pubDate>Thu, 15 Mar 2007 02:27:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033869#M54138</guid>
      <dc:creator>Colin Butcher</dc:creator>
      <dc:date>2007-03-15T02:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: DECNET</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033870#M54139</link>
      <description>Thanks Guys, I am in a better position than when I opened this discussion thanks to you all. There are still a few problems but they are not holding me up, they are just tunning, I hope.&lt;BR /&gt;:-)</description>
      <pubDate>Thu, 15 Mar 2007 05:58:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/decnet/m-p/5033870#M54139</guid>
      <dc:creator>Tim Pride</dc:creator>
      <dc:date>2007-03-15T05:58:03Z</dc:date>
    </item>
  </channel>
</rss>

