Operating System - HP-UX
1752749 Members
4765 Online
108789 Solutions
New Discussion юеВ

Re: MC/SG and trusted system

 
Rainer von Bongartz
Honored Contributor

MC/SG and trusted system


can I have one trusted and one non-trusted system in a two-node cluster ??

Regards
Rainer
He's a real UNIX Man, sitting in his UNIX LAN making all his UNIX plans for nobody ...
4 REPLIES 4
James Murtagh
Honored Contributor

Re: MC/SG and trusted system

Hi Rainer,

I can't think why not! Just make sure root's password doesn't expire (or get de-activated) though or you'll have trouble applying new configs etc!

Regards,

James.
RAC_1
Honored Contributor

Re: MC/SG and trusted system

no connection between this.

You can have SG with one node no-trusted and another non-trusted.
There is no substitute to HARDWORK
David_246
Trusted Contributor

Re: MC/SG and trusted system

Hi,

Be aware that a trusted system most of all has some extra security patches. I had the problem when upgrading my cluster with security patches the cluster died when adding the upgraded node to the cluster.

This again states that patch-levels should be equal on both nodes. So therefor be very carefull in defining what's the definition of trusted.

Regs David
@yourservice
roadrunner_1
Regular Advisor

Re: MC/SG and trusted system

I agree with David. It always a best practice to have the nodes indentical to each other. Since the trusted nodes will have a different patchset from the security aspect.

Moreover I dont see the reason why one should have their systems in trusted mode in their internal network as long as its not in a DMZ. For Service guard, it should not really matter..

This is my opinion