Operating System - HP-UX
1833777 Members
2839 Online
110063 Solutions
New Discussion

Re: MC/SG and trusted mode

 
SOLVED
Go to solution
Enrico Venturi
Super Advisor

MC/SG and trusted mode

Hello colleagues,
someone told me that MC/SG isn't fully compatible with the HP-UX configured in trusted mode.

Is it true?
What does it happen exactly?

regards
Enrico
9 REPLIES 9
melvyn burnard
Honored Contributor

Re: MC/SG and trusted mode

I would suggest you reply to that person saying that it does work fine with the nodes configured as Trusted Nodes.
My house is the bank's, my money the wife's, But my opinions belong to me, not HP!
Marco Santerre
Honored Contributor

Re: MC/SG and trusted mode

Having enabled Trusted Mode on my Service Guard nodes, I can attest that it does work fine.
Cooperation is doing with a smile what you have to do anyhow.
Thomas Schler_1
Trusted Contributor

Re: MC/SG and trusted mode

Enrico,

I, also, can tell you that we have MC/SG running on two nodes in trusted mode without any problem. It's really fine.
no users -- no problems
Jeff Schussele
Honored Contributor

Re: MC/SG and trusted mode

Hi Enrico,

Being in Trusted mode or not has no impact on MC/SG.
But I've seen application SW that can be impacted by the conversion, so check the SW before converting.

Rgds,
Jeff
PERSEVERANCE -- Remember, whatever does not kill you only makes you stronger!
Rainer von Bongartz
Honored Contributor

Re: MC/SG and trusted mode

Enrico,

I have MC/SG running on one cluster with both nodes trusted without any problem.

I even have another cluster with one trusted and one not-trusted node.

Regards
Rainer
He's a real UNIX Man, sitting in his UNIX LAN making all his UNIX plans for nobody ...
Uday_S_Ankolekar
Honored Contributor

Re: MC/SG and trusted mode

Service guard works well with Trusted servers, I have configured cluster with such environment and so far no problem.
Well, if you have any specific problem then let forum know about this.


-USA..
Good Luck..
aparna challagulla
Valued Contributor

Re: MC/SG and trusted mode

Hi Enrico,

All our production servers(hp-ux 11i) are MCSG two node clusters and both the nodes are trusted.
We have never had any issues with this configuration.
So its not true.

HTH
aparna
If you don't have time to do it right you must have time to do it over
Stephen Doud
Honored Contributor
Solution

Re: MC/SG and trusted mode

UXSGKBAN00000032
What security versions are compatible with MC/ServiceGuard?


Trusted Systems security levels are ranked from strongest A - verified, B -
mandatory, C - discretionary, D - minimal with subrankings in each category.
C2 is not "high" security by U.S. government standards: levels A and B
provide greater security. However, C2 is a high rating for business computing
products.

--Supported HP-UX Releases--
Serviceguard is supported on HP-UX 10.20, 11.0, 11.11, 11i v1.6 and 11i v2.
Serviceguard is not supported with the B-Level Security (BLS) and
Compartmented Mode Workstation (CMW) versions of HP-UX.
Serviceguard does support the C2 security option (Trusted Systems)
enabled on standard HP-UX 10.x and 11.x releases.

HP-UX IPsec - Version A.01.07 contains the following new features:
HP-UX IPSec can secure MC/ServiceGuard clusters (MC/ServiceGuard version
A.11.14 and A.11.15). HP-UX IPSec includes a script that monitors HP-UX
IPSec availability, and you can configure this script as a package service
so a package will failover if HP-UX IPSec is unavailable. HP-UX IPSec also
works with the MC/ServiceGuard local link failover feature.

IPSEC: Available on all hardware platforms supporting HP-UX 11.0 and beyond
(except HP-UX 11.20 and HP-UX 11i version 1.6). Also supported on VVOS
11.04 (Virtual Vault). NOTE: HP-UX IPSec version A.01.07 is supported
on HP-UX 11i version 1 only. Version A.01.06 is supported on HP-UX 11i
version 2 only. If you want to install HP-UX IPSec on an HP-UX 11.0 or
11.04 system, you must download version A.01.05.


--HP-UX 10.20--
Only the HFS file system can support the C2 level security because the 10.20
implementation of JFS (Journal File System) does not support ACL's (Access
Control Lists)

--HP-UX 11.00, 11i--
11.00 (with JFS 3.3 patches) and 11.11 (11i) JFS 3.3 support ACLS on a VxFS root
file system. Hence, C2 level security works on a VxFS root file system.

### END ###
-Stephen Doud