- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Serviceguard & Bastille problem
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-22-2007 02:16 AM
08-22-2007 02:16 AM
Serviceguard & Bastille problem
I have a problem with Serviceguard (A.11.17) cluster and Bastille. After configuring Bastille lockdown, cluster continues to operate normally. But when node1 is rebooted, it doesn't rejoin the cluster. node2 reports that node1 is down & halted, and cmviewcl doesn't work on node2:
cmviewcl: Cannot view the cluster configuration: No such file or directory.
Either this node is not configured in a cluster, user doesn't have
access to view the cluster configuration, or there is some obstacle
to viewing the configuration. Check the syslog file for more information.
For a list of possible causes, see the Serviceguard manual for cmviewcl.
Here's the output when I try to start the node manually:
cmrunnode: Validating network configuration...
Gathering network information
Beginning network probing (this may take a while)
Completed network probing
cmrunnode: Network validation complete
Waiting for nodes to join ....Unable to perform the security token exchange with cmclconfd on node ssap105p
Unable to perform the security token exchange with cmclconfd on node ssap104p
.Unable to perform the security token exchange with cmclconfd on node ssap105p
.Unable to perform the security token exchange with cmclconfd on node ssap105p
Unable to perform the security token exchange with cmclconfd on node ssap104p
done
Cluster successfully formed.
Check the syslog files on all nodes in the cluster to verify that no warnings occurred during startup.
Afterwards, the other node reports that the first one is up & running, but cmviewcl still doesn't work on node1. I used interactive mode to configure Bastille and didn't setup firewall/IPFilter nor blocked ident service. If Bastille changes are reverted (-r), everthing works fine.
Regards,
Zlatko
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-22-2007 02:20 AM
08-22-2007 02:20 AM
Re: Serviceguard & Bastille problem
Bastille was written without direct knowledge of Serviceguard.
Bastille recommends closing down .rhost networking and makes other changes to inetd.conf
You need to not let Bastille do changes that impact Serviceguard, primarily inetd.conf changes.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-22-2007 03:13 AM
08-22-2007 03:13 AM
Re: Serviceguard & Bastille problem
http://docs.hp.com/en/B3935-90091/B3935-90091.pdf
Bastille Compatibility
Serviceguard's use of dynamic ports does not work if the pre-defined
configurations are installed for Bastille: Sec20MNGDMZ
(MANDMZ.config) or Sec30DMZ (DMZ.config). These configurations use
different IPFilter rules to define firewall protection than the rules
Serviceguard uses. The required IPFilter-Serviceguard rules are
documented in the HP-UX IPFilter Version A.03.05.09 Administrator's
Guide, which is posted at http://docs.hp.com/-> Internet Security
Solutions -> HP-UX IPFilter
Serviceguard is not compatible with the default settings for the HP-UX
Bastille Sec10Host configuration. The Sec10Host configuration disables
the identd daemon, but Serviceguard requires the identd daemon to be
running for authentication purposes. For information on how to
configure HP-UX Bastille Sec10Host to allow the identd daemon to run,
see the latest HP-UX 11i Version 2 Installation and Update Guide that is
posted at http://docs.hp.com/Core HP-UX - operating environments
-> 11i v2.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2007 01:38 AM
08-23-2007 01:38 AM
Re: Serviceguard & Bastille problem
Customers using the HOST.config configuration of
Bastille should update their configuration by editing the
Bastille config file /etc/opt/sec_mgmt/bastille/config to
allow identd to run.
Change the answer to the question "Should Bastille ensure
inetd's ident service does not run on this system?" by
changing the line:
SecureInetd.deactivate_ident="Y"
to
SecureInetd.deactivate_ident="N"
Users may then select between manually updating the
configuration or using Bastille to do the configuration
for them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-27-2007 12:46 AM
08-27-2007 12:46 AM
Re: Serviceguard & Bastille problem
Z.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-27-2007 01:08 AM
08-27-2007 01:08 AM
Re: Serviceguard & Bastille problem
Yes, Bastille tries to disable insecure services in inetd.conf
Once again, Bastille was not designed with serviceguard in mind.
If you answer the questions carefully you may be able to avoid Bastille hammering your SG configuration.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2007 12:06 AM
08-28-2007 12:06 AM
Re: Serviceguard & Bastille problem
"To ensure compatibility between Serviceguard (and Serviceguard Manager) and Bastille, do the following, ...."
See http://docs.hp.com/en/B3935-90108/ch01s03.html
for more details.