Wednesday, October 24, 2007

ssh keys -- how to setup trust relations

Seting up trust relationship between UNIX hosts is one of the routine requests we get. Here is a brief procedure:

Case I: OpenSSH -> OpenSSH (Simplist)

Steps:
1. Generate SSH Keys

LinuxHostLocal# /usr/bin/ssh-keygen -t dsa

2. Copy Public Key to the Remote Machine

LinuxHostLocal# scp .ssh/id_dsa.pub LinuxHostRemote:/tmp

3. Add Public Key to the list of keys

LinuxHostRemote# cat /tmp/id_dsa.pub >> ~/.ssh/authorized_keys
LinuxHostRemote# rm /tmp/id_dsa.pub


4. Set up permissions

LinuxHostRemote# chmod 640 ~/.ssh/authorized_keys

We can now ssh from LinuxHostLocal to LinuxHostRemote without a password. Make sure never to let anyone get your private key file (keep permissions at 600). Public keys can (and should) be publicly available.


Case II: OpenSSH -> SSH2 (Key conversion will be needed)

From OpenSSH (LinuxLocalHost), to SSH2 (SolarisRemoteHost)

Do the 4 steps in Case I. Since SSH2 cannot directly read an OpenSSH key, we have to do a key conversion here.

1. Convert SSH Public Key to SSH2 Key

LinuxLocalHost# cd ~/.ssh
LinuxLocalHost# /usr/bin/ssh-keygen -e -f id_dsa_pub > id_dsa_ssh2.pub


2. Create the public key file on the Remote Machine that runs SSH2

LinuxLocalHost# scp id_dsa_ssh2.pub SolarisRemoteHost:~/.ssh2/remotehostname.pub

* you will have to supply a passwd at this time; otherwisie use root id to do the scp

2. Add Public Key to the list of keys

SolarisRemoteHost#cd ~/.ssh2
SolarisRemoteHost# echo "key remotehostname.pub" >> ~/.ssh2/authorization



Case III: SSH2 -> OpenSSH ((Again, key converstion is needed)

Now, we'll need to generate a new set of keys on the SSH2 machine, and send its public key to the openssh machine. Again, we will need to convert the public key. This time from SSH2 to OpenSSH form.
* note that the key conversion can only be done on the open ssh side. SSH2, as far as I know now, has not implemented a routine to convert OpenSSH keys.


1. Create SSH2 Keys

SolarisLocalHost# /opt/ssh2/bin/ssh-keygen

example screen:

$ /opt/ssh2/bin/ssh-keygen
Generating 1024-bit dsa key pair
2 Oo.oOo.oOoo.
Key generated.
1024-bit dsa, fsbsc@evitaprod, Wed Oct 24 2007 20:40:27
Passphrase : <<>
$
2. Tell SSH2 who it is

SolarisLocalHost# cd ~/.ssh2
SolarisLocalHost# echo "idkey id_dsa_1024_a" >> .ssh2/identification



3. Set permissions

SolarisLocalHost# chmod 600 idkey id_dsa_1024_a.pub identification

4. Copy the public key to the OpenSSH machine

SolarisLocalHost# scp .ssh/id_dsa_1024_a.pub LinuxRemoteHost:/tmp

5. Convert the public key, and add it authorized_keys2
*note the file name is "authorized_keys2"

LinuxRemoteHost:/usr/bin/ssh-keygen -i -f /tmp/id_dsa_1024_a.pub >> ~/.ssh/authorized_keys2
LinuxRemoteHost:rm /tmp/id_dsa_1024_a.pub

Cheers.

Thursday, May 24, 2007

Solaris fibre channel management

In Solaris 10, storage management is now integrated into the base OS. The leadville driver has been expanded to include HBAs from Emulex, JNI and Qlogic, and the fcinfo utility as well as several mdb DCMDS were added to view fibre channel connectivity information. 'fcinfo' is an useful tool to view HBA and connectivity information.

usage examples are here:

pbeqcmpdb1-h# fcinfo hba-port
HBA Port WWN: 10000000c943458a
OS Device Name: /devices/pci@8,700000/lpfc@2
Manufacturer: Emulex Corporation
Model: LP9002
Type: N-port
State: online
Supported Speeds: 2Gb
Current Speed: 2Gb
Node WWN: 20000000c943458a
HBA Port WWN: 10000000c943944b
OS Device Name: /devices/pci@8,700000/lpfc@3
Manufacturer: Emulex Corporation
Model: LP9002
Type: N-port
State: online
Supported Speeds: 2Gb
Current Speed: 2Gb
Node WWN: 20000000c943944b
HBA Port WWN: 210000144f23cfc4
OS Device Name: /dev/cfg/c1
Manufacturer: QLogic Corp.
Model: 2200
Type: L-port
State: online
Supported Speeds: 1Gb
Current Speed: 1Gb
Node WWN: 200000144f23cfc4
pbeqcmpdb1-h#
pbeqcmpdb2-h# fcinfo hba-port
HBA Port WWN: 10000000c952efec
OS Device Name: /devices/pci@8,700000/lpfc@2
Manufacturer: Emulex Corporation
Model: LP9002
Type: N-port
State: online
Supported Speeds: 2Gb
Current Speed: 2Gb
Node WWN: 20000000c952efec
HBA Port WWN: 10000000c952ee53
OS Device Name: /devices/pci@8,700000/lpfc@3
Manufacturer: Emulex Corporation
Model: LP9002
Type: N-port
State: online
Supported Speeds: 2Gb
Current Speed: 2Gb
Node WWN: 20000000c952ee53
HBA Port WWN: 210000144f00fe72
OS Device Name: /dev/cfg/c1
Manufacturer: QLogic Corp.
Model: 2200
Type: L-port
State: online
Supported Speeds: 1Gb
Current Speed: 1Gb
Node WWN: 200000144f00fe72
pbeqcmpdb2-h#

Further usage information can be found in man page.

Thursday, November 9, 2006

The JumpStart Client Boot Process

When a JumpStart client boots, the boot PROM broadcasts a RARP request to the local subnet.
The in.rarpd daemon on the boot server processes the client's RARP request by:
Looking up the client's Ethernet address and host name in the /etc/ethers file
Checking for a corresponding host name in the /etc/hosts file
Returning the associated IP address to the client
The client's boot programmable read-only memory (PROM) sends a TFTP request for a network bootstrap program.
The in.tftpd daemon on the boot server processes the client's TFTP request. The daemon searches the /tftpboot directory for a file with a hexadecimal representation of the client's IP address. The hexadecimal representation is the name of the file. This file is a symbolic link that points to a network bootstrap program.
The in.tftpd daemon on the boot server returns the network bootstrap program to the JumpStart client.
The JumpStart client runs the network bootstrap program.
The network bootstrap program issues a whoami request to discover the JumpStart client's host name.
The rpc.bootparamd daemon on the boot server looks up the client's host name, and returns it to the client.
The network bootstrap program issues a getfile request to obtain the location of the root (/) file system.
The server responds with the location of the root (/) file system, obtained from the appropriate source:
The /etc/bootparams file.
A name service such as NIS , NIS+, LDAP.
After the client obtains its boot parameters, the network bootstrap program mounts the root (/) file system from the boot server.
The client loads its kernel and starts the init program. When the JumpStart client finishes booting, it attempts to find configuration information.
The client searches for the configuration server using BOOTPARAMS information. The client mounts the configuration directory, and runs the sysidtool daemon.
The client uses BOOTPARAMS information to locate and mount the Solaris Operating System installation image.
The client runs the suninstall program and installs the Solaris Operating System.

Monday, September 25, 2006

DNS Short Hand For Netmasks

The number in the "/xx" shorthand stands for the number of bits (technically, bits set to one) in the subnet mask. The convention is always to start at the left end of the 32-bit subnet mask. The table below shows the correspondence between the "/xx" notation and the actual numeric representation.

Subnet Mask # of Addresses
/1 128.0.0.0 2.1 billion
/2 192.0.0.0 1 billion
/3 224.0.0.0 536 million
/4 240.0.0.0 268 million
/5 248.0.0.0 134 million
/6 252.0.0.0 67 million
/7 254.0.0.0 34 million
/8 255.0.0.0 17 million (Class A)
/9 255.128.0.0 8.4 million
/10 255.192.0.0 4.2 million
/11 255.224.0.0 2.1 million
/12 255.240.0.0 1 million
/13 255.248.0.0 524 thousand
/14 255.252.0.0 262 thousand
/15 255.254.0.0 131 thousand
/16 255.255.0.0 65,534 (Class B)
/17 255.255.128.0 32,766
/18 255.255.192.0 16,382
/19 255.255.224.0 8,190
/20 255.255.240.0 4,094
/21 255.255.248.0 2,046
/22 255.255.252.0 1,022
/23 255.255.254.0 510
/24 255.255.255.0 254 (Class C)
/25 255.255.255.128 126
/26 255.255.255.192 62
/27 255.255.255.224 30 (254-224)
/28 255.255.255.240 14 (254-240)
/29 255.255.255.248 6 (254-248 or 2*2*2-2)
/30 255.255.255.252 2 (254-252 or 2*2-2)
/31 255.255.255.254 RFC 3021
/32 255.255.255.255 Loopback address

Tuesday, August 29, 2006

Staring from today

I got Richard McDougall and Jim Mauro's 'Solaris Internals' at a Sun reception for a Major Investment Bank on Christmas time of 2000. The book was personally signed by Jim. It a shame that I never read the book.The BigAdmin news leter announce that the book is at is second editions now, which covers Solaris 10. I have just downloaded a chapter and here is my starting point.