This soft copy for use by IBM employees only.
3.7.5 dsh and p* Commands
The
dsh
command uses rsh to execute a specific AIX command on any group of
nodes or other remote RS/6000 hosts within the authentication realm, in parallel.
The group of target hosts may be pointed to by the WCOLL variable, which in
turn points to a file containing the hostname of each target host.
There are various
p*
commands (
p_cat, pcp, pdf, pfck
), which all use dsh to
execute a specific AIX command in parallel on multiple hosts.
3.7.6 rsh and rcp
There is a Kerberos-authenticated version of both
rsh
and
rcp
in the
/usr/lpp/ssp/rcmd/bin directory. To use the Kerberos versions, the user must
include this directory before the /usr/bin directory in the local host
′
s PATH.
If the user
′
s authentication fails, the
/usr/lpp/ssp/rcmd/rsh
(or
rcp
) command
issues an error message and passes its arguments to
/usr/bin/rsh
(or
rcp
). In
this case the user will require normal remote command access to the remote
host (through /etc/hosts.equiv or $HOME/.rhosts).
3.7.7 sysctl
The
sysctl
command provides a command line interface for communicating with
the sysctl remote command execution and monitoring server, sysctld. Sysctl
connects to a remote host
′
s sysctld using TCP/IP, passes keywords and
commands to the server, and writes output returned to stdout. Any sysctl user
must be a Kerberos principal.
3.8 Solving Problems
There are a few basic things to check when Kerberos authentication fails. The
following hints and tips should be followed before taking the more drastic
measure of rebuilding the entire Kerberos database. Also consult Chapter 6,
“Diagnosing Authentication Problems,” in the
RS/6000 Scalable POWERparallel
Systems: Diagnosis and Messages Guide, GC23-3899 for further information.
3.8.1 Daemons
Start by checking that both the kerberos and the kadmind daemons are running.
If the daemons are not running, then check /etc/inittab. The entries for these
two daemons should be similar to the following:
root@sp21cw0 /etc > lsitab kerb
kerb:2:respawn:/usr/lpp/ssp/kerberos/etc/kerberos
root@sp21cw0 /etc > lsitab kadm
kadm:2:respawn:/usr/lpp/ssp/kerberos/etc/kadmind -n
Figure 34. inittab Entries for Kerberos Daemons
If the /etc/inittab file is correct, then try to start the daemons from the command
line. Also check the Kerberos daemon log files in the /var/adm/SPlogs/kerberos
directory for any error messages, which may explain why the daemons cannot
be respawned.
82
SP PD Guide
Summary of Contents for RS/6000 SP
Page 2: ......
Page 14: ...This soft copy for use by IBM employees only xii SP PD Guide...
Page 16: ...This soft copy for use by IBM employees only xiv SP PD Guide...
Page 106: ...This soft copy for use by IBM employees only 86 SP PD Guide...
Page 178: ...This soft copy for use by IBM employees only 158 SP PD Guide...
Page 214: ...This soft copy for use by IBM employees only 194 SP PD Guide...
Page 248: ...This soft copy for use by IBM employees only 228 SP PD Guide...
Page 290: ...This soft copy for use by IBM employees only 270 SP PD Guide...
Page 292: ...This soft copy for use by IBM employees only 272 SP PD Guide...
Page 300: ...This soft copy for use by IBM employees only 280 SP PD Guide...
Page 304: ...This soft copy for use by IBM employees only 284 SP PD Guide...
Page 308: ...This soft copy for use by IBM employees only 288 SP PD Guide...
Page 310: ...This soft copy for use by IBM employees only 290 SP PD Guide...
Page 316: ...IBML This soft copy for use by IBM employees only Printed in U S A SG24 4778 00...