Please enter search query.
Search <book_title>...
Cluster Server 7.3.1 Configuration and Upgrade Guide - Solaris
Last Published:
2019-04-17
Product(s):
InfoScale & Storage Foundation (7.3.1)
Platform: Solaris
- Section I. Configuring Cluster Server using the script-based installer
- I/O fencing requirements
- Preparing to configure VCS clusters for data integrity
- About planning to configure I/O fencing
- Setting up the CP server
- Configuring VCS
- Configuring a secure cluster node by node
- Verifying and updating licenses on the system
- Configuring VCS clusters for data integrity
- Setting up disk-based I/O fencing using installer
- Setting up server-based I/O fencing using installer
- Section II. Automated configuration using response files
- Performing an automated VCS configuration
- Performing an automated I/O fencing configuration using response files
- Section III. Manual configuration
- Manually configuring VCS
- Configuring LLT manually
- Configuring VCS manually
- Configuring VCS in single node mode
- Modifying the VCS configuration
- Manually configuring the clusters for data integrity
- Setting up disk-based I/O fencing manually
- Setting up server-based I/O fencing manually
- Configuring server-based fencing on the VCS cluster manually
- Setting up non-SCSI-3 fencing in virtual environments manually
- Setting up majority-based I/O fencing manually
- Manually configuring VCS
- Section IV. Upgrading VCS
- Planning to upgrade VCS
- Performing a VCS upgrade using the installer
- Tasks to perform after upgrading to 2048 bit key and SHA256 signature certificates
- Performing an online upgrade
- Performing a rolling upgrade of VCS
- Performing a phased upgrade of VCS
- About phased upgrade
- Performing a phased upgrade using the product installer
- Performing an automated VCS upgrade using response files
- Upgrading VCS using Live Upgrade and Boot Environment upgrade
- Planning to upgrade VCS
- Section V. Adding and removing cluster nodes
- Adding a node to a single-node cluster
- Adding a node to a single-node cluster
- Adding a node to a multi-node VCS cluster
- Manually adding a node to a cluster
- Setting up the node to run in secure mode
- Configuring I/O fencing on the new node
- Adding a node using response files
- Removing a node from a VCS cluster
- Removing a node from a VCS cluster
- Removing a node from a VCS cluster
- Adding a node to a single-node cluster
- Section VI. Installation reference
- Appendix A. Services and ports
- Appendix B. Configuration files
- Appendix C. Configuring LLT over UDP
- Using the UDP layer for LLT
- Manually configuring LLT over UDP using IPv4
- Manually configuring LLT over UDP using IPv6
- Appendix D. Configuring the secure shell or the remote shell for communications
- Appendix E. Installation script options
- Appendix F. Troubleshooting VCS configuration
- Appendix G. Sample VCS cluster setup diagrams for CP server-based I/O fencing
- Appendix H. Reconciling major/minor numbers for NFS shared disks
- Appendix I. Upgrading the Steward process
Configuring the authentication broker on node sys5
To configure the authentication broker on node sys5
- Extract the embedded authentication files and copy them to temporary directory:
# mkdir -p /var/VRTSvcs/vcsauth/bkup
# cd /tmp; gunzip -c /opt/VRTSvcs/bin/VxAT.tar.gz | tar xvf -
- Edit the setup file manually:
# cat /etc/vx/.uuids/clusuuid 2>&1
The output is a string denoting the UUID. This UUID (without { and }) is used as the ClusterName for the setup file.
{UUID}
# cat /tmp/eat_setup 2>&1
The file content must resemble the following example:
AcceptorMode=IP_ONLY
BrokerExeName=vcsauthserver
ClusterName=UUID
DataDir=/var/VRTSvcs/vcsauth/data/VCSAUTHSERVER
DestDir=/opt/VRTSvcs/bin/vcsauth/vcsauthserver
FipsMode=0
IPPort=14149
RootBrokerName=vcsroot_uuid
SetToRBPlusABorNot=0
SetupPDRs=1
SourceDir=/tmp/VxAT/version
- Set up the embedded authentication file:
# cd /tmp/VxAT/version/bin/edition_number; \ ./broker_setup.sh/tmp/eat_setup
# /opt/VRTSvcs/bin/vcsauth/vcsauthserver/bin/vssregctl -s -f /var/VRTSvcs/vcsauth/data/VCSAUTHSERVER/root/.VRTSat/profile \ /VRTSatlocal.conf -b 'Security\Authentication \ \Authentication Broker' -k UpdatedDebugLogFileName \ -v /var/VRTSvcs/log/vcsauthserver.log -t string
- Copy the broker credentials from one node in the cluster to sys5 by copying the entire
bkup
directory.The
bkup
directory content resembles the following example:# cd /var/VRTSvcs/vcsauth/bkup/
# ls
CMDSERVER HAD VCS_SERVICES WAC
- Import the VCS_SERVICES domain.
# /opt/VRTSvcs/bin/vcsauth/vcsauthserver/bin/atutil import -z \ /var/VRTSvcs/vcsauth/data/VCSAUTHSERVER -f /var/VRTSvcs/vcsauth/bkup \ /VCS_SERVICES -p password
- Import the credentials for HAD, CMDSERVER, and WAC.
# /opt/VRTSvcs/bin/vcsauth/vcsauthserver/bin/atutil import -z \ /var/VRTSvcs/vcsauth/data/VCS_SERVICES -f /var/VRTSvcs/vcsauth/bkup \ /HAD -p password
- Start the vcsauthserver process on sys5.
# /opt/VRTSvcs/bin/vcsauth/vcsauthserver/bin/vcsauthserver.sh
- Perform the following tasks:
# mkdir /var/VRTSvcs/vcsauth/data/CLIENT
# mkdir /var/VRTSvcs/vcsauth/data/TRUST
# export EAT_DATA_DIR='/var/VRTSvcs/vcsauth/data/TRUST'
# /opt/VRTSvcs/bin/vcsauth/vcsauthserver/bin/vssat setuptrust -b \ localhost:14149 -s high
- Create the
/etc/VRTSvcs/conf/config/.secure
file:# touch /etc/VRTSvcs/conf/config/.secure