IBM High Performance Storage System HPSS Installation Manual page 306

High performance storage system
Hide thumbs Also See for High Performance Storage System HPSS:
Table of Contents

Advertisement

*
HPSS_AUTHZ_TYPES
*
HPSS_SITE_LOCATION
*
KRB5_INSTALL_PATH
*
*
KRB5_KDC_DIR
config
*
*
KRB5_KDC_HOST
mkhpss)
*
HPSS_LDAP_URL
*
If set and non-empty, specifies the URL of the LDAP server that
*
the hpss ldap admin tool should connect to by default.
*
HPSS_LDAP_SSL_KEYDB
*
If set and non-empty, specifies the path to the SSL key db
*
to use for SSL and indicates that SSL should be used to
*
communicate with LDAP servers.
*
assumed that that a corresponding password stash file
*
exists as well.
*
the HPSS stash file used for SIMPLE LDAP binding.
*
*
Do not set a default value; unset means something.
*
*
HPSS_LDAP_BIND_TYPE
*
Specifies the type of binding that should be done with LDAP
servers.
*
This is independent of whether SSL is used in the connection to
*
the LDAP server.
you
*
use GSSAPI, for example:
*
- NONE - no bind is done; unauthenticated access
*
- SIMPLE - simple (i.e. dn/password binding) determined by the
*
*
*
*
*
*
- GSSAPI - Kerberos binding via SASL.
*
- (other) - an error is generated
*
*
Do not set a default value; unset means something.
*
*
HPSS_LDAP_BIND_ARG
*
Specifies further data necessary to complete a bind.
*
Interpretation is based on the setting of
*
HPSS_LDAP_BIND_TYPE (which see).
*
*
Do not set a default value; unset means something.
*
**************************************************************************
*
*/
{ "HPSS_SEC_REALM_NAME",
{ "HPSS_SITE_NAME",
{ "HPSS_SEC_REALM_ADMIN",
{ "HPSS_KRB5_AUTHN_MECH",
{ "HPSS_KRB5_KEYTAB_FILE",
NULL},
{ "HPSS_UNIX_AUTHN_MECH",
{ "HPSS_UNIX_KEYTAB_FILE",
{HPSS_PATH_ETC}/hpss.unix.keytab",
NULL},
{ "HPSS_PRIMARY_AUTHN_MECH",
HPSS Installation Guide
Release 6.2 (Revision 2.0)
This is the SSL stash (.sth) file, not
You can still have encrypted communication if
settings of the following:
- if HPSS_LDAP_BIND_ARG is set, it specifies the path to a
stash file containing the dn and password to use; see
ldap_stash.template for an example.
if not set, an error is generated.
- Supported authorization types
- Site Location
- Kerberos installation path
no default - platform dependent
- Kerberos directory containing local
files for KDC
- Host for Kerberos KDC (just used by
If this is used, it is
"%L",
"%H",
"admin/admin",
"krb5",
"${HPSS_PATH_ETC}/hpss.keytab",
"unix",
"$
"${HPSS_KRB5_AUTHN_MECH}",
July 2008
NULL},
NULL},
NULL},
NULL},
NULL},
306

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hpss 6.2

Table of Contents