<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>unixwiz &#187; AIX</title>
	<atom:link href="http://blogs.sungeek.net/unixwiz/category/aix/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.sungeek.net/unixwiz</link>
	<description>anything dealing with *NIX or what ever I want to write about</description>
	<lastBuildDate>Fri, 02 Jul 2010 02:28:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>AIX Most secure OS? Think not.</title>
		<link>http://blogs.sungeek.net/unixwiz/2009/02/15/aix-most-secure-os-think-not/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2009/02/15/aix-most-secure-os-think-not/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 22:44:48 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Interesting]]></category>
		<category><![CDATA[MacOSX]]></category>
		<category><![CDATA[Random Stuff]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[Rant]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=1061</guid>
		<description><![CDATA[IBM&#8217;s Xforce published their new 2008 annual report. In it they had this chart: Surprising is that IBM put&#8217;s one of their own OS&#8217;s near the bottom of the list. Some of my opinions are : 1. No one uses AIX that much, so no one looks for holes in the code. 2. Any one [...]]]></description>
			<content:encoded><![CDATA[<p>IBM&#8217;s Xforce published their new 2008 annual report.  In it they had this chart:<br />
<img src="http://blogs.sungeek.net/unixwiz/wp-content/uploads/2009/02/xforce2008.png" alt="xforce2008" title="xforce2008" width="515" height="690" class="alignnone size-full wp-image-1062" /></p>
<p>Surprising is that IBM put&#8217;s one of their own OS&#8217;s near the bottom of the list. Some of my opinions are :</p>
<p>1. No one uses AIX that much, so no one looks for holes in the code.<br />
2. Any one who uses AIX, doesn&#8217;t have it directly connected to the Internet.<br />
3. It is so cost prohibitive to use, that people are looking at Solaris/Linux or Windows to run their business on.</p>
<p>But the funniest thing about this is the last I used AIX the following were still done on install by IBM:<br />
1. telnet enabled<br />
2. root logins allowed remotely<br />
3. no ssh comes with the OS, you have to install a crappy &#8220;linux toolkit&#8221;, and then install another 10 different packages to get SSH enabled.<br />
4. No RBAC<br />
5. Syslog configuration does not exist<br />
6. Root does not even have a password on install</p>
<p>Seems to me that IBM needs to fix some fundamental issues with their OWN OS before they can say it is not one of the &#8220;Most Vulnerable Operating Systems&#8221;.</p>
<p>The funniest issue with this is for MacOSX to be listed at the top, all most all of those require some one to actually run something on the machine with administrative privileges.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2009/02/15/aix-most-secure-os-think-not/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>AIX LDAP Replication</title>
		<link>http://blogs.sungeek.net/unixwiz/2007/05/17/aix-ldap-replication/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2007/05/17/aix-ldap-replication/#comments</comments>
		<pubDate>Thu, 17 May 2007 23:57:57 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[LDAP]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=746</guid>
		<description><![CDATA[a while ago I wrote about getting AIX authenticating to a SUN LDAP because of problems with AIX&#8217;s LDAP replication that I was having.. I forgot to mention that I &#8220;fixed&#8221; the AIX LDAP Replication problem. The solution was to put the FQDN of each &#8220;master&#8221; server in the /etc/hosts file with the IP address [...]]]></description>
			<content:encoded><![CDATA[<p>a while <a href="http://blogs.sungeek.net/unixwiz/?p=718">ago</a> I wrote about getting AIX authenticating to a SUN LDAP because of problems with AIX&#8217;s LDAP replication that I was having.. I forgot to mention that I &#8220;fixed&#8221; the AIX LDAP Replication problem. The solution was to put the FQDN of each &#8220;master&#8221; server in the /etc/hosts file with the IP address associated with it. It seems that IBM&#8217;s LDAP server is completely brain dead when it comes to DNS and LDAP, and would not replicate correctly unless I put the master server&#8217;s IP&#8217;s in the /etc/hosts.. So if you are having problems with getting replication to work with IBM&#8217;s LDAP server, try putting the entries in /etc/hosts and I bet it will work.. </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2007/05/17/aix-ldap-replication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AIX LDAP to Sun LDAP in 10 Semi Easy Steps</title>
		<link>http://blogs.sungeek.net/unixwiz/2007/02/27/aix-ldap-to-sun-ldap-in-5-semi-easy-steps/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2007/02/27/aix-ldap-to-sun-ldap-in-5-semi-easy-steps/#comments</comments>
		<pubDate>Wed, 28 Feb 2007 00:44:31 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Interesting]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[Solaris]]></category>
		<category><![CDATA[Work]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=718</guid>
		<description><![CDATA[I have been having some problems getting IBM&#8217;s Tivoli Directory Server to replicate properly. So I decided to try and see what it would take to move the IBM AIX machines from using IBM&#8217;s LDAP Server to using Sun&#8217;s LDAP Server. This is what I hope to accomplish: Setup Sun&#8217;s JES Directory Server on a [...]]]></description>
			<content:encoded><![CDATA[<p>I have been having some problems getting IBM&#8217;s Tivoli Directory Server to replicate properly. So I decided to try and see what it would take to move the IBM AIX machines from using IBM&#8217;s LDAP Server to using Sun&#8217;s LDAP Server. This is what I hope to accomplish:</p>
<ol>
<li>Setup Sun&#8217;s JES Directory Server on a Solaris 10 machine</li>
<li>Configure the DS to have the AIX schema and objectclasses needed for user and group info</li>
<li>Configure a AIX test machine to authenticate against the Sun LDAP Server</li>
<li>Eventually move all AIX machines from the IBM DS to Sun DS, thereby having one set of servers that control all users/passwords for all Sun/Linux/AIX machines</li>
</ol>
<p><strong>Step 1: AIX Schema</strong><br />
The first thing I had to overcome is how AIX has 4 different ways of using LDAP for authentication. AIX 4.3.3 and AIX 5.1 used a non RFC2307 compliant schema. AIX 5.2 and AIX 5.3 can use this old schema or RFC2307, or a new one called RFC2307AIX, which combines the old with the new (there is also another one that I will not cover). When I originally setup the IBM LDAP I used the RFC2307AIX because it allows me to store ulimits and other info about AIX accounts in LDAP and not on each individual machine. But this also makes it harder to port these things over to Sun&#8217;s LDAP. Which lead me to yesterday&#8217;s afternoon adventure, creating a schema file that would work. I will link to my final copy below.</p>
<p><strong>Step 2: AIX ObjectClasses</strong><br />
Second up was to create the objectclasses required for AIX Authentication, which consisted of creating the eAccount, AIXAccount,AIXaccessGroup, ibm-SecurityIdentities, container, and account. Some of these may not be needed for a fresh install, but I am trying to move entries from IBM&#8217;s LDAP to Sun&#8217;s LDAP with the least amount of editing an extremely huge ldap ldif export file. I will link to my final copy of this file below as well.</p>
<p><strong>Step 3: Install JES DS</strong><br />
The third step was to download and install the DS 5.2.P4 on my fresh install of Solaris 10 U3 running on a Sparc machine. I did the custom install as I wanted to change the location of where it was installed to. The other thing I did is not load any sample data. Once the install was done, I ran the /usr/lib/ldap/idsconfig script to setup the DS. This is sort of how it went (copied from another doc):</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">It is strongly recommended that you BACKUP the directory server <br />
&nbsp;before running idsconfig. </p>
<p>&nbsp;Hit Ctrl-C at any <span class="kw1">time</span> before the final confirmation to <span class="kw3">exit</span>. </p>
<p>&nbsp;Do you wish to <span class="kw3">continue</span> with server setup <span class="br0">&#40;</span>y/n/h<span class="br0">&#41;</span>? <span class="br0">&#91;</span>n<span class="br0">&#93;</span> y <br />
&nbsp;Enter the iPlanet Directory Server<span class="st0">&#8216;s (iDS) hostname to setup: ldap2 <br />
&nbsp;Enter the port number for iDS (h=help): [389] 389 <br />
&nbsp;Enter the directory manager DN: [cn=Directory Manager] cn=Directory Manager <br />
&nbsp;Enter passwd for cn=Directory Manager : <br />
&nbsp;Enter the domainname to be served (h=help): [ldap2.example.com] ldap2.example.com <br />
&nbsp;Enter LDAP Base DN (h=help): [dc=example,dc=com] dc=example,dc=com<br />
&nbsp;Enter the profile name (h=help): [default] default <br />
&nbsp;Default server list (h=help): [192.168.1.2] 192.168.1.2 <br />
&nbsp;Preferred server list (h=help): <br />
&nbsp;Choose desired search scope (one, sub, h=help): &nbsp;[one] one <br />
&nbsp;The following are the supported credential levels: <br />
&nbsp; &nbsp;1 &nbsp;anonymous <br />
&nbsp; &nbsp;2 &nbsp;proxy <br />
&nbsp; &nbsp;3 &nbsp;proxy anonymous <br />
&nbsp;Choose Credential level [h=help]: [1] 2 <br />
&nbsp;The following are the supported Authentication Methods: <br />
&nbsp; &nbsp;1 &nbsp;none <br />
&nbsp; &nbsp;2 &nbsp;simple <br />
&nbsp; &nbsp;3 &nbsp;sasl/DIGEST-MD5 <br />
&nbsp; &nbsp;4 &nbsp;tls:simple <br />
&nbsp; &nbsp;5 &nbsp;tls:sasl/DIGEST-MD5 <br />
&nbsp;Choose Authentication Method (h=help): [1] 2 </p>
<p>&nbsp;Current authenticationMethod: simple </p>
<p>&nbsp;Do you want to add another Authentication Method? n <br />
&nbsp;Do you want the clients to follow referrals (y/n/h)? [n] y <br />
&nbsp;Do you want to modify the server timelimit value (y/n/h)? [n] n <br />
&nbsp;Do you want to modify the server sizelimit value (y/n/h)? [n] n <br />
&nbsp;Do you want to store passwords in &quot;crypt&quot; format (y/n/h)? [n] y <br />
&nbsp;Do you want to setup a Service Authentication Methods (y/n/h)? [n] n <br />
&nbsp;Client search time limit in seconds (h=help): [30] <br />
&nbsp;Profile Time To Live in seconds (h=help): [43200] <br />
&nbsp;Bind time limit in seconds (h=help): [10] <br />
&nbsp;Do you wish to setup Service Search Descriptors (y/n/h)? [n] n <br />
&nbsp;<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Summary of Configuration </p>
<p>&nbsp; &nbsp;1 &nbsp;Domain to serve &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : example.com <br />
&nbsp; &nbsp;2 &nbsp;Base DN to setup &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: dc=example,dc=com <br />
&nbsp; &nbsp;3 &nbsp;Profile name to create &nbsp; &nbsp; &nbsp; &nbsp;: default <br />
&nbsp; &nbsp;4 &nbsp;Default Server List &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : 192.168.1.2<br />
&nbsp; &nbsp;5 &nbsp;Preferred Server List &nbsp; &nbsp; &nbsp; &nbsp; : <br />
&nbsp; &nbsp;6 &nbsp;Default Search Scope &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: one <br />
&nbsp; &nbsp;7 &nbsp;Credential Level &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: proxy <br />
&nbsp; &nbsp;8 &nbsp;Authentication Method &nbsp; &nbsp; &nbsp; &nbsp; : simple <br />
&nbsp; &nbsp;9 &nbsp;Enable Follow Referrals &nbsp; &nbsp; &nbsp; : TRUE <br />
&nbsp; 10 &nbsp;iDS Time Limit &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: <br />
&nbsp; 11 &nbsp;iDS Size Limit &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: <br />
&nbsp; 12 &nbsp;Enable crypt password storage : TRUE <br />
&nbsp; 13 &nbsp;Service Auth Method pam_ldap &nbsp;: <br />
&nbsp; 14 &nbsp;Service Auth Method keyserv &nbsp; : <br />
&nbsp; 15 &nbsp;Service Auth Method passwd-cmd: <br />
&nbsp; 16 &nbsp;Search Time Limit &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : 30 <br />
&nbsp; 17 &nbsp;Profile Time to Live &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: 43200 <br />
&nbsp; 18 &nbsp;Bind Limit &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: 10 <br />
&nbsp; 19 &nbsp;Service Search Descriptors Menu </p>
<p>&nbsp;Enter config value to change: (1-19 0=commit changes) [0] 0 </p>
<p>&nbsp;Enter DN for proxy agent:<br />
[cn=proxyagent,ou=profile,dc=example,dc=com] <br />
&nbsp;Enter passwd for proxyagent: <br />
&nbsp;Re-enter passwd: <br />
&nbsp; &nbsp;<br />
&nbsp;WARNING: About to start committing changes. (y=continue, n=EXIT) y </p>
<p>&nbsp; &nbsp;1. Changed passwordstoragescheme to &quot;crypt&quot; in cn=config. <br />
&nbsp; &nbsp;2. Schema attributes have been updated. <br />
&nbsp; &nbsp;3. Schema objectclass definitions have been added. <br />
&nbsp; &nbsp;4. NisDomainObject added to dc=example,dc=com. <br />
&nbsp; &nbsp;5. Top level &quot;ou&quot; containers complete. <br />
&nbsp; &nbsp;6. automount maps: auto_home auto_direct auto_master auto_shared<br />
processed. <br />
&nbsp; &nbsp;7. ACI for dc=example,dc=com modified to disable self modify. <br />
&nbsp; &nbsp;8. Add of VLV Access Control Information (ACI). <br />
&nbsp; &nbsp;9. Proxy Agent cn=proxyagent,ou=profile,dc=example,dc=com added. <br />
&nbsp; &nbsp;10. Give cn=proxyagent,ou=profile,dc=example,dc=com read permission for password. <br />
&nbsp; &nbsp;11. Generated client profile and loaded on server. <br />
&nbsp; &nbsp;12. Processing eq,pres indexes: <br />
&nbsp; &nbsp; &nbsp; &nbsp;ipHostNumber (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;uidNumber (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;ipNetworkNumber (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;gidnumber (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;oncrpcnumber (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;automountKey (eq,pres) &nbsp; Finished indexing. <br />
&nbsp; &nbsp;13. Processing eq,pres,sub indexes: <br />
&nbsp; &nbsp; &nbsp; &nbsp;membernisnetgroup (eq,pres,sub) &nbsp; Finished indexing. <br />
&nbsp; &nbsp; &nbsp; &nbsp;nisnetgrouptriple (eq,pres,sub) &nbsp; Finished indexing. <br />
&nbsp; &nbsp;14. Processing VLV indexes: <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.getgrent vlv_index &nbsp; Entry created <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.gethostent vlv_index &nbsp; Entry created <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.getnetent vlv_index &nbsp; Entry created <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.getpwent vlv_index &nbsp; Entry created <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.getrpcent vlv_index &nbsp; Entry created <br />
&nbsp; &nbsp; &nbsp; &nbsp;example.com.getspent vlv_index &nbsp; Entry created </p>
<p>&nbsp;idsconfig: Setup of iDS server ldap2 is complete. <br />
&nbsp; &nbsp;</p>
<p>&nbsp;Note: idsconfig has created entries for VLV indexes. &nbsp;Use the <br />
&nbsp; &nbsp; &nbsp; &nbsp;directoryserver(1m) script on ldap2 to stop <br />
&nbsp; &nbsp; &nbsp; &nbsp;the server and then enter the following vlvindex <br />
&nbsp; &nbsp; &nbsp; &nbsp;sub-commands to create the actual VLV indexes: </p>
<p>
&nbsp;directoryserver -s &amp;lt;server -instance&amp;gt; vlvindex -n userRoot -T example.com.getgrent <br />
&#8230;much deleted&#8230;<br />
&nbsp;directoryserver -s &amp;lt;server -instance&amp;gt; vlvindex -n userRoot -T example.com.getspent</span></div>
</div>
<p>Unfortunately the &#8220;directoryserver&#8221; command does not exist in Solaris 10, so i did the following:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;"><span class="kw3">cd</span> /ldapserver/slapd-ldap2<br />
./stop-slapd<br />
./vlvindex -n userRoot -T example.com.getgrent<br />
./vlvindex -n userRoot -T example.com.gethostent<br />
./vlvindex -n userRoot -T example.com.getnetent<br />
./vlvindex -n userRoot -T example.com.getpwent<br />
./vlvindex -n userRoot -T example.com.getrpcent<br />
./vlvindex -n userRoot -T example.com.getspent<br />
./vlvindex -n userRoot -T example.com.getauhoent<br />
./vlvindex -n userRoot -T example.com.getsoluent<br />
./vlvindex -n userRoot -T example.com.getauduent<br />
./vlvindex -n userRoot -T example.com.getauthent<br />
./vlvindex -n userRoot -T example.com.getexecent<br />
./vlvindex -n userRoot -T example.com.getprofent<br />
./vlvindex -n userRoot -T example.com.getmailent<br />
./vlvindex -n userRoot -T example.com.getbootent<br />
./vlvindex -n userRoot -T example.com.getethent<br />
./vlvindex -n userRoot -T example.com.getngrpent<br />
./vlvindex -n userRoot -T example.com.getipnent<br />
./vlvindex -n userRoot -T example.com.getmaskent<br />
./vlvindex -n userRoot -T example.com.getprent<br />
./vlvindex -n userRoot -T example.com.getip4ent<br />
./vlvindex -n userRoot -T example.com.getip6ent<br />
./start-slapd</div>
</div>
<p>(I installed the ldap server to /ldapserver)</p>
<p>Now that the indexes are created we can go on to the next step of modifying the schema.</p>
<p><strong>Step 4: Importing new schema</strong><br />
Now I can import the AIXAttributes.ldif and the AIXObjectClasses.ldif files to my fresh newly installed server:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">ldapmodify -D<span class="st0">&quot;cn=Directory Manager&quot;</span> -<span class="kw2">w</span> MySuperSecretPass -h localhost -f AIXAttributes.ldif<br />
ldapmodify -D<span class="st0">&quot;cn=Directory Manager&quot;</span> -<span class="kw2">w</span> MySuperSecretPass -h localhost -f AIXObjectClasses.ldif</div>
</div>
<p>All should go well on the above imports. There were a couple of quirks that I found when creating the files, like how IBM uses one OID for a value when Sun uses a different one.</p>
<p><strong>Step 5: Creating an OU for AIX data</strong><br />
By this time I have fired up the Console for the LDAP server and was doing things through the gui. The first thing I did was create a new OU for my aix data, i.e. ou=aixdata,dc=example,dc=com. This OU is where all my AIX stuff will be, the ou=people,dc=example,dc=com will be where my Sun users will go. (Can&#8217;t combine them yet because of massive amounts of differing UIDS between the AIX users and Sun Users).</p>
<p>After creating this, create 2 more OU&#8217;s under the aixdata. The first one will be for all users, ou=aixuser,ou=aixdata,dc=example,dc=com. The second will be for group information, ou=aixgroup,ou=aixdata,dc=example,dc=com.</p>
<p><strong>Step 6: Create and AIX LDAP Admin Account</strong><br />
Because of how the AIX servers need to connect and get/put info into ldap, you will need to create an account that has read/write access to the 2 new ou&#8217;s you created. (This account is sort of similar to the Sun proxyagent account created with the idsconfig). I created my user, uid=aixldap,ou=aixdata,dc=example,dc=com. Also set the password for it to never expire (if you make it expire, you will have to update every AIX server every time the password expires). Once this user is created give it full read/write access to the ou=aixuser and ou=aixgroup with ACI&#8217;s.</p>
<p><strong>Step 7: Export info from IBM LDAP</strong><br />
Since I am planning on moving from IBM LDAP to Sun LDAP I need to export the data from my IBM LDAP to an ldif format:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">db2ldif -o /tmp/ldapexport.ldif</div>
</div>
<p>Do the above on the IBM LDAP server, it will put a file called /tmp/ldapexport.ldif. But now I need to &#8220;clean&#8221; some stuff out of it. Some of the stuff I need to remove is anything that is not User and Group related. For example I had IBM LDAP Replication setup so there are a ton of entries for that.  (so the only thing you should have in your ldif file are entries for the dn&#8217;s like username=*,ou=aixuser,ou=aixdata,dc=example,dc=com and groupname=*,ou=aixgroup,dc=example,dc=com<br />
)</p>
<p><strong>Step 8: Import users and groups</strong><br />
Next I imported the cleaned file:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">ldapadd -D<span class="st0">&quot;cn=Directory Manager&quot;</span> -<span class="kw2">w</span> SuperSecret -f /tmp/ldapexport.ldif</div>
</div>
<p>Now all your users and groups should be in the new ldap server. </p>
<p><strong>Step 9: Misc config in Sun LDAP</strong><br />
Some other stuff I did was add a couple indexes to the non-standard attributes that AIX uses:<br />
groupname<br />
username<br />
hostsallowedlogin</p>
<p>The hostsallowedlogin allows us to put an entry in the persons LDAP entry to say which hosts they can log in to. If the attribute does not exist they can log in to any host that is served by this LDAP server. But if they have a value in this attribute, they can only log in to those host(s). (there is also a hostsdeniedlogin, which is the opposite of the hostsallowedlogin, if you want them to log in to every machine but one you can just populate that single host in to the hostsdeniedlogin).</p>
<p><strong>Step 10: Configure AIX to talk to ldap server</strong><br />
One of the fall backs I don&#8217;t like about LDAP on AIX is that you have to have a local ldap user, and the ldap client software does not come with the base os. So you will have to install the ldap.client.adt and ldap.client.rte (probably don&#8217;t need the adt, but I install it anyways). During this install it usually creates the ldap user and group, which is never where we want it so either create an ldap group and ldap user before you install it, or after it is installed do the following, change the userid and groupid to what you want it to be in /etc/passwd and /etc/group and then run:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;"><span class="kw2">find</span> / -user OLDID -<span class="kw3">exec</span> <span class="kw2">chown</span> -h ldap <span class="br0">&#123;</span><span class="br0">&#125;</span> \;<br />
<span class="kw2">find</span> / -group OLDID -<span class="kw3">exec</span> <span class="kw2">chgrp</span> -h ldap <span class="br0">&#123;</span><span class="br0">&#125;</span> \;</div>
</div>
<p>Now we can run the mksecldap command:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">mksecldap -c -h <span class="st0">&#8216;ldap2.example.com&#8217;</span> \<br />
-a <span class="st0">&#8216;uid=aixldap,ou=aixdata,dc=example,dc=com&#8217;</span> -p <span class="st0">&#8216;myp@ss&#8217;</span> &nbsp;\<br />
-d <span class="st0">&#8216;ou=aixdata,dc=example,dc=com&#8217;</span> -n <span class="st0">&#8217;389&#8242;</span> -t <span class="st0">&#8217;0&#8242;</span> -T <span class="st0">&#8217;100&#8242;</span></div>
</div>
<p>The above is all on one line. You must make sure the -t is set to 0, if it is not then you will get some weirdness that I will talk about later. </p>
<p>Once this is done, then you need to tell AIX that it is to look in LDAP for it&#8217;s info, you will need to edit another file /etc/security/user:</p>
<p>in the &#8220;default:&#8221; stanza, you will need to change the SYSTEM variable to LDAP, and add a registry variable with the value of LDAP. </p>
<p>I.E.:</p>
<div class="codesnip-container" >default:<br />
        admin = false<br />
        login = true<br />
        su = true<br />
        daemon = true<br />
        rlogin = true<br />
        sugroups = ALL<br />
        admgroups =<br />
        ttys = ALL<br />
        auth1 = SYSTEM<br />
        auth2 = NONE<br />
        tpath = nosak<br />
        umask = 022<br />
        expires = 0<br />
        <strong>SYSTEM = LDAP<br />
        registry = LDAP</strong><br />
        logintimes =<br />
        pwdwarntime = 0<br />
        account_locked = false<br />
        loginretries = 0<br />
        histexpire = 0<br />
        histsize = 0<br />
        minage = 0<br />
        maxage = 0<br />
        maxexpired = -1<br />
        minalpha = 0<br />
        minother = 0<br />
        minlen = 0<br />
        mindiff = 0<br />
        maxrepeats = 8<br />
        dictionlist =<br />
        pwdchecks =</div>
<p>Now you should be able to do an id username, and see some results:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">AIXHost&gt; <span class="kw2">id</span> unixwiz<br />
<span class="re2">uid=</span><span class="nu0">106</span><span class="br0">&#40;</span>unixwiz<span class="br0">&#41;</span> <span class="re2">gid=</span><span class="nu0">1</span><span class="br0">&#40;</span>staff<span class="br0">&#41;</span> <span class="re2">groups=</span><span class="nu0">0</span><span class="br0">&#40;</span>system<span class="br0">&#41;</span>,<span class="nu0">7</span><span class="br0">&#40;</span>security<span class="br0">&#41;</span>,<span class="nu0">9</span><span class="br0">&#40;</span>printq<span class="br0">&#41;</span></div>
</div>
<p>Next up try logging in remotely (you may have to create your home directory first). It should work.</p>
<p><strong>Some Notes</strong></p>
<ol>
<li>If you do not set the cachetimeout to be 0, if you change a users password as root, the user will get thrown in to a loop of changing their passwords. I.E. They will never be able to login as everytime they login it will say their password has expired and make them change it again and then it will kick them off (ie close their ssh session). Lather/rinse/repeat.</li>
<li>After importing the users from an existing IBM server, you can delete the IBM-ENTRYUUID and the control attributes, they are for IBM DS only and have no use in Sun&#8217;s LDAP.</li>
<li>Any problems on the import/etc, make sure to look at the ldap server error logs (/ldapserver/slapd-ldap2/logs/error_log) it should tell you exactly what is wrong.</li>
<li>If you replicate this LDAP server, you should probably do a Master/Master relationship because of how AIX always stores info about last logins/etc in LDAP. I have not tested yet if it can follow referrals yet.</li>
</ol>
<p>Here are the two files I was talking about:</p>
<p><a href="/unixwiz/data/2007-02-27/AIXAttributes.ldif">AIXAttributes.ldif</a><br />
<a href="/unixwiz/data/2007-02-27/AIXObjectClasses.ldif">AIXObjectClasses.ldif</a></p>
<p>Some other links:<br />
<a href="http://www.redbooks.ibm.com/abstracts/sg247165.html?Open">IBM&#8217;s Redbook : Integrating AIX into Heterogeneous LDAP Environments</a>, which I found was missing some stuff</p>
<p><a href="http://sunsolve.sun.com/search/document.do?assetkey=1-9-67966-1">Sun&#8217;s Cookbook for Solaris 8 client with Directory Server 5.1/Solaris 9</a> which I follow some times if I need to connect Solaris 8 machines in.</p>
<p>Hope this helps some one, if it does leave me a message.</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/IBM" rel="tag">IBM</a>, <a href="http://technorati.com/tag/Sun" rel="tag">Sun</a>, <a href="http://technorati.com/tag/LDAP" rel="tag">LDAP</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2007/02/27/aix-ldap-to-sun-ldap-in-5-semi-easy-steps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting AIX tip</title>
		<link>http://blogs.sungeek.net/unixwiz/2006/09/29/interesting-aix-tip/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2006/09/29/interesting-aix-tip/#comments</comments>
		<pubDate>Fri, 29 Sep 2006 21:04:44 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=642</guid>
		<description><![CDATA[Ever wonder were all the space went in a file system? Does du and df show different results on the same file system? Chances are some one deleted a file that was open in a particular file system. For example the /tmp file system on one of our machines has been filling up and then [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wonder were all the space went in a file system? Does du and df show different results on the same file system? Chances are some one deleted a file that was open in a particular file system. For example the /tmp file system on one of our machines has been filling up and then some one was deleting files from it. But the space is never recovered. In the AIX errpt you may see something like this:</p>
<div class="codesnip-container" >LABEL:          JFS_FS_FULL<br />
IDENTIFIER:     369D049B</p>
<p>Date/Time:       Wed Sep 27 16:58:08 2006<br />
Sequence Number: 780<br />
Machine Id:      002AA9AF4C00<br />
Node Id:         aixbox<br />
Class:           O<br />
Type:            INFO<br />
Resource Name:   SYSPFS</p>
<p>Description<br />
UNABLE TO ALLOCATE SPACE IN FILE SYSTEM</p>
<p>Probable Causes<br />
FILE SYSTEM FULL</p>
<p>        Recommended Actions<br />
        USE FUSER UTILITY TO LOCATE UNLINKED FILES STILL REFERENCED<br />
        INCREASE THE SIZE OF THE ASSOCIATED FILE SYSTEM<br />
        REMOVE UNNECESSARY DATA FROM FILE SYSTEM</p>
<p>Detail Data<br />
MAJOR/MINOR DEVICE NUMBER<br />
000A 0007<br />
FILE SYSTEM DEVICE AND MOUNT POINT<br />
/dev/hd3, /tmp</p></div>
<p>The hint to finding the files is given in the first line of the recommended actions. Use the fuser command. The actual command is:
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;"><span class="kw2">fuser</span> -dV /tmp</div>
</div>
<p>What this will show you is something similar to this:</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">root@aixbox:/&gt;fuser -dV /tmp<br />
/tmp:<br />
<span class="re2">inode=</span><span class="nu0">34</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">675155</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">200858</span><br />
<span class="re2">inode=</span><span class="nu0">43</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">114531</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">286764</span><br />
<span class="re2">inode=</span><span class="nu0">66</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">59021846</span> &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">335986</span><br />
<span class="re2">inode=</span><span class="nu0">77</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">2322588</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">389232</span><br />
<span class="re2">inode=</span><span class="nu0">46</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">601938</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">413872</span><br />
<span class="re2">inode=</span><span class="nu0">61</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">28498</span> &nbsp; &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">430332</span><br />
<span class="re2">inode=</span><span class="nu0">44</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">1280774965</span> &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">434292</span><br />
<span class="re2">inode=</span><span class="nu0">40</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">2884063</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">442590</span><br />
<span class="re2">inode=</span><span class="nu0">51</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">2395908</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">467132</span><br />
<span class="re2">inode=</span><span class="nu0">73</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">8224333</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">479402</span><br />
<span class="re2">inode=</span><span class="nu0">42</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">140607</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">524474</span><br />
<span class="re2">inode=</span><span class="nu0">64</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">163405</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">553054</span><br />
<span class="re2">inode=</span><span class="nu0">49</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">350562</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">618644</span><br />
<span class="re2">inode=</span><span class="nu0">63</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">2375730</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">663568</span><br />
<span class="re2">inode=</span><span class="nu0">74</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">3372392</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">696356</span><br />
<span class="re2">inode=</span><span class="nu0">58</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">65535</span> &nbsp; &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; &nbsp;<span class="nu0">819204</span><br />
<span class="re2">inode=</span><span class="nu0">57</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">424777</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1106024</span><br />
<span class="re2">inode=</span><span class="nu0">62</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">2030397</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1147064</span><br />
<span class="re2">inode=</span><span class="nu0">76</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">57187</span> &nbsp; &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1163494</span><br />
<span class="re2">inode=</span><span class="nu0">31</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">1376255</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1171540</span><br />
<span class="re2">inode=</span><span class="nu0">56</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">53834</span> &nbsp; &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1216530</span><br />
<span class="re2">inode=</span><span class="nu0">52</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">361520961</span> &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1278152</span><br />
<span class="re2">inode=</span><span class="nu0">81</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">15972886</span> &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1294462</span><br />
<span class="re2">inode=</span><span class="nu0">70</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">13390097</span> &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1323224</span><br />
<span class="re2">inode=</span><span class="nu0">60</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">7559</span> &nbsp; &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1380400</span><br />
<span class="re2">inode=</span><span class="nu0">50</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">40132</span> &nbsp; &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1429514</span><br />
<span class="re2">inode=</span><span class="nu0">65</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">720895</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1450220</span><br />
<span class="re2">inode=</span><span class="nu0">79</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">12582477</span> &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1507350</span><br />
<span class="re2">inode=</span><span class="nu0">47</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">169682</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1593582</span><br />
<span class="re2">inode=</span><span class="nu0">48</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">259432</span> &nbsp; &nbsp; &nbsp; <span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1605642</span><br />
<span class="re2">inode=</span><span class="nu0">78</span> &nbsp; &nbsp; <span class="re2">size=</span><span class="nu0">1488191</span> &nbsp; &nbsp; &nbsp;<span class="re2">fd=</span><span class="nu0">0</span> &nbsp; &nbsp; <span class="nu0">1671280</span></div>
</div>
<p>The column we are really interested in is the last one. That is the column that contains the Process ID of the process that has a particular file open in that file system. So for example process id 1671280 has inode 78 in the /tmp file system open, and that file is using ~1.4MB of space. So if you &#8220;kill 1671280&#8243; you would recover the 1.4MB of space. (But make sure you kill it in the proper way, i.e. find out what the process really is and shut it down nicely.)</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2006/09/29/interesting-aix-tip/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Interesting stuff in the mail today</title>
		<link>http://blogs.sungeek.net/unixwiz/2006/06/15/interesting-stuff-in-the-mail-today/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2006/06/15/interesting-stuff-in-the-mail-today/#comments</comments>
		<pubDate>Fri, 16 Jun 2006 02:57:32 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[Funny]]></category>
		<category><![CDATA[IBM]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=597</guid>
		<description><![CDATA[Got a couple of magazines in the mail today. One is SysAdmin. Every once in a while they bundle something with it, todays bundle was a CDROM from IBM on &#8220;Migrating to Linux or AIX from Solaris OS&#8221;. It was one of their &#8220;RedBook&#8221; cdrom&#8217;s. Funny part to me is why would any one want [...]]]></description>
			<content:encoded><![CDATA[<p>Got a couple of magazines in the mail today. One is <a href="http://www.samag.com">SysAdmin</a>. Every once in a while they bundle something with it, todays bundle was a CDROM from IBM on &#8220;Migrating to Linux or AIX from Solaris OS&#8221;. It was one of their &#8220;RedBook&#8221; cdrom&#8217;s. Funny part to me is why would any one want to migrate from Solaris to Linux or AIX. I have been using AIX since about 1995, and to be honest, I would much rather use Solaris any day over AIX. The _only_ thing on AIX I &#8220;like&#8221; better is maybe printing. As for Linux, I have used it in the past, but in my own opinion it has fallen to it&#8217;s own success. Yeah a lot of people have learned how *NIX &#8220;works&#8221; by using it, but every day there is a distro coming out, and a new way of doing something. Basicly every distro has it&#8217;s own way of doing things and most of the time they don&#8217;t work on other distros. So for me I definately will not be migrating from Solaris to AIX or Linux, if any it would be the opposite. </p>
<p>The other magazine I got is the &#8220;IBM Systems Magainze&#8221;. It is funny reading through this &#8220;magazine&#8221; where everything is Pro-IBM and how much better it is than any thing else. One of the articles was &#8220;new&#8221; features to AIX 5.3, here are some of the things they list:</p>
<ul>
<li>An environment variable LD_LIBRARY_PATH for runtime library path has been added for compatibility with SVR4 bases systems.</li>
</ul>
<p>Interesting, that they say that as I have seen our DBA&#8217;s &#8220;misusing it&#8221; for years now. Doesn&#8217;t seem new to me..</p>
<p>Next up, in the base commands and libraries</p>
<ul>
<li>A new flag has been added to the tar command, which would specifiy the list of files and/or directories to be excludede from the tar file  being created,extracted or listed.</li>
<li>Text-processiong commands ed/vi/ex support unlimited line lengths</li>
<li>vi and ex can handle files up to 2GB</li>
<li>Support for unlimited number of fields and size of a line for awk</li>
<li>Cimand buffer sizes are unlimited, allowing an increased number of arguments o a command line</li>
</ul>
<p>Seems AIX tar is a little behind in the game.. (Not to mention that I am still not sure if it can handle largerfiles. And the problem it has with it&#8217;s own userid nobody which is something to large to fit in uid_t in a tar archive.)</p>
<p>That is all cool about VI being able to handle 2Gb files, but how often do normal SA&#8217;s want to edit a 2gb file. (DBA&#8217;s, maybe all the time, but I do not try to ever edit a file that big)..</p>
<p>The unlimited line length is a definate plus, but wonder if there is a buffer overflow in that.</p>
<p>And the funniest of all, (you probably have to be an AIX administrator to get this, but it sounds funny if you are not).:</p>
<ul>
<li>The PP size starts at 1MB and goes up to 128GB.</li>
</ul>
<p>If you read it aloud around people who are not AIX adminstrators, they will probably start laughing. (For those who are not AIX administrators a PP is a physical partition size. Each logical volume in a volume group is made up of physical partitions. )</p>
<p>Here is a quick AIX LVM overview:<br />
<img src="http://blogs.sungeek.net/unixwiz/wp-content/uploads/2006/06/aixlvm.png" alt="AIX LVM Overview"  /></p>
<p>Basicly, we have a volume group called &#8220;testvg&#8221; that has 4 harddrives in it, (hdisk1, 2,3,4). In this volume group there are 3  Logical volumes created that are mounted to /filesystem1, /fs2 and /fs3. In this example /filesystem1 is made up of 4 PP&#8217;s, /fs2 is made up of 3 PP&#8217;s, and /fs3 is made up of 2 PP&#8217;s. They do not have to be in sequential order and if in fact when you change the size of file systems (usually increasing) it will grab the next free PP assuming there is one in the file system. The PP size is the &#8220;minimum&#8221; size a file system can be made and increased. So if I were to say that the PP size of each of the PP&#8217;s in the testvg were 512MB, then /filesystem1 would be roughly 2 GB, /fs2 would be 1.5 gb, and /fs3 would be 1 gig. This volume group is also not mirrored so the LV&#8217;s are just allocated in sequence. Maybe later I will do a more indepth picture out different options for AIX Volume Groups.</p>
<p>The &#8220;enhancements&#8221; to aix 53 for LVM include this:</p>
<blockquote><p>
AIX 5L Version 5.2 offers a new volume group type called scalable volume group (VG), which can accommodate up to 1,204 physical volumes,(N.B. old regular VG&#8217;s are limited to 32, Big VG&#8217;s it was increased but not sure to what) 4,096 logical volumes (LV&#8217;s) and 2,048K physical partitions (PPs). )</p></blockquote>
<p>Needless to say you can make some pretty big volume groups with some pretty big file systems, but in my personal experience, the larger they are the longer they take to fix etc when a file system becomes corrupted, which for some reason seems to happen more with JFS2 than with JFS. Have not figured out what the exact cause is though.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2006/06/15/interesting-stuff-in-the-mail-today/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IBM New &#8220;low cost&#8221; desktop</title>
		<link>http://blogs.sungeek.net/unixwiz/2006/02/14/ibm-new-low-cost-desktop/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2006/02/14/ibm-new-low-cost-desktop/#comments</comments>
		<pubDate>Wed, 15 Feb 2006 03:26:23 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[Computer Hardware]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Random Stuff]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Solaris]]></category>
		<category><![CDATA[Sun]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=534</guid>
		<description><![CDATA[Thought this was intresting. If IBM wants people to use their PowerPC chips on the desktop then need to go a lot lower than $4,000 for a &#8220;desktop&#8221; workstation. I can get an entry level Sun Blade 150 machine for under $1,000. Granted it does not have the same specs as the IBM one does, [...]]]></description>
			<content:encoded><![CDATA[<p>Thought this was <a href="http://osnews.com/permalink.php?news_id=13678&#038;comment_id=95637">intresting</a>. If IBM wants people to use their PowerPC chips on the desktop then need to go a lot lower than $4,000 for a &#8220;desktop&#8221; workstation. I can get an entry level Sun Blade 150 machine for under $1,000. Granted it does not have the same specs as the IBM one does, but for some one starting out on a platform, I would much rather spend less money and get a slightly slower machine than a lot to find out that something does not work right. One thing that is not mentioned on that page, but on the IBM page is that it is really a &#8220;server&#8221;. Which means this little desktop machine weighs in a 55 pounds. Now to compare this machine versus a Sun Ultra 45, just on specs from each vendors web site lets see both maxed out:</p>
<table>
<tr bgcolor="#CCCCCC">
<td>System Option</td>
<td>Sun Ultra45</td>
<td>IBM pSeries 185 Express</td>
<td>Advantage</td>
</tr>
<tr>
<td>Memory (Max)</td>
<td>16GB</td>
<td>8GB</td>
<td>Ultra45</td>
</tr>
<tr>
<td>Processor Speed</td>
<td>2 x 1.6GHz UltraIIIi</td>
<td>2 x 2.5GHZ PPC 970 (not the real G5&#8242;s)</td>
<td>Ultra45</td>
</tr>
<tr>
<td>L2 Cache</td>
<td>1MB/Processor</td>
<td>1MB/Processor</td>
<td>Tie</td>
</tr>
<tr>
<td>Network</td>
<td>Dual Onboard Gig</td>
<td>Dual Onboard Gig</td>
<td>Tie</td>
</tr>
<tr>
<td>USB</td>
<td>6 USB 2.0</td>
<td>4 USB (does not mention whether 2.0 or not)</td>
<td>Ultra45</td>
</tr>
<tr>
<td>Disk Drives</td>
<td>4 x 146GB 15K SAS</td>
<td>3 x Ultra320 SCSI</td>
<td>Ultra45</td>
</tr>
<tr>
<td>Optical</td>
<td>DVDRW/CDRW</td>
<td>DVD-ROM or DVDRAM </td>
<td>Ultra45</td>
</tr>
<tr>
<td>Weight</td>
<td>58 Pounds Fully loaded</td>
<td>55 Pounds empty</td>
<td>Ultra45</td>
</tr>
<tr>
<td>OS</td>
<td>Solaris 10, Free</td>
<td>AIX 5.3, $300</td>
<td>Ultra45</td>
</tr>
<tr>
<td>OS Support</td>
<td>3 Years, $648</td>
<td>3 Years, $1,614</td>
<td>Ultra 45</td>
</tr>
<tr>
<td>Hardware Warrenty (default)</td>
<td>90 days</td>
<td>3 Years</td>
<td>pSeries 185</td>
</tr>
</table>
<p>All in all, you may end up paying a little more for a Ultra45, but then again, it is a way better machine than the pSeries 185. It also runs Solaris which I feel is far superior to AIX. AIX is cool and all, but has too many quirks that just does not make to much sense. There are things in Solaris that are done so much easier and faster than in AIX that just make me laugh when I have to answer how to do something in AIX vs Solaris. </p>
<p>Here are some of my pet quirks about AIX:</p>
<ol>
<li>Disk numbering scheme: all disks in AIX are named in the form of hdisk#. To find out exactly where they are at you have to do either a &#8220;lsdev -Cc disk&#8221; or &#8220;lsattr -El hdisk#&#8221; to find the actual controller and slot it is connected to.</li>
<li>ODM: Seems too much like the windows registry to me. Screw it up, and your machine does not boot right</li>
<li>The &#8220;dumbing&#8221; of Sysadmins by their dependence on SMIT. Take a AIX admin and put them in front of Solaris/Linux/etc and have them try to do any administrative tasks, and it is a complete loss with out smit. But take a Solaris/Linux/etc admin and put them on AIX, and they can accomplish most of the same administrative tasks with out touching SMIT</li>
<li>NIM, Nim is AIX&#8217;s equivelant of Jumpstart on Solaris. Jumpstart can be setup in probably under 10 minutes and be booting and installing machines. Nim on the other hand is an all day affair. I kid you not, I spent 8+ hours one day configuring an NIM environment to boot 1 machine. And even then, it did not install all the needed software. It also takes forever to copy 8 CD&#8217;s of AIX install media, plus the &#8220;Linux ToolKit&#8221;, Plus the expansion pack just to get SSH installed on AIX when NIM is used to install a system. If I could only get AIX to boot from a jumpstart server I would be set.</li>
<li>Missing core software that should be installed no matter what type of install you do. For example SSH. What operating system besides Microsoft Windows now days does not come installed with SSH? AIX, yup, you have to have 3 different cd&#8217;s to install it, and you better be using the OpenSSH supplied by IBM, or they will refuse to talk to you about any problems. (Yes they actually had me verify every part of the version of SSH before they would talk to me.</li>
<li>Root allowed to log in remotely. By default when you install AIX, root can log in remotely. MMM Bad Mkay&#8230;..</li>
<li>Default Open Relay: Last time I checked Sendmail on AIX is still configured by default to be an open relay.</li>
<li>Syslog: AIX likes to put stuff in its proprietory errpt. Which means to get the information to log to a central syslog server,  you have to modify the ODM to run a script to grab output from the errpt command to send to syslog. Why can&#8217;t it send to syslog by default? </li>
</ol>
<p>And the list could go on for ever, but right now it is time to go to bed. </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2006/02/14/ibm-new-low-cost-desktop/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>AIX Tip</title>
		<link>http://blogs.sungeek.net/unixwiz/2006/01/26/aix-tip/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2006/01/26/aix-tip/#comments</comments>
		<pubDate>Fri, 27 Jan 2006 02:15:21 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=516</guid>
		<description><![CDATA[Well, one of the things I was doing this week was moving mail servers around. While I was doing that I was going through some old mail and found this, might be of some help to some one. For those who are interested in knowing how to access a volume group that has quorum checking [...]]]></description>
			<content:encoded><![CDATA[<p>Well, one of the things I was doing this week was moving mail servers around. While I was doing that I was going through some old mail and found this, might be of some help to some one.</p>
<p>For those who are interested in knowing how to access a volume group that has quorum checking turned on but not enough disks&#8230; This is what I did on a IBM B80, that lost a disk that was in a volume group that held paging space and was not mirrored for what ever reason, and as a result it crashed the machine.</p>
<p>#Force the varyon of the volume group in to systems maintenance mode</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">varyonvg -f -s miscvg</div>
</div>
<p>#remove the disk from the volume group that had died, you need the PVID</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">reducevg -d miscvg 00084a4f50c2c7e6</div>
</div>
<p>#Show what disks are in the vg, should only be one now</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">lsvg -p miscvg</div>
</div>
<p>#Varyoff and on to make sure it works right</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">varyoffvg miscvg<br />
varyonvg miscvg</div>
</div>
<p>#add the replaced disk in to the vg</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">extendvg miscvg hdisk2</div>
</div>
<p>#show that it was added</p>
<div class="codesnip-container" >
<div class="codesnip" style="font-family: monospace;">lsvg -p miscvg</div>
</div>
<p>After this was done, I then added the paging space back to hdisk 2 and then mirrored the volume group. The reason the machine crashed was from a couple of different things.</p>
<p>1. The volume group was not mirrored, and when hdisk2 died, it took a paging space with it.</p>
<p>2. quorum checking was left on. If there are only 2 disks in a volume group, make sure that quorum checking is off, otherwise you will never be able to access the volume group with out doing the above steps. </p>
<p>Technorati Tags: <a href="http://technorati.com/tag/AIX" rel="tag">AIX</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2006/01/26/aix-tip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Because AIX does not want to be normal</title>
		<link>http://blogs.sungeek.net/unixwiz/2005/11/29/because-aix-does-not-want-to-be-normal/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2005/11/29/because-aix-does-not-want-to-be-normal/#comments</comments>
		<pubDate>Wed, 30 Nov 2005 03:16:01 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[Sendmail]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=451</guid>
		<description><![CDATA[Had a problem today with an AIX machine trying to send mail to the Internet. It seems that by default AIX ignores the DS line in the sendmail.cf if it thinks the receiving host is on a local network. So to fix it you need to find the line that contains the followig: (it is [...]]]></description>
			<content:encoded><![CDATA[<p>Had a problem today with an AIX machine trying to send mail to the Internet. It seems that by default AIX ignores the DS line in the sendmail.cf if it thinks the receiving host is on a local network. So to fix it you need to find the line that contains the followig: (it is about 60% down in the file) ::</p>
<div class="codesnip-container" >R$* < @ $* .$=m. > $*  $#esmtp $@ $2.$3. $: $1 < @ $2.$3. > $4</div>
<p>And comment it out. It &#8220;should&#8221; have a comment like such above it:</p>
<div class="codesnip-container" ># Added for AIX<br />
# figure out what should stay in our local mail system<br />
# Comment out this rule if you want all mail to go to the<br />
# Smart-Host relay defined by &#8220;DS&#8221; macro.</div>
<p>Once you comment it out, all the mail will now be sent directly to the host defined in the DS entry. You may have to stop and restart sendmail for it to take effect.</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/AIX" rel="tag">AIX</a>, <a href="http://technorati.com/tag/Sendmail" rel="tag"> Sendmail</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2005/11/29/because-aix-does-not-want-to-be-normal/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IBM AIX LDAP authenication</title>
		<link>http://blogs.sungeek.net/unixwiz/2005/02/27/old-log-7/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2005/02/27/old-log-7/#comments</comments>
		<pubDate>Sun, 27 Feb 2005 14:31:45 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[LDAP]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=187</guid>
		<description><![CDATA[I have spent over a week trying to get this to work. After going through 3 different level 2 LDAP techs with IBM, it is working, (knocking extremly freaking hard on wood). Here are my suggestions for IBM: Drop the use of DB2 Drop the requirement of needing 2 seperate userid&#8217;s just to get it [...]]]></description>
			<content:encoded><![CDATA[<p>I have spent over a week trying to get this to work. After going through 3 different level 2 LDAP techs with IBM, it is working, (knocking extremly freaking hard on wood). Here are my suggestions for IBM:</p>
<ol>
<li>Drop the use of DB2
</li>
<li>Drop the requirement of needing 2 seperate userid&#8217;s just to get it installed.
</li>
<li>Get the documentation on your web site updated, and take down the white papers that are referencing information that is 2 years old.
</li>
<li>Call Sun and learn how to do it right.
</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2005/02/27/old-log-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AIX Tip of the day</title>
		<link>http://blogs.sungeek.net/unixwiz/2005/02/16/old-log-8/</link>
		<comments>http://blogs.sungeek.net/unixwiz/2005/02/16/old-log-8/#comments</comments>
		<pubDate>Wed, 16 Feb 2005 23:02:32 +0000</pubDate>
		<dc:creator>unixwiz</dc:creator>
				<category><![CDATA[AIX]]></category>
		<category><![CDATA[LDAP]]></category>

		<guid isPermaLink="false">http://blogs.sungeek.net/unixwiz/?p=183</guid>
		<description><![CDATA[If you are going to try to do LDAP user authenication on AIX 5.2 or 5.3, make sure you have the latest bos.rte.security installed (at the time 5.2.0.51 for 5.2 aix). If you don&#8217;t you will get some extrememly weird things happening.]]></description>
			<content:encoded><![CDATA[<p>If you are going to try to do LDAP user authenication on AIX 5.2 or 5.3, make sure you have the latest bos.rte.security installed (at the time 5.2.0.51 for 5.2 aix). If you don&#8217;t you will get some extrememly weird things happening.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.sungeek.net/unixwiz/2005/02/16/old-log-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
