Telnet Question (Brent Bischoff)

From: Devendra Agrawal (devendra.agrawal@patni.com)
Date: Wed Jul 30 2003 - 08:23:11 EDT


A simple solution: remove the execute (x) permission of telnet command on
the Solaris machine. In this way, nobody can run telnet command from that
Solaris machine.

Regards,

Dev

-----Original Message-----
From: sunmanagers-bounces@sunmanagers.org
[mailto:sunmanagers-bounces@sunmanagers.org]On Behalf Of
sunmanagers-request@sunmanagers.org
Sent: Saturday, July 26, 2003 9:10 AM
To: sunmanagers@sunmanagers.org
Subject: sunmanagers Digest, Vol 4, Issue 49

Send sunmanagers mailing list submissions to
        sunmanagers@sunmanagers.org

To subscribe or unsubscribe via the World Wide Web, visit
        http://www.sunmanagers.org/mailman/listinfo/sunmanagers
or, via email, send a message with subject or body 'help' to
        sunmanagers-request@sunmanagers.org

You can reach the person managing the list at
        sunmanagers-owner@sunmanagers.org

When replying, please edit your Subject line so it is more specific
than "Re: Contents of sunmanagers digest..."

Today's Topics:

   1. Telnet Question (Brent Bischoff)
   2. SUMMARY: VxVM 3.5 patch and VxFS 3.5 MP1 rolling patch (Tom Davis)
   3. Sun Cluster v3.0 and HA for Oracle 9i on Solaris 8 (Rob Main)
   4. SUMMARY: Glacial ufsrestore from 8mm tape (Bob Rahe)
   5. Getting email from private network to internet via sendmail
      (Allen Belk)
   6. Printing..... (acuario6@servidor.unam.mx)
   7. Summary: Sol7 Compilation Woes (David Rieger)
   8. Ideas needed for syncronizing /etc/passwd and /etc/group uids
      and gids (Lumpkin, Buddy)
   9. mq fragmentation (alex)
  10. Live Upgrade of CD 2 of 2? (Tim Evans)

----------------------------------------------------------------------

Message: 1
Date: Fri, 25 Jul 2003 14:29:06 -0400
From: "Brent Bischoff" <bischoff@lucent.com>
Subject: Telnet Question
To: <sunmanagers@sunmanagers.org>
Message-ID: <01aa01c352da$a270de80$69505c87@ascc.lucent.com>
Content-Type: text/plain; charset="UTF-8"

Hello Managers,

I am trying to determine if it is possible to allow telnet access into a Sun
machine but not allow telnet access from this same machine. Basically, only
permit a one-way in telnet capability.

I appreciate in advance any thoughts.

Thanks,
Brent

------------------------------

Message: 2
Date: Fri, 25 Jul 2003 14:48:06 -0400
From: Tom Davis <tjdavis@reyrey.net>
Subject: SUMMARY: VxVM 3.5 patch and VxFS 3.5 MP1 rolling patch
To: sunmanagers@sunmanagers.org
Message-ID: <3F217B66.4050204@reyrey.net>
Content-Type: text/plain; charset="us-ascii"

It appears that these patches can be installed with little or no problem.
Thanks to Topher Dick and Mads Vaagland.

I appear to have both installed, and I don't seem to be having any
issues --

to be fair, I think I may have just installed it with the media that
had it on there...

but the 3.5 install with those patches on about a dozen Solaris 9
systems seems to be working just fine -- I've not had any issues...

toph

Hi,
We are using those patches on two of our Solaris 9 boxes, and have had no
problems with them.
We've just followed the installation instructions included with the
patches.
I should mention that the patches were applied agains fresh installations,
no vxvm/fs volumes/filesystems existed on the boxes before the patches
were installed.

Hope this helps.

-

Tom Davis <tjdavis@reyrey.net> writes:

> Does anyone who has applied patches 113207-05 and/or 112392-04 to VxFS
> and VxVM respectively on Solaris 9
> have any caveats or warnings in regard to their experiences. I am
> planning on applying those patches this weekend.
> I don't have a test system to test these patches. Any comments,
> concerns or warnings will be greatly appreciated.
>
> Thanks
> Tom Davis

------------------------------

Message: 3
Date: Fri, 25 Jul 2003 15:20:33 -0400
From: Rob Main <rmain@ncsu.edu>
Subject: Sun Cluster v3.0 and HA for Oracle 9i on Solaris 8
To: sunmanagers@sunmanagers.org
Message-ID: <3F218301.6040606@ncsu.edu>
Content-Type: text/plain; charset="us-ascii"

 When I scswitch a failover resource group from one cluster node to
another, the following error message appears in the message log:

----------------------------------------------------------------------------
-

---
Jul 25 10:54:17
SC[SUNWscor.oracle_server.stop]:oraclerg:oracle_server_instanceName:
Server is not running. Calling shutdown abort to clear shared memory (if
any)
SQL*Plus: Release 9.2.0.3.0 - Production on Fri Jul 25 10:54:18 2003
Copyright (c) 1982, 2002, Oracle Corporation.B  All rights reserved.
Enter user-name: SP2-0306: Invalid option.
Usage: CONN[ECT] [logon] [AS {SYSDBA|SYSOPER}]
where <logon>B  ::= <username>[/<password>][@<connect_string>] | /
Enter user-name: SP2-0306: Invalid option.
Usage: CONN[ECT] [logon] [AS {SYSDBA|SYSOPER}]
where <logon>B  ::= <username>[/<password>][@<connect_string>] | /
Enter user-name:
----------------------------------------------------------------------------
-
---
Shutdown immediate and shutdown abort both fail, resulting in the data
services going into a STOP_FAILED state.B  Is this a bug with the Oracle
HA binaries?B  Has anyone else seen this?B  Thanks in advance.
-Rob Main
------------------------------
Message: 4
Date: Fri, 25 Jul 2003 15:43:15 EDT
From: bob@dtcc.edu (Bob Rahe)
Subject: SUMMARY: Glacial ufsrestore from 8mm tape
To: sunmanagers@sunmanagers.org
Cc: bob@hobbes.dtcc.edu
Message-ID: <200307251943.h6PJhFn26005@hobbes.dtcc.edu>
  Well, after a HUGE amount of go-round with Sun the conclusion, which
totally amazes me, is that this is within normal tolerances for Exabyte
Mammoth drives.  This quoted from Exabyte themselves by Sun.
  A bit more info than the original message:  Turns out that the
problem has to do with cross-compatibility of tapes written on different
drives.  I.e. the one drive we use to write most of our tapes (drive A)
writes tapes that are not 'easily' read by the other drive on that system
(Drive B).  BUT... they ARE readable on another drive on, as it turns
out, my workstation.  And if we try writing on drive B we get that it
doesn't read well on either A or my workstation.  And various other
combos with other drives in the shop here.
  In going over this with Sun I made up a matrix of which drives would
read which other drive's tapes and it was amazing...  And it does seem
to actually do a reposition or search when it is having problems with
a tape - I could actually see it on the L400 display of drive status.
That explains the time it takes - all that repositioning is time
spent at 0 transfer rate.
  It was fun trying to get them to actually understand what I was saying
and then the couple/three different replacement drives some of which did
exactly the same thing(!).  We even got a firmware upgrade to them to
see if that would help.
  Finally, Exabyte told them it was normal(!).  Bottom line is, we'll be
sure to, if at all possible, read tapes on the drive that created them.
  Original message follows:
----------
From: bob@dtcc.edu (Bob Rahe)
To: sunmanagers@sunmanagers.org
Subject: Glacial ufsrestore from 8mm tape
  Well, this drove me nuts.  Does anyone know what might be going on to
cause these symptoms and how to fix it?
   System is an E6500, 14x400Mhzx14G with two Exabyte 8900 (Mammoth)
8mm tape drives.  Solaris 8.
   The problem is that a ufsrestore of files from backup tapes can take
a HUGE amount of time.  Case in point - last nite, tried to restore a
directory containing approximately 125 Megabytes in approximately 1200
files.  Restoring into the /tmp directory ('swap' in the df listing).
  This is a multi-file tape, the filesystem that we needed to recover
the directory from was the second file on the tape so an mt command
with fsf 1 was used on the no-rewind device and then an interactive
ufsrestore (blocking of 480) to select the directory.  The ufsdump
(with a block specified as 480) of this file system (approximately 10G)
took about 50 minutes.  The restore of just the direcory took
over 4.5 HOURS!
  Now I could see it taking 50 minutes but this was ridiculous.  And
not the first time we've seen this kind of thing altho this was
definitely the worst.
  One other point I might mention: I happened to be in the room where
the tape is situated and it sounded like the tape was in high-speed
search/motion at least twice during the restore.  For whatever THAT
might mean....
  Thanks and I'll summarize.
Bob
--
----------------------------------------------------------------------------
|Bob Rahe, Delaware Tech&Comm Coll. /                                      |
|Computer Center, Dover, Delaware /                                        |
|Internet: bob@dtcc.edu  (RWR50) /                                         |
----------------------------------------------------------------------------
------------------------------
Message: 5
Date: Fri, 25 Jul 2003 15:41:21 -0500
From: "Allen Belk" <allen.belk@usm.edu>
Subject: Getting email from private network to internet via sendmail
To: <sunmanagers@sunmanagers.org>
Message-ID: <000701c352ed$1b18e910$f7ad5f83@taz>
Content-Type: text/plain; charset="iso-8859-1"
Managers,
    I have several Solaris 8 machines on a private, non-routable network
from which I need the ability to send email to the outside world.  One of
the hosts on that network is a bastion between the private network and the
public network.  This host is running sendmail and uses the DS (smart relay)
option to direct all of its email to our email gateway.  Mail sent directly
from the bastion host to the outside world works without any problems.
However, email sent from any of the hosts on the private network addressed
for an internet host winds up queuing with the following error reported by
mailq.
                /var/spool/mqueue (2 requests)
----Q-ID---- --Size-- -----Q-Time----- ------------Sender/Recipient---------
---
h6PK9bi00334      543 Fri Jul 25 15:09 abelk
                 (host map: lookup (usm.edu): deferred)
                                       allen.belk@usm.edu
Each host on the private network is configured with the DS option in their
sendmail.cf file that points to the bastion host.  I am not a sendmail
expert and am not sure if the DS option is what I should be using in the
first place.
I am also running a private caching-only name server on the bastion that
provides name services to the private network only.  I do not have MX
records for the private hosts but have seen some articles on the web that
suggest using a single wildcard MX record for all private hosts.  I have
tried this without any success.  If anyone out there has had experience with
this type of configuration or has some words of wisdom to impart, please
email me.  Your help is greatly appreciated.
Thanks,
Allen
 | Allen Belk, Systems Administrator III
 | University of Southern Mississippi
 | iTech, Technology Infrastructure Unit
 | allen.belk@usm.edu  -  601.266.5973
------------------------------
Message: 6
Date: Fri, 25 Jul 2003 16:41:53 -0500 (CDT)
From: acuario6@servidor.unam.mx
Subject: Printing.....
To: sunmanagers@sunmanagers.org
Message-ID: <1059169313.3f21a42111f85@www.correo.unam.mx>
Content-Type: text/plain; charset=ISO-8859-1
Hi Gurus...
I have a SUN box and SCO box, in the SCO have a printer , and we want to
know w
to send files printing from SUN box to the SCO box.
Anibody know some URL o something information.
Thanks..
-------------------------------------------------
Obtin tu correo en www.correo.unam.mx
UNAMonos Comunicandonos
------------------------------
Message: 7
Date: Fri, 25 Jul 2003 15:12:42 -0700
From: David Rieger <drieger@olac.berkeley.edu>
Subject: Summary: Sol7 Compilation Woes
To: sunmanagers@sunmanagers.org
Message-ID: <5.1.0.14.2.20030725145738.01e38b60@olac.berkeley.edu>
Content-Type: text/plain; charset="us-ascii"; format=flowed
 From woe to joy here's the summary for the myriad of issues:
1.) Have your path set correctly (don't forget to export it)
2.) Have your LD_LIBRARY_PATH set correctly (and exported)
3.) Have your envVar to CC & C set correctly ("" "")
4.) Have the proper binaries installed from OS media:
>>SUNWbtool, SUNWsprot, SUNWtoo, SUNWcpp
>>
>>for libraries & headers:
>>SUNWhea, SUNWarc, SUNWlibm, SUNWlibms
>>SUNWdfbh, SUNWcg6h, SUNWxwinc, SUNWolinc,
>>SUNWxglh, SUNWlibC, SUNWzlib, SUNWscpu
>>for 64 bit development:
>>
>>SUNWarcx, SUNWbtoox, SUNWdplx, SUNWscpux, SUNWsprox,
>>SUNWtoox, SUNWlmsx, SUNWlmx, SUNWlibCx, SUNWzlibx
>>for ucb compat:
>>
>>SUNWsra, SUNWsrh
5.) These are found in the Solaris OS installation disk (not the product
supplement) and with each of these packages do a:
pkgadd -d /cdrom/[pathToProduct] [productName]
6.) Try to ./configure again from within the program folder you wish to
compile (if this is a repeated attempt don't forget to rm config.cache)
7.) Joy - a Ode to it and the following people who helped:
Randy Romero
Thomas J. Jones
Charley Paffenbarger
Jay Sparks
Jason.Shatzkamer
Angel Alejandro Vega Soto
CSOWEN @ Cal
Crist Clark
Michael Sinatra
Sandwich Maker
Reggie Beavers
Ryan Iwai
Mark Cain
Kelly Ormsby
Evan Gold
Chakravarthi_Muralidharan
Lisa Blackshear
Brian Pardy
Henrik Mortensen
Luc I. Suryo
Patrick O'Reilly
Alan Pae
I do help my summary will help in the future - Thank you.
david
------------------------------
Message: 8
Date: Fri, 25 Jul 2003 15:45:33 -0700
From: "Lumpkin, Buddy" <Buddy.Lumpkin@nordstrom.com>
Subject: Ideas needed for syncronizing /etc/passwd and /etc/group uids
	and gids
To: <sunmanagers@sunmanagers.org>
Message-ID:
	<3BD8AA3B9C18D34BA5099929909CFA05027583E4@m0319p35.nordstrom.net>
Content-Type: text/plain; charset="iso-8859-1"
Hello All,
We have a few hundred systems that all share a common /etc/passwd and
/etc/shadow file. Recently we have inherited a couple pre-existing systems
that have common usernames and groups with different uids and gids. This is
especially a consern for usernames like oracle.
I can certainly cook something up that will convert all of the files on
these
systems before/after putting in the new /etc/passwd and /etc/group files but
I
was wondering if anyone had already done this and already had some good
ideas
on how to tackle this with minimal pain.
I was thinking about benchmarking a quick and dirty shell script on one of
our
lab systems but im scared that I might find that this is going to take hours
unless I write something in perl or C that only iterates thru each file on
the
system once (one stat() per file).
Thanks in advance for any ideas,
--Buddy
------------------------------
Message: 9
Date: Fri, 25 Jul 2003 17:47:19 -0800
From: "alex" <techtalk@fastmail.fm>
Subject: mq fragmentation
To: sunmanagers@sunmanagers.org
Message-ID: <20030726014719.B42586C436@smtp.us2.messagingengine.com>
Content-Type: text/plain; charset="ISO-8859-1"
each time ran fsck noticed higher fragmentation. it is at 4% now.
ide drive.
Alex
--
  alex
  techtalk@fastmail.fm
--
http://www.fastmail.fm - Access all of your messages and folders
                          wherever you are
------------------------------
Message: 10
Date: Fri, 25 Jul 2003 23:35:47 -0400 (EDT)
From: Tim Evans <tkevans@tkevans.com>
Subject: Live Upgrade of CD 2 of 2?
To: sunmanagers@sunmanagers.org
Message-ID: <200307260335.h6Q3ZlbO011777@osprey.tkevans.com>
Content-Type: TEXT/plain; charset=us-ascii
Trying to complete upgrade to Solaris 9 4/03 via Live Upgrade to my
Alternate Boot disk.  First pass suceeded:
luupgrade -u -s /cdrom/cdrom0 -n bootdisk
[ "bootdisk" is the alternate boot environment name ]
Per the man page, I need to run luupgrade with the '-i' option to load
the contents of the second cdrom--right from the man page:
# luupgrade -i -n bootdisk -s /dev/cdrom/cdrom0 \
     -O "-nodisplay -noconsole"
This starts out as if it were going to work:
    Validating the contents of the media </cdrom/cdrom0>.
The media is a standard Solaris media.
The media contains a standard Solaris installer.
The media contains <Solaris_2_of_2> version <9>.
Mounting BE <bootdisk>.
Running installer on BE <bootdisk>.
After a few seconds, however, I get:
INFORMATION: </var/sadm/system/logs/upgrade_log> contains a log of the
upgrade operation.
INFORMATION: </var/sadm/system/data/upgrade_cleanup> contains a log of
cleanup operations required.
WARNING: <162> packages must be installed on boot environment <bootdisk>.
INFORMATION: </var/sadm/system/data/packages_to_be_added> on boot
environment <bootdisk> contains a list of packages that must be installed
on the boot environment for the upgrade to be complete. The packages in
this list were not present on the media that was used to upgrade this boot
environment.
INFORMATION: If the boot environment was upgraded using one media of a
multiple media distribution, for example the Solaris CD media, you must
continue the upgrade process with the next media. Complete the upgrade by
using the luupgrade <-i> option to install the next media of the
distribution.
Then:
Failure to complete the upgrade process with all media of
the software distribution makes the boot environment unstable.
INFORMATION: Review the files listed above on boot environment <bootdisk>.
Before you activate the boot environment, determine if any additional
system maintenance is required or if additional media of the software
distribution must be installed.
Unmounting BE <bootdisk>.
The installer run on boot environment <bootdisk> is complete.
Despite the "installer run is complete" message, the target bootdisk
won't 'luactivate'.
Anyone have a workaround to pkgadd those "162" packages to the alternate
and convice luactivate to do its thing?  Do I dare manually flip the eeprom
to boot from the other disk, installboot it, and give it a go, then run the
cdrom #2 installer later?
Hate to waste the four hours I've already spent on this...
Thanks.
--
Tim Evans			|    5 Chestnut Court
tkevans@tkevans.com		|    Owings Mills, MD 21117
http://www.tkevans.com/		|    443-394-3864
http://www.come-here.com/News/	|    410-748-0160 (pager)
------------------------------
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers
End of sunmanagers Digest, Vol 4, Issue 49
******************************************
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers


This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:26:49 EDT