Re: [lopsa-tech] Directory Server for Apple and Unix Environment

2015-03-23 Thread Brian J. Atkisson
+1 for FreeIPA or Red Hat IdM (if you wanted the supported version). If you don't want the full blown IPA product with Kerberos and PKI, you can use the 389 Directory Server. I've found it to have the best multi-master support of any of the options out there. Disclaimer: I do work with with the

Re: [lopsa-tech] Authentication

2014-09-16 Thread Brian J. Atkisson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Check out http://www.freeipa.org, if you are looking for an integrated solution that can sync with AD. It supports One Time Passwords in order to obtain a kerberos TGT and has an integrated OTP server. If you are looking for a standalone 2 factor aut

Re: [lopsa-tech] Cobbler - still the best provisioning system for RHEL-family?

2014-06-11 Thread Brian J. Atkisson
On 06/11/2014 12:23 PM, Will Dennis wrote: > Hi all, > > > > We have a research dept that has cooked up a homebrew provisioning > system over time, that uses PXE, kickstart, some custom scripts, and > Puppet to provision their bare-metal servers. While it has worked well > in the past, its show

Re: [lopsa-tech] It might be time to change email client

2014-04-18 Thread Brian J. Atkisson
+1 to Thunderbird. I tend to use Mutt at work, which is great at cutting through the cruft. Cheers, Brian > On Apr 17, 2014, at 9:09 PM, Glenn Sieb wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > >> On 4/17/14, 7:36 PM, john boris wrote: >> With the recent heartbleed issue my pr

Re: [lopsa-tech] Provisioning systems

2014-02-16 Thread Brian J. Atkisson
Cobbler works well, but it's a little stale these days. You might also look at http://theforeman.org Cheers, Brian > On Feb 16, 2014, at 9:46 AM, Christopher Webber wrote: > > I have used cobbler in the past but if I were going another round would > probably look at razor (https://github.com

Re: [lopsa-tech] Fibre-Channel Performance issue [SEC=UNCLASSIFIED]

2014-02-10 Thread Brian J. Atkisson
Turning off ALUA on the host and controller would be a good test as well. ALUA is usually something you want to use, however, I've seen it cause performance and failover issues in certain environments. Cheers, Brian > On Feb 3, 2014, at 8:04 PM, "Robinson, Greg" > wrote: > > UNCLASSIFIED >

Re: [lopsa-tech] ethernet bond mode 6

2013-03-08 Thread Brian J. Atkisson
On 03/08/2013 08:45 AM, Andrew Hume wrote: > does anyone have real experience with ethernet bond mode 6 (balanced-alb)? > > we have 5 source servers each connected to two switches (A and B). > each server operates their pair of 1Gbps connections as an > active/passive pair > (under Solaris). > >

Re: [lopsa-tech] ethernet bonding under RHEL

2013-01-30 Thread Brian J. Atkisson
On 01/30/2013 03:38 PM, Andrew Hume wrote: > is it possible to do two levels of binding under RHEL? > we want to do something like: > > ec0 = bond rr eth0 eth1 > ec1 = bond rr eth2 eth3 > poot = bond active-backup ec0 ec1 No, that won't work. If you don't have LACP support on your switch(es), yo

Re: [lopsa-tech] Rack Management software

2012-07-02 Thread Brian J. Atkisson
On 07/02/2012 01:17 PM, Ray Van Dolson wrote: > On Mon, Jul 02, 2012 at 01:14:30PM -0400, Brian J. Atkisson wrote: >> All, >> >> I'm looking for suggestions/feedback on rack management software. The >> basic problem I want to solve is tracking what hardware is in

[lopsa-tech] Rack Management software

2012-07-02 Thread Brian J. Atkisson
All, I'm looking for suggestions/feedback on rack management software. The basic problem I want to solve is tracking what hardware is installed in what rack and colo. I'd rather stick with an open source web product. The commercial products all seem to want to be your CMDB and take over your env

Re: [lopsa-tech] Directory Services for Linux

2012-07-02 Thread Brian J. Atkisson
On 07/02/2012 11:43 AM, Matt Lawrence wrote: > I've been asked to research the various options for Directory Services > for Linux. The likely environment will be SLES and the requirements are > not terribly complex. At this point the main interest is in doing > account and password management in

Re: [lopsa-tech] Weird problem with trunking on RedHat EL 6.x

2012-05-03 Thread Brian J. Atkisson
Do you also have a native/default/untagged vlan for eth0? Cheers, Brian On 05/02/2012 12:26 PM, Will Dennis wrote: > We ran into a problem with trunking (multi-VLAN over one NIC) with > RedHat EL 6 that we haven't seen before. We do have RedHat EL 4 machines > that are running multi-VLAN over on

Re: [lopsa-tech] Kerberos

2012-04-27 Thread Brian J. Atkisson
On 04/27/2012 07:38 AM, "Paul DiSciascio" wrote: > Hi, > I'm in the early stages of a project to deploy a unix-only kerberos > realm that will serve around 1000 unix servers. It's an MIT kerberos > realm with the KDCs on SuSE Linux. > > Does anyone have any experience doing something like thi

Re: [lopsa-tech] The "Enterprise Apple Laptop"

2012-04-06 Thread Brian J. Atkisson
On 04/06/2012 11:26 AM, Tim Kirby wrote: > Much to my surprise and contrary to many years of prior stance > to the contrary, a "fast track" project has appeared at $WORK > with a view to "supporting" Mac laptops as an alternative to > the Dell windows systems - certain area, in particular in > engi

Re: [lopsa-tech] Unix Group Weirdness

2011-06-29 Thread Brian J. Atkisson
On 29/06/11 11:33 -0400, Patrick Cable wrote: This one's probably pretty simple -- but the exact phrase to google for is, well, elusive to me. So, when I 'su' or 'su -' to a user's account, all his groups show up. [root@user ~]# su - juser user:/home/juser> groups stapusr wheel p2218808 p10022

Re: [lopsa-tech] FreeIPA Opinions?

2011-06-22 Thread Brian J. Atkisson
On 22/06/11 11:23 -0400, Will Dennis wrote: From my vantage point as a “Windows guy” (I do also use and appreciate Linux, but not really a hard-core Linux admin), this looks like “Active Directory for Linux”… Am I correct in this analysis? If not, can anyone help me understand this? We still are

Re: [lopsa-tech] FreeIPA Opinions?

2011-06-21 Thread Brian J. Atkisson
On 21/06/11 17:43 -0500, Justin Ellison wrote: >I finally had some time to download and install Fedora 15 on a VM and installed >FreeIPA. Holy cow, is that a nice web-based interface they have going for them >-- if you haven't seen it in the last year or so, you owe it to yourself to >take a look.

Re: [lopsa-tech] NIS to LDAP anyone?

2011-05-28 Thread Brian J. Atkisson
On 27/05/11 12:06 -0700, Matthias Birkner wrote: >At $ork we have been "granted the opportunity" to consolidate our 20-odd, >globally dispersed, NIS domains into a central LDAP database. If anyone has >success stories, war stories, or good references they'd be willing to share, >I'd >appreciate a

Re: [lopsa-tech] Xen to KVM Migration Steps

2011-03-22 Thread Brian J. Atkisson
On 22/03/11 15:00 -0400, Brian Gold wrote: >Hello all, > >I recently took over the position of Sysadmin in an organization that has a >number of Xen virtual machines running in RHEL on older hardware. They recently >purchased some newer servers that can handle hardware virtualization. I've had >exp

Re: [lopsa-tech] Password synchronization (Active Directory/OpenLDAP)

2011-02-15 Thread Brian J. Atkisson
On 15/02/11 20:52 +, Ari Constancio wrote: >Hi, > >We're about to introduce Active Directory in an environment based on >LDAP (OpenLDAP) for accounts. Password synchronization should be >bidirectional if possible. >I'd like to hear any advice on how folks are integrating AD and LDAP servers. >

Re: [lopsa-tech] Linux I/O scheduler choice can make a big, big difference

2010-12-16 Thread Brian J. Atkisson
On 16/12/10 11:50 -0800, da...@lang.hm wrote: >On Thu, 16 Dec 2010, Ski Kacoroski wrote: > >> Thanks for the info. I wonder if this will make a difference for >> machines running on vmware through a vmdk file system? In my email >> server case, it was a direct connection to a lun on the SAN. > >