LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

ssh service using lvs-dr

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: ssh service using lvs-dr
From: Karen Shepelak <shepelak@xxxxxxxx>
Date: Fri, 04 Feb 2005 17:37:01 -0600
    I have met with success at getting ssh connections to work to LVS
by running a separate sshd for the VIP on each realserver. I don't know
if this is a normal part of the setup for the realservers or not, as I did not see any instruction about having to do this anywhere, but it certainly got things
working. Also note that arp patches, arptable settings, nor noarp module,
made any difference in getting ssh to work.
Though I am finally able to ssh to LVS, I am now encountering a new battle.
To complete our LVS configuration, we need to have LVS working with
kerberos and opensafs (also installed on our machines). So now, though I am
finally able to ssh to LVS, I am seeing that we are not able to create afs tokens. We have narrowed down this new problem to our version of ssh: OpenSSH_3.5p1f1.
Error we get is:

[karen@neptune karen]$ ssh -l shepelak minos-lvs01

Last login: Fri Feb  4 16:34:23 2005 from linux-test.fnal.gov
aklog: Couldn't get fnal.gov AFS tickets:
aklog: unknown RPC error (-1765328346) while getting AFS tickets
/usr/X11R6/bin/xauth:  timeout in locking authority file 
/afs/fnal.gov/files/home/room3/shepelak/.Xauthority
Terminal type is xterm
There are no available articles.
/bin/touch: creating `/afs/fnal.gov/files/home/room3/shepelak/.Info': 
Permission denied
<minos09>

Any of you out there running LVS with kerberos, openafs and openssh on your LTS303 linux machines?
Thanks for any help,

karen
-----------------

Karen Shepelak wrote:
>>

>>> Hi all,
>>>
>>>       I am not having any luck getting ssh service to run to LVS
>>> running on LTS3.0,
>>> kernel 2.4.21-20.ELsmp. Main problem seems to be in getting rid of arp
>>> problems.
>>> Odd thing is that after having used the "Horms method" to the
>>> realservers, telnet
>>> service to LVS works ok. I tried installing the suggested "hidden"
>>> patch
>>> for this kernel to see if it would control the arp issues differently
>>> enough to get ssh
>>> service to work, but the patch will not install with this kernel.
--
Karen Shepelak
SCS-GROUP (Scientific Computing Support)
FERMILAB (Work: 630-840-2715 -- Pager:630-266-2383 -- FAX:630-840-6345)


<Prev in Thread] Current Thread [Next in Thread>