Computer and Network/Account and Project
/local/admin/2016/ 00_ms1_create_pwDBs.sh 10_create_accdata.sh 20_create_homedir.sh 25_1s_prep_obstable.sh 30_create_project.sh 40_ms1_vncpasswd.sh common.inc config.inc siteinfo.inc gen_one_passwd do_account_test
/home/common/etc/ bashrc.common bashrc.template -- .bashrc cshrc.csh cshrc.template sample.Xresources sample.eggrc sample_cp.sh -- スクリプトからはこれを呼び出す
/home/common/naoj/bin/create_project.sh
ms1 1s as1 ss1 (LDAP アカウント登録 / ホームやプロジェクトの作成) gw (ゲートウェイアカウント登録 (パスワードファイル) / ホームの作成)
aste-xxx{admin}: cd /local/admin/2016
aste-ms1{admin}: cd /local/admin/2016 aste-ms1{admin}: ./00_ms1_create_pwDBs.sh => pw/pwdb_crypt_2016.csv pw/pwdb_secret_2016.csv pw/pwdb_secret_2016_vnc.csv pw/lock
aste-ms1{admin}: rm pw/lock ; ./00_ms1_create_pwDBs.sh
aste-ms1{root}# mv pwdb_secret_2016.csv /local/admin/secret/ aste-ms1{root}# mv pwdb_secret_2016_vnc.csv /lcoal/admin/secret/ aste-ms1{root}# chown root /local/admin/secret aste-ms1{root}# chmod 700 /local/admin/secret
aste-ms1{admin}: cd /local/admin aste-ms1{admin}: rsync -auvzH 2016 aste-xxx:/local/admin/
aste-xxx{admin}: cd /local/admin/2016 aste-xxx{admin}: ./10_create_accdata.sh => xxx.out/ldapvi.add xxx.out/useradd.run
aste-gw{admin}: cd /local/admin/2016/gw.out aste-gw{admin}: su password: xxxxxxxx (root になります) aste-gw{root}# ./useradd.run => /home/acc000 ... /home/acc099
aste-srv{admin}: /usr/bin/ldapvi -h ldaps://localhost/ -b dc=aste,dc=naoj -D cn=root,dc=aste,dc=naoj
ms1, 1s, as1, ss1 gw
% id a16000 uid=16000(a16000) gid=9600(astgrp) groups=9600(astgrp) % echo ~a16000 /home/a16000 % su a16000 ....
2016 年: ms1 1s as1 -- /raid11/home_cu2016 (/a16000 ... /a16099) ss1 -- /disk06/home_cu2016 (/a16000 ... /a16099)
/etc/fstab: /raid11/home_cu2016 /export/home_cu2016 none bind 0 0 or /disk06/home_cu2016 /export/home_cu2016 none bind 0 0 # mkdir /export/home_cu2016 # mount /export/home_cu2016
/etc/exports: /export aste-xxx(rw,fsid=0,crossmnt,no_root_squash)
ldap auto.home: cn=a16000,nisMapName=auto.home,dc=aste,dc=naoj objectClass: nisObject cn: a16000 nisMapName: auto.home nisMapEntry: disk_h:/home_cu2016/a16000
/home/common/etc: aste-ms1{admin}: rsync -auvzH /home/common/etc/ aste-srv:/home/common/etc/
aste-srv{admin}: cd /local/admin/2016 aste-srv{admin}: su password: xxxxxxxx (root になります) aste-srv{root}# ./20_create_homedir.sh
ms1, 1s, as1, ss1
aste-1s{admin}: cd /local/admin/2016 aste-1s{admin}: su password: xxxxxxxx (root になります) aste-obstab{root}# ./25_1s_prep_obstable.sh
aste-obstab{admin}: cd /local/admin/2016 aste-obstab{admin}: su password: xxxxxxxx (root になります) aste-obstab{root}# ./30_create_project.sh
ms1, 1s, as1, ss1
aste-ms1{admin}: cd /local/admin/2016 aste-ms1{admin}: su password: xxxxxxxx (root になる) aste-ms1{root}# ./40_ms1_vncpasswd.sh => /home/[user]/.vnc/vncpasswd
aste-mx3{admin}: cd /local/admin/2016 aste-mx3{admin}: su password: xxxxxxxx (root になる) aste-mx3{root}# ./50_mx3_vnc_xinetd.sh => mx3.out/aste-gdm.conf mx3.out/services.add mx3.out/xinetd-aste.d/ aste-vnc-5900 ... aste-vnc-5999
aste-mx3{root}# service xinetd restart
aste-mx1{root}# sudo -u asterobs passwd Changing password for user asterobs. Current Password: yyyyyyyy New password: xxxxxxxx Retype new password: xxxxxxxx passwd: all authentication tokens updated successfully. aste-mx1{root}# /usr/bin/vncpasswd /etc/vncpasswd Password: yyyyyyyy Verify: yyyyyyyy aste-mx1{root}# /bin/chown root.astctl /etc/vncpasswd aste-mx1{root}# /bin/chmod 440 /etc/vncpasswd
aste-mx1{root}# ls -l /etc/vncpasswd -r--r----- 1 root astctl 8 Apr 6 05:45 /etc/vncpasswd
a16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 a16099 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 acc000 - gw acc099 - gw
a16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 a16099 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 acc000 - gw acc099 - gw
a16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1
a16000 - ms1 mx1 mx3 ax1 as1 1x 1s ss1
a16000 - mx1 mx3 ax1 1x asteobs - mx1
pw ログイン可能 - ok 2016-09-06 sftp 不可 - ok 2016-09-06 ("Request for subsystem 'sftp' failed on channel 0")
pubkey ログイン可 (sshd122.conf) - ok 2016-09-06 pw ログイン不可 - ok 2016-09-06 ("Permission denied (publickey,gssapi-keyex,gssapi-with-mic).") sftp 不可 - ok 2016-09-06 ("Request for subsystem 'sftp' failed on channel 0")
ssh コマンドで到達不可 - ok 2016-09-06 (ssh -v や telnet 22 で確認)
pw ログイン不可 - ok 2016-09-06 (pubkey 設置なしで "Permission denied (publickey,gssapi-keyex,gssapi-with-mic).") sshd122.conf 許可で pubkey ログイン可 - ok 2016-09-06 sshd122.conf 不許可で pubkey ログイン不可 - ok 2016-09-06 ("Connection closed by 133.40.7.130") sftp アクセス不可 - ok 2016-09-06 ("subsystem request failed on channel 0")
ls -ld /home/acc???
acc000@gw -> a16000-VNC on mx3 接続後の画面で a16000 としてログインできること
acc000@gw -> VNC on mx1 接続後の画面で asterobs としてログインできること
ms1 (2015のみ残す) as1+1s (2013,2014,2015すべて削除)
2015年分のみ mx2 -> ms1 にコピーして残す それ以前は、 ~account/proj?/obstable のみ nrodb に当面保存
/etc/xinetd-aste.d/ 情報削除 (2015年分停止、2016年分に入れ替えた)