2005-12-08 12:14:33 +00:00
|
|
|
=head1 NAME
|
|
|
|
|
|
|
|
ptserver - Initializes the Protection Server
|
|
|
|
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
|
2006-03-01 05:02:29 +00:00
|
|
|
=for html
|
|
|
|
<div class="synopsis">
|
|
|
|
|
2008-04-02 21:47:27 +01:00
|
|
|
B<ptserver> S<<< [B<-database> <I<db path>>] >>> S<<< [B<-p> <I<number of threads>>] >>>
|
2005-12-13 19:21:13 +00:00
|
|
|
[B<-rebuildDB>] [B<-enable_peer_stats>] [B<-enable_process_stats>]
|
2008-04-02 21:47:27 +01:00
|
|
|
[B<-allow-dotted-principal>] [B<-rxbind>] [B<-help>]
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2006-03-01 05:02:29 +00:00
|
|
|
=for html
|
|
|
|
</div>
|
|
|
|
|
2005-12-08 12:14:33 +00:00
|
|
|
=head1 DESCRIPTION
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The B<ptserver> command initializes the Protection Server, which must run
|
|
|
|
on every database server machine. In the conventional configuration, its
|
|
|
|
binary file is located in the F</usr/afs/bin> directory on a file server
|
|
|
|
machine.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The ptserver command is not normally issued at the command shell prompt,
|
|
|
|
but rather placed into a database server machine's
|
|
|
|
F</usr/afs/local/BosConfig> file with the B<bos create> command. If it is
|
|
|
|
ever issued at the command shell prompt, the issuer must be logged onto a
|
|
|
|
file server machine as the local superuser C<root>.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
The Protection Server performs the following tasks:
|
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
|
|
|
=item *
|
|
|
|
|
|
|
|
Maintains the Protection Database, which contains entries for every user
|
2005-12-13 19:21:13 +00:00
|
|
|
and group in the cell. Use the B<pts> commands to administer the database.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
|
|
|
Allocates AFS IDs for new user, machine and group entries and maps each ID
|
|
|
|
to the corresponding name.
|
|
|
|
|
|
|
|
=item *
|
|
|
|
|
|
|
|
Generates a current protection subgroup (CPS) at the File Server's
|
2005-12-13 19:21:13 +00:00
|
|
|
request. The CPS lists all groups to which a user or machine belongs.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=back
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
This command does not use the syntax conventions of the AFS command
|
|
|
|
suites. Provide the command name and all option names in full.
|
|
|
|
|
2005-12-08 12:14:33 +00:00
|
|
|
=head1 OPTIONS
|
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-database> <I<db path>>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Specifies the pathname of an alternate directory in which the Protection
|
2005-12-13 19:21:13 +00:00
|
|
|
Database files reside. Provide the complete pathname, ending in the base
|
|
|
|
filename to which the C<.DB0> and C<.DBSYS1> extensions are appended. For
|
|
|
|
example, the appropriate value for the default database files is
|
|
|
|
F</usr/afs/db/prdb>.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2008-04-02 21:47:27 +01:00
|
|
|
=item B<-p> <I<number of threads>>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2008-04-02 21:47:27 +01:00
|
|
|
Sets the number of server lightweight processes (LWPs or pthreads) to run.
|
|
|
|
Provide a positive integer from the range C<3> to C<16>. The default
|
|
|
|
value is C<3>.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-rebuildDB>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Rebuilds the Protection Database at the beginning of Protection Server
|
|
|
|
initialization. Use this argument only in consultation with AFS
|
|
|
|
Development or Product Support.
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-enable_peer_stats>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Activates the collection of Rx statistics and allocates memory for their
|
2005-12-13 19:21:13 +00:00
|
|
|
storage. For each connection with a specific UDP port on another machine,
|
|
|
|
a separate record is kept for each type of RPC (FetchFile, GetStatus, and
|
|
|
|
so on) sent or received. To display or otherwise access the records, use
|
|
|
|
the Rx Monitoring API.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-enable_process_stats>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Activates the collection of Rx statistics and allocates memory for their
|
|
|
|
storage. A separate record is kept for each type of RPC (FetchFile,
|
|
|
|
GetStatus, and so on) sent or received, aggregated over all connections to
|
|
|
|
other machines. To display or otherwise access the records, use the Rx
|
|
|
|
Monitoring API.
|
|
|
|
|
2008-01-23 04:13:55 +00:00
|
|
|
=item B<-allow-dotted-principal>
|
|
|
|
|
|
|
|
By default, the RXKAD security layer will disallow access by Kerberos
|
|
|
|
principals with a dot in the first component of their name. This is to avoid
|
|
|
|
the confusion where principals user/admin and user.admin are both mapped to the
|
|
|
|
user.admin PTS entry. Sites whose Kerberos realms don't have these collisions
|
|
|
|
between principal names may disable this check by starting the server
|
|
|
|
with this option.
|
|
|
|
|
2008-04-02 21:47:27 +01:00
|
|
|
=item B<-rxbind>
|
|
|
|
|
|
|
|
Bind the Rx socket to the primary interface only. (If not specified, the
|
|
|
|
Rx socket will listen on all interfaces.)
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-help>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
Prints the online help for this command. All other valid options are
|
|
|
|
ignored.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=back
|
|
|
|
|
|
|
|
=head1 EXAMPLES
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The following B<bos create> command creates a C<ptserver> process on the
|
|
|
|
machine C<fs3.abc.com>. The command appears here on multiple lines only
|
|
|
|
for legibility.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
% bos create -server fs3.abc.com -instance ptserver \
|
2005-12-08 12:14:33 +00:00
|
|
|
-type simple -cmd /usr/afs/bin/ptserver
|
|
|
|
|
|
|
|
=head1 PRIVILEGE REQUIRED
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The issuer must be logged in as the superuser C<root> on a file server
|
|
|
|
machine to issue the command at a command shell prompt. It is conventional
|
|
|
|
instead to create and start the process by issuing the B<bos create>
|
|
|
|
command.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=head1 SEE ALSO
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
L<BosConfig(5)>,
|
|
|
|
L<prdb.DB0(5)>,
|
|
|
|
L<bos_create(8)>,
|
|
|
|
L<bos_getlog(8)>,
|
2005-12-08 12:14:33 +00:00
|
|
|
L<pts(1)>
|
|
|
|
|
|
|
|
=head1 COPYRIGHT
|
|
|
|
|
|
|
|
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
|
|
|
|
|
|
|
|
This documentation is covered by the IBM Public License Version 1.0. It was
|
|
|
|
converted from HTML to POD by software written by Chas Williams and Russ
|
|
|
|
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.
|