Re: Newbie Question

"Frank D. Engel, Jr." <[email protected]> Wed, 18 Dec 2019 18:57:27 -0500
Newsgroups gmane.os.plan9.general
Message-ID <[email protected]>
ok, I seem to have run into another one.

I now have the file server booting as a cpu server with authentication=20
enabled, and am trying to net boot another host from there.

I have dhcpd and tftpd running on the file server; my /cfg/pxe/default=20
looks like this:


bootfile=3D/386/9pc

bootargs=3Dtls

auth=3D192.168.81.12

fs=3D192.168.81.10

mouseport=3Dps2intellimouse

monitor=3Dvesa

vgasize=3D1440x900x32

*acpi=3D1


The entry in /lib/ndb/local is (with "..." being the actual MAC address):


sys=3Dthinker ether=3D... ip=3D192.168.81.20

 =C2=A0=C2=A0=C2=A0 dom=3Dthinker.9cluster

 =C2=A0=C2=A0=C2=A0 bootf=3D/386/9bootpxe



The "thinker" system is starting the plan9 kernel over the network (it=20
has no local disk); I get prompted for a user account and for now am=20
just using "glenda".=C2=A0 I enter the password I set for the auth server,=
=20
for secstore, and for the filesystem on the file server (I used the same=20
for each), and I am getting this on "thinker":


mount: mount /root: tls error

mount -c #s/boot /root: mount 145: mount


bootargs is (tcp, tls, il, local!device)[tls]


When this happens the file server console shows this:


/bin/aux/trampoline: dial net!$fs!9fs: connection rejected


I'm not sure if this means that the file server is rejecting the=20
connection from the (currently) terminal, or what might be going on...=C2=
=A0=20
the "$fs" showing up on the file server console seems curious to me as I=20
would have thought if that were coming from the terminal the "$fs" would=20
have been translated from there?=C2=A0 Again not sure where to go from here=
...


I was originally having a problem with secstored not having a "factotum"=20
file for the terminal to retrieve, but after having worked that one out=20
it now stored a key in it (and is no longer asking me to set one) for my=20
"dom=3D9cluster", so I did manage to get past that one.


I also noticed that if I retry from the bootargs prompt I get the=20
additional message "ipconfig: dialicmp6: address in use", but I am=20
guessing that is simply a leftover from the earlier attempt, and=20
assuming I can safely ignore that...




On 12/16/19 4:40 PM, Frank D. Engel, Jr. wrote:
> Thank you!
>
>
> When I tried bringing it up as a cpu server with auth enabled it did=20
> indeed make it past the errors.
>
> I'll see if I can work things out from there.
>
>
> On 12/16/19 2:27 PM, [email protected] wrote:
>> i believe that this is due to running a with service=3Dterminal.
>> this causes factotum to be started as a client with no keys in it.
>>
>> the p9any auth protocol starts by the server presenting a set of
>> keys, auth domains and protocols, which you wont have in this
>> case (no keys there). which is most likely the reason the whole
>> thing fails.
>>
>> if you boot your fileserver with service=3Dcpu, then when factotum starts
>> it will prompt you for authid and password which will be the credentials
>> of the hostowner (of the fileserver) which should have to match what you
>> have on the authentication server. this information can be stored in
>> nvram to avoid the prompt on boot.
>>
>> even if it doesnt match the auth key for (that user) on the authserver,
>> the fileserver should be able to boot and mount its root filesystem
>> as factotum talks to itself in this scenario and having the same keys
>> on both sides.
>>
>> its just about to fail when there are no keys at all.
>>
>> i hope this makes sense.
>>
>> --=20
>> cinap
>>
>=20

------------------------------------------
9fans: 9fans
Permalink: https://9fans.topicbox.com/groups/9fans/Tda6e61e03ce222c0-Mb0812=
7daf7703de537047e02
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription