Dear all,

I have a question regarding the CES service, aka protocol nodes.
Our CES cluster is configured with the AD authentication and, accordingly to 
the documentation [1], SSSD should not be running on the CES nodes. For us 
that's quite annoying, since we can't login with our personal/central accounts 
and then sudo.
Neither we can use winbind, since samba-winbind-modules package (that provides 
the necessary PAM module) conflicts with the gpfs.smb package.
We will probably end up creating one or more local accounts and using ssh keys 
for access.
But I wonder if someone with a similar problem found a better workaround.

Thanks,
Ivano

[1] 
https://www.ibm.com/docs/en/storage-scale/5.2.0?topic=authentication-limitations

__________________________________________
Paul Scherrer Institut
Ivano Talamo
OBBA/230
Forschungsstrasse 111
5232 Villigen PSI
Schweiz

Phone: +41 56 310 47 11
E-Mail: [email protected]

Available: Monday - Wednesday

_______________________________________________
gpfsug-discuss mailing list
gpfsug-discuss at gpfsug.org
http://gpfsug.org/mailman/listinfo/gpfsug-discuss_gpfsug.org

Reply via email to