Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Michael Weiner
Good morning Chuck. Just follow up from my last email.  I am still having
trouble getting zhcp up.

Thanks !
On Sep 26, 2014 10:31 AM, Michael Weiner mwei...@infinite-blue.com
wrote:

 Hi Chuck

 Have you had a chance to take a look at my zHCP log?

 I have a PMR open as well with Mike.

 Thanks!

 On Thu, Sep 25, 2014 at 3:43 PM, Michael Weiner mwei...@infinite-blue.com
  wrote:

 Chuck here is my startup of my zHCP machine.

 On Thu, Sep 25, 2014 at 3:21 PM, Michael Weiner 
 mwei...@infinite-blue.com wrote:

 I can ping my xCAT and xCAT MN from command prompt. I can access the GUI
 through either .83 or .84.

 I can't ping my zHCP node at all. From my previous email

 sspmodload: Failed
 sspmodload: -105
 sspmodload: Socket read retry error
 sspmodload: Unable to determine SMAPI level.
 sspmodload: Replacing user profile OSDFLT... Failed
 sspmodload: -105
 sspmodload:
 sspmodload: Couldn't process PROFILE OSDFLT (OSDFLT.SAMPPROF on 193)
 sspmodload: Creating user profile OSDFLT... Failed
 sspmodload: -105

 As a result of the SSH it says

 1
  Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).
 0
 1

 1



 On Thu, Sep 25, 2014 at 3:11 PM, Chuck Brazie bra...@us.ibm.com wrote:

 So how do you ping it? From browser, z/VM, or xCAT GUI?

 One way to tell if xCAT can get to zhcp is in the xCAT user interface,
 go to Nodes-Nodes, select xcat, then actions-run script
  (From the troubleshooting appendix  B in IBM Cloud Manager with
 OpenStack for System z).

  Put in your zhcp ip address in place of the default 10.10.10.20

 ssh 10.10.10.20 ls -al /var/log/zhcp

 If you get back a listing of log files on zhcp, then your xcat
 management node can get to zhcp.

 Chuck Brazie
 bra...@us.ibm.com




 From:Michael Weiner mwei...@infinite-blue.com
 To:xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date:09/25/2014 02:29 PM
 Subject:Re: [xcat-user] Error Issues zVM
 --



 Chuck

 I dug a little further.

 My xCAT user IP is 10.100.0.83 and my MGMNT NODE is 10.100.0.84.. I can
 PING both of these machines.

 I can't PING 10.100.0.85 which is my zHCP server. Could that be causing
 the problems?



 On Thu, Sep 25, 2014 at 1:59 PM, Chuck Brazie *bra...@us.ibm.com*
 bra...@us.ibm.com wrote:
 Mike,
 It thinks you have two zhcp's but I would guess you do not. Go to
 Configure-Tables and take a look at the data in these tables:

 nodehm
 nodelist
 zvm

 The code does a query of  (which you can run if you like: go to
 Nodes-Nodes, select xcat, then Actions-run script)

 /opt/xcat/bin/nodels mgt==zvm zvm.hcp

 That gets back the list of zhcp's (could be duplicates) then it grabs
 the first dot delimited token in the long name like
 *zhcp.endicott.ibm.com* http://zhcp.endicott.ibm.com/ (gets zhcp)
 and then keeps the unique ones for the zhcp node names.

 Chuck Brazie
 *bra...@us.ibm.com* bra...@us.ibm.com




 From:Michael Weiner *mwei...@infinite-blue.com*
 mwei...@infinite-blue.com
 To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net*
 xcat-user@lists.sourceforge.net
 Date:09/25/2014 09:47 AM
 Subject:Re: [xcat-user] Error Issues zVM
  --




 Chuck

 Thanks for the help yesterday, I am not sure if you got my last message
 as it was to large to send. I had a screenshot in there.

 When I look at Provision / z/VM

 on the tabs:

 Disks
 zFCP
 Networks

 I am getting

 Querying 2 zhcp(s) for networks.


 Querying networks from: zhcpzhcp (1 of 2)
 Querying networks from: (2 of 2)
 Error: Invalid nodes and/or groups in noderange: zhcpzhcp

 I don't see anything


 I also can't see the storage I added to localmod.

 --
 Michael Weiner
 Systems Admin
 Infinity Systems Software, Inc.
 One Penn Plaza Suite 2010
 New York, NY 10119
 o: (646) 405-9300
 c: (845) 641-0517
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/xcat-user



 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 

Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Chuck Brazie
Did you try what Mike recommended? I was out of town Friday. I checked 
with Mike yesterday and he has not heard from you.

Chuck Brazie 
bra...@us.ibm.com




From:   Michael Weiner mwei...@infinite-blue.com
To: xCAT Users Mailing list xcat-user@lists.sourceforge.net
Date:   09/30/2014 07:45 AM
Subject:Re: [xcat-user] Error Issues zVM



Good morning Chuck. Just follow up from my last email.  I am still having  
trouble getting zhcp up.
Thanks !
On Sep 26, 2014 10:31 AM, Michael Weiner mwei...@infinite-blue.com 
wrote:
Hi Chuck

Have you had a chance to take a look at my zHCP log? 

I have a PMR open as well with Mike.

Thanks!

On Thu, Sep 25, 2014 at 3:43 PM, Michael Weiner mwei...@infinite-blue.com
 wrote:
Chuck here is my startup of my zHCP machine.

On Thu, Sep 25, 2014 at 3:21 PM, Michael Weiner mwei...@infinite-blue.com
 wrote:
I can ping my xCAT and xCAT MN from command prompt. I can access the GUI 
through either .83 or .84.

I can't ping my zHCP node at all. From my previous email

sspmodload: Failed  
sspmodload: -105
sspmodload: Socket read retry error 
sspmodload: Unable to determine SMAPI level.
sspmodload: Replacing user profile OSDFLT... Failed 
sspmodload: -105
sspmodload: 
sspmodload: Couldn't process PROFILE OSDFLT (OSDFLT.SAMPPROF on 193)
sspmodload: Creating user profile OSDFLT... Failed  
sspmodload: -105

As a result of the SSH it says

1
 Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password).

0
1
1


On Thu, Sep 25, 2014 at 3:11 PM, Chuck Brazie bra...@us.ibm.com wrote:
So how do you ping it? From browser, z/VM, or xCAT GUI? 

One way to tell if xCAT can get to zhcp is in the xCAT user interface, go 
to Nodes-Nodes, select xcat, then actions-run script 
 (From the troubleshooting appendix  B in IBM Cloud Manager with OpenStack 
for System z). 

 Put in your zhcp ip address in place of the default 10.10.10.20 

ssh 10.10.10.20 ls -al /var/log/zhcp 

If you get back a listing of log files on zhcp, then your xcat management 
node can get to zhcp. 

Chuck Brazie   
bra...@us.ibm.com




From:Michael Weiner mwei...@infinite-blue.com 
To:xCAT Users Mailing list xcat-user@lists.sourceforge.net 
Date:09/25/2014 02:29 PM 
Subject:Re: [xcat-user] Error Issues zVM 



Chuck 

I dug a little further. 

My xCAT user IP is 10.100.0.83 and my MGMNT NODE is 10.100.0.84.. I can 
PING both of these machines. 

I can't PING 10.100.0.85 which is my zHCP server. Could that be causing 
the problems? 



On Thu, Sep 25, 2014 at 1:59 PM, Chuck Brazie bra...@us.ibm.com wrote: 
Mike, 
It thinks you have two zhcp's but I would guess you do not. Go to 
Configure-Tables and take a look at the data in these tables: 

nodehm 
nodelist 
zvm 

The code does a query of  (which you can run if you like: go to 
Nodes-Nodes, select xcat, then Actions-run script) 

/opt/xcat/bin/nodels mgt==zvm zvm.hcp 

That gets back the list of zhcp's (could be duplicates) then it grabs the 
first dot delimited token in the long name like zhcp.endicott.ibm.com 
(gets zhcp) and then keeps the unique ones for the zhcp node names. 

Chuck Brazie   
bra...@us.ibm.com




From:Michael Weiner mwei...@infinite-blue.com 
To:xCAT Users Mailing list xcat-user@lists.sourceforge.net 
Date:09/25/2014 09:47 AM 
Subject:Re: [xcat-user] Error Issues zVM 




Chuck 

Thanks for the help yesterday, I am not sure if you got my last message as 
it was to large to send. I had a screenshot in there. 

When I look at Provision / z/VM  

on the tabs: 

Disks 
zFCP 
Networks 

I am getting 
Querying 2 zhcp(s) for networks. 

Querying networks from: zhcpzhcp (1 of 2)
Querying networks from: (2 of 2)
Error: Invalid nodes and/or groups in noderange: zhcpzhcp 

I don't see anything 


I also can't see the storage I added to localmod. 

-- 
Michael Weiner 
Systems Admin
Infinity Systems Software, Inc.
One Penn Plaza Suite 2010 
New York, NY 10119
o: (646) 405-9300
c: (845) 641-0517
--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user


--
Meet PCI DSS 3.0 Compliance 

Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Michael Weiner
I did as suggested in the pmr and still the same results. Zhcp unreachable.

I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously -
waited 5 minutes and ran script and still the same issue.
--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user


Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Michael Weiner
When those commands were isdued i got

Permission denied.

From the X cat user I ran them.
On Sep 30, 2014 8:42 AM, Chuck Brazie bra...@us.ibm.com wrote:

 What was the output from these two commands?

 Finally, he should wait 3 minutes and attempt to use the Run Script
 dialog against XCAT node to issue the following commands:
 ssh zhcp pwd
 perl /opt/xcat/bin/zxcatIVP.pl

 Chuck Brazie
 bra...@us.ibm.com




 From:Michael Weiner mwei...@infinite-blue.com
 To:xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date:09/30/2014 08:21 AM
 Subject:Re: [xcat-user] Error Issues zVM
 --



 I did as suggested in the pmr and still the same results. Zhcp
 unreachable.

 I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously -
 waited 5 minutes and ran script and still the same issue.
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/xcat-user



 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/xcat-user


--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user


Re: [xcat-user] Questions on prerequisites for external DNS and makedns -e

2014-09-30 Thread Josh Nielsen
Hi Xiao,

Here is the relevant zone:

zone morgan.haib.org in {
  type master;
  file morgan/db.morgan.haib.org;
  allow-transfer {
10.20.0.100/32;
10.20.0.101/32;
   };
   allow-update {
   key xcat_key;
   };
   notify yes;
};

Its allow-update looks the same as the one for zone
20.10.IN-ADDR.ARPA. I saw no messages in /var/log/messages
concerning named.

But I did just try it again this morning and the opposite happened:
'morgan.haib.org' updated but 20.10.IN-ADDR.ARPA. did not. So the
issue is very inconsistent, other than that one of the two entries
gets omitted. See below (which I have shortened some), and notice
where it says request is not signed for the 20.10 zone, but it
signed (this time!) the morgain.haib.org zone:

0-Sep-2014 10:01:39.446 socket 0x7ff551edebc8 172.26.42.60#58640:
packet received correctly
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: UDP request
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: using view '_default'
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: request is not signed
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: recursion available
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: query
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640
(20.10.IN-ADDR.ARPA): ns_client_attach: ref = 1
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640
(20.10.IN-ADDR.ARPA): query '20.10.IN-ADDR.ARPA/NS/IN' approved
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): send
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): sendto
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640
(20.10.IN-ADDR.ARPA): senddone
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): next
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640
(20.10.IN-ADDR.ARPA): ns_client_detach: ref = 0
30-Sep-2014 10:01:39.446 client 172.26.42.60#58640
(20.10.IN-ADDR.ARPA): endrequest
30-Sep-2014 10:01:39.446 client @0x7ff5480d7710: udprecv
...
...
30-Sep-2014 10:01:39.454 socket 0x7ff551edebc8 172.26.42.60#42345:
packet received correctly
30-Sep-2014 10:01:39.454 client 172.26.42.60#42345: UDP request
30-Sep-2014 10:01:39.454 client 172.26.42.60#42345: using view '_default'
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345: request has valid
signature: xcat_key
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
recursion available
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: update
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
ns_client_attach: ref = 1
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': prerequisites are OK
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
signer xcat_key approved
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
update 'morgan.haib.org/IN' approved
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': update section prescan OK
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': adding an RR at
'node0014.morgan.haib.org' A 10.20.101.14
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': checking for NSEC3PARAM changes
30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': writing journal
morgan/db.morgan.haib.org.jnl
30-Sep-2014 10:01:39.455 writing to journal
30-Sep-2014 10:01:39.455 del morgan.haib.org. 86400 IN SOA
dns01.morgan.haib.org. root.dns01.morgan.haib.org. 2012080935 10800
3600 604800 86400
30-Sep-2014 10:01:39.455 add morgan.haib.org. 86400 IN SOA
dns01.morgan.haib.org. root.dns01.morgan.haib.org. 2012080936 10800
3600 604800 86400
30-Sep-2014 10:01:39.455 add node0014.morgan.haib.org. 86400 IN A 10.20.101.14
30-Sep-2014 10:01:39.476 client 172.26.42.60#42345/key xcat_key:
updating zone 'morgan.haib.org/IN': committing update transaction
30-Sep-2014 10:01:39.477 zone_needdump: zone morgan.haib.org/IN: enter
30-Sep-2014 10:01:39.477 zone_settimer: zone morgan.haib.org/IN: enter
30-Sep-2014 10:01:39.477 zone_settimer: zone morgan.haib.org/IN: enter

I'll send another email with other possibly relevant details to keep
this one's length down.

-Josh

On Mon, Sep 29, 2014 at 9:40 PM, Xiao Peng Wang w...@cn.ibm.com wrote:
 Then, in this case, did you check the 'allow of key xcat_key' has been set
 correctly in name.conf for zone morgan.haib.org? And did you see any useful
 message for this error in the syslog of external server?

 Thanks
 Best Regards
 --
 Wang Xiaopeng (王晓朋)
 IBM China System Technology Laboratory
 Tel: 86-10-82453455
 Email: w...@cn.ibm.com
 Address: 28,ZhongGuanCun Software Park,No.8 Dong Bei Wang West Road, Haidian
 District Beijing P.R.China 100193

 Josh Nielsen ---2014/09/30 06:49:50---Okay, I have the external DNS server
 working: partly. For some very odd reason the external 

Re: [xcat-user] Questions on prerequisites for external DNS and makedns -e

2014-09-30 Thread Josh Nielsen
Xiao,

For some additional details I am running BIND 9.10.0-P2 which I compiled
from source. I used --enable-largefile which specfies 64-bit file
support but I noticed this in the kernel boot messages in
/var/log/messages:

Sep 29 11:25:25 dns01 kernel: warning: `named' uses 32-bit capabilities
(legacy support in use)

When I start named in the foreground here are the first few lines, where
you can see my compile options and a few things about startup:

30-Sep-2014 09:59:20.672 built with '--prefix=/opt/bind9'
'--sysconfdir=/etc' '--with-gtest' '--with-log4cplus=/opt/log4cplus'
'--with-pythonpath=/usr/bin/python' '--localstatedir=/var'
'--mandir=/usr/share/man' '--enable-threads' '--enable-largefile'
'--with-libtool' '--disable-static' '--with-openssl'
30-Sep-2014 09:59:20.672

30-Sep-2014 09:59:20.672 BIND 9 is maintained by Internet Systems
Consortium,
30-Sep-2014 09:59:20.672 Inc. (ISC), a non-profit 501(c)(3) public-benefit
30-Sep-2014 09:59:20.672 corporation.  Support and training for BIND 9 are
30-Sep-2014 09:59:20.672 available at https://www.isc.org/support
30-Sep-2014 09:59:20.672

30-Sep-2014 09:59:20.672 adjusted limit on open files from 4096 to 1048576
30-Sep-2014 09:59:20.672 found 1 CPU, using 1 worker thread
30-Sep-2014 09:59:20.672 using 1 UDP listener per interface
30-Sep-2014 09:59:20.672 using up to 4096 sockets
30-Sep-2014 09:59:20.672 Registering DLZ_dlopen driver
30-Sep-2014 09:59:20.672 Registering SDLZ driver 'dlopen'
30-Sep-2014 09:59:20.672 Registering DLZ driver 'dlopen'
30-Sep-2014 09:59:20.676 decrement_reference: delete from rbt:
0x7ff551ecd148 .
30-Sep-2014 09:59:20.678 socket 0x7ff551ede010: created
30-Sep-2014 09:59:20.678 sockmgr 0x7ff551ec6010: watcher got message -3 for
socket 20
30-Sep-2014 09:59:20.678 sockmgr 0x7ff551ec6010: watcher got message -2 for
socket -1
30-Sep-2014 09:59:20.678 socket 0x7ff551ede010: socket_recv: event
0x7ff551ee0010 - task 0x7ff551ed9250
30-Sep-2014 09:59:20.678 loading configuration from '/etc/named.conf'
30-Sep-2014 09:59:20.679 reading built-in trusted keys from file
'/etc/bind.keys'

I've been planning to move to an RPM based installation rolled out with
CentOS but was testing with a source install first. Does any of this look
like a likely culprit for the problems I'm seeing?

Thanks,
Josh

On Mon, Sep 29, 2014 at 9:40 PM, Xiao Peng Wang w...@cn.ibm.com wrote:

 Then, in this case, did you check the 'allow of key xcat_key' has been set
 correctly in name.conf for zone morgan.haib.org? And did you see any
 useful message for this error in the syslog of external server?

 Thanks
 Best Regards
 --
 Wang Xiaopeng (王晓朋)
 IBM China System Technology Laboratory
 Tel: 86-10-82453455
 Email: w...@cn.ibm.com
 Address: 28,ZhongGuanCun Software Park,No.8 Dong Bei Wang West Road,
 Haidian District Beijing P.R.China 100193

 [image: Inactive hide details for Josh Nielsen ---2014/09/30
 06:49:50---Okay, I have the external DNS server working: partly. For some]Josh
 Nielsen ---2014/09/30 06:49:50---Okay, I have the external DNS server
 working: partly. For some very odd reason the external DNS serv

 From: Josh Nielsen jniel...@hudsonalpha.org
 To: xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date: 2014/09/30 06:49
 Subject: Re: [xcat-user] Questions on prerequisites for external DNS and
 makedns -e
 --



 Okay, I have the external DNS server working: partly. For some very odd
 reason the external DNS server is only receiving the request to enter the
 reverse lookup for a new node (ex: makedns -e node0014), but does not even
 attempt to add the forward lookup zone. I see the key authorization passed
 successfully for the reverse entry, so there are no authentication issues,
 and when I try a manual 'nsupdate' it adds the forward lookup definition
 just fine:

 # nsupdate -k /etc/rndc.key
  server [external_dns_ip]
  prereq nxdomain *node0014.morgan.haib.org*
 http://node0014.morgan.haib.org/.
  update add *node0014.morgan.haib.org* http://node0014.morgan.haib.org/.
 300 A 10.20.101.14
  send

 It looks like 'makedns -e node0014' is somehow sending ONLY the reverse
 lookup definition (though this is only a guess). This is what the client
 sees:

 [root@JNDev ~]# makedns -e node0014
 Handling node0014 in /etc/hosts.
 Getting reverse zones, this may take several minutes for a large cluster.
 Completed getting reverse zones.
 Updating DNS records, this may take several minutes for a large cluster.
 Error: No reply received when sending DNS update to zone *morgan.haib.org*
 http://morgan.haib.org/.
 Completed updating DNS records.

 It updates my reverse zone '20.10.IN-ADDR.ARPA' in the file 'db.10.20' but
 for the DNS zone '*morgan.haib.org* http://morgan.haib.org/' I see the
 message: Error: No reply received when sending DNS update to zone
 

Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Chuck Brazie
Did Mike have you erase the ID_RSA PUB key(s)? Ex:

  Resetting the SSH keys is a little simpler.  
a.  LOGON MAINT630  
b.  ACCESS 193 T  
c.  ACCESS 493 U  
d.  LINK XCAT 191 1191 MR  
e.  ACCESS 1191 V  
f.  FILELIST ID_RSA PUB *  
g.  ERASE all copies of this file  
h.  DETACH 1191  
i.  Restart XCAT and ZHCP userids

Chuck Brazie 
bra...@us.ibm.com




From:   Michael Weiner mwei...@infinite-blue.com
To: xCAT Users Mailing list xcat-user@lists.sourceforge.net
Date:   09/30/2014 08:21 AM
Subject:Re: [xcat-user] Error Issues zVM



I did as suggested in the pmr and still the same results. Zhcp 
unreachable. 
I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - 
waited 5 minutes and ran script and still the same issue. 
--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user

--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user


Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Michael Weiner
Chuck

No I have no done that but I just did and I am getting the same error.
There was only 1 public key file.

Do I need to go onto zHCP and repeat that process as well?

On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie bra...@us.ibm.com wrote:

 Did Mike have you erase the ID_RSA PUB key(s)? Ex:

   Resetting the SSH keys is a little simpler.

a.  LOGON MAINT630

b.  ACCESS 193 T

c.  ACCESS 493 U

d.  LINK XCAT 191 1191 MR

e.  ACCESS 1191 V

f.  FILELIST ID_RSA PUB *

g.  ERASE all copies of this file

h.  DETACH 1191

i.  Restart XCAT and ZHCP userids

 Chuck Brazie
 bra...@us.ibm.com




 From:Michael Weiner mwei...@infinite-blue.com
 To:xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date:09/30/2014 08:21 AM
 Subject:Re: [xcat-user] Error Issues zVM
 --



 I did as suggested in the pmr and still the same results. Zhcp
 unreachable.

 I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously -
 waited 5 minutes and ran script and still the same issue.
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/xcat-user



 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/xcat-user




-- 
Michael Weiner
Systems Admin
Infinity Systems Software, Inc.
One Penn Plaza Suite 2010
New York, NY 10119
o: (646) 405-9300
c: (845) 641-0517
--
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user


Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Michael Weiner
Did all of the steps and I am having the same results. I linked over to the
new restored disks to see the messages and they are the same as before.

Is it possible to send me your zCHP (OS) ? I am wondering if I upload your
copy and DDRREST, that would work.

What are your thoughts? I don't understand why we are having so much
trouble getting this up and running here.

On Tue, Sep 30, 2014 at 2:31 PM, Chuck Brazie bra...@us.ibm.com wrote:

 zhcp just needs the xCAT public key so it will allow xCAT to issue
 commands to zhcp.

 You can clear out more things by erasing the zhcp persistent disk along
 with the SSH keys in zhcp.


 From MAINT, do

SIGNAL SHUTDOWN XCAT WITHIN 20
SIGNAL SHUTDOWN ZHCP WITHIN 20

 From MAINT, you need to reset the ZHCP 100 disk by doing the following:

LINK ZCHCP 100 1100 MR
ACCESS 193 T
ACCESS 400 R
DDRREST 1100 ECKD100 IMAGE R
DETACH 1100

 From MAINT

ACCESS 193 T
ERASE ID_RSA PUB T
link maint 493 493 mr
ACCESS 493 T
ERASE ID_RSA PUB T
LINK XCAT 191 291 MR
ACCESS 291 T
ERASE ID_RSA PUB T
DETACH 291

 From MAINT

XAUTOLOG XCAT
XAUTOLOG ZHCP


 Chuck Brazie
 bra...@us.ibm.com




 From:Michael Weiner mwei...@infinite-blue.com
 To:xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date:09/30/2014 01:47 PM
 Subject:Re: [xcat-user] Error Issues zVM
 --



 Chuck

 No I have no done that but I just did and I am getting the same error.
 There was only 1 public key file.

 Do I need to go onto zHCP and repeat that process as well?

 On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie *bra...@us.ibm.com*
 bra...@us.ibm.com wrote:
 Did Mike have you erase the ID_RSA PUB key(s)? Ex:

   Resetting the SSH keys is a little simpler.

a.  LOGON MAINT630

b.  ACCESS 193 T

c.  ACCESS 493 U

d.  LINK XCAT 191 1191 MR

e.  ACCESS 1191 V

f.  FILELIST ID_RSA PUB *

g.  ERASE all copies of this file

h.  DETACH 1191

i.  Restart XCAT and ZHCP userids

 Chuck Brazie
 *bra...@us.ibm.com* bra...@us.ibm.com




 From:Michael Weiner *mwei...@infinite-blue.com*
 mwei...@infinite-blue.com
 To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net*
 xcat-user@lists.sourceforge.net
 Date:09/30/2014 08:21 AM
 Subject:Re: [xcat-user] Error Issues zVM
  --



 I did as suggested in the pmr and still the same results. Zhcp
 unreachable.
 I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously -
 waited 5 minutes and ran script and still the same issue.
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk*
 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net
 *https://lists.sourceforge.net/lists/listinfo/xcat-user*
 https://lists.sourceforge.net/lists/listinfo/xcat-user


 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk*
 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net
 *https://lists.sourceforge.net/lists/listinfo/xcat-user*
 https://lists.sourceforge.net/lists/listinfo/xcat-user




 --
 Michael Weiner
 Systems Admin
 Infinity Systems Software, Inc.
 One Penn Plaza Suite 2010
 New York, NY 10119
 o: (646) 405-9300
 c: (845) 641-0517
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 xCAT-user@lists.sourceforge.net
 

Re: [xcat-user] Error Issues zVM

2014-09-30 Thread Tom Huegel
I had a similar problem .. Do the same thing to xcat 100 as zhcp 100. Erase
the RSA files and give it a try.

On Tue, Sep 30, 2014 at 11:49 AM, Michael Weiner mwei...@infinite-blue.com
wrote:

 Did all of the steps and I am having the same results. I linked over to
 the new restored disks to see the messages and they are the same as before.

 Is it possible to send me your zCHP (OS) ? I am wondering if I upload your
 copy and DDRREST, that would work.

 What are your thoughts? I don't understand why we are having so much
 trouble getting this up and running here.

 On Tue, Sep 30, 2014 at 2:31 PM, Chuck Brazie bra...@us.ibm.com wrote:

 zhcp just needs the xCAT public key so it will allow xCAT to issue
 commands to zhcp.

 You can clear out more things by erasing the zhcp persistent disk along
 with the SSH keys in zhcp.


 From MAINT, do

SIGNAL SHUTDOWN XCAT WITHIN 20
SIGNAL SHUTDOWN ZHCP WITHIN 20

 From MAINT, you need to reset the ZHCP 100 disk by doing the following:

LINK ZCHCP 100 1100 MR
ACCESS 193 T
ACCESS 400 R
DDRREST 1100 ECKD100 IMAGE R
DETACH 1100

 From MAINT

ACCESS 193 T
ERASE ID_RSA PUB T
link maint 493 493 mr
ACCESS 493 T
ERASE ID_RSA PUB T
LINK XCAT 191 291 MR
ACCESS 291 T
ERASE ID_RSA PUB T
DETACH 291

 From MAINT

XAUTOLOG XCAT
XAUTOLOG ZHCP


 Chuck Brazie
 bra...@us.ibm.com




 From:Michael Weiner mwei...@infinite-blue.com
 To:xCAT Users Mailing list xcat-user@lists.sourceforge.net
 Date:09/30/2014 01:47 PM
 Subject:Re: [xcat-user] Error Issues zVM
 --



 Chuck

 No I have no done that but I just did and I am getting the same error.
 There was only 1 public key file.

 Do I need to go onto zHCP and repeat that process as well?

 On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie *bra...@us.ibm.com*
 bra...@us.ibm.com wrote:
 Did Mike have you erase the ID_RSA PUB key(s)? Ex:

   Resetting the SSH keys is a little simpler.

a.  LOGON MAINT630

b.  ACCESS 193 T

c.  ACCESS 493 U

d.  LINK XCAT 191 1191 MR

e.  ACCESS 1191 V

f.  FILELIST ID_RSA PUB *

g.  ERASE all copies of this file

h.  DETACH 1191

i.  Restart XCAT and ZHCP userids

 Chuck Brazie
 *bra...@us.ibm.com* bra...@us.ibm.com




 From:Michael Weiner *mwei...@infinite-blue.com*
 mwei...@infinite-blue.com
 To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net*
 xcat-user@lists.sourceforge.net
 Date:09/30/2014 08:21 AM
 Subject:Re: [xcat-user] Error Issues zVM
  --



 I did as suggested in the pmr and still the same results. Zhcp
 unreachable.
 I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously -
 waited 5 minutes and ran script and still the same issue.
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk*
 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net
 *https://lists.sourceforge.net/lists/listinfo/xcat-user*
 https://lists.sourceforge.net/lists/listinfo/xcat-user


 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer

 *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk*
 http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk
 ___
 xCAT-user mailing list
 *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net
 *https://lists.sourceforge.net/lists/listinfo/xcat-user*
 https://lists.sourceforge.net/lists/listinfo/xcat-user




 --
 Michael Weiner
 Systems Admin
 Infinity Systems Software, Inc.
 One Penn Plaza Suite 2010
 New York, NY 10119
 o: (646) 405-9300
 c: (845) 641-0517
 --
 Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
 Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
 Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
 Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer