Re: [xcat-user] Error Issues zVM
Good morning Chuck. Just follow up from my last email. I am still having trouble getting zhcp up. Thanks ! On Sep 26, 2014 10:31 AM, Michael Weiner mwei...@infinite-blue.com wrote: Hi Chuck Have you had a chance to take a look at my zHCP log? I have a PMR open as well with Mike. Thanks! On Thu, Sep 25, 2014 at 3:43 PM, Michael Weiner mwei...@infinite-blue.com wrote: Chuck here is my startup of my zHCP machine. On Thu, Sep 25, 2014 at 3:21 PM, Michael Weiner mwei...@infinite-blue.com wrote: I can ping my xCAT and xCAT MN from command prompt. I can access the GUI through either .83 or .84. I can't ping my zHCP node at all. From my previous email sspmodload: Failed sspmodload: -105 sspmodload: Socket read retry error sspmodload: Unable to determine SMAPI level. sspmodload: Replacing user profile OSDFLT... Failed sspmodload: -105 sspmodload: sspmodload: Couldn't process PROFILE OSDFLT (OSDFLT.SAMPPROF on 193) sspmodload: Creating user profile OSDFLT... Failed sspmodload: -105 As a result of the SSH it says 1 Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). 0 1 1 On Thu, Sep 25, 2014 at 3:11 PM, Chuck Brazie bra...@us.ibm.com wrote: So how do you ping it? From browser, z/VM, or xCAT GUI? One way to tell if xCAT can get to zhcp is in the xCAT user interface, go to Nodes-Nodes, select xcat, then actions-run script (From the troubleshooting appendix B in IBM Cloud Manager with OpenStack for System z). Put in your zhcp ip address in place of the default 10.10.10.20 ssh 10.10.10.20 ls -al /var/log/zhcp If you get back a listing of log files on zhcp, then your xcat management node can get to zhcp. Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/25/2014 02:29 PM Subject:Re: [xcat-user] Error Issues zVM -- Chuck I dug a little further. My xCAT user IP is 10.100.0.83 and my MGMNT NODE is 10.100.0.84.. I can PING both of these machines. I can't PING 10.100.0.85 which is my zHCP server. Could that be causing the problems? On Thu, Sep 25, 2014 at 1:59 PM, Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com wrote: Mike, It thinks you have two zhcp's but I would guess you do not. Go to Configure-Tables and take a look at the data in these tables: nodehm nodelist zvm The code does a query of (which you can run if you like: go to Nodes-Nodes, select xcat, then Actions-run script) /opt/xcat/bin/nodels mgt==zvm zvm.hcp That gets back the list of zhcp's (could be duplicates) then it grabs the first dot delimited token in the long name like *zhcp.endicott.ibm.com* http://zhcp.endicott.ibm.com/ (gets zhcp) and then keeps the unique ones for the zhcp node names. Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com From:Michael Weiner *mwei...@infinite-blue.com* mwei...@infinite-blue.com To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net* xcat-user@lists.sourceforge.net Date:09/25/2014 09:47 AM Subject:Re: [xcat-user] Error Issues zVM -- Chuck Thanks for the help yesterday, I am not sure if you got my last message as it was to large to send. I had a screenshot in there. When I look at Provision / z/VM on the tabs: Disks zFCP Networks I am getting Querying 2 zhcp(s) for networks. Querying networks from: zhcpzhcp (1 of 2) Querying networks from: (2 of 2) Error: Invalid nodes and/or groups in noderange: zhcpzhcp I don't see anything I also can't see the storage I added to localmod. -- Michael Weiner Systems Admin Infinity Systems Software, Inc. One Penn Plaza Suite 2010 New York, NY 10119 o: (646) 405-9300 c: (845) 641-0517 -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list
Re: [xcat-user] Error Issues zVM
Did you try what Mike recommended? I was out of town Friday. I checked with Mike yesterday and he has not heard from you. Chuck Brazie bra...@us.ibm.com From: Michael Weiner mwei...@infinite-blue.com To: xCAT Users Mailing list xcat-user@lists.sourceforge.net Date: 09/30/2014 07:45 AM Subject:Re: [xcat-user] Error Issues zVM Good morning Chuck. Just follow up from my last email. I am still having trouble getting zhcp up. Thanks ! On Sep 26, 2014 10:31 AM, Michael Weiner mwei...@infinite-blue.com wrote: Hi Chuck Have you had a chance to take a look at my zHCP log? I have a PMR open as well with Mike. Thanks! On Thu, Sep 25, 2014 at 3:43 PM, Michael Weiner mwei...@infinite-blue.com wrote: Chuck here is my startup of my zHCP machine. On Thu, Sep 25, 2014 at 3:21 PM, Michael Weiner mwei...@infinite-blue.com wrote: I can ping my xCAT and xCAT MN from command prompt. I can access the GUI through either .83 or .84. I can't ping my zHCP node at all. From my previous email sspmodload: Failed sspmodload: -105 sspmodload: Socket read retry error sspmodload: Unable to determine SMAPI level. sspmodload: Replacing user profile OSDFLT... Failed sspmodload: -105 sspmodload: sspmodload: Couldn't process PROFILE OSDFLT (OSDFLT.SAMPPROF on 193) sspmodload: Creating user profile OSDFLT... Failed sspmodload: -105 As a result of the SSH it says 1 Permission denied (publickey,gssapi-keyex,gssapi-with-mic,password). 0 1 1 On Thu, Sep 25, 2014 at 3:11 PM, Chuck Brazie bra...@us.ibm.com wrote: So how do you ping it? From browser, z/VM, or xCAT GUI? One way to tell if xCAT can get to zhcp is in the xCAT user interface, go to Nodes-Nodes, select xcat, then actions-run script (From the troubleshooting appendix B in IBM Cloud Manager with OpenStack for System z). Put in your zhcp ip address in place of the default 10.10.10.20 ssh 10.10.10.20 ls -al /var/log/zhcp If you get back a listing of log files on zhcp, then your xcat management node can get to zhcp. Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/25/2014 02:29 PM Subject:Re: [xcat-user] Error Issues zVM Chuck I dug a little further. My xCAT user IP is 10.100.0.83 and my MGMNT NODE is 10.100.0.84.. I can PING both of these machines. I can't PING 10.100.0.85 which is my zHCP server. Could that be causing the problems? On Thu, Sep 25, 2014 at 1:59 PM, Chuck Brazie bra...@us.ibm.com wrote: Mike, It thinks you have two zhcp's but I would guess you do not. Go to Configure-Tables and take a look at the data in these tables: nodehm nodelist zvm The code does a query of (which you can run if you like: go to Nodes-Nodes, select xcat, then Actions-run script) /opt/xcat/bin/nodels mgt==zvm zvm.hcp That gets back the list of zhcp's (could be duplicates) then it grabs the first dot delimited token in the long name like zhcp.endicott.ibm.com (gets zhcp) and then keeps the unique ones for the zhcp node names. Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/25/2014 09:47 AM Subject:Re: [xcat-user] Error Issues zVM Chuck Thanks for the help yesterday, I am not sure if you got my last message as it was to large to send. I had a screenshot in there. When I look at Provision / z/VM on the tabs: Disks zFCP Networks I am getting Querying 2 zhcp(s) for networks. Querying networks from: zhcpzhcp (1 of 2) Querying networks from: (2 of 2) Error: Invalid nodes and/or groups in noderange: zhcpzhcp I don't see anything I also can't see the storage I added to localmod. -- Michael Weiner Systems Admin Infinity Systems Software, Inc. One Penn Plaza Suite 2010 New York, NY 10119 o: (646) 405-9300 c: (845) 641-0517 -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance
Re: [xcat-user] Error Issues zVM
I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user
Re: [xcat-user] Error Issues zVM
When those commands were isdued i got Permission denied. From the X cat user I ran them. On Sep 30, 2014 8:42 AM, Chuck Brazie bra...@us.ibm.com wrote: What was the output from these two commands? Finally, he should wait 3 minutes and attempt to use the Run Script dialog against XCAT node to issue the following commands: ssh zhcp pwd perl /opt/xcat/bin/zxcatIVP.pl Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/30/2014 08:21 AM Subject:Re: [xcat-user] Error Issues zVM -- I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user
Re: [xcat-user] Questions on prerequisites for external DNS and makedns -e
Hi Xiao, Here is the relevant zone: zone morgan.haib.org in { type master; file morgan/db.morgan.haib.org; allow-transfer { 10.20.0.100/32; 10.20.0.101/32; }; allow-update { key xcat_key; }; notify yes; }; Its allow-update looks the same as the one for zone 20.10.IN-ADDR.ARPA. I saw no messages in /var/log/messages concerning named. But I did just try it again this morning and the opposite happened: 'morgan.haib.org' updated but 20.10.IN-ADDR.ARPA. did not. So the issue is very inconsistent, other than that one of the two entries gets omitted. See below (which I have shortened some), and notice where it says request is not signed for the 20.10 zone, but it signed (this time!) the morgain.haib.org zone: 0-Sep-2014 10:01:39.446 socket 0x7ff551edebc8 172.26.42.60#58640: packet received correctly 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: UDP request 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: using view '_default' 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: request is not signed 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: recursion available 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640: query 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): ns_client_attach: ref = 1 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): query '20.10.IN-ADDR.ARPA/NS/IN' approved 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): send 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): sendto 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): senddone 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): next 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): ns_client_detach: ref = 0 30-Sep-2014 10:01:39.446 client 172.26.42.60#58640 (20.10.IN-ADDR.ARPA): endrequest 30-Sep-2014 10:01:39.446 client @0x7ff5480d7710: udprecv ... ... 30-Sep-2014 10:01:39.454 socket 0x7ff551edebc8 172.26.42.60#42345: packet received correctly 30-Sep-2014 10:01:39.454 client 172.26.42.60#42345: UDP request 30-Sep-2014 10:01:39.454 client 172.26.42.60#42345: using view '_default' 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345: request has valid signature: xcat_key 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: recursion available 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: update 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: ns_client_attach: ref = 1 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': prerequisites are OK 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: signer xcat_key approved 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: update 'morgan.haib.org/IN' approved 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': update section prescan OK 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': adding an RR at 'node0014.morgan.haib.org' A 10.20.101.14 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': checking for NSEC3PARAM changes 30-Sep-2014 10:01:39.455 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': writing journal morgan/db.morgan.haib.org.jnl 30-Sep-2014 10:01:39.455 writing to journal 30-Sep-2014 10:01:39.455 del morgan.haib.org. 86400 IN SOA dns01.morgan.haib.org. root.dns01.morgan.haib.org. 2012080935 10800 3600 604800 86400 30-Sep-2014 10:01:39.455 add morgan.haib.org. 86400 IN SOA dns01.morgan.haib.org. root.dns01.morgan.haib.org. 2012080936 10800 3600 604800 86400 30-Sep-2014 10:01:39.455 add node0014.morgan.haib.org. 86400 IN A 10.20.101.14 30-Sep-2014 10:01:39.476 client 172.26.42.60#42345/key xcat_key: updating zone 'morgan.haib.org/IN': committing update transaction 30-Sep-2014 10:01:39.477 zone_needdump: zone morgan.haib.org/IN: enter 30-Sep-2014 10:01:39.477 zone_settimer: zone morgan.haib.org/IN: enter 30-Sep-2014 10:01:39.477 zone_settimer: zone morgan.haib.org/IN: enter I'll send another email with other possibly relevant details to keep this one's length down. -Josh On Mon, Sep 29, 2014 at 9:40 PM, Xiao Peng Wang w...@cn.ibm.com wrote: Then, in this case, did you check the 'allow of key xcat_key' has been set correctly in name.conf for zone morgan.haib.org? And did you see any useful message for this error in the syslog of external server? Thanks Best Regards -- Wang Xiaopeng (王晓朋) IBM China System Technology Laboratory Tel: 86-10-82453455 Email: w...@cn.ibm.com Address: 28,ZhongGuanCun Software Park,No.8 Dong Bei Wang West Road, Haidian District Beijing P.R.China 100193 Josh Nielsen ---2014/09/30 06:49:50---Okay, I have the external DNS server working: partly. For some very odd reason the external
Re: [xcat-user] Questions on prerequisites for external DNS and makedns -e
Xiao, For some additional details I am running BIND 9.10.0-P2 which I compiled from source. I used --enable-largefile which specfies 64-bit file support but I noticed this in the kernel boot messages in /var/log/messages: Sep 29 11:25:25 dns01 kernel: warning: `named' uses 32-bit capabilities (legacy support in use) When I start named in the foreground here are the first few lines, where you can see my compile options and a few things about startup: 30-Sep-2014 09:59:20.672 built with '--prefix=/opt/bind9' '--sysconfdir=/etc' '--with-gtest' '--with-log4cplus=/opt/log4cplus' '--with-pythonpath=/usr/bin/python' '--localstatedir=/var' '--mandir=/usr/share/man' '--enable-threads' '--enable-largefile' '--with-libtool' '--disable-static' '--with-openssl' 30-Sep-2014 09:59:20.672 30-Sep-2014 09:59:20.672 BIND 9 is maintained by Internet Systems Consortium, 30-Sep-2014 09:59:20.672 Inc. (ISC), a non-profit 501(c)(3) public-benefit 30-Sep-2014 09:59:20.672 corporation. Support and training for BIND 9 are 30-Sep-2014 09:59:20.672 available at https://www.isc.org/support 30-Sep-2014 09:59:20.672 30-Sep-2014 09:59:20.672 adjusted limit on open files from 4096 to 1048576 30-Sep-2014 09:59:20.672 found 1 CPU, using 1 worker thread 30-Sep-2014 09:59:20.672 using 1 UDP listener per interface 30-Sep-2014 09:59:20.672 using up to 4096 sockets 30-Sep-2014 09:59:20.672 Registering DLZ_dlopen driver 30-Sep-2014 09:59:20.672 Registering SDLZ driver 'dlopen' 30-Sep-2014 09:59:20.672 Registering DLZ driver 'dlopen' 30-Sep-2014 09:59:20.676 decrement_reference: delete from rbt: 0x7ff551ecd148 . 30-Sep-2014 09:59:20.678 socket 0x7ff551ede010: created 30-Sep-2014 09:59:20.678 sockmgr 0x7ff551ec6010: watcher got message -3 for socket 20 30-Sep-2014 09:59:20.678 sockmgr 0x7ff551ec6010: watcher got message -2 for socket -1 30-Sep-2014 09:59:20.678 socket 0x7ff551ede010: socket_recv: event 0x7ff551ee0010 - task 0x7ff551ed9250 30-Sep-2014 09:59:20.678 loading configuration from '/etc/named.conf' 30-Sep-2014 09:59:20.679 reading built-in trusted keys from file '/etc/bind.keys' I've been planning to move to an RPM based installation rolled out with CentOS but was testing with a source install first. Does any of this look like a likely culprit for the problems I'm seeing? Thanks, Josh On Mon, Sep 29, 2014 at 9:40 PM, Xiao Peng Wang w...@cn.ibm.com wrote: Then, in this case, did you check the 'allow of key xcat_key' has been set correctly in name.conf for zone morgan.haib.org? And did you see any useful message for this error in the syslog of external server? Thanks Best Regards -- Wang Xiaopeng (王晓朋) IBM China System Technology Laboratory Tel: 86-10-82453455 Email: w...@cn.ibm.com Address: 28,ZhongGuanCun Software Park,No.8 Dong Bei Wang West Road, Haidian District Beijing P.R.China 100193 [image: Inactive hide details for Josh Nielsen ---2014/09/30 06:49:50---Okay, I have the external DNS server working: partly. For some]Josh Nielsen ---2014/09/30 06:49:50---Okay, I have the external DNS server working: partly. For some very odd reason the external DNS serv From: Josh Nielsen jniel...@hudsonalpha.org To: xCAT Users Mailing list xcat-user@lists.sourceforge.net Date: 2014/09/30 06:49 Subject: Re: [xcat-user] Questions on prerequisites for external DNS and makedns -e -- Okay, I have the external DNS server working: partly. For some very odd reason the external DNS server is only receiving the request to enter the reverse lookup for a new node (ex: makedns -e node0014), but does not even attempt to add the forward lookup zone. I see the key authorization passed successfully for the reverse entry, so there are no authentication issues, and when I try a manual 'nsupdate' it adds the forward lookup definition just fine: # nsupdate -k /etc/rndc.key server [external_dns_ip] prereq nxdomain *node0014.morgan.haib.org* http://node0014.morgan.haib.org/. update add *node0014.morgan.haib.org* http://node0014.morgan.haib.org/. 300 A 10.20.101.14 send It looks like 'makedns -e node0014' is somehow sending ONLY the reverse lookup definition (though this is only a guess). This is what the client sees: [root@JNDev ~]# makedns -e node0014 Handling node0014 in /etc/hosts. Getting reverse zones, this may take several minutes for a large cluster. Completed getting reverse zones. Updating DNS records, this may take several minutes for a large cluster. Error: No reply received when sending DNS update to zone *morgan.haib.org* http://morgan.haib.org/. Completed updating DNS records. It updates my reverse zone '20.10.IN-ADDR.ARPA' in the file 'db.10.20' but for the DNS zone '*morgan.haib.org* http://morgan.haib.org/' I see the message: Error: No reply received when sending DNS update to zone
Re: [xcat-user] Error Issues zVM
Did Mike have you erase the ID_RSA PUB key(s)? Ex: Resetting the SSH keys is a little simpler. a. LOGON MAINT630 b. ACCESS 193 T c. ACCESS 493 U d. LINK XCAT 191 1191 MR e. ACCESS 1191 V f. FILELIST ID_RSA PUB * g. ERASE all copies of this file h. DETACH 1191 i. Restart XCAT and ZHCP userids Chuck Brazie bra...@us.ibm.com From: Michael Weiner mwei...@infinite-blue.com To: xCAT Users Mailing list xcat-user@lists.sourceforge.net Date: 09/30/2014 08:21 AM Subject:Re: [xcat-user] Error Issues zVM I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user
Re: [xcat-user] Error Issues zVM
Chuck No I have no done that but I just did and I am getting the same error. There was only 1 public key file. Do I need to go onto zHCP and repeat that process as well? On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie bra...@us.ibm.com wrote: Did Mike have you erase the ID_RSA PUB key(s)? Ex: Resetting the SSH keys is a little simpler. a. LOGON MAINT630 b. ACCESS 193 T c. ACCESS 493 U d. LINK XCAT 191 1191 MR e. ACCESS 1191 V f. FILELIST ID_RSA PUB * g. ERASE all copies of this file h. DETACH 1191 i. Restart XCAT and ZHCP userids Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/30/2014 08:21 AM Subject:Re: [xcat-user] Error Issues zVM -- I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user -- Michael Weiner Systems Admin Infinity Systems Software, Inc. One Penn Plaza Suite 2010 New York, NY 10119 o: (646) 405-9300 c: (845) 641-0517 -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk___ xCAT-user mailing list xCAT-user@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/xcat-user
Re: [xcat-user] Error Issues zVM
Did all of the steps and I am having the same results. I linked over to the new restored disks to see the messages and they are the same as before. Is it possible to send me your zCHP (OS) ? I am wondering if I upload your copy and DDRREST, that would work. What are your thoughts? I don't understand why we are having so much trouble getting this up and running here. On Tue, Sep 30, 2014 at 2:31 PM, Chuck Brazie bra...@us.ibm.com wrote: zhcp just needs the xCAT public key so it will allow xCAT to issue commands to zhcp. You can clear out more things by erasing the zhcp persistent disk along with the SSH keys in zhcp. From MAINT, do SIGNAL SHUTDOWN XCAT WITHIN 20 SIGNAL SHUTDOWN ZHCP WITHIN 20 From MAINT, you need to reset the ZHCP 100 disk by doing the following: LINK ZCHCP 100 1100 MR ACCESS 193 T ACCESS 400 R DDRREST 1100 ECKD100 IMAGE R DETACH 1100 From MAINT ACCESS 193 T ERASE ID_RSA PUB T link maint 493 493 mr ACCESS 493 T ERASE ID_RSA PUB T LINK XCAT 191 291 MR ACCESS 291 T ERASE ID_RSA PUB T DETACH 291 From MAINT XAUTOLOG XCAT XAUTOLOG ZHCP Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/30/2014 01:47 PM Subject:Re: [xcat-user] Error Issues zVM -- Chuck No I have no done that but I just did and I am getting the same error. There was only 1 public key file. Do I need to go onto zHCP and repeat that process as well? On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com wrote: Did Mike have you erase the ID_RSA PUB key(s)? Ex: Resetting the SSH keys is a little simpler. a. LOGON MAINT630 b. ACCESS 193 T c. ACCESS 493 U d. LINK XCAT 191 1191 MR e. ACCESS 1191 V f. FILELIST ID_RSA PUB * g. ERASE all copies of this file h. DETACH 1191 i. Restart XCAT and ZHCP userids Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com From:Michael Weiner *mwei...@infinite-blue.com* mwei...@infinite-blue.com To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net* xcat-user@lists.sourceforge.net Date:09/30/2014 08:21 AM Subject:Re: [xcat-user] Error Issues zVM -- I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk* http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net *https://lists.sourceforge.net/lists/listinfo/xcat-user* https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk* http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net *https://lists.sourceforge.net/lists/listinfo/xcat-user* https://lists.sourceforge.net/lists/listinfo/xcat-user -- Michael Weiner Systems Admin Infinity Systems Software, Inc. One Penn Plaza Suite 2010 New York, NY 10119 o: (646) 405-9300 c: (845) 641-0517 -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list xCAT-user@lists.sourceforge.net
Re: [xcat-user] Error Issues zVM
I had a similar problem .. Do the same thing to xcat 100 as zhcp 100. Erase the RSA files and give it a try. On Tue, Sep 30, 2014 at 11:49 AM, Michael Weiner mwei...@infinite-blue.com wrote: Did all of the steps and I am having the same results. I linked over to the new restored disks to see the messages and they are the same as before. Is it possible to send me your zCHP (OS) ? I am wondering if I upload your copy and DDRREST, that would work. What are your thoughts? I don't understand why we are having so much trouble getting this up and running here. On Tue, Sep 30, 2014 at 2:31 PM, Chuck Brazie bra...@us.ibm.com wrote: zhcp just needs the xCAT public key so it will allow xCAT to issue commands to zhcp. You can clear out more things by erasing the zhcp persistent disk along with the SSH keys in zhcp. From MAINT, do SIGNAL SHUTDOWN XCAT WITHIN 20 SIGNAL SHUTDOWN ZHCP WITHIN 20 From MAINT, you need to reset the ZHCP 100 disk by doing the following: LINK ZCHCP 100 1100 MR ACCESS 193 T ACCESS 400 R DDRREST 1100 ECKD100 IMAGE R DETACH 1100 From MAINT ACCESS 193 T ERASE ID_RSA PUB T link maint 493 493 mr ACCESS 493 T ERASE ID_RSA PUB T LINK XCAT 191 291 MR ACCESS 291 T ERASE ID_RSA PUB T DETACH 291 From MAINT XAUTOLOG XCAT XAUTOLOG ZHCP Chuck Brazie bra...@us.ibm.com From:Michael Weiner mwei...@infinite-blue.com To:xCAT Users Mailing list xcat-user@lists.sourceforge.net Date:09/30/2014 01:47 PM Subject:Re: [xcat-user] Error Issues zVM -- Chuck No I have no done that but I just did and I am getting the same error. There was only 1 public key file. Do I need to go onto zHCP and repeat that process as well? On Tue, Sep 30, 2014 at 1:30 PM, Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com wrote: Did Mike have you erase the ID_RSA PUB key(s)? Ex: Resetting the SSH keys is a little simpler. a. LOGON MAINT630 b. ACCESS 193 T c. ACCESS 493 U d. LINK XCAT 191 1191 MR e. ACCESS 1191 V f. FILELIST ID_RSA PUB * g. ERASE all copies of this file h. DETACH 1191 i. Restart XCAT and ZHCP userids Chuck Brazie *bra...@us.ibm.com* bra...@us.ibm.com From:Michael Weiner *mwei...@infinite-blue.com* mwei...@infinite-blue.com To:xCAT Users Mailing list *xcat-user@lists.sourceforge.net* xcat-user@lists.sourceforge.net Date:09/30/2014 08:21 AM Subject:Re: [xcat-user] Error Issues zVM -- I did as suggested in the pmr and still the same results. Zhcp unreachable. I logged off zhcp and xcat. I xautolog xcat and zhcp simultaneously - waited 5 minutes and ran script and still the same issue. -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk* http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net *https://lists.sourceforge.net/lists/listinfo/xcat-user* https://lists.sourceforge.net/lists/listinfo/xcat-user -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer *http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk* http://pubads.g.doubleclick.net/gampad/clk?id=154622311iu=/4140/ostg.clktrk ___ xCAT-user mailing list *xCAT-user@lists.sourceforge.net* xCAT-user@lists.sourceforge.net *https://lists.sourceforge.net/lists/listinfo/xcat-user* https://lists.sourceforge.net/lists/listinfo/xcat-user -- Michael Weiner Systems Admin Infinity Systems Software, Inc. One Penn Plaza Suite 2010 New York, NY 10119 o: (646) 405-9300 c: (845) 641-0517 -- Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer