Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ssh on a VIO server?

Status
Not open for further replies.

Chapter11

Technical User
Apr 15, 2002
791
US
Does anyone know if there is any danger to installing OpenSSH on a VIO server?

The main reason I want to do this is so that I can perform certain activities remotely. Our 570 is attached to a SAN, so when I need additional disk space, there's a nice bit of black magic involved to make that LUN available to an LPAR that requires consulting an increasing large and unpleasent table in Excel.

I want to automate this. My scripting skills are completely up to the task, the only issue that I have is that the rksh environment of padmin won't run any scripts I create there, and running them as root isn't doable since certain commands don't exist, or don't return the same sort of output that I need to parse. I would be using ssh primary as a remote execution facility, so I would have say, ServerA run a script ssh in, run a command, then parse the output back on ServerA to both catalog the LUN allocation/configuration characteristics, as well as construct the appropriate mkvdev command to push a new LUN out to a given LPAR. (and all the while, maintain our naming convention for devices)
 
Hi

Its officialy Supported to install OpenSSH on the VIO Server. ( OpenSSL -> Linux Toolbox, OpenSSH -> Expansion CD )
Other Hardening Stuff must be aproved by IBM Support.
 
AIX 5L? Have you seen this is documentation. I was told at a class it was supported, however, I haven't seen it in documentation anywhere.

I have noticed that the version on the 5.3 expansion cd ignores the root rlogin value, however, the latest version available from sourceforge.net which is linked from the IBM Linux toolbox website, does check the root rlogin value so you don't need to make the config (sshd_config) file entry.

I haven't installed ssl/ssh on a VIO yet because I can't find anything online saying it's supported.
 
Hi hfaix

It's not from Documentation.
I opened a PMR and that was the Answer of the Support ;->
I allways modifiy the sshd_config.
If you need your specific OpenSSH BFF File you can build it from Scratch.

 
it's funny you mention "I allways modifiy the sshd_config." I've been going back and forth on it. I like the pop box saying rlogin=false I get without it when using OpenSSH_3.8.1p1, but from an auditting standpoint, I suppose it's better to not have to defend why it's not commented out.

Thanks for the info.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top