Jump to content

Recommended Posts

Posted
I blame John personally...

 

Well I suppose that is the other thing that links the two problems. And on closer consideration the root cause of the problem! Everything else must just be coincidence :eek:

 

Sorry I broke it :o :p

Posted
I blame John personally...

:o Now didn't Andy want this invoice on my desk paying....... :p hehe :)

 

Nah defo not my fault as such forward thinking Edugeeks there would be someone fairly quickly to spot this I suspect if I hadn't, maybe there all using it as a traditional SAN was though and mapping iSCSI LUNs to Servers and serving them that way where as I'm being a SANAS user and server directly to cut the middle man out :D

Posted
Well I suppose that is the other thing that links the two problems. And on closer consideration the root cause of the problem! Everything else must just be coincidence :eek:

 

Sorry I broke it :o :p

Yup, I was thinking it was my LACP Trunk I setup that had done it as it occured when I rebooted it all from doing that (long story as to why I rebooted it all) but I think that just masked it having a secret love affair with a 2008 R2 DC behind the poor 2003 R2 DC's back poor 2003 Server I bet its feeling very unloved and upset, first the San takes all its work (it was a file server as a main role as well as DC, DHCP, DNS.... ok maybe it had a few more roles lol) so it stole all them roles, and then it got them jobs and went and starting being very cosy behind its back with a new friend (a £200 HP ML110 as well VS a big 8GB Ram Evesham Server - Clearly the SUN kit has taste dumping an Evesham for a HP ;) )

Posted
Don't worry, I've broken our 7410 enough times that Andy or Phil just phone me up and sigh now. :p

 

I think of it as doing Sun a favour by stress testing it... :whistle:

 

Keeps us busy sir :)

Posted
Guys,

 

just been doing some digging. As it is late I have not had chance to digest or test

 

CIFS Service Troubleshooting - Genunix

 

Will have Kim follow up in the morning as I am out and about.

Seems that those hot fixes don't apply to R2 and from reading the Wiki you linked to Andy that it suggests that you should use an R2 Copy of Server 2008 OR 2008 SP2 patched etc etc so I think that its expecting it to be working....

Posted
Seems that those hot fixes don't apply to R2 and from reading the Wiki you linked to Andy that it suggests that you should use an R2 Copy of Server 2008 OR 2008 SP2 patched etc etc so I think that its expecting it to be working....

 

Ah ok.

 

I am going to try to escalate this as I have just tried 2008 against my AR sim and it fails. The 2003 DC is happy as Larry.

Posted
Ah ok.

 

I am going to try to escalate this as I have just tried 2008 against my AR sim and it fails. The 2003 DC is happy as Larry.

110% Confirmed neither of those MS Patches or regedits make a bit of difference as I've tested them on the work setup (see another dedicated sole! - who also has a lot of users, some of whom will be in tomorrow - aka results day, who would like to get onto there documents, department shared areas, roaming profiles, mandatory profiles..... that are now inaccessible to them) I can see my USB Socket on my PC is going to be busy (Revoked all access to old copies of data on old servers before copying over and then unshared them etc as it was working until it had it "love affair" with my 2008 R2, strange thing is the 2008 R2 DC had been in about 3 days before the SAN went in so why did it decided not to rendevouz with it sooner?

Posted (edited)

Ok, I can confirm 110% it seems to be a 2008 issue, restarted my 2008 R2 DC and attempted to join my SAN to the Domain whilst it was rebooting and it has decided to have a relationship with my 2003 DC, wonder what happens when its back up and I reboot the AD and CIFS service on the san.....

 

Before someone says set the join preference to a 2003 DC, Kim already suggested and we tried that and nope it prefers a bit of 2008 :p

 

Edit - 2008 R2 DC back up, restarted CIFS and AD on the S7000 and it shows in the AD Screen that its now back in bed with the 2008 R2 and it no longer lets me integrated authenticate my CIFS which it did fine with 2003. So is there any way of hacking the code in these as I fear that this may take a bit of time for Sun to fix in the code (based on the very large amount of stuff all over i've found on the earlier 2008 problems that were present where it was lower the security levels, apply MS request patches etc...) to force it to ALWAYS talk to a 2003 DC?

 

2nd Edit: Ok continued poking around seems to get it going.... Turn off 2008 R2 DC (assuming you can so my friend on R2 only your a bit snookered), join to domain with out, when it picks it back up (reboot CIFS and AD a couple of times) you will see when you browse it won't authenticate, go to CIFS settings, ensure compat level is 3, set it to 4 then reboot, browse again > fail, set to 3 reboot, browse again > Fail, set to 2, reboot, Browse again > Success!

 

Seems to be VERY tetchy on if it want's to do it so clearly is some bug I think still but mine is now on again and seems to be, touch wood, behaving.

 

I have also done the following:

The mailing lists suggest that the problem might be related to smb signing. On the DC, I opened up the Group Policy Management tool and changed the following:

 

Computer Configuration\Policies\Administrative Templates\System\Net

Logon\Allow Cryptography Algorithms Compatible with Windows NT 4.0 -> Enabled

 

I then ran a gpupdate /force.

 

Source: http://livingonthecloud.blogspot.com/2009/02/joining-opensolaris-cifs-server-to-ad.html

 

Fine this was part of the original 2008 Fix which isn't needed now as the box should be updated to a release that fixes it, but that seemed to do it, I set that in the Default Domain Policy so everything gets it. I can reboot the SAN now and it seems fine every time and reboot the 2008 and 2003 DCs and it not drop off so seems to be happy for the moment but clearly somethings not quite right........

Edited by john
  • Thanks 1
Posted
Ok, I can confirm 110% it seems to be a 2008 issue, restarted my 2008 R2 DC and attempted to join my SAN to the Domain whilst it was rebooting and it has decided to have a relationship with my 2003 DC, wonder what happens when its back up and I reboot the AD and CIFS service on the san.....

 

Before someone says set the join preference to a 2003 DC, Kim already suggested and we tried that and nope it prefers a bit of 2008 :p

 

Edit - 2008 R2 DC back up, restarted CIFS and AD on the S7000 and it shows in the AD Screen that its now back in bed with the 2008 R2 and it no longer lets me integrated authenticate my CIFS which it did fine with 2003. So is there any way of hacking the code in these as I fear that this may take a bit of time for Sun to fix in the code (based on the very large amount of stuff all over i've found on the earlier 2008 problems that were present where it was lower the security levels, apply MS request patches etc...) to force it to ALWAYS talk to a 2003 DC?

 

Does your S7000 actually connect to the 2008 R2 domain? Mine doesn't even get that far :(

 

I've tried playing with the various security policies to enable NT4.0 level compatability (Modify Default Security Policies on Windows Server 2008-Based Domain Controllers) but it still doesn't want to work unfortunately. Have to say I'm really hoping that Sun fix this issue quickly!

Posted
That's it ... crack the whip .. get the minion on the job whilst you get a sun-tan on the beach ;-)

 

Minion! I'll give you minion Shep.

 

:getmecoat:

Posted
Ok, I can confirm 110% it seems to be a 2008 issue, restarted my 2008 R2 DC and attempted to join my SAN to the Domain whilst it was rebooting and it has decided to have a relationship with my 2003 DC, wonder what happens when its back up and I reboot the AD and CIFS service on the san.....

 

Before someone says set the join preference to a 2003 DC, Kim already suggested and we tried that and nope it prefers a bit of 2008 :p

 

Edit - 2008 R2 DC back up, restarted CIFS and AD on the S7000 and it shows in the AD Screen that its now back in bed with the 2008 R2 and it no longer lets me integrated authenticate my CIFS which it did fine with 2003. So is there any way of hacking the code in these as I fear that this may take a bit of time for Sun to fix in the code (based on the very large amount of stuff all over i've found on the earlier 2008 problems that were present where it was lower the security levels, apply MS request patches etc...) to force it to ALWAYS talk to a 2003 DC?

 

2nd Edit: Ok continued poking around seems to get it going.... Turn off 2008 R2 DC (assuming you can so my friend on R2 only your a bit snookered), join to domain with out, when it picks it back up (reboot CIFS and AD a couple of times) you will see when you browse it won't authenticate, go to CIFS settings, ensure compat level is 3, set it to 4 then reboot, browse again > fail, set to 3 reboot, browse again > Fail, set to 2, reboot, Browse again > Success!

 

Seems to be VERY tetchy on if it want's to do it so clearly is some bug I think still but mine is now on again and seems to be, touch wood, behaving.

 

I have also done the following:

The mailing lists suggest that the problem might be related to smb signing. On the DC, I opened up the Group Policy Management tool and changed the following:

 

Computer Configuration\Policies\Administrative Templates\System\Net

Logon\Allow Cryptography Algorithms Compatible with Windows NT 4.0 -> Enabled

 

I then ran a gpupdate /force.

 

Source: Living on the Cloud: Joining an OpenSolaris CIFS server to an AD domain

 

Fine this was part of the original 2008 Fix which isn't needed now as the box should be updated to a release that fixes it, but that seemed to do it, I set that in the Default Domain Policy so everything gets it. I can reboot the SAN now and it seems fine every time and reboot the 2008 and 2003 DCs and it not drop off so seems to be happy for the moment but clearly somethings not quite right........

 

Good post John, investigating your findings now on a 2008 R2 functional set up to see if we can refine them with KB942564 and the LM Compat levels above.

Posted
Does your S7000 actually connect to the 2008 R2 domain? Mine doesn't even get that far :(

 

I've tried playing with the various security policies to enable NT4.0 level compatability (Modify Default Security Policies on Windows Server 2008-Based Domain Controllers) but it still doesn't want to work unfortunately. Have to say I'm really hoping that Sun fix this issue quickly!

Yes mine "plays fine" when you look at the AD screen it shows it as using my 2008 R2 DC as the AD Server. It will not join the AD at all though on 2008 R2 (and I'm not giving it another go now as its on and working so its not being touched again for fear of locking every user out of everything!!!) Maybe worth trying my later part fix about the CIFS but obviously you won't be able to browse it as its not in domain mode but give it a go and do my steps and see if it then magically allows you to join the R2 Domain?

 

After I set the option I list in my Fix post, I set it at the Default Domain Policy so it applies to EVERYTHING, Workstations, Servers, SAN, DCs the lot, and rebooted the DC a few times so maybe you need to do that rather than letting it do its usual refresh

Posted
Yes mine "plays fine" when you look at the AD screen it shows it as using my 2008 R2 DC as the AD Server. It will not join the AD at all though on 2008 R2 (and I'm not giving it another go now as its on and working so its not being touched again for fear of locking every user out of everything!!!) Maybe worth trying my later part fix about the CIFS but obviously you won't be able to browse it as its not in domain mode but give it a go and do my steps and see if it then magically allows you to join the R2 Domain?

 

After I set the option I list in my Fix post, I set it at the Default Domain Policy so it applies to EVERYTHING, Workstations, Servers, SAN, DCs the lot, and rebooted the DC a few times so maybe you need to do that rather than letting it do its usual refresh

 

I'll give that a try in a bit. I've always got the fallback of just setting up some 2008 R2 file servers to serve files off the SAN that way - one of the benefits of virtualisation :)

Posted
Well I've got the CIFS shares connecting over NFS on a Windows file server and then being shared out that way for now. Just hope that there's a fix so I can do the sharing without the file server in the middle :)
  • 3 weeks later...
Posted

We have our 5 virtualised (VMWARE) admin servers running on our two X4140’s and 7110 now and all seems to be well – so far after 2 weeks live anyhow.

 

SIMS runs really well virtualised – I was a bit worried about that initially. The benefits of snapshots have already helped us roll back a mistake on the RIS server in a matter of minutes! Also separating out the services has really helped being able to reboot a server and not lose every network service.

 

The sun kit is great (this is the first time I’ve used it) – the service processor is excellent for remote management - The analytics on the 7110 are superb too, Thanks to Andy from cutter for his help with the sun kit.

 

This has been a really useful thread – thanks for the help and info received.

  • Thanks 3
Posted
We have our 5 virtualised (VMWARE) admin servers running on our two X4140’s and 7110 now and all seems to be well – so far after 2 weeks live anyhow.

 

This is really good to hear as we'll be doing something very similar next summer! Would you mind posting the odd update if you run into any major issues over the next few months? From what I've heard it all sounds good though. :)

 

Update from me too - 300GB of shared resources are live on our 7410 with no issues. The flash accelerators and analytics are really great. New Year 7 intake on the SAN as well and the storage is functioning fine, we're just running into a couple of issues with mapped folder redirection (XP bug).

 

Cheers,

Chris

  • Thanks 1
Posted
This is really good to hear as we'll be doing something very similar next summer! Would you mind posting the odd update if you run into any major issues over the next few months? From what I've heard it all sounds good though. :)

 

Cheers,

Chris

 

Yep I'll keep posting any issues etc. As we installed our kit we have documented everything in depth for our Disaster recovery plan. Once we tidy that up I’ll post it along with schematics - obviously with sensitive information omitted but someone may find it useful.

  • Thanks 1
Posted
Yep I'll keep posting any issues etc. As we installed our kit we have documented everything in depth for our Disaster recovery plan. Once we tidy that up I’ll post it along with schematics - obviously with sensitive information omitted but someone may find it useful.

 

Do not forget to post it on our forums also

  • 3 weeks later...
Posted (edited)

I thought I might as well re-use this thread rather than making a new one, hope someone can help...

 

(I've emailed Cutter support but figured I'd post here too)

 

I’ve got a CIFS share which contains student’s userspaces (i.e. lots of subfolders with their usernames). Permissions are set for the individual student users by the program that creates the folders and accounts, no problems there.

 

Staff need read-only permissions on these folders, which I set by doing ‘Read Data/List Directory ®’ and ‘Execute File/Traverse Directory (x)’ with inheritance on the root directory ACL of the share. This has just been properly tested for the first time and staff can’t open student’s files.

 

They can access the share, browse through folders, but when they try to open a file Word tells them they do not have permission. Looking at the file ALC in Windows, staff have ‘Special Permissions’ (unsurprising since it’s a Solaris box which sets them) and running effective permissions gives them traverse folder / execute file and list folder / read data.

 

Question 1: What needs to be set on the S7000 to give them read permissions?

Question 2: How do I do this now there is data in the share? Last time I tried it, adding permissions to a share didn’t affect any data that already existed in the share. I am convinced this behaviour is incorrect as it defeats the purpose of being able to modify an ACL on the S7000 once the share is in use. Windows defaults to inheriting any changed permissions down through the folder tree, and with Linux you can do it with chown -R.

 

Separate question: When browsing the shares I noticed that it looks like all my share permissions (not the root directory permissions) have been reset to everyone:allowed rather than how I configured them. The only thing I've changed recently was upgrading to Q2.5.0. Has anyone else experienced this? It would be a bit of a major problem if I'd used share level ACL for security!

 

Many thanks in advance for any help anyone can provide! :)

Chris

Edited by Duke
Posted

Hi Chris, I set my shares up on the SAN as everyone full control them re-set them all in Windows by doing \\SAN then right click on the share and set them manually.

 

I have on my student areas a group for staff and gave them special permisisons for read and execute everything from that folder down inc sub folders and files and it seemed to work fine on my testing, staff don't know they have this access, I put it in place so it was there for if needed was my idea rather than having to re-tweak them. I would screenshot but awaiting my box to come back up from the Q3.1.0 software which has the fix in for my crashing problem :)

 

Haven't noticed the share permissions on mine but will check in the morning for you....

  • Thanks 1
Posted

FYI Excellent document on Windows Integration and S7000 from Sun

 

BigAdmin Feature Article: Microsoft Windows Integration on the Sun Storage 7000 Unified Storage System

  • 1 Overview
  • 2 Scope
  • 3 Prerequisites
    • 3.1 Operating System Prerequisites
    • 3.2 Storage System Prerequisites

     

    [*]4 Sun Storage 7000 Unified Storage System Configuration Best Practices

    • 4.1 System Configuration

     

    [*]5 Implementation Procedures

    • 5.1 System Configuration
    • 5.2 Services Configuration
    • 5.3 Share Configuration
    • 5.4 Share Management From Windows Server 2003 R2
    • 5.5 Publishing Shares to Active Directory
    • 5.6 Data Migration
    • 5.7 DFS Target
    • 5.8 Snapshot
    • 5.9 Analytics

     

    [*]6 Quick Troubleshooting

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...