Re: GSK - IBM Global Security Kit
Posted in 2009
Topics: Installation, Setup & Upgrades, Security, Permissions & Auditing, Cloud, Docker & Containers
On 5 May, 10:27, PeterP <peterp...@gmail.com> wrote: > Installing V11.50.XC4. I'm just wondering a few things about this IBM > GSK - oh no it has IBM written on it :O > And why is the Info Centre offline with the manual detailing it? To > hard to ask for a 24x7 website from IBM? > > When you install Informix nowadays it seems to create /opt/ibm/gsk7 or > gsk7_64 and link some things to it as well. Are we back to the old / > usr/bin /usr/lib shared objects unable to install more than one > version of Informix on a host. I noticed it when reading my > $INFORMIXDIR/tmp/gskit.log install log - lots of errors. > > Also, if your hosts team use the "container clone method" to install > then is /opt/ibm/gsk* required along with the /usr symlinks? > Can you just clone the $INFORMIXDIR (I know unsupported)? Or will you > run into errors, e.g. some internal part of the server requires a .so > in /usr. Or is it just if you're using SSL and if not (whatever that > may be) you can forget about the GSK? > > There is a blurb in the machine notes. But it's not 110% clear what > uses it? > > IBM Informix Dynamic Server uses the libraries and utilities provided > by > the IBM Global Security Kit (GSKit) for data encryption and Secure > Sockets > Layer (SSL) communication. > > So Exactly what do I not have to be using to uninstall it or not care > when cloning? > And is it me or is this messy like Windows having to think about /usr/ > lib versions and architectures? Can someone from IBM confirm this was done and provide a fix? Can we override the location? What if /opt is part of a standard OS build that cannot be changed just because this machine runs informix?
On May 7, 8:42 am, "da...@smooth1.co.uk" <da...@smooth1.co.uk> wrote: > On 5 May, 10:27, PeterP <peterp...@gmail.com> wrote: > > > > > Installing V11.50.XC4. I'm just wondering a few things about this IBM > > GSK - oh no it has IBM written on it :O > > And why is the Info Centre offline with the manual detailing it? To > > hard to ask for a 24x7 website from IBM? > > > When you install Informix nowadays it seems to create /opt/ibm/gsk7 or > > gsk7_64 and link some things to it as well. Are we back to the old / > > usr/bin /usr/lib shared objects unable to install more than one > > version of Informix on a host. I noticed it when reading my > > $INFORMIXDIR/tmp/gskit.log install log - lots of errors. > > > Also, if your hosts team use the "container clone method" to install > > then is /opt/ibm/gsk* required along with the /usr symlinks? > > Can you just clone the $INFORMIXDIR (I know unsupported)? Or will you > > run into errors, e.g. some internal part of the server requires a .so > > in /usr. Or is it just if you're using SSL and if not (whatever that > > may be) you can forget about the GSK? > > > There is a blurb in the machine notes. But it's not 110% clear what > > uses it? > > > IBM Informix Dynamic Server uses the libraries and utilities provided > > by > > the IBM Global Security Kit (GSKit) for data encryption and Secure > > Sockets > > Layer (SSL) communication. > > > So Exactly what do I not have to be using to uninstall it or not care > > when cloning? > > And is it me or is this messy like Windows having to think about /usr/ > > lib versions and architectures? > > Can someone from IBM confirm this was done and provide a fix? Can we > override the location? > > What if /opt is part of a standard OS build that cannot be changed > just because this machine runs informix? David, good luck with relocating. :) Confirmation from IBM. I've not tried yet, but sounds good. Still somewhat grumpy about the /opt install & linking though. IBM said they will maybe update release notes. My gripe is I wasn't really much aware that anything is installed outside the INFORMIXDIR/... and I have bad memories of the old linking ways. I think this fix is specific to 'sparse-root-model' zones rather than for 'full-root-model' zones. I imagine most people use this more efficient / smaller model though? See 3.4 here: http://www.sun.com/bigadmin/features/articles/zones_partition.jsp The diagnosis from the technote is- "GSKit is not installed because GSKit was not properly prepared for a local zone installation" You were correct in anticipating the answer was to install in the global zone. The document is marked for 'internal use only' so I will summarise the resolution... In order to resolve the GSKit installation issue, it is necessary to perform a GSKit installation in the global zone, which will allow files to be written to /usr/bin and /usr/lib. The GSKit can then be installed in the local zone. This subsequent installation of GSKit in the local zone does not require write access to /usr/bin and /usr/lib, because the necessary files have been written there. This solution assumes that the local zone has write access to its own copy of /opt/ibm, and does not share /opt/ibm from the global zone. 1. Log into the global zone as the root user. Note: GSKit must always be installed as the root user. This is part of the design of GSKit. 2. Navigate to the "GSKit" directory of your product installation image. 3. Run the following command, which will install GSKit into the global zone: pkgadd -G -a ./admin -n -d . gsk7bas Note: See the note following these instructions regarding the use of the "-G" parameter. 4. The following command will install 64-bit GSKit into the global zone (The 32-bit libraries, installed in the previous step, must also be installed.): pkgadd -G -a ./admin -n -d . gsk7bas64 Note: Regarding 64-bit- It is generally better to install it if it is available, rather than not install it and encounter problems because it is missing. 5. After GSKit is installed in the global zone, Informix can be installed in the local zone. Log into the local zone to which Informix will be installed. Proceed to install Informix following normal procedures. About the -G parameter used with the pkgadd command in Part 1 of this solution When installing GSKit into the global zone, it is necessary to use the "-G" parameter with the pkgadd command, as shown in the instructions above. The "-G" parameter instructs the pkgadd utility to install the package only in the global zone. If the "-G" parameter is accidentally omitted, then pkgadd will try to install GSKit into every zone. This is not necessarily bad, but it is preferable to avoid doing that.