Re: GSK - IBM Global Security Kit
Posted in 2009
On May 6, 12:43 am, Jonathan Leffler <jonathan.leff...@gmail.com>
wrote:
> On May 5, 2:27 am, PeterP <peterp...@gmail.com> wrote:
>
> > Installing V11.50.XC4. I'm just wondering a few things about this IBM
> > GSK - oh no it has IBM written on it :O
> > And why is the Info Centre offline with the manual detailing it? Too
> > hard to ask for a 24x7 website from IBM?
>
> > When you install Informix nowadays it seems to create /opt/ibm/gsk7 or
> > gsk7_64 and link some things to it as well. Are we back to the old /
> > usr/bin /usr/lib shared objects unable to install more than one
> > version of Informix on a host.
>
> You have always been able to install more than one version of IDS on a
> host. You must be confusing it with another DBMS.
>
>
> Yes, IDS 11 uses GSKit 7. It needs one copy of it on the machine; it
> is quite happy to share it with any other application that also uses
> GSKit.
>
> > I noticed it when reading my
> > $INFORMIXDIR/tmp/gskit.log install log - lots of errors.
>
> Not so good.
>
> > Also, if your hosts team use the "container clone method" to install
> > then is /opt/ibm/gsk* required along with the /usr symlinks?
>
> When IDS is running, it needs the GSKit links on the target machine.
>
> If you copy $INFORMIXDIR around, you get a copy of the GSKit
> installer, precisely so that you can fix up the target machine.
>
> > Can you just clone the $INFORMIXDIR (I know unsupported)?
>
> You can clone it; you have to run the GSKit installer on the target.
>
> > Or will you
> > run into errors, e.g. some internal part of the server requires a .so
> > in /usr. Or is it just if you're using SSL and if not (whatever that
> > may be) you can forget about the GSK?
>
> Anything cryptographic uses GSKit; not just SSL. You might get away
> without it, but probably won't. And your system is prone to sudden
> errors even if you manage to start it without GSKit. Think of GSKit
> as part of the woodwork; it has to be there for IDS to work.
>
> > There is a blurb in the machine notes. But it's not 110% clear what
> > uses it?
>
> > IBM Informix Dynamic Server uses the libraries and utilities provided
> > by
> > the IBM Global Security Kit (GSKit) for data encryption and Secure
> > Sockets
> > Layer (SSL) communication.
>
> > So Exactly what do I not have to be using to uninstall it or not care
> > when cloning?
>
> IDS? AFAIK, you need GSKit. You might get away with it being absent,
> but I'd not bet on it and certainly don't recommend it.
>
> > And is it me or is this messy like Windows having to think about /usr/
> > lib versions and architectures?
>
> I don't know whether it is you.
>
> Software like IDS sometimes has to build on other software - and using
> GSKit means you get FIPS 140-2 compliant encryption in IDS, and you
> get encryption software developed by professionals. If IDS did not
> use it, you would not get those benefits. It is also a carefully
> engineered, non-intrusive piece of software; the GSKit team has done
> an excellent job on the packaging of their product.
>
> And it is 'install and forget' too - it will be used by other IBM
> software that needs cryptographic support.
>
> You simply need to be aware that when you copy IDS to a 'virgin'
> machine that has not seen IDS before (not using the installer - that
> will deal with it for you), then you have to worry about installing
> GSKit. Once. This is better than the old days when IDS installed
> shared libraries into /usr/lib and you had to remember to set up the
> links from /usr/lib to the install location when you copied your
> software around. At least you get an installer to do the job for you.
>
> Thanks.
>
> -=JL=-
Hi Jonathan,
Thanks for the prompt reply.
I worked it out. :)
IBM needs to consider 'sparse containers' on Solaris or perhaps they
are unsupported? You can't write to /usr/lib with them. A Workaround
might be to install 32/64 gsk for each Node.
Damn, so I have to install GSK7 on every new host (sparse container
NODE IMC) in case some internal part of IDS needs it - this is what I
feared or at least it's playing safe. Now you pointed out the gsk
install dir under $INFORMIXDIR it's quite clearly in the README file
about tarring for install. Although it would have been nice if this
was in the machine notes. I didn't read the bit related to
uninstalling GSK and didn't think to look there as I was just happy to
leave it installed. Although if what you say above is true, then
uninstalling GSK isn't an option so why is it in the machine notes.
I'll get my hosts team who did this install to do but it would have
been a lot easier if Informix put everything in the INFORMIXDIR.
rather than /opt and create links. As you say, having an installer
helps and having to work with external programs isn't Informix's fault
and you do get encryption.
That said, my hosts team did just send me this in relation to the
32/64 bit directories, so an FYI. I imagine they are not the only host
people in the world who might install software this way and hence the
machine notes might need to be updated? Tha't your call though.
"I have copied over the two directories as requested from orantestinx2
instead of doing an install as I am pressed for time. If this doesn't
work let me know and I will run install when I can."
And after talking to them, they are of the opinion that if there are
any dependencies then it should be clearly noted somewhere to avoid
these situations or so they can foresee the sparse container problem.
It's not quite as messy as before when linking /usr/lib as you mention
(ISM wasn't it, I forget such a long time ago now) but that's what I
was getting at with my windows comment.
I can mail you / post my logfile, but it's only going to cause
searching groups to return lots of results, so I'll leave for the
moment. Basically any sparse container writes failed. I'll put in a
PMR.
I presume it's not at all possible that some other IBM program /
crypto might need an earlier version of an .so in GSK7 and fail? I did
note the _64 suffix though in the error log file, so it should work
cross architectures.
I'll open a PMR about the container issue. But I'll be interested to
hear your thoughts on the matter.
Mark says above that oninit is smart. Smart enough to run the
installer for gsk if it isn't there, that's how I read what he is
saying?
Cheers,
PP.