際際滷

際際滷Share a Scribd company logo
File Access and LUM Deployment with Novell 速   Open Enterprise Server 2 Martin Weiss , Senior Technical Specialist [email_address] Dr. Frieder Schmidt , Senior Technical Specialist [email_address]
Agenda Linux User Management (LUM)
File Access Protocols and Proxy User
NCP  , AFP, CIFS, (S)FTP, HTTP(S)
Deploying Multiple Methods for File Access
Troubleshooting
Question and Answer
Linux User Management (LUM)
Linux User Management Before deployment What does LUM do? Allow eDirectory   users and groups to show up as Linux users Why and what for do YOU need LUM? All services that run on base of Linux ex. Apache, FTP, SSH, SFTP, Samba
Administration Prepare your environment Naming conventions
Case sensitivity
POSIX attributes
ODBC / DSReport is your friend
Linux User Management Implementation Placement of objects in the tree Unix config object
Unix workstation objects Configuration of NAMCD  alternative-ldap-server-list
SSL certificates
 convert-lower
 cache-only
 persistent-search
Linux User Management LUM Enablement iManager or CLI
Groups
Users
namconfig cache_refresh
Which users should be LUM enabled for which servers? Troubleshooting duplicate UIDs/GIDs
Certificates for alternate LDAP server (namconfig -k)
File Access Protocols and Proxy User
Novell 速  Open Enterprise Server 2 The best multi-protocol file server Multiple choices of file systems Novell Storage Services
POSIX file systems: ext3, Reiser, XFS Multiple choices of file access protocols NCP   - Novell NetWare 速  Core Protocol
CIFS/SMB  Novell CIFS, Samba
AFP  Novell AFP
HTTP  NetStorage, Apache
FTP  PureFTP with Novell changes
NFS  Linux NFS
Proxy Users No server based authentication to eDirectory  Security Requirement for Kernel- vs. User-space CIFS, AFP, NetStorage and Samba require proxy users For accessing information from eDirectory
For reading user passwords for non-cleartext authentication Proxy user problem Too many proxy users per server
Management of proxy user password expiry
Security issue of reading user passwords
Proxy Users  (continued) Novell 速  Open Enterprise Server (OES) 2 FCS, SP1, SP2 One proxy user per service per server (AFP, CIFS, Samba, NetStorage, other OES services) Novell  Open Enterprise Server 2 SP3 Novell is looking at less proxy users and improved security
Default to a single OES common proxy for all services
Proxy user is made less powerful  no password read privileges NMAS   methods to do authentication on behalf of the services Auto-change of proxy passwords before expiry Future Novell is looking at service based authentication
Novell 速  NetWare Core Protocol   (NCP  )
NCP    High Level Features NCP Novell 速  Open Enterprise Server 2 SP2 Cross protocol file locking support between NCP, AFP and CIFS
Trustee change synchronization with eDirectory   - Deletion and rename of trustees
Trustee information obtained from _NETWARE/.trustee_database.xml
Auditing support for NCP file events
Salvage support (deleter) for non-LUM users Novell Open Enterprise Server 2 SP3 NCP volumes read only support functionality
Add the ability to disable logins per volume and automated clear connection Future release Improved performance
Ad

Recommended

Cl107
Cl107
Juliette Ponnet
Cl219
Cl219
Juliette Ponnet
Cl115
Cl115
Juliette Ponnet
Cl310
Cl310
Juliette Ponnet
Cl309
Cl309
Juliette Ponnet
Cl207
Cl207
Juliette Ponnet
Active directory installation windows 2003 1
Active directory installation windows 2003 1
tameemyousaf
Cl221
Cl221
Juliette Ponnet
Domain Services for Windows: Best Practices for Windows Interoperability
Domain Services for Windows: Best Practices for Windows Interoperability
Novell
Server interview[1]
Server interview[1]
sourav nanda
Failover cluster
Failover cluster
Chinmoy Jena
Distributed Filesystems Review
Distributed Filesystems Review
Schubert Zhang
Dfs (Distributed computing)
Dfs (Distributed computing)
Sri Prasanna
New File Server Features Of Windows Server 2008
New File Server Features Of Windows Server 2008
Microsoft TechNet
Clustering and High Availability
Clustering and High Availability
Information Technology
Mcse 2012
Mcse 2012
Mohammed Zainul Abiddin
Distributed file system
Distributed file system
Naza hamed Jan
MCSA Installing & Configuring Windows Server 2012 70-410
MCSA Installing & Configuring Windows Server 2012 70-410
omardabbas
Server 2008 r2 ppt
Server 2008 r2 ppt
Raj Solanki
Introduction to failover clustering with sql server
Introduction to failover clustering with sql server
Eduardo Castro
Ctive directory interview question and answers
Ctive directory interview question and answers
sankar palla
Distributed file systems
Distributed file systems
Sri Prasanna
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVA
Preparing forfirstconnectionsinstall
Preparing forfirstconnectionsinstall
Gabriella Davis
Lesson 4 intro to advanced o perating systems
Lesson 4 intro to advanced o perating systems
Jo Ko
11 distributed file_systems
11 distributed file_systems
longly
11. dfs
11. dfs
Dr Sandeep Kumar Poonia
Curriculum vitae
Curriculum vitae
dhanrajsharma2
File Access in Novell Open Enterprise Server 2 SP2
File Access in Novell Open Enterprise Server 2 SP2
Novell
Ram
Ram
Rami reddy

More Related Content

What's hot (20)

Domain Services for Windows: Best Practices for Windows Interoperability
Domain Services for Windows: Best Practices for Windows Interoperability
Novell
Server interview[1]
Server interview[1]
sourav nanda
Failover cluster
Failover cluster
Chinmoy Jena
Distributed Filesystems Review
Distributed Filesystems Review
Schubert Zhang
Dfs (Distributed computing)
Dfs (Distributed computing)
Sri Prasanna
New File Server Features Of Windows Server 2008
New File Server Features Of Windows Server 2008
Microsoft TechNet
Clustering and High Availability
Clustering and High Availability
Information Technology
Mcse 2012
Mcse 2012
Mohammed Zainul Abiddin
Distributed file system
Distributed file system
Naza hamed Jan
MCSA Installing & Configuring Windows Server 2012 70-410
MCSA Installing & Configuring Windows Server 2012 70-410
omardabbas
Server 2008 r2 ppt
Server 2008 r2 ppt
Raj Solanki
Introduction to failover clustering with sql server
Introduction to failover clustering with sql server
Eduardo Castro
Ctive directory interview question and answers
Ctive directory interview question and answers
sankar palla
Distributed file systems
Distributed file systems
Sri Prasanna
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVA
Preparing forfirstconnectionsinstall
Preparing forfirstconnectionsinstall
Gabriella Davis
Lesson 4 intro to advanced o perating systems
Lesson 4 intro to advanced o perating systems
Jo Ko
11 distributed file_systems
11 distributed file_systems
longly
11. dfs
11. dfs
Dr Sandeep Kumar Poonia
Curriculum vitae
Curriculum vitae
dhanrajsharma2
Domain Services for Windows: Best Practices for Windows Interoperability
Domain Services for Windows: Best Practices for Windows Interoperability
Novell
Server interview[1]
Server interview[1]
sourav nanda
Failover cluster
Failover cluster
Chinmoy Jena
Distributed Filesystems Review
Distributed Filesystems Review
Schubert Zhang
Dfs (Distributed computing)
Dfs (Distributed computing)
Sri Prasanna
New File Server Features Of Windows Server 2008
New File Server Features Of Windows Server 2008
Microsoft TechNet
Distributed file system
Distributed file system
Naza hamed Jan
MCSA Installing & Configuring Windows Server 2012 70-410
MCSA Installing & Configuring Windows Server 2012 70-410
omardabbas
Server 2008 r2 ppt
Server 2008 r2 ppt
Raj Solanki
Introduction to failover clustering with sql server
Introduction to failover clustering with sql server
Eduardo Castro
Ctive directory interview question and answers
Ctive directory interview question and answers
sankar palla
Distributed file systems
Distributed file systems
Sri Prasanna
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVACon 2013: Novell Open Enterprise Server - Roadmap and Future
GWAVA
Preparing forfirstconnectionsinstall
Preparing forfirstconnectionsinstall
Gabriella Davis
Lesson 4 intro to advanced o perating systems
Lesson 4 intro to advanced o perating systems
Jo Ko
11 distributed file_systems
11 distributed file_systems
longly

Similar to Cl116 (20)

File Access in Novell Open Enterprise Server 2 SP2
File Access in Novell Open Enterprise Server 2 SP2
Novell
Ram
Ram
Rami reddy
Resume
Resume
Shyama nand
BSDCan2006.pdf
BSDCan2006.pdf
JoseRamirez260192
Cl306
Cl306
Juliette Ponnet
Kamailio - Secure Communication
Kamailio - Secure Communication
Daniel-Constantin Mierla
RHCE (RED HAT CERTIFIED ENGINEERING)
RHCE (RED HAT CERTIFIED ENGINEERING)
Sumant Garg
Integrating Apple Macs Using Novell Technologies
Integrating Apple Macs Using Novell Technologies
Novell
2008-09-09 IBM Interaction Conference, Red Hat Update for System z
2008-09-09 IBM Interaction Conference, Red Hat Update for System z
Shawn Wells
pradip_mote_MCA_AIX-TSM_L2_Admin_4.8+Years_EXP
pradip_mote_MCA_AIX-TSM_L2_Admin_4.8+Years_EXP
Pradip Mote
2013 linux days final
2013 linux days final
RandomShare
Next Generation Security Solution
Next Generation Security Solution
MarketingArrowECS_CZ
LOAD BALANCING OF APPLICATIONS USING XEN HYPERVISOR
LOAD BALANCING OF APPLICATIONS USING XEN HYPERVISOR
Vanika Kapoor
NetApp ONTAP tools れ 覦 蟲 螳企_v0.1.pptx
NetApp ONTAP tools れ 覦 蟲 螳企_v0.1.pptx
yonggiseo1
[覦襭] ろ Pacemaker zabbix 伎 覦(w/ Zabbix Korea Community)
[覦襭] ろ Pacemaker zabbix 伎 覦(w/ Zabbix Korea Community)
Cl212
Cl212
Juliette Ponnet
Resume
Resume
Sun Technologies Inc
Linux SME 5+ Years
Linux SME 5+ Years
Sun Technologies Inc
Hardening Linux and introducing Securix Linux
Hardening Linux and introducing Securix Linux
Security Session
IBM Spectrum Scale Security
IBM Spectrum Scale Security
Sandeep Patil
File Access in Novell Open Enterprise Server 2 SP2
File Access in Novell Open Enterprise Server 2 SP2
Novell
RHCE (RED HAT CERTIFIED ENGINEERING)
RHCE (RED HAT CERTIFIED ENGINEERING)
Sumant Garg
Integrating Apple Macs Using Novell Technologies
Integrating Apple Macs Using Novell Technologies
Novell
2008-09-09 IBM Interaction Conference, Red Hat Update for System z
2008-09-09 IBM Interaction Conference, Red Hat Update for System z
Shawn Wells
pradip_mote_MCA_AIX-TSM_L2_Admin_4.8+Years_EXP
pradip_mote_MCA_AIX-TSM_L2_Admin_4.8+Years_EXP
Pradip Mote
2013 linux days final
2013 linux days final
RandomShare
Next Generation Security Solution
Next Generation Security Solution
MarketingArrowECS_CZ
LOAD BALANCING OF APPLICATIONS USING XEN HYPERVISOR
LOAD BALANCING OF APPLICATIONS USING XEN HYPERVISOR
Vanika Kapoor
NetApp ONTAP tools れ 覦 蟲 螳企_v0.1.pptx
NetApp ONTAP tools れ 覦 蟲 螳企_v0.1.pptx
yonggiseo1
[覦襭] ろ Pacemaker zabbix 伎 覦(w/ Zabbix Korea Community)
[覦襭] ろ Pacemaker zabbix 伎 覦(w/ Zabbix Korea Community)
Hardening Linux and introducing Securix Linux
Hardening Linux and introducing Securix Linux
Security Session
IBM Spectrum Scale Security
IBM Spectrum Scale Security
Sandeep Patil
Ad

More from Juliette Ponnet (6)

Cl210
Cl210
Juliette Ponnet
Cl210 lab
Cl210 lab
Juliette Ponnet
Cl302
Cl302
Juliette Ponnet
Cl105
Cl105
Juliette Ponnet
Cl117
Cl117
Juliette Ponnet
Cl104
Cl104
Juliette Ponnet
Ad

Cl116

  • 1. File Access and LUM Deployment with Novell 速 Open Enterprise Server 2 Martin Weiss , Senior Technical Specialist [email_address] Dr. Frieder Schmidt , Senior Technical Specialist [email_address]
  • 2. Agenda Linux User Management (LUM)
  • 3. File Access Protocols and Proxy User
  • 4. NCP , AFP, CIFS, (S)FTP, HTTP(S)
  • 5. Deploying Multiple Methods for File Access
  • 9. Linux User Management Before deployment What does LUM do? Allow eDirectory users and groups to show up as Linux users Why and what for do YOU need LUM? All services that run on base of Linux ex. Apache, FTP, SSH, SFTP, Samba
  • 10. Administration Prepare your environment Naming conventions
  • 13. ODBC / DSReport is your friend
  • 14. Linux User Management Implementation Placement of objects in the tree Unix config object
  • 15. Unix workstation objects Configuration of NAMCD alternative-ldap-server-list
  • 20. Linux User Management LUM Enablement iManager or CLI
  • 22. Users
  • 24. Which users should be LUM enabled for which servers? Troubleshooting duplicate UIDs/GIDs
  • 25. Certificates for alternate LDAP server (namconfig -k)
  • 26. File Access Protocols and Proxy User
  • 27. Novell 速 Open Enterprise Server 2 The best multi-protocol file server Multiple choices of file systems Novell Storage Services
  • 28. POSIX file systems: ext3, Reiser, XFS Multiple choices of file access protocols NCP - Novell NetWare 速 Core Protocol
  • 29. CIFS/SMB Novell CIFS, Samba
  • 30. AFP Novell AFP
  • 32. FTP PureFTP with Novell changes
  • 33. NFS Linux NFS
  • 34. Proxy Users No server based authentication to eDirectory Security Requirement for Kernel- vs. User-space CIFS, AFP, NetStorage and Samba require proxy users For accessing information from eDirectory
  • 35. For reading user passwords for non-cleartext authentication Proxy user problem Too many proxy users per server
  • 36. Management of proxy user password expiry
  • 37. Security issue of reading user passwords
  • 38. Proxy Users (continued) Novell 速 Open Enterprise Server (OES) 2 FCS, SP1, SP2 One proxy user per service per server (AFP, CIFS, Samba, NetStorage, other OES services) Novell Open Enterprise Server 2 SP3 Novell is looking at less proxy users and improved security
  • 39. Default to a single OES common proxy for all services
  • 40. Proxy user is made less powerful no password read privileges NMAS methods to do authentication on behalf of the services Auto-change of proxy passwords before expiry Future Novell is looking at service based authentication
  • 41. Novell 速 NetWare Core Protocol (NCP )
  • 42. NCP High Level Features NCP Novell 速 Open Enterprise Server 2 SP2 Cross protocol file locking support between NCP, AFP and CIFS
  • 43. Trustee change synchronization with eDirectory - Deletion and rename of trustees
  • 44. Trustee information obtained from _NETWARE/.trustee_database.xml
  • 45. Auditing support for NCP file events
  • 46. Salvage support (deleter) for non-LUM users Novell Open Enterprise Server 2 SP3 NCP volumes read only support functionality
  • 47. Add the ability to disable logins per volume and automated clear connection Future release Improved performance
  • 48. NCP - Recommendations on Novell 速 Open Enterprise Server 2 Linux Monitor usage and evictions LOG_CACHE_STATISTICS = 1 will log statistics in ncpserv.log Configure based on working set and available memory MAXIMUM_CACHED_FILES_PER_VOLUME Default 20000 MAXIMUM_CACHED_SUBDIRECTORIES_PER_VOLUME Default 50000 MAXIMUM_CACHED_FILES_PER_SUBDIRECTORY Default - 2048 Cache Entry memory usage - ~216 bytes + Full path name Additional Information http://www.novell.com/documentation/oes2/file_ncp_lx/data/bc06ts8.html
  • 49. TID 7004888 NCP Performance Tuning on OES2 Linux
  • 50. Novell 速 Common Internet Filesystem (CIFS)
  • 51. Novell 速 CIFS High Level Features Novell CIFS Novell Open Enterprise Server 2 SP2 Cross protocol file locking support between NCP , AFP and CIFS
  • 52. DFS support (including junctions pointing to sub-directories)
  • 54. No LUM or SAMBA enablement required Novell Open Enterprise Server 2 SP3 NTLM v2 support for Windows Vista and Windows 7
  • 56. CIFS context search to be LDAP enabled
  • 57. Enhanced auditing support Future release Kerberos and CIFS, DSFW support
  • 58. Novell 速 CIFS - Recommendations Cluster Restart CIFS service whenever eDirectory is restarted
  • 59. You have to offline and online resources whenever the CIFS service is restarted on a node
  • 60. CIFS service will bind to the cluster resource IP Troubleshooting cifsctxs.conf
  • 61. novcifs -sl (share list), novcifs -o (current configuration)
  • 62. novcifs --enable-debug=yes --enable-info=yes
  • 64. Novell 速 Apple Filing Protocol (AFP)
  • 65. Novell 速 AFP - High Level Features Novell AFP Novell Open Enterprise Server 2 SP2 Cross protocol file locking support between NCP , AFP and CIFS
  • 66. Auditing support Novell Open Enterprise Server 2 SP3 Enhanced auditing
  • 68. LDAP Proxy User simplifications Future release Support for spotlight on MAC
  • 71. Novell 速 AFP - Recommendations Clustering When a client connects to the cluster IP, then only cluster enabled shared volumes associated with the IP are exported
  • 72. Machine name and volume name (e.g. server.afp_vol)
  • 73. Edit /etc/opt/novell/afptcpd/afpvols.conf on each cluster node Syntax: Servername.VolumeName VolumeName Troubleshooting Use CASAcli
  • 78. NetStorage High Level Features NetStorage Novell 速 Open Enterprise Server 2 SP2 NCP , CIFS, SSH
  • 84. NetStorage Recommendations Clustering Install and configure on all nodes
  • 85. just migrate the IP-Address (maybe use a shared SSL certificate) Troubleshooting Registry (xregd and xsrvd)
  • 90. FTP High Level Features Pure-FTP Novell 速 Open Enterprise Server 2 SP2 Remote Server navigation support (Gateway)
  • 91. LUM required Novell Open Enterprise Server 2 SP3 Support FTP share on a locally mounted Novell Storage Services volume
  • 92. Support for multiple instances of Pure-FTP instances running either on different or a same node within a cluster Future release FTP common home directory option
  • 93. FTP Recommendations Configuration pam configuration (pam_ldap vs. pam_nam)
  • 94. ldap.conf (context and LDAP sever)
  • 95. /etc/pure-ftpd/pure-ftpd.conf Parameters remote_server 油油油油油油油油油油油油油油油油油油油yes disallow_list_oes_server 油油油no edir_ldap_port 油油油油油油油油油油油油油油油油油油油389 NoRename 油油油油油油油no AutoRename 油油油油no
  • 96. Deploying Multiple Methods for File Access
  • 97. Deploying Multiple Methods for File Access Data integrity Cross-protocol file locking: AFP, CIFS, NCP , Samba Commonly supported capabilities DST: Supported across NCP and Samba (Novell-CIFS in SP3)
  • 98. Auditing: Supported in Novell 速 Open Enterprise Server (OES) 2 SP2 across NCP, AFP, CIFS
  • 99. DFS: Supported only by NCP, Novell-CIFS and NetStorage
  • 100. LUM-less operation: NCP, AFP, CIFS but not Samba Performance and scalability Scale: NCP: 20,000 connections, CIFS ~ 5000 connections tested in field, AFP: 200 connections
  • 101. Performance: OES2 SP2: CIFS around the same as Samba OES2 SP3: CIFS performs better than Samba with scaled connections
  • 102. Cross Protocol File Locking Lock DB /var/lib/samba/locking.tdb NCP Server CIFS Server AFP Server
  • 103. Cross Protocol File Locking Configuration Enable/Disable CPFL NCP : ncpcon set CROSS_PROTOCOL_LOCKS=1/0 CPFL is enabled by default To ensure data integrity is always maintained
  • 104. If only one of the protocols is used, CPFL can be disabled Performance improved with CPFL disabled
  • 105. Support for Distributed File Services
  • 106. DFS Support for NCP and CIFS NCP, CIFS and NetStorage on Novell 速 Open Enterprise Server 2 SP2 support DFS junctions that point to Root of Novell Storage Services (NSS) volume
  • 107. Sub-directories on NSS volumes Trustee rights are set both on the junction and the target of the junction
  • 108. Support for Dynamic Storage Technology
  • 109. Dynamic Storage Technology PRIMARY TREE: Subdirectory 1 file 1 file 2 Subdirectory 2 file 4 Important Data Less Important Data SHADOW TREE: Subdirectory 1 file 3 Subdirectory 2 file 5 file 6 NCP, CIFS Client View Subdirectory 1 file 1 file 2 file 3 Subdirectory 2 file 4 file 5 file 6
  • 110. Dynamic Storage Technology Components NCP Engine
  • 113. Volume
  • 114. Dynamic Storage Technology Configuration Novell 速 Remote Manager (NRM) https://server_IP_address:8009 or other_configured_port_number Command line utility ncpcon
  • 115. Dynamic Storage Technology Novell 速 Remote Manager
  • 116. Dynamic Storage Technology Global Configuration Manage NCP Services > Manage Server > Server Parameter Information
  • 118.
  • 119. Unpublished Work of Novell, Inc. All Rights Reserved. This work is an unpublished work and contains confidential, proprietary, and trade secret information of Novell, Inc. Access to this work is restricted to Novell employees who have a need to know to perform tasks within the scope of their assignments. No part of this work may be practiced, performed, copied, distributed, revised, modified, translated, abridged, condensed, expanded, collected, or adapted without the prior written consent of Novell, Inc. Any use or exploitation of this work without authorization could subject the perpetrator to criminal and civil liability. General Disclaimer This document is not to be construed as a promise by any participating company to develop, deliver, or market a product. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. Novell, Inc. makes no representations or warranties with respect to the contents of this document, and specifically disclaims any express or implied warranties of merchantability or fitness for any particular purpose. The development, release, and timing of features or functionality described for Novell products remains at the sole discretion of Novell. Further, Novell, Inc. reserves the right to revise this document and to make changes to its content, at any time, without obligation to notify any person or entity of such revisions or changes. All Novell marks referenced in this presentation are trademarks or registered trademarks of Novell, Inc. in the United States and other countries. All third-party trademarks are the property of their respective owners.
  • 121. NCP Server Architecture NCP service eDirectory NSS posix iManager Plugin POSIX IPC CIM IPC trustee file
  • 122. Novell 速 CIFS Architecture NCP Server eDirectory NSS CASA store CIFS Server iManager Plugin ldap dclient (ncp) ncp-rpc POSIX IPC CIM IPC Volume policies trustee file DST global policies
  • 123. Novell 速 CIFS Authentication Configuration
  • 124. Latest Novell 速 CIFS vs. Samba Performance
  • 125. Novell 速 AFP Architecture NSS CASA store CIM Provider NCP Server eDirectory AFP Server iManager Plugin ncp-rpc nmas-ldap xplat (ncp) zAPI conf file
  • 126. File Access Protocols (combined) NCP-RPC zAPI Rights, trustee changes, DST events Lock DB Samba AFP Service Novell CIFS File System posix CPL NCP Server eDirectory

Editor's Notes

  • #5: f
  • #6: f
  • #7: f
  • #13: f
  • #16: f
  • #17: f
  • #19: f
  • #20: f
  • #23: f
  • #25: f
  • #26: f
  • #43: CIFS can be configured using iManager, and uses the _admin interface to pass on the configuration to the CIFS server. The CIFS server uses a NW Rights model and cache similar to the NCP server. It stores its secrets (the secrets required for the CIFS server to authenicate) in CASA, and also provides a file-based alternative. The CIFS server uses the same trustee file that is created by NCP server, but does not write to the trustee file.
  • #44: CIFS can be configured using iManager, and uses the _admin interface to pass on the configuration to the CIFS server. The CIFS server uses a NW Rights model and cache similar to the NCP server. It stores its secrets (the secrets required for the CIFS server to authenicate) in CASA, and also provides a file-based alternative. The CIFS server uses the same trustee file that is created by NCP server, but does not write to the trustee file.
  • #47: -The AFP configuration is done using iManager. The iManager plugins are written to CIM, and the CIM provider at the backend writes the configuration data into an AFP configuration file. The AFP server takes its configuration from the configuration file. The secrets required for the AFP server to startup are stored in CASA and secret store there is also an option to store secrets without CASA being installed. AFP server uses zAPI to talk to NSS file-system. The AFP server supports cross-protocol locking by having lock arbitration done by the NCP server.