AIX and TCB


 
Thread Tools Search this Thread
Operating Systems AIX AIX and TCB
# 8  
Old 09-19-2008
Excellent info guys. Thanx
Smilie
# 9  
Old 09-19-2008
This limitation only exists when performing nimadm operations on TCB enabled systems over NFS. That's right, NFS.

If you use the caching feature of nimadm, instead of NFS, then you can use nimadm to migrate TCB enabled systems. That's right, no need to disable TCB. No need to tempt fate and try enabling TCB after the migration.

Ensure you have TL6 installed and APAR IY87344.

I have tested this in both a lab and customer environment. It worked great.

Cheers.
# 10  
Old 09-20-2008
Excellent feedback, thanx Gibbo. Smilie
I will defiantly check this out.
Sounds like you have some practical experience working with TCB. Do you have any info with regards to the daily CPU and MEM overhead of TCB?

thanx
# 11  
Old 09-20-2008
No problem. At the time the Redbook was written, the fix for nimadm+cache & TCB was not available to customers. It was released some time after the Redbook was published, so the book missed out on this new information.

Indeed I do have some experience with TCB.

I have 150 AIX LPARs, all with TCB enabled. We run a TCB script to check system integrity once a day. From what I've seen, there is no performance (resource usage) impact at all.

Cheers.
# 12  
Old 09-20-2008
Good to know that you have it working and see no performance degradation. That was a big concern I had.
Sorry to throw all these questions your way, but it's tough to find somebody who uses TCB. I have 1 more question, if your rootvg is on internal mirrored SCSI and your data/config files to be monitored are on SAN, would this cause an I/O lag? As TCB would be SCSI based.

thanx
# 13  
Old 09-20-2008
Generally speaking I don't think you'll see any I/O issues. Of course, it can depend on things like your I/O config in terms of number of disks and adapters and your file system and LV layout. But as far as TCB is concerned it shouldn't matter at all.

Just curious. What are planning on doing with TCB? What are you trying to achieve?

Yes, I have TCB on my systems but apart from the occassional interesting report we get, it's not much use to us. Even our security team are disinterested in the information and integrity checking it can provide.

Cheers.
# 14  
Old 09-21-2008
Once again great info Smilie, thanx

Well I have a client that is interested in TCB. They have fraud issues on their servers and need to secure them. They have done the standard stuff like stop ftp/tn, etc enable ssh, tcp wrappers, check umask, permissions, etc. However we have explained that TCB will not show what is happening in the database, only flat files, user details, etc. So I am just trying to confirm what I have "heard" about TCB and find out as much info as I can (very little at this stage). It is always tough to explain to none technical management that 9 out of 10 times there is no "quick-fix" for security issues. Especially on systems that have been running for ages and have multiple child dependencies!

Anyway thank you again for the excellent feedback. If I could just ask, what would your personal opinion be of TCB in AIX? worth installing and leaving dormant, it does provide some use, not worth the effort & complicates systems.

regards
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. AIX

Samba 3.6 on AIX 7.1 - Windows 10 Access to AIX file shares using Active Directory authentication

I am running AIX 7.1 and currently we have samba 3.6.25 installed on the server. As it stands some AIX folders are shared that can be accessed by certain Windows users. The problem is that since Windows 10 the guest feature no longer works so users have to manually type in their Windows login/pwd... (14 Replies)
Discussion started by: linuxsnake
14 Replies

2. AIX

Will it affect my AIX LPAR security, when i set up email alerts on AIX server.

Hello, I've set up email alerts on AIX Servers. so that i can get email notifications (via mail relay server) when ever there is abnormal behavior. for example 1) my script monitors CPU/disk/memory etc... when it reaches high water ark, it will send an email alert. 2) disk usage alerts 3)... (5 Replies)
Discussion started by: System Admin 77
5 Replies

3. AIX

Is it must to enable TCB on AIX LPARs ?

Hi, I've verified my AIX 7.1 LPAR , and TCB is disabled by default. #odmget -q attribute=TCB_STATE PdAt PdAt: uniquetype = "" attribute = "TCB_STATE" deflt = "tcb_disabled" values = "" width = "" type = "" generic = "" ... (3 Replies)
Discussion started by: System Admin 77
3 Replies

4. AIX

Nim on AIX 7.1 used to migrate AIX 5.3 to AIX 6.1...is possible?

Using nimadm: nimadm -j nimadmvg -c sap024 -s spot_6100 -l lpp_6100 -d "hdisk1" -Y Initializing the NIM master. Initializing NIM client sap024. 0505-205 nimadm: The level of bos.alt_disk_install.rte installed in SPOT spot_6100 (6.1.3.4) does not match the NIM master's level (7.1.1.2).... (2 Replies)
Discussion started by: sciacca75
2 Replies

5. AIX

Implementing a TCB-Environment in AIX

Habe folgende Frage an der ich mich schwer tue, Welche Möglichkeiten bietet IBM's Betriebssystem "AIX" hinsichtlich der Ausbildung einer TCB-Umgebung? vielen Dank (6 Replies)
Discussion started by: Invisibleye86
6 Replies

6. AIX

How to upgrade AIX Firmware & TL Maintenance Level in AIX

Steps to upgrade AIX TL ( technology Level ) / Maintenance Level in AIX ( including Firmware HMC VIOS ) This article or post covers upgrades for - Hardware Management Console ( HMC ) - Firmware ( also known as microcode ) - VIO ( Virtual I/O Server = PowerVM ) - AIX Version, Technology... (2 Replies)
Discussion started by: filosophizer
2 Replies

7. AIX

IY17981 fix required for aix 4.3.3 to aix 5L migration but not found

Hi, redbook documentation is telling that IY17981 fix is required for aix 4.3.3 to aix 5L migration. But there is no mention about that fix in any ML installation packages. - My system is ML11 : oslevel –r 4330-11 - But xlC.rte is on wrong version : lslpp -L xlC.rte xlC.rte ... (3 Replies)
Discussion started by: astjen
3 Replies

8. AIX

How to apply aix 5.3 TL8 properly on ML5 aix system ?

Is it necessary to put system into single user mode for applying aix 5.3 TL8 on a aix 5.3.5.0 system ? Is the TL8 installation not totally safe ? thank you. (6 Replies)
Discussion started by: astjen
6 Replies

9. AIX

Switch off TCB (Trusted Computing Base)

I wanted to do an "Alternate Disk Migration" via my NIM server to update several clients (all LPARs in a p670) from 5.1 ML6 to 5.2 ML3. As a prerequisite the procedure says "if the system has the Trusted Computing Base enabled it has to be switched off before". Well, i didn't give this too much... (3 Replies)
Discussion started by: bakunin
3 Replies
Login or Register to Ask a Question