UNSOLVED

reacharavindh

updated

9 years ago

R

reacharavindh

1 Rookie

3 Posts

0

840

January 13th, 2018 10:00

Isilon authentication from both NIS and FreeIPA at the same time?

Hi Isilon community.

I have a bit of a unique situation and appreciate some brainstorming about it. Please tell me if I'm thinking wrong or have alternate ideas or advice.

Our current compute cluster (say 60 machines) use a centralised NIS for user authentication, and talk to NetApp filers for shared NFS storage.

We bought and configured an Isilon cluster to replace the ageing NetApp filers.

During this move to Isilon from NetApp, I'm wanting to move away from NIS to use FreeIPA for auth. But, I hit a roadblock where some of the compute nodes are running an ancient version of Fedora that they cannot participate with FreeIPA. So, I came up with the following strategy to make the move less painful/risky.

Step # 1: Add the existing NIS as an authentication provider in Isilon

Step # 2: During the cluster down time, replace all NetApp NFS mounts with equivalent Isilon NFS mounts.

Step # 3: Add FreeIPA as an additional/second authentication provider in Isilon and mimic the Users(UIDs) and Groups(GIDs) as is with NIS.

Step # 4: Slowly sunset the older compute nodes and make the new ones use FreeIPA for auth.

During this period of transition, any new users will be created on both NIS and FreeIPA (with same UID and GID).

Would Isilon be okay with having two authentication providers (supplying same users and groups with same UIDs and GIDs)?

Is there any other problem I should think about?

Thanks for any responses.

No Responses