[torqueusers] NFS installed Torque/PBS ... security issues ...

Martin Siegert siegert at sfu.ca
Wed Sep 27 18:22:40 MDT 2006


On Wed, Sep 27, 2006 at 06:05:55PM -0600, Garrick Staples wrote:
> On Wed, Sep 27, 2006 at 04:19:55PM -0700, Martin Siegert alleged:
> > On Wed, Sep 27, 2006 at 04:04:23PM -0700, Garrick Staples wrote:
> > > On Wed, Sep 27, 2006 at 03:49:59PM -0700, Martin Siegert alleged:
> > > > Hi,
> > > > 
> > > > you do not really need the no_root_squash option.
> > > > Just run
> > > > chmod og+rx <prefix>/sbin/pbs_mom
> > > > after running "make install" on the NFS server.
> > > > (and no, I do not know why it isn't installed with those permissions
> > > > in the first place).
> > > 
> > > You still need root privs for pbs_iff.
> > 
> > Hmm. I thought pbs_iff is 4755 by default.
> 
> It is, but won't root squash break setuid apps over NFS?

Nope.

> I don't like running daemons and TORQUE over NFS anyways.  NFS is too
> unreliable.  Do you really want your entire cluster melting down
> because one NFS server has a hiccup?

Never happens with a reliable NFS server :-)

[NFS can be extremely reliable for small to midsize clusters. For 1000+
nodes you probably want to look at something else. In this case you
would export read-only anyway. That usually just works.]

Cheers,
Martin


More information about the torqueusers mailing list