Amanda-Users

Re: Self check failing - what happens when you have duplicate amanda UID's

2006-02-26 11:37:02
Subject: Re: Self check failing - what happens when you have duplicate amanda UID's
From: "Lengyel, Florian" <flengyel AT gc.cuny DOT edu>
To: amanda-users AT amanda DOT org, amanda-users AT amanda DOT org
Date: Sun, 26 Feb 2006 11:29:00 -0500



Jon LaBadie <jon AT jgcomp DOT com> wrote:
__________
>On Sun, Feb 26, 2006 at 06:09:21AM -0500, Lengyel, Florian wrote:
>> This is a success story, in case anyone moves their NIS server and finds,
>> to their dismay, duplicate amanda entries in their passwd file. One of them
>> has to go. The problem is that one of the servers may have depended on it...
>
>Your story sounds like an ordered trouble-shooting sequence.
>Nice work.

Thanks...it was edited to fit your monitor. I was scratching my heead for a 
while. I forgot to mention that
/etc/amandates also had the wrong
ownership after I  removed the duplicate amanda /etc/passwd entry.
>> 

>> 
>> This was after a duplicate passwd entry for amanda was found.
>> 
>> [amanda@amanda ~]$ amcheck Daily
>> Amanda Tape Server Host Check
>> -----------------------------
>> Holding disk /var/tmp/amanda: 14875232 KB disk space available, that's plenty
>> amcheck-server: slot 17: date 20060128 label Daily017 (exact label match)
>> NOTE: skipping tape-writable test

>> 
>> After removing [the duplicate passwd entry-one with a higher UID], and 
>> looking at the documentation, I was directed to look at
>> /tmp/amanda
>> 
>> But this directory was owned by the former amanda, now an orphaned UID.
>
>Did amcheck/amdump indicate incorrect ownership? 


No: up to the point that I had changed the ownership of /etc/amandates back to 
amanda:disk, and removed the /tmp/amanda directory, amcheck told me nothing 
except that there was a problem obtaining estimates from that host (host timed 
out). The amdump reported RESULTS MISSING. So no, I had to go hunting around 
the file system for the invalid UID.

 If not,
>I wonder if (for admin friendliness) the code that checks
>should make a more explicit check of ownership and permissions
>and indicate the problem(s).

That would be very helpful. Setting them to the most restrictive values amanda 
needs (following the principle of least privilege) could be enforced also.
>> 
>> So I removed /tmp/amanda
>> 
>> After this I had a missing gnutar-lists subdirectory in /usr/local/var/amanda
>> Easy enough to fix
>> 
>> A third amcheck Daily resulted in success!
>> 
>
>-- 
>Jon H. LaBadie                  jon AT jgcomp DOT com
> JG Computing
> 4455 Province Line Road        (609) 252-0159
> Princeton, NJ  08540-4322      (609) 683-7220 (fax)


Florian Lengyel, Ph.D.
Asst. Dir. for Research Computing,
Dept. of IT and Adjunct Professor
of Computer Science
The Graduate Center, CUNY
Rm C413
365  5th Ave, NY 10016
VOX: 212-817-7374
Email: flengyel AT gc.cuny DOT edu
WWW: http://research.gc.cuny.edu


<Prev in Thread] Current Thread [Next in Thread>