AFS server symlinks and Kerberos authentication

Samuel L. Bayer sam at mitre.org
Fri Nov 9 05:35:33 CET 2001



   > According to my sysadmin, setting up these aliases on the server side
   > is recommended best practice in the IBM Transarc docs, so it would be
   > nice if Arla were to support it. Anybody have any ideas?

   I don't agree that it is the best practice, but if you really want
   this, turn off dynroot and use your cell's root.afs. You can do this
   by changing removing the -D in /Library/StartupItems/Arla/Arla.

   We use dynroot on Mac OS X since the GUI lets you choose what cells
   you want, and typically a cell's root.afs contains too many cells that
   you don't want to talk to.

That's absolutely true, and in fact pretty troublesome. Arla pretty
much takes over the machine trying to contact all those cells (none of
which it can reach, since I'm behind a firewall). It boots just fine,
and I can log in, but it takes 5 minutes or more before it satisfies
itself that it knows what's going on in /afs. During that time, the
machine barely responds. After that, it's fine, and you're absolutely
right that the authentication works as described, but is there any
simple way to make this work a little better?

Thanks in advance to all -
Sam Bayer







More information about the Arla-drinkers mailing list