Skip to main content

Posts

Showing posts with the label aix

Dig that!

Here are some handy ‘dig’ commands to verify DNS records: Do a hostname lookup # dig www.google.com ; <<>> DiG 9.4.1 <<>> www.google.com ;; global options:  printcmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 76 ;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;www.google.com.                        IN      A ;; ANSWER SECTION: www.google.com.         84790   IN      CNAME   www.l.google.com. www.l.google.com.       259     IN      A       209.85.148.104 www.l.google.com.       259     IN  ...

AIX file system group

Group a bunch of file systems together using mount group option:                            Add an Enhanced Journaled File System Type or select values in entry fields. Press Enter AFTER making all desired changes.                                                         [Entry Fields]   Volume group name                                   datavg   SIZE of file system           Unit Size     ...

Retrieve SSL certificate expiration date

There are several ways to extract the expiration date from the certificate file. Here is one of the easiest way if you have the file locally: # openssl x509 –noout –in < cert_file >  -dates [root@mysystem][/opt/certificates ]> openssl x509 -noout -in private_key -dates notBefore=Jul 14 16:23:57 2010 GMT notAfter=Jul 14 16:23:57 2012 GMT

sed regular expression to extract mes...

sed regular expression to extract message part of the syslog (AIX): #>sed 's/\(...\) \(..\) \(..\:..\:..\) \(.*\)/\4/' /var/adm/syslog myhost auth|security:err|error tsm: : 3004-025 - tcgetattr  failed errno "25".  myhost auth|security:notice su: from dude to root at /dev/pts/109 myhost daemon:err|error root: Msg from Err Log: A924A5FC 0524165910 P S SYSPROC SOFTWARE PROGRAM ABNORMALLY TERMINATED  myhost daemon:err|error last message repeated 2 times myhost user:info syslog: libtt[1224956]: _Tt_rpc_client::init(): fcntl(F_SETFD) failed for socket =  20 myhost user:info last message repeated 10 times myhost user:info syslog: libtt[3125324]: _Tt_rpc_client::init(): fcntl(F_SETFD) failed for socket =  20 myhost user:info last message repeated 10 times myhost auth|security:info sshd[946242]: Received disconnect from 127.0.0.1: 0:  myhost auth|security:info sshd[946178]: Accepted password for dude from 127.0.0.1 port 4341 ssh2 will print everything aft...

AIX: kill all the processes started b...

AIX: kill all the processes started by an user You can kill all the processes started by an specific user using the following methods: 1.  login as the user (su if you are a root) and execute killall 2.  form the kill command using a ps/awk/ksh combination       ps -u <user> | awk '{print "kill -9 "$2""}' | ksh 3.  use xargs to do the same      ps -u <user> | awk '{print $2}' | xargs -t kill -9 I prefer the (3) as it takes care of long listing of processes and it does the executes on kill command for all the processes. Additional notes: find . -name "*.bak" -print0 | xargs -0 -I file  mv file ~/old.files

Cryptographic Sum Command

Users often use the sum command to generate a checksum to verify the integrity of a file. However, it is possible for two distinct files to generate the same checksum. A cryptographic sum command, csum , has been implemented in AIX 5L Version 5.3 that offers a more reliable tool to verify file integrity. This command allows users to generate message digests using the AIX Cryptographic Library. The new, cryptographic, checksum is considered more secure than the old mechanism. While it is reasonably straightforward to construct data that will match the checksum generated by the sum command; it is computationally infeasible to construct data to generate a known cryptographic checksum, as provided by csum . csum allows users the option to select the algorithm that they prefer, including both MD5 and SHA-1, which are considered secure. It is estimated that the order of 2**64 operations would be required to derive two different files, which generate the same MD5 message digest. Also, t...

List only SYMMETRIX disks

Here is an easy way to list just the symmetrix disk (excluding internal or even other FC disks): #lsdev –CtMSYMM* Use –t to specify the type of the disk, and all symmetrix disks are of the same type starting with MSYMM* - comes from the EMC ODM fileset.

Creating NFS mount points in AIX

/usr/sbin/mknfsmnt -f '[local directory] ' -d '[remote directory] ' -h ' ' -M 'sys' '-B' '-A' -t 'rw' -w 'bg' -b '32768' -c '32768' -K '3' -k 'tcp' '-Y' '-Z' '-X' '-S' '-j' -R '5' '-q' '-g' The values used are as per oracle database requirement [ FROM AIX INFO CENTER ] -A The /etc/filesystems entry for this file system specifies that it should be automatically mounted at system restart. -a The /etc/filesystems entry for this file system specifies that it should not be automatically mounted at system restart. This is the default flag. -B Adds an entry to the /etc/filesystems file and attempts to mount the file system. This is the default flag. -b ReadBufferSize Indicates the size of the read buffer in bytes specified by the ReadBufferSize variable. -c WriteBufferSize Indicates the size of the wri...

Collecting data for Performance issues in AIX

The following are the few commands I used heavily for troubleshooting a performance Issue on the AIX servers: 1. tprof: tprof -kes -x sleep 60 This will collect tprof data for 60 seconds and will store it in a file called sleep.prof 2. Collecting data for SPLAT: splat command uses the output create by the trace command to analyze the lock performance on the system where you have multi-threaded applications running. a. Collect trace data: generate gensyms data gensyms > gensyms.out trace -aC all -o trace -3; sleep 60 ; trcstop This will collect trace data for 60 seconds and will generate files starting with trace, trace-1 etc depending on the number of virtual cpus. b. run splat command to analyze the lock performance: splat -sa -da -S100 -i trace -n gensyms.out -o splat.out The final analysis of the lock performance can be found in splat.out. There are various options available for the above commands and also documents in AIX information center on how to inter...

Commands to restart RMC connection (t...

Commands to restart RMC connection (to HMC from LPAR) It has become very common with the IBM HMC to LPAR (logical/micro partition) communication to drop for unknown reasons.  Most of the time this is not a problem unless there is a need to do a dynamic logical partition operation (or DLAPR operation to add/remove resources on the fly).  This will become evident during the DLPAR operation when HMC complains about having no RMC connection to LPAR in operation.  When this happens run the following commands on the LPAR in question before reattemping the operation.  The DLPAR operation will still work with out this connection, but the LPAR needs a restart to see the change in the resources.  Restart the RMC connection on the LPAR: # /usr/sbin/rsct/install/bin/recfgct # /usr/sbin/rsct/bin/rmcctrl -p Verify the connection by running: lsrsrc IBM.ManagementServer This will show the HMC IP/hostname and the LPAR information.

RAM disk in AIX

RAM disk in AIX AIX provides 'mkramdisk' command for producing a disk that resides in the RAM for very high I/O intensive applications like database. Here is a simple set of commands to create a ramdisk and a filesystem on top of it: create a RAM disk specifying the size          # mkramdisk 5G The system will assign the available RAM disk.  Since this is the first one, it will be called as ramdisk0 Check for the new disk         # ls -l /dev | grep -i ram If there isn't sufficient available memory, the mkramdisk command will warn about the same during the creation. Create and mount a filesystem on top of the ram disk     # mkfs -V jfs2 -o log=INLINE /dev/ramdisk0     # mkdir -p /ramdisk0     # mount -V jfs2 -o log=INLINE /dev/ramdisk0 /ramdisk0 The new filesystem will now be available like any other FS.   To remove a ram disk, unmount/remove the filesystem and us...

Convert Epoch Time in AIX

One of the frequent conversion I do on UNIX is to and from epoch time to regular date time. Epoch time is the number of seconds elassed since midnight 1970 till now. It is widely used in the UNIX operating systems to represent timestamp for an event etc. For example, it is used to store the last time a password was changed by a user, which will be used by the OS to lock the user if the password has expired. As a unix administrator, we have to frequently convert this information to and from epoch time to find out when was the last time the password was changed for a particular user. There are many online sites available for this conversions. But most of the time we will be needing this to incorporate in a script run from the system where you cannot access online resources. Here are some of the 'one liners' we can use to convert to and from epoch time: 1. Print curent epoch time: date +%s perl -e 'print time' 2. Convert regular time to epoch time: date +%s -d...

Mask Password from /etc/security/passwd file

I was recently working on a project where I had to provide the screenshot of /etc/security/passwd file. Even though the passwords on this file are encrypted, it was against the security policy to even expose that information. Earlier this information was redacted from the screenshots that was provided to the external entities (from the image file). But this didn't look like the effective way to do. So after researching different test processing tools available, I created this 'sed' one liner to mask the password fields from the /etc/security/passwd file while listing. [/]> sed 's/\(password = \).*/\1[removed]/' /etc/security/passwd root: Password = [removed] lastupdate = 1248123420 flags = daemon: Password = [removed] bin: Password = [removed] sys: Password = [removed] adm: Password = [removed] uucp: Password = [removed] guest: Password = [removed] nobody: Password = [removed] lpd: Password = [removed] Hope this is helpful in same or differe...

Shared Ethernet Adapter failover

Shared Ethernet Adapter (SEA): Shared Ethernet Adapter (SEA) provides the ability to share a physical adapter between multiple client partitions. It provides the connection between the virtual and physical network. The SEA acts like a layer-2 bridge between internal and external network SEA failover: SEA failover can be achieved by having SEA configured on two VIO servers which with the bridging functionality enabled ('Access External network'). They use a control channel to determine who is currently providing the Ethernet service to the client partitions. The client partition gets one virtual Ethernet adapter bridged by two VIO servers. From the client partition it looks like it has one virtual Ethernet adapter bridged by one VIO server - any given point of time. The SEA also support 802.1Q VLAN tagging like a regular SEA. Requirements for implementing SEA failover: VIO servers (on the same physical m...

AIX NTP Configuration

NTP is used to synchronize time between a client and time server. To enable NTP on AIX server, Uncomment the xntpd line in rc.tcpip update /etc/ntp.conf file with the time server information start xntpd manually by with startsrc command startsrc -s xntpd Verify if the xntpd has started correctly lssrc -s xntpd To list all the NTP information, use lssrc with long listing lssrc -ls xntpd Other tools available for debugging NTP: ntpdate - syncs date with timeserver ntpq - query ntp server for information ntptrace - trace ntp communication