glassfish
  1. glassfish
  2. GLASSFISH-3719

[UB]Fix the problems with SMF and GlassFish

    Details

    • Type: Bug Bug
    • Status: Resolved
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 9.0peur1
    • Fix Version/s: 9.1peur1_dev
    • Component/s: docs
    • Labels:
      None
    • Environment:

      Operating System: All
      Platform: Macintosh

    • Issuezilla Id:
      3,719
    • Status Whiteboard:
      Hide

      91ur1Approved

      Show
      91ur1Approved

      Description

      Rajeev was trying to set up GFV2 with SMF on a Solaris-10 machine and just
      watching him do it revealed these usability issues:

      • If you are setting up the service for a domain, you have access to its
        configuration. If you see that it uses privileged ports, you should not
        make the administrator key in --serviceproperties net_privaddr for the
        domain to be able to bind to privileged ports. Just figure it out.
      • If possible remove the constraint of creating a passwordfile.

        Activity

        Hide
        km added a comment -

        accepting it.

        Show
        km added a comment - accepting it.
        Hide
        gfbugbridge added a comment -

        <BT6612287>

        Show
        gfbugbridge added a comment - <BT6612287>
        Hide
        shreedhar_ganapathy added a comment -

        ..

        Show
        shreedhar_ganapathy added a comment - ..
        Hide
        km added a comment -

        Checking in Domain-service-smf.xml.template;
        /cvs/glassfish/admin/templates/pe80/Domain-service-smf.xml.template,v <--
        Domain-service-smf.xml.template
        new revision: 1.8.8.1; previous revision: 1.8
        done
        Checking in NodeAgent-service-smf.xml.template;
        /cvs/glassfish/admin/templates/pe80/NodeAgent-service-smf.xml.template,v <--
        NodeAgent-service-smf.xml.template
        new revision: 1.8.8.1; previous revision: 1.8
        done

        I am NOT removing the constraint of removing the passwordfile. That remains.

        Paul:

        Please get the following documented in this regard. I am assigning the bug to
        you for further action. Let me know if the information suffices.

        <document>
        When a domain is registered under the control of SMF using asadmin
        create-service, the following holds:

        • The privileges granted to the start process (i.e. asadmin start-domain) are
          the privileges of the user account. To see the privileges of a user, logon
          to the system with that user and issue the command "ppriv -l".
          The privilege of interest is net_privaddr. This privilege is required if
          your process were to bind to ports < 1024 on Solaris.
        • If the administrator thinks that a particular app server domain should not
          have default user privileges, the service's manifest should be modified
          and the service should be reimported.

        </document>

        Show
        km added a comment - Checking in Domain-service-smf.xml.template; /cvs/glassfish/admin/templates/pe80/Domain-service-smf.xml.template,v <-- Domain-service-smf.xml.template new revision: 1.8.8.1; previous revision: 1.8 done Checking in NodeAgent-service-smf.xml.template; /cvs/glassfish/admin/templates/pe80/NodeAgent-service-smf.xml.template,v <-- NodeAgent-service-smf.xml.template new revision: 1.8.8.1; previous revision: 1.8 done I am NOT removing the constraint of removing the passwordfile. That remains. Paul: Please get the following documented in this regard. I am assigning the bug to you for further action. Let me know if the information suffices. <document> When a domain is registered under the control of SMF using asadmin create-service, the following holds: The privileges granted to the start process (i.e. asadmin start-domain) are the privileges of the user account. To see the privileges of a user, logon to the system with that user and issue the command "ppriv -l". The privilege of interest is net_privaddr. This privilege is required if your process were to bind to ports < 1024 on Solaris. If the administrator thinks that a particular app server domain should not have default user privileges, the service's manifest should be modified and the service should be reimported. </document>
        Hide
        km added a comment -

        accepting it for documentation.

        Show
        km added a comment - accepting it for documentation.
        Hide
        Paul Davies added a comment -

        Changed subcomponent to docs and prefixed summary with [UB] to denote that this
        issue affects the unbundled documentation.

        Show
        Paul Davies added a comment - Changed subcomponent to docs and prefixed summary with [UB] to denote that this issue affects the unbundled documentation.
        Hide
        Paul Davies added a comment -

        Information added to Admin Guide as requested.

        Show
        Paul Davies added a comment - Information added to Admin Guide as requested.
        Hide
        km added a comment -

        This is ported to 9.1.1 as well.

        Show
        km added a comment - This is ported to 9.1.1 as well.

          People

          • Assignee:
            Paul Davies
            Reporter:
            km
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: