infrastructure unit george, ian, toby. infrastructure unit: areas ● network ● server rooms ●...

8
Infrastructure Unit George, Ian, Toby

Upload: horatio-stanley

Post on 05-Jan-2016

212 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Infrastructure UnitGeorge, Ian, Toby

Page 2: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Infrastructure Unit: Areas

● Network● Server rooms● Authentication● Directory services● Account management

Page 3: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Network: infrastructure

● Switches– 7 core switch/routers– 200+ edge switches– 6000+ connected ports– Configuration and monitoring tools– Overall management

● Routers– 12 Linux edge routers

Page 4: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Network: services

● DNS– Local zones, DNSSEC-validating resolvers

● NTP● OpenVPN● DHCP● Routing

– OSPF, router-discovery

Page 5: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Server rooms

● Physical infrastructure– Racks– Power bars

● Consoles– Serial, IPMI

● Monitoring● E&B and IS liaison

Page 6: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Authentication

● Kerberos– INF.ED.AC.UK and FRIEND.INF.ED.AC.UK realms– Cross-realm trust with EASE and other realms– 6000+ user principals– 10k+ host and service principals

● Cosign– Web applications

● kx509– Not much used now

Page 7: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Directory services

● OpenLDAP– User data– Authorization data– Sundry other stuff

● Netgroups● Automounter maps

– Around 25k entries

Page 8: Infrastructure Unit George, Ian, Toby. Infrastructure Unit: Areas ● Network ● Server rooms ● Authentication ● Directory services ● Account management

Account management

● Automatic creation and deletion– Tools (prometheus)– Database feeds– Manual configuration files– Kerberos, LDAP and AFS entries created– Lifecycle: accounts gracefully expired and deleted

● (coming shortly!)