a secure infrastructure for system console and reset access a

17
A Secure Infrastructure For System Console and Reset Access Andras Horvath, Markus Schulz, Emanuele Leonardi A.Horvath, IT/ADC/LE 27/03/03 1 A Secure Infrastructure For System Console and Reset Access

Upload: others

Post on 12-Sep-2021

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: A Secure Infrastructure For System Console and Reset Access A

A Secure Infrastructure For System Console and Reset Access

Andras Horvath, Markus Schulz, Emanuele Leonardi

A.Horvath, IT/ADC/LE 27/03/03

1A Secure Infrastructure For System Console and Reset Access

Page 2: A Secure Infrastructure For System Console and Reset Access A

Area of operation

� Commodity computing(cheap standard PC + Linux)

� Large number of nodes

� Maximum CPU power / $$$

A.Horvath, IT/ADC/LE 27/03/03

2A Secure Infrastructure For System Console and Reset Access

Page 3: A Secure Infrastructure For System Console and Reset Access A

Current technology

A.Horvath, IT/ADC/LE 27/03/03

3A Secure Infrastructure For System Console and Reset Access

Page 4: A Secure Infrastructure For System Console and Reset Access A

Requirements

� keep costs low

� least possible restriction on the hardware of nodes managed

� remote access (without special client software)

� secure communication and data storage

� strong authentication, role - based authorization, strict accounting

� automatization possible

A.Horvath, IT/ADC/LE 27/03/03

4A Secure Infrastructure For System Console and Reset Access

Page 5: A Secure Infrastructure For System Console and Reset Access A

Available technology

�KVM switches

� analogue:cheapnot accessible remotelyno resets

� digital:expensivealso no resets

� IPMI (Intelligent Platform Management Interface)all-in-one solutiontests not satisfactorynot widespread enough

� Serial consolewidespread, common technologyCC boxes: either cheap or secure but not bothno resetsno BIOS access

� VGA emulator PCI cards ("weasel board" etc.)all-in-one solutionvery expensive

A.Horvath, IT/ADC/LE 27/03/03

5A Secure Infrastructure For System Console and Reset Access

Page 6: A Secure Infrastructure For System Console and Reset Access A

Rack of PCs

A.Horvath, IT/ADC/LE 27/03/03

6A Secure Infrastructure For System Console and Reset Access

Page 7: A Secure Infrastructure For System Console and Reset Access A

Console servers

console servers (CS)

A.Horvath, IT/ADC/LE 27/03/03

7A Secure Infrastructure For System Console and Reset Access

Page 8: A Secure Infrastructure For System Console and Reset Access A

Our hardware solution

A.Horvath, IT/ADC/LE 27/03/03

8A Secure Infrastructure For System Console and Reset Access

Page 9: A Secure Infrastructure For System Console and Reset Access A

Console and reset servers

Relay box

both CS and RS

reset server (RS)

A.Horvath, IT/ADC/LE 27/03/03

9A Secure Infrastructure For System Console and Reset Access

Page 10: A Secure Infrastructure For System Console and Reset Access A

Interfacing the system

� web-based human interface, SSL, X.509 authentication

� role-based access control model

� well-defined database API for machines

� interconnection data and authorization information in the database

� internal communication over SSH

A.Horvath, IT/ADC/LE 27/03/03

10A Secure Infrastructure For System Console and Reset Access

Page 11: A Secure Infrastructure For System Console and Reset Access A

A.Horvath, IT/ADC/LE 27/03/03

11A Secure Infrastructure For System Console and Reset Access

Page 12: A Secure Infrastructure For System Console and Reset Access A

A.Horvath, IT/ADC/LE 27/03/03

12A Secure Infrastructure For System Console and Reset Access

Page 13: A Secure Infrastructure For System Console and Reset Access A

Architecture - consoles

A.Horvath, IT/ADC/LE 27/03/03

13A Secure Infrastructure For System Console and Reset Access

Page 14: A Secure Infrastructure For System Console and Reset Access A

Architecture - reset subsystem

A.Horvath, IT/ADC/LE 27/03/03

14A Secure Infrastructure For System Console and Reset Access

Page 15: A Secure Infrastructure For System Console and Reset Access A

Costs

� serial console solution: $24 / node

� remote reset system: $17 / node

� worktime:

� node cabling: 10 nodes / person / hour

� (cable making: for 5 nodes / person / hour)

Commercial ssh-enabled serial console servers:starting from about $110 / node

Digital KVM switches:from about $500 / node

A.Horvath, IT/ADC/LE 27/03/03

15A Secure Infrastructure For System Console and Reset Access

Page 16: A Secure Infrastructure For System Console and Reset Access A

Current status, next steps

� Current status

� hand-made cabling - deployed to 50 nodes

� received user feedback

� got request for more nodes

� Immediate future

� move to large-scale deployment

� Goal: LHC grid - 6000 nodes!

A.Horvath, IT/ADC/LE 27/03/03

16A Secure Infrastructure For System Console and Reset Access

Page 17: A Secure Infrastructure For System Console and Reset Access A

Thank you for your attention

Reset board control software developed by:

� Preslav Konstantinov

� Guner Passage

For more information, please e-mail:[email protected]

A.Horvath, IT/ADC/LE 27/03/03

17A Secure Infrastructure For System Console and Reset Access