Table of Contents minLevel 1 outline true
General Overview of OpenAFS
...
AFS (Andrew File System or A File System) is a distributed file system. The top
directory of the AFS hierarchy is the same all over the world, and is /afs.
Every institution in the world with AFS fileservers has its own unique "cell"
subdirectory under /afs. CNF's cell is named "cnf.cornell.edu" and is located at
/afs/cnf.cornell.edu
Within a cell, files are located on fileservers and are grouped within entities
named volumes. Volumes are partition partitions of physical disks (of the data servers), in
which quotas are applied. Backups of data can also be performend on a per-volume
basis. And, data on readonly volumes can be replicated across multiple
fileservers.
...
Your token has a limited lifetime, which is 8 hours at CNF. To check your
token's expiration date, do the following:
Windows
Click the lock icon in your system tray. Select the "Tokens" tab
if it is not already selected. If there is no lock icon in your
system tray, from the Start Menu, choose All Programs, OpenAFS, then
Authentication.
Linux
From the "Applications" menu, choose "afstokens". Your tokens are
displayed in the box labeled "My AFS Tokens".
Use the AFS "Authentication" application to obtain new AFS tokens or view your current tokens. Check your system tray for two lock icons, possibly with a red 'x' over them.
Of the potentially two lock icons, the correct one for AFS authentencation is the one that says "AFS Client" when you mouse over the icon. The other one will mention AFS and its version number and is not the correct one – this will start the related and separate Keberos for Windows application if you click it.
If you don't see the correct lock icon in your system tray, you can start the AFS Authentication application from the Windows start menu ... Start - O - OpenAFS - Authentication .
In the AFS Authentication application window, to obtain new tokens, click "Obtain new tokens"... your username will be formatted as one of two ways depending on if you have a Cornell NetID or Cornell GuestID:
- guestids and netids are both: your_guestid_or_netid@CORNELL.EDU
both are case sensitive... the part after the '@' symbol must be all caps. While your netid or guestid itself must be lowercase.
If you run into problems where the Windows AFS GUI throws an error and will not give you tokens, and you have verified you are using the correct username format and correct password, see the General - Windows AFS GUI Login Error section below.
Linux
Open an XTerm by choosing from the menus: Applications - CNF - XTerm .
From the commandline, type "tokens" to see your tokens.
To obtain new tokens, again open an XTerm from the menus via Applications - CNF - XTerm and type in: kinit followed followed by pressing return... your identity will autopopulate based on your linux login. When entering in your password, the cursor will not move. After pressing return, if you do not receive an error, type in: aklog . There will not be any output after pressing return if there are not any errors. Type in "tokens" again to see your new tokens and expiration time.
On CNF Thin, AFS Tokens will generally auto renew for up to 8 days after you re-connect to your session.
On Korat and Minx, Tokens will generally auto renew for up to 8 days after you first connect. After those 8 days are up, you will need to use the kinit and aklog commands as mentioned above to obtain new tokens.
You can view the final expiration time of your Kerberos tickets (AFS Tokens are derived from Kerberos tickets either with the aklog command or automatically) by typing in the command: klist
Macintosh
The built-in System Preferences panel for managing AFS tokens does not work properly in the CNF environment if your system is not configured correctly. Do not use it without talking to CNF IT.
We suggest using the GUI AFSLog application . This application will first open the Kerberos Ticket Viewer. After logging into Kerberos, exit the Kerberos Ticket Viewer. In approximately 5 seconds, the AFSLog application will either bounce for your attention or pop up a new window. The new window will show you your AFS tokens.
Alternatively, you may use the commandline. Open a terminal.On the commandline, type in kinit <username> followed by aklog .See below for proper formatting of your username. The "tokens" command will list your AFS tokens.
General
You can both destroy your existing tokens and obtain new tokens using the above
Windows and Linux applications.
If using a Cornell GuestID (gid-xxxx), your username must be formatted as:
guestid@CORNELL.EDU (@CORNELL.EDU must be all caps).
If using a Cornell NetID, your username must be formatted as:
netid@CORNELL.EDU (@CORNELL.EDU must be all caps).
Windows AFS Gui Login Error
We have seen some problems when attempting to obtain AFS Tokens using the Windows AFS client GUI. To work around this, you can use the Windows Powershell to get AFS Tokens:
- Open a Powershell prompt
- Type in the following:
(make sure to capitalize "CORNELL.EDU" ) .Code Block language powershell PS> cd "C:\Program Files\MIT\Kerberos\bin" PS> .\kinit <netid_or_guestid>@CORNELL.EDU
You will be prompted for your netid or guestid password. The cursor will not move while you type in your password. Hit return when done. - Now type in the following:
you will see some debug output showing that you have successfully obtained AFS tokens.Code Block language powershell PS> cd "c:\Program Files\OpenAFS\Client\Program" PS> .\aklog -d - The AFS GUI will now show your tokens.
Access Control Lists
An Access Control List (ACL) is the AFS mechanism which let you access
directories and files. This access mechanism works as follows:
*base permissions apply to directories (not files)
*new sub-directories inherit from parent directory permissions
*files have no individual protection. They inherit the protection from
the directory they sit in.
ACLs are composed of pairs [ protection group or user, access rights ]. For
example, grp_users (the group of all users) might have read permissions on a
particular directory.
Access Rights
There are seven access rights. Four deal with directories:
*a (administer) : right to administer of the ACLs of this directory
*l (lookup) : right to list the content of the directory
*d (delete) : right to delete files or sub-directories
*i (insert) : right to create new files or directories
The three others, while set on the directory, apply to the files within the
directory:
*r (read) : right to read a file
*w (write) : right to write in a file
*k (lock) : right to lock a file
Some aliases of the above ACLs:
*read = rl
*write = rlidwk
*all = rlidwka
*none = no right at all
Unix group and other mode bits on files are ignored.
Protection Groups
There are several pre-existing AFS protection groups:
*system:administrators
whose members are the AFS administrators of the current cell
*system:anyuser
every user, being or not authenticated within this cell or another cell
*grp_all
everyone who has an account on our fileserver
*grp_staff
all CNF staff
*grp_users
all CNF users
*grp_it
Your friendly CNF IT staff
*cnfhosts
Every computer on the CNF office and lab networks (but not on RedRover)
Working with AFS Protection Groups
Windows
Open up a command prompt (Start - Run - cmd). View your group
membership with the following command:
pts membership
Linux
From a terminal (XTerm from the Applications - CNF Applications menu on CNF Thin, or simply a terminal on your own Linux box), type in (all lower case):
pts membership netid@cit.cornell.eduor for a GuestID: pts membership gid-guestid@cornell.eduSubstituting your netid or guestid for "netid" and "gid-guestid" above.
Working with Directory ACLs
Windows
Right click on a folder in AFS. Choose AFS, and then choose Access
Control Lists. You may edit ACLs on folders for which you have "all"
(rlidwka) permissions (for example, those in your AFS home directory)
Linux
Use the linux commandline...
From a terminal, use fs la directory and fs sa directory acl. For
example:
| No Format |
|---|
$ fs la /afs/cnf.cornell.edu
Access list for /afs/cnf.cornell.edu is
Normal rights:
cnfhosts rl
grp_all rl
grp_it rlidwka
system:administrators rlidwka
system:anyuser rl
|
If I was in the system:administrators group, I could change the ACLs
on /afs/cnf.cornell.edu to, for example, give system:anyuser write
access:
| No Format |
|---|
$ fs sa /afs/cnf.cornell.edu system:anyuser write
|
Home Directories
Every CNF user has a personal home directory in its own volume under AFS. User
home directories are located at /afs/cnf.cornell.edu/home/users/username .
Initial quota is TBD. Staff home directories are located at
/afs/cnf.cornell.edu/home/staff/ .
On Windows, your W drive is your AFS home directory. And your X drive is the top
level of the CNF AFS cell.
In your home directory are a few pre-defined folders with permissions set
appropriately:
*public - others can read but not write to this directory. You can
place files to be shared with others, here.
*private - as implied by the name, no one but you can get to or even
see the files here
*incoming - others can place files for you here (but not read or
modify existing files in this directory)
*windows_profile - where your Windows XP roaming profile is stored
(Desktop, My Documents, etc)
*win_folders - where your Windows 7 Desktop, My Documents,
Downloads, Pictures, etc folders are stored
*Yesterday - a daily snapshop of the files and folders in your AFS
home directory.
The rest of the folders and files, by default, can be seen, but not read, by
others. So, feel free to create other directories in your home directory. You
can, of course, also change the Access Control Lists on any of these predefined
folders however you choose.
CNF Shares
CNF Public Share
Located at /afs/cnf.cornell.edu/shares/public/cnf
Anyone on a computer on one of the CNF networks any any user
of our files server can read, write, create, modify, and
delete files here.
CNF Outside Users Share
Located at /afs/cnf.cornell.edu/shares/public/outside_users
Only staff can write to this share.
Files in this share can be read by anyone anywhere in the world Or from the commandline, type "tokens" to see your tokens.