Veritas Storage Foundation 5.1 SP1 for Oracle RAC Administrator"s Guide (5900-1512, April 2011)
Figure 1-12
End-To-end communication flow with security enabled on CP server
and SF Oracle RAC clusters
Root broker
Client cluster nodes
Authentication
broker
CP server
(vxcpserv)
Authentication
broker
CP client
(cpsadm)
Communication flow between CP server and SF Oracle RAC cluster nodes with
security configured on them is as follows:
■ Initial setup:
Identities of authentication brokers configured on CP server, as well as SF
Oracle RAC cluster nodes are configured in the root broker’s authentication
private domain repository.
Note: If authentication brokers configured on CP server and SF Oracle RAC
cluster nodes do not use the same root broker, then a trust should be established
between the root brokers or authentication brokers, so that vxcpserv process
can authenticate requests from theSF Oracle RAC cluster nodes.
The cpsadm command gets the user name, domain type from the environment
variables CPS_USERNAME, CPS_DOMAINTYPE. The user is expected to export
these variables before running the cpsadm command manually. The customized
fencing framework exports these environment variables internally before
running the cpsadm commands.
Overview of Veritas Storage Foundation for Oracle RAC
About preventing data corruption with I/O fencing
68