2009年11月27日 星期五

RACF提供給Auditor的功能

為了讓Auditor更有效地監控系統的安全狀態,RACF提供了下列功能

  • Logging 的routine程式,可記錄系統發生的事件,將這些事件寫入 SMF record中
  • SETROPTS指令提供一些專門給Auditor才能用(連Special用戶都不能呼叫)的功能選項,以便Auditor進行查核
  • 提供 RACF SMF data unload公用程式,可以將SMF record倒出來,並轉換成易於import進 RDB的格式
  • RACF report writer,可以產生客制化的報表  (目前Report Writer已不出更新版了,因此不建議使用,現在建議使用 RACF SMF unload utility)
  • Dataset Security Monitor(DSMon),可以產生目前環境的安全狀態 (zSecure Audit提供類似功能,不過zSecure除了RACF的資料外,還可以結合其它MVS的資訊)

2009年11月22日 星期日

如何查詢Guest目前使用了多少的Virtual CP,以及增加Guest的Virtual CP

在z/VM的 guest zLinux環境中,若要知道該Linux image配置了多少的Virtual CP,只需打入下列命令

cat       /proc/cpuinfo       ###結果如下

[root@ihs01 ~]# cat /proc/cpuinfo
vendor_id       : IBM/S390
# processors    : 2
bogomips per cpu: 3447.19
features        : esan3 zarch stfle msa ldisp eimm dfp
processor 0: version = 00,  identification = 04F4C0,  machine = 2094
processor 1: version = 00,  identification = 04F4C0,  machine = 2094

若要增加Linux guest的 logical CP,則打入下列command

echo 1 > /sys/devices/system/cpu/cpu1/online    #把cpu1 bring online

2009年11月21日 星期六

WAS的 Profile管理

要建立一個新的Node時,可以在 was安裝目錄下的  bin目錄中,執行下列指令,其中templatePath裡面放置了建立一個Node所需要的資訊的範本,在/opt/IBM/WebSphere/AppServer/profileTemplates/ 這個目錄下有四個子目錄,分別是 managed、default、cell及dmgr等,分別放置建立 node、獨立was Server、1個cell(dmgr + 被管理的was server)以及 deployment manager所需的 profile範本。下面的例子是建立一個單獨的Node的例子,其中-hostName是放Node本身所在機器的hostname或IP,若要設hostname的話,記得在Dmgr那台機器的 /etc/hosts 裡面要設定hostname與 IP的對應。另外,-cellName所設定的名稱必需與將來要加到的Dmgr所在的cell名稱不同,否則在 addNode時,會出現錯誤訊息。在做完addNode之後,這裡所設定的cellName會被取代成 Dmgr所屬的Cell Name

./manageprofiles.sh -create -profileName SecNode02 -profilePath /var/wasprofiles/SecNode02 -templatePath /opt/IBM/WebSphere/AppServer/profileTemplates/managed/ -cellName mycell -nodeName SecNode02 -hostName nodeServer_ip(or hostname)

建立完後,要到其profile下的bin目錄中,執行 addNode.sh,向deployment manager註冊這個Node。

./addNode.sh dmgr_host_ip

若要看目前的WAS環境中,已有多少的Profile,執行下列指令

./manageprofiles.sh -listProfiles

2009年11月15日 星期日

CPU time的定義

CPU Time指的是CPU實際工作的時間,理論上可用下列式子表示

image  
其中,

Cycle Time 是指CPU電路閃一次所需的時間,為我們平常聽到的頻率(GHz) 的倒數,與CPU的 model有關

Path length則是指完成一個交易,所要執行的CPU指令的數目。這個值與 CPU的架構以及Compiler的品質有關。不同的CPU架構決定了不同的指令集;而好的 Compiler能夠將程式轉換成執行起來較有效率的指令群。

Cycles/Instructions 則是指平均需要多少次的CPU cycle,才能執行完一個CPU指令。對於較簡單的指令,主機可在一次的CPU cycle中,指行多次;而對於較複雜的指令,則可能需要多個CPU cycle可能執行完成

由此定義可知,影響 CPU 速率的因子,除了一般大家所知的 Cycle time之外,還受Path length及 Cycles/Instructions所影響,因此不能單純由CPU的時脈,就決定那個CPU處理交易的速度較快

系統Utilization Rate與 ETR的關係

系統的Utilization Rate定義了單位時間內,系統真正有在做事情的時間百分比。依此定義,可以用下列公式表示

image

考慮只有一台Server的情況下,Busy_Time為單位時間的交易處理量   乘上   單一交易所需的處理時間,如下公式

image

將Busy_Time代入上面 U% 的式子,可得到

image

其中 #Transactions/Elapsed_time 即為 ETR(External Transaction Rate),因此,這個式子又可寫成

image

External Transaction Rate (ETR) 與 (Internal Transaction Rate) ITR的關係

在計算資訊系統的Capacity(處理能力)時,有兩個數值,一個是External Transaction Rate(ETR),另一個是Internal Transaction Rate(ITR)。

ETR:是系統外部的使用者所觀察到的單位時間內,系統能處理的交易數。依此定義,ETR可由下列公式表示


image

若將Elapse Time進一步分解,可得到下列公式:


image

其中,N是處理的交易量;Tt 是使用者在執行交易時的Think Time;而 Tr 則是系統的回應時間。對於ETR來說,IT人員能控制的因子只有Tr,因此要維持用 ETR定出來的Service Level Agreement會有困難。
另外,任何bottleneck都會影響ETR,如I/O的限制、page delay、tape mount delay…等


 

ITR:指的是系統內單位CPU時間內,能處理的交易數。依此定義,ITR可由下列公式表示

image

ITR與下列因子相關:  CPU的速度(CPU快愈快,ITR高)、作業系統(作業系統好,ITR高)、交易的屬性(交易愈簡單,ITR愈高)

若把ETR除以ITR,可以得到

ETR/ITR = CPU_time/Elapsed_time ,即

ETR/ITR = CPU utilization_rate。因此,當CPU的使用率在百分之百時,ETR會等於ITR

2009年11月13日 星期五

TCPIP的 TIME_WAIT

Description

Specifies the time that must elapse before TCP can release a closed connection and reuse its resources. This interval between closure and release is known as the TIME_WAIT state or 2MSL state. During this time, the connection can be reopened at much less cost to the client and server than establishing a new connection.

RFC 793 requires that TCP maintains a closed connection for an interval at least equal to twice the maximum segment lifetime (2MSL) of the network. When a connection is released, its socket pair and TCP control block can be used to support another connection. By default, the maximum segment lifetime is defined to be 120 seconds, and the value of this entry is equal twice that, or 4 minutes. However, you can use this entry to customize the interval.

Reducing the value of this entry allows TCP to release closed connections faster, providing more resources for new connections. However, if the value is too low, then TCP might release connection resources before the connection is complete, requiring the server to use additional resources to reestablish the connection.

出處:http://technet.microsoft.com/en-us/library/cc757512%28WS.10%29.aspx

根據上述的說明,TIME_WAIT值是在TCP connection關閉後,要經過多少時間,TCP才會真的釋出這個 connection,以及這個connection所用到的資源。這個設計的好處是,如果在TIME_WAIT時間內,要重新使用已關掉的connection,只要在TCP釋出它的資源之前,不需重新建立,而可以直接re-open該connection。一般來說,TIME_WAIT的值會是 2倍的 Maximum Segment Lifetime的時間。