Re: can't prevent root lockout under Tru64/C2 security

From: Nico Kadel-Garcia (nkadel_at_comcast.net)
Date: 01/31/05

  • Next message: cp: "putty fails with "server's host key did not match the signature supplied""
    Date: Sun, 30 Jan 2005 22:58:23 -0500
    
    

    "Darren Tucker" <dtucker@gate.dodgy.net.au> wrote in message
    news:slrncvrace.ib9.dtucker@gate.dodgy.net.au...
    > Warning: topic drift ahead. For a potential solution see my other
    > post up-thread.
    >
    > On 2005-01-30, Nico Kadel-Garcia <nkadel@comcast.net> wrote:
    >> Number 1: Tru64 support is basically dead as a doornail.
    >
    > HP may be fitting it for a coffin but it's not dead yet.
    >
    >> I strongly urge you
    >> to take the money for electricity used powering those older systems and
    >> invest it in a modest modern Opteron box running a decent Linux distro.
    >
    > That's not always easy, cost effective or even possible.

    I've seen that analysis tried. I've also run some numbers several times in
    the past year, comparing the costs of a Tru64 maintenance and the hardware
    maintenance costs, cooling requirements, software issues with the
    limitations of the older and no longer developed software vs. re-engineering
    any core applications from scratch or based on newer core tools.

    The new tools won hands down, but you did have to amortize over at least one
    year to see the savings. By now, since ASU is dead, Matlab is no longer
    supported on Tru64, and it's difficult if not impossible to bring gcc over
    to Tru64 to compile other useful tools anymore rather than the amazingly
    optimized-to-the-point-of-incompatible compiler, it's an even shorter
    period. Call it six months in a typical multi-user environment, especially
    if you need large storage arrays. (Ever tried using one of these with large
    IDE or SATA arrays instead of the vastly more expensive SCSI? Don't.)

    > In many environments, the new hardware cost is pocket change compared to
    > the the cost of time, effort, application upgrades, approvals, testing,
    > (re)certifications and contract renegotiations required to implement it.

    That's quite true. But the cost of maintenance, ye ghods, man!

    > An application may not even be available on a newer platform at all.
    > Contractual obligations, regulations and/or certifications may prevent.

    Yup. Contractual obligations and paperwork can trump any wise technical
    idea.

    >> There just aren't enough of these systems left alive to constitute an
    >> open
    >> source community to keep them going.
    >
    > Digression: as far as I'm concerned, OpenSSH support is alive on a given
    > platform as long as *someone* is prepared to do the work, and it can be
    > done without compromising the integrity of it.
    >
    > For example, I still test releases on AIX 4.2.1 even though that version
    > has been EOLed for nearly half a decade. It's similar enough to modern
    > versions that the effort involved is small (and I get a kick out of the
    > occasional email I get telling me that it works on those systems or ones
    > even older).

    Cool. I've found OSF releases to be amazingly painful to deal with, in
    particular getting popular open source system tools (such as gcc and ddd)
    ported over to it.

    > In the case of sshd's SIA support, it's pretty well written and the
    > author usually pops up when a pre-release call-for-testing goes out.
    > Even if he stops doing that, as long as someone steps up it'll still be
    > "supported". And if no one does and you still need support, drop me a
    > line, we might be able to work something out :-)

    But getting gcc over to it to compile OpenSSH is non-trivial, and the
    built-in compiler is just not up to the job, at least the last time I tried
    last year. And that underlying support community is evaporating if they're
    not already gone.


  • Next message: cp: "putty fails with "server's host key did not match the signature supplied""

    Relevant Pages

    • Re: Question about mixed scalar type operation
      ... it through `%d`, which requires an `int`; ... Compile with warnings turned up: gcc spots ... the cost of the check should ...
      (comp.lang.c)
    • Re: Thinking about upgrading from dual PII
      ... Yes, in most cases, 32-bit apps run a little faster on a 64-bit CPU, ... >> may not even compile, or if it does, may not run. ... less than the cost difference, ...
      (comp.os.linux.hardware)
    • Re: PCI Express support for 2.4 kernel
      ... this initialization with 0 cost nothing. ... Try it with an older version of gcc, which most people are still using ... is allocated and zeroed at run time, no disk space is required. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • ISE 7.1 improvements plus meandering....
      ... Now when you click on the error code - it ... no errors and appears to compile just fine. ... about regarding Xilinx sotware now that I've tried Atmel's Prochip Designer. ... and these cost many times the $5 price. ...
      (comp.arch.fpga)
    • Re: Is necessary to switch to C++ or some object-oriented language?
      ... considered minor differences. ... like "It would cost over one million dollars to convert PostgreSQL ... It is true that there is a subset of C that will compile and run as ... If you want to use the common subset, ...
      (comp.lang.c)