You are on page 1of 12

Open, secure, scalable, reliable UNIX operating system for

IBM Power Architecture platforms

AIX Version 6.1

The next step in the evolution of the


UNIX OS
Businesses today need to maximize
their return on investment in information
technology. Their IT infrastructure
should have the flexibility to quickly
adjust to changing business computing
requirements and scale to handle ever
expanding workloads—without adding
Highlights complexity. But just providing flexibility
and performance isn’t enough; the IT
■ Next generation of IBM’s well- ■ Built on IBM POWER6™ tech- infrastructure also needs to provide
proven, scalable, open nology and virtualization to help rock solid security and near-continuous
standards-based UNIX® operat- deliver superior performance, availability and while managing energy
ing system increase system utilization and and cooling costs.
efficiency, provide for easy
■ New features for virtualization, administration and reduce These are just some of the reasons why
security, availability and man- total costs more and more businesses are choos-
ageability designed to make ing the AIX operating system (OS) run-
AIX® 6 even more flexible, ning on IBM systems designed with
secure and available than Power Architecture™ technology. With
previous versions its proven scalability, advanced virtual-
ization, security, manageability and reli-
ability features, the AIX OS is an
excellent choice for building an IT infra-
structure. And, AIX is the only operating
system that leverages decades of
IBM technology innovation designed to
provide the highest level of performance
and reliability of any UNIX operating
system.
The newest version of AIX, Version 6.1, new security features to improve and applying patches to multiple copies
is binary compatible with previous ver- simplify security administration, new of AIX 6.1, using WPARs, you can
sions of the AIX OS, including AIX 5L™ availability features inspired by patch the global instance, and all
and even earlier versions of AIX. This IBM legacy systems and numerous fea- WPARs inherit that same patch level.
means that applications that ran on tures designed to make the AIX OS This helps manage growth by allowing
earlier versions will continue to run easier and less expensive to manage. you to concentrate on managing appli-
on AIX 6.1—guaranteed.1 AIX 6.1 is an This AIX release underscores IBM’s firm cations instead of spending time on
open standards-based UNIX OS that is commitment to long-term UNIX innova- repetitive administration tasks.
designed to comply with the Open tions that deliver business value.
Group’s Single UNIX Specification Each Workload Partition can be sepa-
Version 3. Workload Partitions and Live Application rately administered from other WPARs
Mobility in the system. For example, each
AIX 6.1 runs on systems based on Workload Partitions WPAR can have unique users and
POWER4™, PPC970, POWER5™ and AIX 6.1 introduces a new, software- groups and a unique root administrator.
the latest generation of POWER™ based, virtualization approach called The root user for a WPAR cannot take
processor, POWER6. Most of the new Workload Partitions (WPARs). WPARs actions that would affect the global
features of AIX 6.1 are available on the enable the creation of multiple virtual instance or other WPARs. This isolation
earlier POWER platforms, but the most AIX 6.1 environments inside of a single provides for further savings through del-
capability is delivered on systems AIX 6.1 instance. Each WPAR can have egation of administrative work.
based on the new POWER6 proces- a unique “root” administrator, network
sors. The AIX OS is designed for the addresses, filesystems and security Workload Partitions share a single
IBM System p™, System p5™, context (users and groups). WPARs AIX 6.1 instance, so there is less isola-
eServer™ p5, eServer pSeries® and share a regulated portion of the pro- tion than there is with logical partitions
eServer i5 server product lines, as well cessing and I/O resources of the global (LPAR) in which each LPAR has its own
as IBM BladeCenter® blades based on instance but are isolated from the independent copy of AIX 6.1. Feedback
Power Architecture technology and processes and users in other WPARs or from early users of AIX 6.1 is that
IBM IntelliStation® POWER™ in the global instance. WPARs provide enough isolation for
workstations. many workloads—at a substantial sav-
You can use Workload Partitions to ings of administrative effort. WPARs can
AIX 6.1 extends the capabilities of the save administrative overhead when be used inside of LPARs, allowing the
AIX OS to include new virtualization consolidating systems, by reducing the combination of the two technologies to
approaches including the ability to relo- number of AIX instances that have to leverage the superior isolation of LPARs
cate applications between systems be managed. For example, instead of with the administrative ease of WPARs.
without restarting the application,
AIX 6.1 provides for two types of AIX 6.1 includes Workload Partitions as Applications do not have to be
Workload Partitions—System WPARs part of the base operating system. restarted because the entire WPAR,
and Application WPARs: WPARs can be created and managed including the application context, has
on a single AIX 6.1 instance using SMIT been moved to the target system. The
● System WPARs look like independ- and command line interfaces. IBM also WPAR Manager will also typically be
ent AIX 6.1 instances. They have provides a new licensed program prod- used to control the relocation, but com-
their own copies of many system uct, the IBM Workload Partitions mand line interfaces can also be used.
services like init and mail, they can Manager for AIX™ (WPAR Manager)
be logged into via telnet, and they that lets you manage WPARs across Live Application Mobility can provide
have their own users and groups. multiple systems. The WPAR Manager several benefits: first, it allows some
● Application WPARs are much product is available separately; it is not outages to be avoided by moving the
simpler; an Application WPAR is part of AIX 6.1. application off of a system that needs
simply a wrapper around an appli- to be shut down for maintenance;
cation that makes it more manage- Live Application Mobility second, it can be used to balance
able. Application WPARs run inside Workload Partitions can be moved from workloads across several systems—
of the global instance and do not one system to another without restart- automatically or manually; and finally, it
have their own administrator, ing the application or causing significant can be used to move workloads off
filesystems or security context. All disruption to the application end user. servers during non-peak periods
processes running inside of an This process is called Live Application so that those servers could be turned
Application WPAR can be grouped Mobility, a feature of AIX 6.1 and the off—saving energy.
together for management, including Workload Partitions Manager for AIX
resource controls. Because (WPAR Manager). During the relocation Live Application Mobility is a feature of
Application WPARs are not running process, the WPAR Manager first cre- AIX 6.1 and the WPAR Manager and
their own copies of system processes ates a checkpoint of the Workload can be used on any hardware sup-
like init, they have an even smaller Partition, then the memory and other ported by AIX 6.1.
resource footprint than System WPAR configuration information is
WPARs. moved to the target system, and finally,
the WPAR is resumed on the new
system—right where it left off.
Security features ● Trusted AIX ● AIX Security Expert
Providing for a secure computing envi- Trusted AIX extends the security The AIX Security Expert was intro-
ronment has always been a key goal for capabilities of the AIX OS by inte- duced with Technology Level 5
the AIX OS. AIX 6.1 is designed to be grating compartmentalized, multi- update to the AIX 5.3 OS, and pro-
compliant under the Common Criteria level security (MLS) into the base vides clients with the capability to
at Common Access Protection operating system to meet critical manage more than 300 system
Profile/Evaluation Assurance Level 4+, government and private industry security settings from a single inter-
including the Role Based Access security requirements. Trusted AIX face. To configure security on a sys-
Control Protection Profile (RBACPP) is implemented as an installation tem, you start with a template that
and the Labeled Security Protection option that can provide the highest provides the initial configuration
Profile (LSPP). It includes many new levels of label based security to and then customize to fit security
features that can increase security while meet critical government and pri- requirements. The Security Expert
reducing the effort needed to provide a vate industry security requirements. provides four templates: high,
secure infrastructure: Trusted AIX supports various medium or low security or a
MLS features such as partitioned Sarbanes Oxley template designed
● Role Based Access Control directories, trusted networking and to help you become compliant
Role Based Access Control (RBAC) labeled printing. with the security requirements of
provides improved security and the Sarbanes Oxley Act. Once the
manageability by allowing adminis- ● Encrypting Filesystem Security Expert has been used to
trators to grant authorization for The IBM Enhanced Journaled configure security on a system, you
management of specific AIX 6.1 Filesystem Extended (JFS2) adds can export those security settings
resources to users other than root. even greater data security with the and use them to set other systems
RBAC can also be used to associate capability to encrypt the data in a identically. With AIX 6.1, you can
specific management privileges filesystem. Clients can select from even store these security configura-
with programs, which can reduce a number of different encryption tions directly in a Lightweight
the need to run those programs algorithms. The encrypted data can Directory Protocol (LDAP)
under the root user or via setuid. even be backed up in encrypted for- directory—simplifying implementa-
RBAC improves security by reduc- mat, reducing the risk of data being tion of consistent security across an
ing the number of root users compromised if backup media is entire enterprise.
required to manage systems. It can lost or stolen. The Encrypting
reduce administrative costs and Filesystem can even help prevent
improve administrative efficiency by the compromise of data by root
allowing secure delegation of rou- level users. The Encrypting
tine administrative tasks to non- Filesystem does not require signifi-
root users. cant additional administrative
effort because the key management
is automatic and fully integrated
into the login authentication
process.
● Secure by Default Installation Option ● Support for Long Pass Phrases ● Kernel Support for POWER6
The AIX 6.1 installation process AIX 6.1 and AIX 5.3 Technology Storage Keys
will offer a new option, Secure by Level 7 will support greater than This AIX 6.1 feature brings a
Default that enables only the mini- eight character passwords for mainframe-inspired reliability capa-
mal number of system and network authentication of users. These bility to the UNIX market for the
services to provide the maximum releases will provide for storing of first time. Enabled by the POWER6
amount of security. Secure by passwords using encryption algo- processor, Storage Keys can reduce
Default works best when used in rithms such as SHA/256/512, MD5 the number of intermittent outages
conjunction with the AIX Security etc. System-wide controls can be associated with undetected memory
Expert to tightly control the security configured by the administrator to overlays inside the AIX kernel and
configuration of each system. choose the algorithm as well as the kernel extensions. Applications can
size of the password which could be also use the POWER6 Storage
● Trusted Execution up to 255 characters. Enhanced Keys feature to increase the relia-
In Trusted Execution mode, AIX 6.1 support will also include support for bility of large, complex applications
will verify the integrity programs at pass phrases. running under the AIX 5.3 or
execution time. This can increase AIX 6.1 releases.
security by reducing the possibility In addition to these new features,
that tampered programs could AIX 6.1 provides a wide range of other ● Dynamic Tracing
be used to compromise the integrated security features—all AIX 6.1 provides a new dynamic
security of the system. A signature designed to provide a high level of con- tracing capability that can simplify
(SHA256/RSA) database for fidence in the safety of mission-critical debugging complex system or appli-
important system files is created processes and applications. cation code. This dynamic tracing
automatically as part of the regular facility will be introduced through a
AIX 6.1 install. The Trusted Near-continuous availability features new tracing command, probevue,
Execution tool can be used to check Over the years, the AIX OS has which allows a developer or system
the integrity of the system against included many reliability features administrator to dynamically place
the database. Also the administra- inspired by IBM legacy technologies. probes in existing application or
tor can define policies such that the The release of AIX 6.1 introduces kernel code, without requiring spe-
loads of files listed in the database unprecedented availability features to cial source code or even recompila-
are monitored and execution/loads the UNIX market that can help reduce tion. probevue is very flexible
not allowed if hashes do not match. planned and unplanned outages. These allowing dynamic specification of
Additionally the administrator can features include: the data to be captured at probe
lock the signature database or the points and providing the ability to
files in the database from being ● Concurrent AIX Kernel Updates associate execution pre-conditions
modified by any one in the system, Concurrent AIX updates provides a with a given probe.
including root. new capability to deliver some ker-
nel updates as interim fixes that
will not require a system reboot to
put into effect. This can reduce the
number of unplanned outages
required to maintain a secure,
reliable system.
● Non-intrusive Service Aids ● Enhanced Software FFDC ● Functional Recovery Routines
AIX 6.1 serviceability aids are IBM has included many availabil- When many operating systems other
designed to minimally impact per- ity features in the AIX 5.3 and than IBM z/OS® encounter a
formance and availability. Second earlier releases. One of the key severe problem inside the heart of
Failure Data Capture (SFDC) tech- innovations used to improve the the OS, the kernel—the operating
nology involves building highly tun- reliability, availability and servicea- system crashes. AIX 6.1 is the first
able diagnostic and data capture bility features of the AIX OS was UNIX OS to introduce new technol-
features into the operating system, the introduction of FFDC technol- ogy that can, in some cases, recover
but only enabling them after prob- ogy. As a concept borrowed from from errors that would otherwise
lem diagnosis has started. The IBM hardware reliability features, cause the operating system to crash.
result is faster, less-disruptive prob- FFDC gathers diagnostic informa- This is just another example of a
lem determination, without the tion about a problem at the time feature inspired by IBM’s legacy
need to install special “debug” the problem occurs–dramatically technology and designed to improve
code. AIX 6.1 also introduces a reducing the need to recreate the the reliability of AIX, our premier
mainframe-inspired live dump facil- problem (and impact performance UNIX OS.
ity which allows selected subsys- and availability) at a later time to
tems to dump their diagnostic generate diagnostic information. Manageability features
information for subsequent service Because clients do not typically Many of the features already described
analysis, without requiring a full interact with this technology, it is such as Workload Partitions, Live
system dump and partition outage. one of the “hidden innovations” Application Mobility, Role Based Access
For those problems that still require that is largely unseen but is Control, AIX Security Expert, and AIX
a partition restart in order to designed to help increase the over- Concurrent Updates can significantly
recover, AIX 6.1 provides a all reliability, serviceability and improve the administrative efficiency of
firmware-assisted dump mode on most important, availability of managing the AIX OS, particularly as
systems based on POWER6 proces- the AIX OS. AIX 6.1 builds on the AIX environments grow. AIX 6.1 also
sor technology. In this new mode, FFDC capabilities introduced in
AIX 6.1 cooperates with system previous AIX releases by introduc-
firmware to write the First Failure ing even more instrumentation
Data Capture (FFDC) information to provide real time diagnostic
to the dump device using the information.
restarted AIX 6.1 image, rather
than writing to the dump device at
the time of the failure. The result is
fewer dump failures which can
enable quicker problem determina-
tion and resolution.
includes additional features specifically ● Solution Performance Tuning ● Network Installation Manager Support
intended to improve the manageability The default tuning parameters for for NFSv4
of the AIX OS: AIX 6.1 have been changed to pro- The Network Installation Manager
vide much better performance for (NIM) has been enhanced to pro-
● IBM Systems Director Console for AIX most applications right out of the vide additional security features
This new management interface box. In many cases, administrators and flexibility by enabling the use
allows administrators to manage can get good applications perform- of NFS version 4. NIM can
AIX 6.1 remotely through a ance without the need to make any use NVSv4 to provide stronger,
browser. The IBM Systems Director tuning changes. Kerberos-based security during the
Console for AIX (console) provides installation of AIX 6.1 and other
responsive Web access to common ● Name Resolver Caching Daemon software.
systems management tools such as This daemon caches requests to
the Systems Management Interface resolve a hostname, service or net- Platform Support
Tool (SMIT). The console is group to improve the efficiency of AIX Version 6.1 will run on systems
included as part of AIX 6.1—no subsequent requests for the same based on POWER4, PPC970,
other products are required to use information. Use of this facility can POWER5 and POWER6 processors.
it other than a Web browser. dramatically improve the perform- Most features of AIX 6.1 are available
The console is named after the ance of applications that are on all supported hardware. A few fea-
IBM Systems Director because it is dependent on repeated requests for tures are only available when AIX 6.1 is
built on the same graphical user name resolution. running on a system built with
interface as the IBM Systems POWER6 processors. The table below
Director. The console also provides ● Graphical Installation lists selected features of AIX 6.1 and
the capability to securely run This new installation option is whether those features require
administrative commands on multi- intended primarily for use by POWER6 processors.
ple systems. administrators with limited AIX
installation experience. Graphical
● Automatic Variable Page Size for Installation simplifies the installa-
POWER6 tion process but includes options to
AIX 6.1 will automatically manage navigate to the traditional installa-
the size of pages used when it is tion menus if required.
running on a system based on
POWER6 processors. AIX 6.1 will
automatically use 4K, 64K or a
combination of those page sizes to
optimize performance without
administrative effort. This self tun-
ing feature can be controlled by the
administrator but the default
behavior is to let AIX 6.1 manage
page sizes automatically.
AIX 6.1 Feature Platforms Supported

Workload Partitions POWER4, PPC970, POWER5 and POWER6

Live Application Mobility POWER4, PPC970, POWER5 and POWER6

Application Storage Keys POWER6 (also supported by AIX 5.3)

Kernel Storage Keys POWER6

Automatic Variable Page Size POWER6

Firmware Assisted Dump POWER6

Decimal Floating-Point POWER6 (also supported by AIX 5.3)

Role Based Access Control POWER4, PPC970, POWER5 and POWER6

Encrypting Filesystem POWER4, PPC970, POWER5 and POWER6

Trusted AIX POWER4, PPC970, POWER5 and POWER6

probevue Dynamic Tracing POWER4, PPC970, POWER5 and POWER6


AIX 6.1 only supports the 64-bit kernel. ● Shared Dedicated Capacity which is a collection of open source
32-bit and 64-bit applications that This new configuration option for and GNU software commonly found
ran on AIX 5L will continue to run dedicated processor partitions with Linux distributions. Because the
unchanged on AIX 6.1, but 32-bit ker- enables the administrator to donate applications run on AIX, businesses can
nel extensions and device drivers are excess processor cycles to a Shared combine the flexibility of Linux with the
not supported on AIX 6.1. Processor Pool without affecting the advanced features of AIX 6.1, including
workload running in the dedicated advanced workload management,
IBM systems based on the processor partition. sophisticated systems management
POWER6 processor such as tools, scalability and security.
the IBM System p 570 provide addi- ● Multiple Shared Processor Pools
tional virtualization capabilities of the Most POWER6 processor-based AIX Expansion Pack
IBM Advanced POWER Virtualization systems support multiple separate The AIX Expansion Pack extends the
feature that are supported by AIX 5.3 Shared Processor Pools. This fea- base operating system by providing an
as well as AIX 6.1. These features ture can be used for additional integrated directory server, encryption
include: control of processor resource alloca- support, an HTTP server to serve online
tions and potentially can reduce the publication pages and support Web-
● Live Partition Mobility license charges for applications run- based System Manager and a number
This new capability of POWER6 ning in a micro-partition. of other useful applications. The AIX
processor-based systems allows an Expansion Pack also includes new,
entire logical partition to be relo- Open source flexibility supported versions of the lsof, openssh
cated from one server to another AIX 6.1 offers a wide range of system and openssl administrative tools.
while end users are using applica- interoperability features and open
tions running in the partition. The source tools to enable Linux® applica- Service and support to help keep
relocation is transparent to the end tions to be recompiled and run in a businesses running
user and occurs with no application native AIX 6.1 environment. AIX affinity AIX 6.1 provides a platform that lets
downtime. Like Live Application with Linux can promote faster and less you get the most out of today’s applica-
Mobility, Live Partition Mobility costly deployment of multi-platform, tions while positioning your business for
can enable increased availability, integrated solutions. Many solutions the future. And like all System p prod-
workload balancing and energy developed for Linux will run on AIX 6.1 ucts, AIX 6.1 is backed by IBM’s world-
savings. with a simple recompilation of the wide service and support.
source code. IBM provides the AIX
Toolbox for Linux Applications,
AIX Version 6.1 New Features

Feature Benefits

Virtualization

Workload Partitions ● Reduced administration, improved system efficiency

Live Application Mobility ● Increased application availability, enhanced workload manageability and energy savings

Live Partition Mobility ● Increased application availability, enhanced workload manageability and
energy savings * **

Multiple Shared Processor Pools ● Greater resource management flexibility and reduced application software expense * **

Shared Dedicated Processors ● Improved server utilization * **

Security

Role Based Access Control ● Improved security, decreased administration costs

Encrypting Filesystem ● Improved security

Trusted AIX ● Highest level of security for critical government and business workloads

AIX Security Expert ● Improved security, decreased administration costs by enabling federated management of
security across multiple AIX systems

Secure by Default ● Improved security on initial installations of AIX 6.1

Trusted Execution ● Improved security

Filesystem Permissions Tool ● Improved security


Feature Benefits

Near-continuous Availability

Concurrent AIX Updates ● Greater system availability, improved security by enabling critical security patches to be
installed without causing an outage

Storage Keys ● Improved AIX availability* and improved application availability**

Dynamic Tracing ● Easier resolution to application execution and performance problems

Enhanced First Failure Data Capture ● Increased AIX reliability and quicker problem resolution

Non-intrusive Service Aids ● Increased AIX reliability and quicker problem resolution

Functional Recovery Routines ● Increased AIX and application reliability and availability

Manageability

Workload Partitions ● Reduced administrative expense by reducing the number of AIX operating systems to
maintain. Greater flexibility to deploy and manage workloads

Live Application Mobility ● Improved flexibility to improve application availability and performance and to reduce
energy costs

Workload Partitions Manager ● Reduced management costs by providing federated management of workload partitions
across the enterprise

Live Partition Mobility ● Improved flexibility to improve application availability and performance and to reduce
energy costs * **

IBM System Director Console for AIX ● Reduced administrative costs and improved administrative effectiveness by enabling Web-
based administration across multiple AIX instances

Automatic Variable Page Size ● Improved performance with reduced administrative effort

* Supported only on System p and eServer i5 servers with POWER6 technology


** Also supported by AIX 5.3
For more information
For more information on
AIX 6.1 releases and upgrade benefits,
contact your IBM representative or
IBM Business Partner or visit the
© Copyright IBM Corporation 2007
following Web sites:
IBM Corporation
Integrated Marketing Communications,
Systems and Technology Group
● ibm.com/servers/aix
Route 100
● ibm.com/systems/p Somers, NY 10589
Produced in the United States of America
November 2007
All Rights Reserved
This publication was developed for products
and/or services offered in the United States.
IBM may not offer the products, features or
services discussed in this publication in other
countries.
The information may be subject to change
without notice. Consult your local IBM business
contact for information on the products, features
and services available in your area.
All statements regarding IBM’s future direction
and intent are subject to change or withdrawal
without notice, and represent goals and
objectives only.
IBM, the IBM logo, AIX, AIX 5L, BladeCenter,
eServer, IntelliStation, POWER, POWER4,
POWER5, POWER6, Power Architecture,
pSeries, System p, System p5, Workload
Partitions Manager are trademarks or registered
trademarks of International Business Machines
Corporation in the United States, other
countries or both. A full list of U.S. trademarks
owned by IBM may be found at:
ibm.com/legal/copytrade.shtml.
UNIX is a registered trademark of The Open
Group in the United States, other countries
or both.
Linux is a trademark of Linus Torvalds in the
United States, other countries or both.
Other company, product, and service names
may be trademarks or service marks of others.
IBM hardware products are manufactured from
new parts, or new and used parts. Regardless,
our warranty terms apply.
Photographs show engineering and design
models. Changes may be incorporated in
production models.
Copying or downloading the images contained
in this document is expressly prohibited without
the written consent of IBM.
Information concerning non-IBM products was
obtained from the suppliers of these products.
Questions on the capabilities of the non-
IBM products should be addressed with the
suppliers.
All performance estimates are provided “AS IS”
and no warranties or guarantees are expressed
or implied by IBM. Buyers should consult other
1
More information on the binary compatibility of sources of information, including system
AIX 6.1 can be found at ibm.com/systems/p/ benchmarks, to evaluate the performance of a
os/aix/compatibility/index.html. system they are considering buying.

PSD03005-USEN-00

You might also like