
The install process adds a number of sudoers entries for the sdnadmin user. These are as follows:
•
/sbin/ifconfig
•
/sbin/reboot
•
/sbin/iptables
•
/usr/bin/service
•
/usr/bin/at
•
/usr/bin/dpkg
•
/usr/sbin/arp
•
/usr/bin/arping
All, or any, of the above entries can be blocked or removed from the sudoers configuration. The
/sbin/ifconfig
entry is only required when running in teamed mode. Otherwise the controller
cannot migrate the team IP address from node to node as team leader changes. The /sbin/iptables
is also required in teamed mode to secure team communication.
The
sdna
process must be present and active for the SDN controller to function. The
sdnc
process will not start without
sdna
.
Virgo admin UI access via localhost only
You can access the Virgo admin UI by using a remote browser at
https://<ip
address>:8443/admin
. This should not be used under normal circumstances, but can be
useful for debugging purposes.
To change the credentials of this console, get root console access to the machine(s) running the
HPE VAN SDN Controller and edit the following file:
/opt/sdn/virgo/configuration/org.eclipse.virgo.kernel.users.properties
This file includes the following two entries:
user.admin=sdn
role.admin=admin
where
role.admin
defines the user and
user.admin
defines the password. This file needs
to be owned by
user:sdn
,
group:sdn
. Changes to this file require a restart of the controller
to recognize the new credentials.
To disable access to the Virgo Admin UI, either remove the following file or move it to a safe
location outside the pickup directory.
Virgo console access disabled by default
The Virgo console is disabled by default as it is not security hardened. If you choose to enable
it for debugging purposes, make sure you are in a trusted environment and disable it as soon as
possible.
To access the Virgo Admin WEB UI (GUI), copy the
org.eclipse.virgo.management.console_3.6.2.RELEASE.jar
file from the
/opt/sdn/admin
directory to the
/opt/sdn/virgo/pickup
directory. You must either be
the
sdn
user on the SDN controller to copy the file or change the file ownership to
sdn
once it
is copied.
JMX console enabled for local access only
The JMX console is only enabled for local access. This is used by the controller for metering and
can also be used for debugging. The JMX console is not security hardened and should be enabled
for remote access only in trusted environments.
Virgo admin UI access via localhost only
123