background image

8 Initializing the software for the first time

After you have installed and configured HP SMH for the first time, a process to create a private key and
corresponding self-signed Base64-encoded certificate is initiated. This certificate is a Base64-encoded PEM
file.

Key and certificate information

In HP-UX operating systems, both public and private keys for HP SMH are stored in the

/var/opt/hpsmh/sslshare

directory. The files are called

file.pem

(private key) and

cert.pem

(server certificate).

With HP SMH running on Apache 2.2 (HP-UX 11iv3), the Apache Tomcat communication requires
certificate-based authentication through

https

connection on port 1188 (by default). The certificate

/var/opt/hpsmh/sslshare/proxy.pem

, generated during installation, is used for this purpose.

For effective Apache Tomcat communication required to launch the Java plug-ins, do not alter this
certificate on the system.

In Linux operating systems, both public and private keys for HP SMH are stored in the

/etc/opt/hp/sslshare

directory. The files are called

file.pem

and

cert.pem

.

In Windows operating systems, public and private keys are stored in the

<System

Drive>:\hp\sslshare

directory of the system drive.

To protect the keys, this subdirectory is only accessible to administrators if the file system allows such
security. For private key security reasons, HP recommends that you install Windows installations of HP
SMH on New Technology File System (NTFS).

IMPORTANT:

For Windows operating systems, the file system must use NTFS for the private key to have

administrator only access through the file.

If the private key is compromised, you can delete the

<System Drive>:\hp\sslshare\cert.pem

file

and restart the server. This action causes HP SMH to generate a new certificate and private key.

NOTE:

Certificate and private key generation occurs only the first time HP SMH starts or when no certificate

and key pair exists.

A certificate from a certificate authority (CA), such as Verisign or Entrust, can replace self-generated certificates.
These certificate and key files are shared with other HP Management software, such as HP SIM.

Key and certificate information

59

Содержание Integrity BL860c

Страница 1: ...HP System Management Homepage 6 2 Installation Guide HP UX Linux and Windows Operating Systems HP Part Number 466305 007 Published October 2010 Edition 1 ...

Страница 2: ...orial errors or omissions contained herein Trademark Notices AMD and Opteron are trademarks of Advanced Micro Devices Inc Adobe and Acrobat are trademarks of Adobe Systems Incorporated HP UX Release 10 20 and later and HP UX Release 1 1 00 and later in both 32 and 64 bit configurations on all HP 9000 computers are Open Group UNIX 95 branded products Intel and Itanium are trademarks or registered t...

Страница 3: ...21 Installing HP SMH for Windows silently 32 Generating a setup iss file 32 Installing silently using the CLI 32 Reinstalling silently using the CLI 32 Configuring HP SMH 33 5 Installing HP SMH using HPSUM 35 Installing HP SMH on a Windows operating system using HPSUM 35 Installing HP SMH on a Linux operating system using the HPSUM 41 Preconfiguring the HP SMH component 47 6 Installing HP SMH dire...

Страница 4: ...g from a Windows operating system 65 Uninstalling from a Windows 2008 operating system 65 Uninstalling HP SMH on a CLI based Windows system 65 Uninstalling manually for Windows and Linux operating systems 66 Uninstalling manually for HP UX operating systems 67 Support and other resources 69 Intended audience 69 New and changed information in this edition 69 Typographic conventions 69 Related infor...

Страница 5: ...List of Tables 3 1 Bundle information 13 3 2 Variables and tags 17 4 1 Environment variables and tags 33 4 Publishing history 71 5 ...

Страница 6: ...6 ...

Страница 7: ... 2003 Small Business Server SP2 Windows Vista Business Edition Windows Vista Enterprise Edition Windows Vista Ultimate Edition Windows Vista SP2 Windows XP SP2 Windows XP SP3 Red Hat Enterprise Linux 6 for x64 Red Hat Enterprise Linux 6 for x86 and AMD64 EMT64T Red Hat Enterprise Linux 5 update 5 for x86 and AMD64 EMT64 Red Hat Enterprise Linux 5 update 4 for x86 and AMD64 EMT64T Red Hat Enterpris...

Страница 8: ...56 MB of RAM HP UX 1 1i v1 B 1 1 1 1 Operating Environments are for PA RISC systems only HP UX 1 1i v2 B 1 1 23 Operating Environments September 2004 and later HP UX 1 1i v3 B 1 1 31 Operating Environments February 2007 and later support both PA RISC and Itanium based operating systems NOTE To install the HP SMH application a minimum of 100 MB free disk space is required Supported browsers For HP ...

Страница 9: ... 1 31 Applications DVD February 2007 or later HP UX 1 1i v2 B 1 1 23 Operating Environment DVD May 2005 or later HP UX 1 1i v2 B 1 1 23 Applications DVD September 2005 or later HP UX 1 1i v1 B 1 1 1 1 Operating Environment DVD September 2005 or later HP UX 1 1i v1 B 1 1 1 1 Applications DVD May 2005 or later HP SmartSetup CD 6 20 or later HP SmartStart CD 8 20 or later HP ProLiant Support Pack 8 2...

Страница 10: ...10 ...

Страница 11: ... asking you to configure any settings After the installation is complete run the script opt hp hpsmh sbin smhconfig on a ProLiant system or opt hp hpsmh smhconfig hpSMHSetup pl on Itanium based operating systems to set the security options used by all HP Web based Agents on the system Otherwise these settings use default values To change the default configuration values type the following command ...

Страница 12: ...12 ...

Страница 13: ... UX To install HP SMH on HP UX you have several options Installing from the HP UX 1 1i v3 B 1 1 31 OE media February 2007 and later and from the HP UX 1 1i v3 B 1 1 31 Applications media February 2007 and later Installing from the HP UX 1 1i v2 B 1 1 23 OE media May 2005 and later and from the HP UX 1 1i v2 B 1 1 23 Applications media September 2005 and later Installing from the HP UX 1 1i v1 B 1 ...

Страница 14: ...ed Servlet Engine HP UX 1 1i v3 Recommended HP SMH plug ins such as Partition Manager require it opt hpws22 tomcat hpuxws22Tomcat NOTE This version of Tomcat is compatible with Apache 2 2 server only HP UX Tomcat based Servlet Engine HP UX 1 1i v1 v2 v3 Recommended HP SMH plug ins such as Property Pages found on the Home page require it opt wbem WBEMSvcs HP WBEM Services HP UX 1 1i v1 v2 v3 Recomm...

Страница 15: ...H using the Applications media page 15 You can go to the Software Depot Home at http www hp com go softwaredepot to search for and download the application bundles You can then use swinstall to install the applications See Installing using HP SMH Software Depot page 16 You can also download the bundles to a depot on your network and use Ignite UX and Software Distributor to install them This proce...

Страница 16: ... s var temp SysMgmtHomepage_A2214_HP UX_B 11 23_IA PA depot SysMgmtWeb 8 Start using HP SMH NOTE When HP SMH is installed the user hpsmh and group hpsmh is automatically added to the etc passwd file If you are using LDAP or any other network service to manage user and group accounts there might be a possibility that the user ID UID and the group ID GID is already in use by the LDAP users which can...

Страница 17: ...n use the timeout mechanism does not start TIMEOUT_SMH opt hpsmh conf timeout conf This variable defines the Tomcat timeout in minutes in the opt hpsmh conf timeout conf file If it is defined Tomcat istops after this time period has elapsed without any request to a Java web application By default the timeout for the HP UX Tomcat based Servlet Engine is 20 minutes and the timeout for the HP UX Apac...

Страница 18: ...arts off Starts Tomcat on demand default You can start HP SMH from the HP UX CLI To configure the Apache version to be used by the HP SMH HP UX 1 1i v3 execute the following script smhstartconfig v 2 0 2 2 where selecting 2 2 starts HP SMH with Apache 2 2 2 0 starts HP SMH with Apache 2 0 If you do not specify an option then smhstartconfig displays the current startup mode The smhstartconfig comma...

Страница 19: ...umentation website at http docs hp com HP might issue software updates to HP SMH Check the following resources for any notices regarding software updates HP UX OE media HP UX Applications media HP SMH web page on the Software Depot home at http www hp com go softwaredepot HP SMH website at http hp com go smh Patching or updating HP SMH software 19 ...

Страница 20: ...20 ...

Страница 21: ...ows Note You can click Cancel at any time during configuration of HP SMH settings 1 Initiate the setup exe file to begin the installation wizard After the wizard begins the Welcome dialog box appears 2 Click Next The OS Groups dialog box appears Installing HP SMH directly on Windows 21 ...

Страница 22: ...Version Control Repository Manager because it might lock out the administrator account Using the administrator account add another account with administrator privileges for Version Control Repository Manager access The operating system user group must be present on the system before you can add the user group to the System Management Homepage group list c Click Add The group name is added You can ...

Страница 23: ...trator grants access to both secure and unsecured pages Caution Selecting Local Access with administrator privileges provides all users with access to the local console full access without prompting them for a user name or password The Port 2301 field provides the option to enable the port 2301 Select Enable Port 2301 to enable the port 2301 during the installation process NOTE By default the Port...

Страница 24: ...he following trust modes Trust By Certificate Click Next The Trusted Certificates dialog box appears The Trusted Certificates dialog box allows you to add trusted certificate files to the Trusted Certificate List 1 24 Installing HP SMH on a Windows operating system ...

Страница 25: ...tion enables the HP SMH system and the HP SIM system to establish a trust relationship using certificates This mode is the strongest method of security because it requires certificate data and verifies the digital signature before enabling access 3 Click Next The IP Binding dialog box appears To import a certificate 1 Click Import The Import Server Certificate dialog box appears 2 Enter the name o...

Страница 26: ...the HP SIM certificate name submitted 3 Enter the names of the certificate of HP Systems Insight Manager servers you want to trust Note The HP SIM server certificate name cannot contain the following characters and 4 Click Add to add the name of a certificate of HP SIM server you want to trust Note You can enter a maximum of five HP SIM server names 5 Click Next The IP Binding dialog box appears N...

Страница 27: ...r the NetMask in the designated field c Click Add and the Subnet IP Address NetMask appears in the dialog box To delete a Subnet IP Address Netmask from the dialog box select a Subnet IP Address NetMask and click Delete The Subnet IP Address Netmask is removed from the dialog box Note You can add up to five Subnet IP Address NetMask pairs If you enter an invalid Subnet IP Address Netmask pair an e...

Страница 28: ...28 Installing HP SMH on a Windows operating system ...

Страница 29: ... box Enter a single address in the first box a In the Include field enter a beginning IP address b In the To field enter an ending IP address All IP addresses that fall between the beginning and ending IP addresses have login access c Click Add The IP address or IP address range is added to the Inclusion list To delete an IP address or IP address range select an IP address or IP address range and ...

Страница 30: ...or IP address range an error message appears indicating the IP address is invalid Click OK Enter a valid IP address or IP address range and click Add again Note If you select Next without adding any IP addresses to either the Include or Exclude lists a warning message appears stating IP Restricted Login checkbox will be marked as disabled Do you want to proceed without adding any IP Address restri...

Страница 31: ...te During the installation of HP SMH the Cancel button is disabled Even if you click X in the upper right corner of the box the current operation cannot be canceled 12 Click Finish to complete the installation Installing HP SMH directly on Windows 31 ...

Страница 32: ... your choice Installing silently using the CLI To install silently using the CLI use the following command setup exe s f1full_path_to_setup iss_file For example you might enter setup exe s f1c mydirectory setup iss Note There are no spaces between f1 and the path Reinstalling silently using the CLI To reinstall silently using the CLI setup exe s reinst f1full_path_to_setup iss_file Note The s rein...

Страница 33: ...out SystemDrive hp hpsmh conf smhpd xml The ui timeout tag defines the HP SMH GUI timeout in seconds If it is defined then HP SMH limits the loading time of the webapps If it is not defined then the default for the HP SMH GUI timeout is 20 seconds You can define the ui timeout tag using any value between 10 and 3600 seconds ui timeout 20 ui timeout SystemDrive hp hpsmh conf smhpd xml The rotate lo...

Страница 34: ...34 ...

Страница 35: ...e present in the same directory as the HPSUM EXE program for the PSP or ISP to be properly installed You can install HP SMH as a part of the complete ProLiant or Integrity Support Pack or you can install the HP SMH component individually The HP SMH component also provides support for preconfiguration which enables you to configure and save the configuration as part of the component itself before i...

Страница 36: ...3 If you want to install HP SMH on the local server check the Local Host checkbox and click Next 36 Installing HP SMH using HPSUM ...

Страница 37: ...ect the Remote Host or Group checkbox and click Manage Host The Manage Host panel appears b Click Add Host You can add new hosts by DNS name or IP address or you can add a range of IP addresses Installing HP SMH on a Windows operating system using HPSUM 37 ...

Страница 38: ...s Note If you chose to Manage Groups you will need to give the Windows credentials for each remote server 5 Select the target server and click Next A Discovery Progress screen appears while the system checks for installed items Then the Select Bundle Filter page appears 38 Installing HP SMH using HPSUM ...

Страница 39: ...you to update other items on your system at the same time as applying the bundle as a convenience or because updates in the bundle might depend on them Force All Bundle Updates Automatically sets the force flag for updates in the bundle This option enables you to update the installation as long as the supported hardware is present and installation conditions are met Note You do not need to select ...

Страница 40: ...the target server the HP SMH component is listed under the Installation not needed section In this case click Installation Options for HP SMH component and select the For Install checkbox The HP SMH component is listed under Updates to be Installed 9 After selecting the HP SMH component click Install A screen appears showing the installation progress 40 Installing HP SMH using HPSUM ...

Страница 41: ...inux operating sytem using the HPSUM your system must meet the minimun requirements in addition you must have the psp 8 40 x i686 en tar file 1 To start the deployment execute the command tar xvf psp 8 40 x i686 en tar which extracts the tar file contents to the current directory and then execute the command hpsum to run the the HPSUM The Screen Selections screen appears 2 Click Start Inventory bu...

Страница 42: ...3 If you want to install HP SMH on the local server check the Local Host checkbox and click Next 42 Installing HP SMH using HPSUM ...

Страница 43: ...ct the Remote Host or Group checkbox and click Manage Host The Manage Host panel appears b Click Add Host You can add new hosts by DNS name or IP address or you can add a range of IP addresses Installing HP SMH on a Linux operating system using the HPSUM 43 ...

Страница 44: ...s Note If you chose to Manage Groups you will need to give the Windows credentials for each remote server 5 Select the target server and click Next A Discovery Progress screen appears while the system checks for installed items Then the Select Bundle Filter page appears 44 Installing HP SMH using HPSUM ...

Страница 45: ...ou to update other items on your system at the same time as applying the bundle as a convenience or because updates in the bundle might depend on them Force All Bundle Updates Automatically sets the force flag for updates in the bundle This option enables you to update the installation as long as the supported hardware is present and installation conditions are met Note You do not need to select t...

Страница 46: ...the target server the HP SMH component is listed under the Installation not needed section In this case click Installation Options for HP SMH component and select the For Install checkbox The HP SMH component is listed under Updates to be Installed 9 After selecting the HP SMH component click Install A screen appears showing the installation progress 46 Installing HP SMH using HPSUM ...

Страница 47: ...Local Access Local Access is disabled by default Local Access enables a user to locally gain access to the HP SMH without being challenged for authentication If you select Administrator any user with access to the local console is granted full access If you select Anonymous any local user has access limited to unsecured pages without being challenged for a user name and password CAUTION HP does no...

Страница 48: ... certificate name appears under the Trusted Servers list You can click Save to save your changes up to this point or click Cancel to discard the changes and close the wizard 4 Click Next The IP Binding page appears Trust All Sets HP SMH to accept certain changes from any server CAUTION HP strongly recommends using the Trust by Certificate option because the other options are less secure To trust a...

Страница 49: ...y those IP addresses are allowed login access with the exception of localhost If no IP addresses are in the inclusion list then login access is allowed to any IP addresses not in the exclusion list To include or exclude IP addresses 1 In the From field enter the IP addresses to include or exclude You can enter an IP address range to be included or excluded by entering a beginning IP address in the...

Страница 50: ...50 ...

Страница 51: ...enter the following command line rpm ivh hpsmh 6 x x y i386 rpm A message appears indicating that HP SMH installed successfully with default configuration values For more information regarding minimum requirements see Chapter 1 Installation requirements Installing HP SMH on x86_64 operating systems To install HP SMH on x86_64 operating systems your system must meet the minimum requirements In addi...

Страница 52: ...52 ...

Страница 53: ...m a version of HP SMH prior to 3 0 the previous settings are retained However the retained settings are configurable To configure the HP SMH settings 1 Enter the following command to start the configuration opt hp hpsmh smhconfig hpSMHSetup pl The Welcome screen indicates that you can configure security and access parameters for HP SMH and related HP web based management tools 2 Press Enter The Op...

Страница 54: ...ous Access Enter 3 to disable Local Access Enter 4 to enable Local Access Anonymous Local Access Anonymous enables you to locally gain access to HP SMH without authentication Any local user has access limited to unsecured pages without being challenged for a username and password CAUTION HP does not recommend the use of local access unless your management server software enables it Enter 5 to enab...

Страница 55: ...rtificate files by repeating these steps 4 Press Enter when you finish Trust by Name Enter 2 to Trust by Name Trust Mode Trust by Name appears 1 2 Enter 4 to Modify Server Name list To add an HP SIM server certificate name A Enter 1 You are prompted to add an HP SIM server certificate name B Enter the name of the certificate of HP SIM server to be trusted and press Enter The certificate name appea...

Страница 56: ...he Inclusion List A Enter 1 for Include Login Restriction IP Address B Enter 1 for Add C Enter the IP address or IP address range you want to add to the Inclusion List The IP address or IP address range appears under the IP Address Inclusion List Note You can add or delete as many IP addresses or IP address ranges as you want To delete an IP address or IP address range from the Inclusion list A En...

Страница 57: ...ble IP Restricted Login which sets it to OFF IP Restricted Login OFF appears Note Only IPv4 address ranges are supported for IP restricted login 9 Enter n to go to the next screen The configuration completes and a message appears indicating that HP SMH is successfully set up The HP SMH service stops and starts automatically 10 Verify HP SMH is configured and working properly by navigating to it an...

Страница 58: ...58 ...

Страница 59: ... stored in the etc opt hp sslshare directory The files are called file pem and cert pem In Windows operating systems public and private keys are stored in the System Drive hp sslshare directory of the system drive To protect the keys this subdirectory is only accessible to administrators if the file system allows such security For private key security reasons HP recommends that you install Windows...

Страница 60: ...60 ...

Страница 61: ... to an HP UX system then you can use port 2381 if you changed the default configuration to have autostart disabled and start on boot enabled or if you have disabled port 2301 If you keep the default installed configuration you can use the following URL http hostname 2301 NOTE You can also use the port 1 188 to access HP SMH This port is used by the Tomcat instance of the HP SMH By default HP UX is...

Страница 62: ...bsite Certified by an Unknown Authority dialog box appears asking you to indicate whether to trust the server If you do not select Accept this certificate permanently the Website Certified by an Unknown Authority dialog box appears every time you use a browser 2 Click OK The Sign In page appears unless you have enabled Anonymous access then the HP System Management Homepage appears 3 Enter the use...

Страница 63: ... the web browser that you use to sign in to HP SMH You can stop HP SMH from the HP UX command line opt hpsmh lbin hpsmh stop This will not stop the mini daemon smhstartd but will stop the HP UX Apache based web server The next time you contact HP SMH through http hostname 2301 the HP UX Apache based web server will again start on port 2381 https If autostart is configured the HP UX Apache based we...

Страница 64: ...64 ...

Страница 65: ...HP SMH directory where HP SMH directory is System Drive hp hpsmh is not deleted The HP SMH directory contains the user configured SMH files and the same configuration is utilized when the HP SMH is reinstalled again Uninstalling from a Windows 2008 operating system Use the Programs and Features feature in Windows 2008 and complete the following steps to remove HP SMH 1 Select Start Control Panel P...

Страница 66: ...eleted hp hpsmh lib hp hpsmh logs hp hpsmh modules hp hpsmh namazu hp hpsmh session hp sslshare For Linux sslshare is located in etc opt hp sslshare Important Do not remove this file from a system that uses the Linux OS You will lose certificates stored in this file if it is deleted For Windows sslshare is located in SystemDrive hp sslshare For Linux remove the following additional files usr local...

Страница 67: ... in Uninstalling from an HP UX operating system page 65 The following procedure manually uninstalls HP SMH on an HP UX system 1 Stop the HP SMH service 2 Remove using rm rf the following directories var opt hpsmh opt hpsmh session opt hpsmh certs opt hpsmh cookies opt hpsmh sslshare opt hpsmh tmp CAUTION On HP UX operating systems do not remove all files under the opt hpsmh directory because files...

Страница 68: ...68 ...

Страница 69: ...uage attrib An attribute used in a markup language Related information HP SMH documentation For more information about HP SMH see the following sources HP System Management Homepage Release Notes The release notes provide documentation for what s new with the release features and change notifications system requirements and known issues The release notes are available on the HP Technical Documenta...

Страница 70: ...nd This information is not available for Linux and Windows operating systems smhassist 1m manpage You can use the smhassist command to verify the configurations of SMH and see if there are any dependent software patches or configuration errors For HP UX 1 1i v3 B 1 1 31 and HP UX 1 1i v2 B 1 1 23 operating system releases the manpage is available from the CLI using the man smhassist command This i...

Страница 71: ...tems Insight Manager A dedicated server is recommended to host both HP Systems Insight Manager and HP Insight Remote Support Advanced Details for both versions are available at http www hp com go insightremotesupport To download the software go to Software Depot http www software hp com Select Insight Remote Support from the menu on the right Publishing history Table 4 Publishing history Publicati...

Страница 72: ...5 HP UX 1 1i v2 B 1 1 23 HP UX 1 1i v1 B 1 1 1 1 HP UX 381372 007 June 2006 4 For HP UX HP UX 1 1i v2 B 1 1 23 HP UX 1 1i v1 B 1 1 1 1 For Linux and Windows See Installation requirements page 7 HP UX Linux and Windows 381372 006 en February 2006 4 See Installation requirements page 7 Linux and Windows 381372 005 December 2005 3 HP UX 1 1i v2 B 1 1 23 HP UX 1 1i v1 B 1 1 1 1 HP UX 381372 004 en Sep...

Страница 73: ... browsers 8 Windows 21 35 L Linux installation 51 Linux Itanium based system system preparation 53 Linux x86_64 installation 51 M manpages 69 media 9 O OpenSSH 35 operating systems supported 7 R removal of HP SMH 65 requirements installation 7 verifying system requirements 9 resources 69 S service and support 72 setup 1 1 signing in 61 signing out 61 software 9 59 U uninstallation 65 W web browser...

Отзывы: