Veritas InfoScale™ Operations Manager 8.0.2 Installation and Configuration Guide
- Section I. Installing and configuring Veritas InfoScale Operations Manager
- Planning your Veritas InfoScale Operations Manager installation
- About Veritas InfoScale Operations Manager
- Downloading Veritas InfoScale Operations Manager 8.0.2
- Using the product documentation
- Host considerations for installing Veritas InfoScale Operations Manager
- Typical Veritas InfoScale Operations Manager deployment configuration
- Veritas InfoScale Operations Manager 8.0.2 installation overview
- Choosing a Management Server host
- Choosing the managed hosts
- System requirements
- Installing, upgrading, and uninstalling Veritas InfoScale Operations Manager
- Packages included in Veritas InfoScale Operations Manager
- About installing Management Server
- Verifying Management Server installation on Linux
- Verifying Management Server installation on Windows
- Configuring Veritas InfoScale Operations Manager on Linux and Windows
- Implementing US Executive Order (EO) requirements
- Configuring Veritas InfoScale Operations Manager Management Server and Agents in FIPS mode on Linux
- Configuring Service groups using CLI script
- Configuring Veritas InfoScale Operations Manager Management Server on Linux using CLI
- Importing third-party certificates for xprtld
- About installing managed host
- Verifying managed host installation on UNIX
- Verifying managed host installation on Windows
- About upgrading Management Server
- About backing up and restoring Veritas InfoScale Operations Manager data
- Taking regular backups of Veritas InfoScale Operations Manager data on Linux
- Backing up Veritas InfoScale Operations Manager data on Linux before upgrading to version 8.0.2
- Restoring backed up data on Linux
- Taking regular backups of Veritas InfoScale Operations Manager data on Windows
- Backing up Veritas InfoScale Operations Manager data on Windows before upgrading to version 8.0.2
- Restoring backed up data on Windows
- About upgrading managed hosts to Veritas InfoScale Operations Manager 8.0.2
- Verifying the version of Management Server in the console
- Verifying the version of a managed host in the console
- Uninstalling Management Server on Linux
- Uninstalling Management Server on Windows
- Uninstalling managed host on UNIX
- Uninstalling managed host on Windows
- Configuring Veritas InfoScale Operations Manager in a high availability and disaster recovery environment
- Configuring the high availability feature in Veritas InfoScale Operations Manager
- Configuring a new Veritas InfoScale Operations Manager installation in high availability environment
- Prerequisites for configuring a new Management Server in high availability environment
- Performing initial configuration of Management Server in HA environment
- Creating the base service groups for HA configuration
- Creating the base service groups for CFS HA configuration
- Completing the configuration of a Management Server installation in HA environment
- Configuring an existing Veritas InfoScale Operations Manager installation in high availability environment
- Configuring a new Veritas InfoScale Operations Manager installation in high availability environment
- Configuring CMS HA on Linux using Command Line (CLI)
- Configuring Management Server in one-to-one DR environment
- Configuring Veritas InfoScale Operations Manager in high availability and disaster recovery environment
- About upgrading the high availability configurations
- About upgrading the high availability and disaster recovery configurations
- Removing the high availability configuration
- Configuring the high availability feature in Veritas InfoScale Operations Manager
- Installing and uninstalling Veritas InfoScale Operations Manager add-ons
- About deploying Veritas InfoScale Operations Manager add-ons
- Downloading a Veritas InfoScale Operations Manager add-on
- Uploading a Veritas InfoScale Operations Manager add-on to the repository
- Installing a Veritas InfoScale Operations Manager add-on
- Uninstalling a Veritas InfoScale Operations Manager add-on
- Removing a Veritas InfoScale Operations Manager add-on from the repository
- Canceling deployment request for a Veritas InfoScale Operations Manager add-on
- Installing a Veritas InfoScale Operations Manager add-on on a specific managed host
- Uninstalling a Veritas InfoScale Operations Manager add-on from a specific managed host
- Enabling a Veritas InfoScale Operations Manager add-on on a specific managed host
- Disabling a Veritas InfoScale Operations Manager add-on from a specific managed host
- Refreshing the repository
- Restarting the web server
- Planning your Veritas InfoScale Operations Manager installation
- Section II. Setting up the Management Server environment
- Basic Veritas InfoScale Operations Manager tasks
- Adding and managing hosts
- Overview of host discovery
- Overview of agentless discovery
- About agentless discovery using the Control Host
- About agentless discovery of remote hosts
- Prerequisites for agentless configuration
- How agentless discovery of a UNIX or Linux host works
- How agentless discovery of a Windows host works
- Requirements for agentless discovery of UNIX hosts
- Requirements for agentless discovery of Windows hosts
- Requirements for deep array discovery for agentless hosts
- Commands that require the root access for agentless discovery of UNIX hosts
- Using the privilege control software with agentless discovery of UNIX hosts
- SSH configuration requirements for agentless discovery
- About installing OpenSSH on a UNIX host
- Adding the managed hosts to Management Server using an agent configuration
- Adding the managed hosts to Management Server using an agentless configuration
- Adding Agentless hosts to the Management Server using Profile
- Adding managed hosts to Management Server using the Auto Configure (gendeploy.pl) script
- Editing the agentless host configuration
- Refreshing the details of the managed host
- Removing managed hosts from the Management Server domain
- Setting up user access
- About managing authentication brokers and authentication domains in the Veritas InfoScale Operations Manager domain
- Adding Lightweight Directory Access Protocol or Active Directory-based authentication on Management Server
- Unconfiguring Lightweight Directory Access Protocol or Active Directory configuration from the authentication broker
- Configuring LDAP using CLI
- Configuring Single Sign-On in Veritas InfoScale Operations Manager
- Enabling the authentication domain
- Disabling the authentication domain
- About predefined roles in Veritas InfoScale Operations Manager
- About Organizations, objects, and roles in Veritas InfoScale Operations Manager
- Assigning permissions to user groups for a perspective
- Modifying permissions assigned to user groups for a perspective
- Deleting permissions assigned to user groups on a perspective
- Restricting users or user groups from accessing the Veritas InfoScale Operations Manager console
- Example: Managing user access in Veritas InfoScale Operations Manager using Organizations and existing user groups
- Setting up fault monitoring
- About alerts and rules
- Creating rules in the Management Server perspective
- Editing rules in the Management Server perspective
- Deleting rules in the Management Server perspective
- Enabling rules in the Management Server perspective
- Disabling rules in the Management Server perspective
- About faults and risks
- Suppressing faults in the Management Server perspective
- Restoring a suppressed fault in the Management Server perspective
- Suppressing a fault definition in the Management Server perspective
- Restoring a suppressed fault definition in the Management Server perspective
- Setting up virtualization environment discovery
- About the virtualization technologies supported
- About Control Hosts in Veritas InfoScale Operations Manager
- Requirements for discovering vCenter and ESX servers using Veritas InfoScale Operations Manager
- About near real-time discovery of VMware events
- Setting up near real-time discovery of VMware events
- Configuration settings for VMware vCenter discovery
- Requirements for discovering the Solaris zones
- Requirements for discovering Solaris Logical domains
- Requirements for discovering logical partitions
- Requirements for Microsoft Hyper-V virtualization discovery
- Requirements for Kernel-based Virtual Machine (KVM) virtualization discovery
- Adding a virtualization server
- Editing a virtualization discovery configuration
- Refreshing a virtualization discovery configuration
- Removing a virtualization discovery configuration
- Configuring performance metering for a VMware vCenter server
- Disable performance metering for a VMware vCenter server
- Deploying hot fixes, packages, and patches
- About deploying Veritas InfoScale Operations Manager hot fixes
- About deploying maintenance release packages and patches
- About deploying base release packages
- Downloading a hot fix, package, or patch
- Uploading a Veritas InfoScale Operations Manager hot fix or package to the repository
- Installing a Veritas InfoScale Operations Manager hot fix, package, or patch
- Removing a hot fix, package, or patch from the repository
- Canceling deployment request for a hot fix, package, or patch
- Installing a Veritas InfoScale Operations Manager hot fix on a specific managed host
- Configuring Management Server settings
- Configuring the Management Server settings
- Configuring SMTP settings for email notifications
- Configuring SNMP trap settings for alert notifications
- Configuring the proxy server settings
- Configuring two-factor authentication (2FA)
- Setting the period for retaining the alert and the task logs in the database
- Configuring Web server settings
- Setting the generation time for subscribed reports
- Configuring advance authorization settings
- Enabling or disabling policy signatures for the data center
- Forwarding audit logs
- Setting up extended attributes
- Viewing information on the Management Server environment
- Viewing the details of an add-on, hot fix, package, or patch on SORT website
- Viewing the hosts configured in the Management Server domain
- Viewing the details of the authentication broker and the domains associated with the broker
- Viewing faults in the Management Server perspective
- Viewing the faults definitions
- Viewing details of alert logs
- Viewing the details of rules
- Viewing the details of active users logged in to Management Server
- Viewing the Management Server settings
- Viewing the list of extended attributes
- Viewing audit information for Management Server
- Viewing task information for the data center
- Viewing or exporting a list of available policy signatures
- Appendix A. Troubleshooting
- Management Server (MS)
- Veritas InfoScale Operations Manager processes running on Management Server for Linux
- Veritas InfoScale Operations Manager services running on Management Server for Windows
- Commands to start and stop the Veritas InfoScale Operations Manager processes on Management Server on Linux
- Commands to start and stop the Veritas InfoScale Operations Manager processes on Management Server on Windows
- Management Server log file locations on Linux
- Management Server log file locations on Windows
- Managed host (MH)
- Veritas InfoScale Operations Manager processes running on managed host on Unix/Linux
- Veritas InfoScale Operations Manager services running on managed host on Windows
- Commands to start and stop Veritas InfoScale Operations Manager processes on managed host on UNIX/Linux
- Managed host log files
- Agentless driver log files
- Gathering information for troubleshooting
- Management Server (MS)
- Index
Importing third-party certificates for xprtld
Veritas InfoScale Operations Manager (VIOM)lets you import third-party certificates for the xprtld service on Management Servers that run on Linux. It also lets you import third-party certificates for the agents on AIX, Linux, and Solaris, provided that the agent version is 7.3.1 or later. VIOM supports the use of a third-party certificate without a passphrase for xprtld that runs on port 5634. However, it only supports 2048-bit certificates.
To generate a third-party certificate for xprtld
- Use the openssl command as follows to generate a private key and a certificate signing request (CSR):
openssl req -newkey rsa:2048 -nodes -keyout sfmAgentPrivateKeyFileName -out sfmAgentCSRFileName
For example:
openssl req -newkey rsa:2048 -nodes -keyout sfm_agent.private.key -out sfm_agent.csr
- The openssl command prompts you to provide some information that is to be added to the CSR. Specify the exact values that are provided in the following example:
Country Name (2 letter code) [XX]: . State or Province Name (full name) []: . Locality Name (eg, city) [Default City]: . Organization Name (eg, company) [Default Company Ltd]: vx Organizational Unit Name (eg, section) []: sfm_domain@nameOfCMS Common Name (eg, your name or your server's hostname) []: sfm_agent Email Address []:
Note:
The nameOfCMS value should match exactly with the value of the cs_config_name attribute that is present in the
/etc/default/sfm_resolv.conffile on the Central Management Server (CMS).Specify the exact values that are provided in the following example for this additional information that is also to be sent with the CSR:
A challenge password []: . An optional company name []:
- Send the CSR file - for example,
sfm_agent.csr -to your certificate signing authority and ask them to provide the corresponding certificate. The certificate should be provided in thepemformat, along with the intermediate CA certificate and the root CA certificate, and it should support SSL clients. Veritas recommends that you assign a validity of 10 years to the certificate, or the maximum duration possible. - Optionally, run the following command to verify the purpose of the certificate, including the support for SSL clients:
openssl x509 -purpose -noout -in sfmAgentCertFileName
For example:
openssl x509 -purpose -noout -in sfm_agent.cert.pem
Certificate purposes:
SSL client : Yes SSL client CA :No
SSL server : Yes SSL server CA :No
Netscape SSL server : Yes Netscape SSL server CA : No
- Ensure that you have the following files ready before you import the certification on a Management Server:
File
Sample file name
Private key file for
sfm_agentsfm_agent.private.keyCertificate file for
sfm_agentsfm_agent.cert.pemCertificate file for intermediate CA
intermediate.cert.pemCertificate file for root CA
ca.cert.pem
To import a third-party certificate on a Management Server and on the agents
Copy all the files that are mentioned in the last step of the previous procedure on the Management Server at the appropriate location, for example:
/viom/certs/.Run the following command to import the certificates:
/opt/VRTSsfmh/bin/perl /opt/VRTSsfmh/util/import_sfm_agent_certificate.pl --import_sfm_agent_cert --sfm_agent_certificate=/viom/certs/sfmAgentCertificateFileName --sfm_agent_privatekey=/viom/certs/sfmAgentPrivateKeyFileName --subCA_certificate=/viom/certs/intermediateCertificateFileName --rootCA_certificate=/viom/certs/caCertificateFileName
For example:
/opt/VRTSsfmh/bin/perl /opt/VRTSsfmh/util/import_sfm_agent_certificate.pl --import_sfm_agent_cert --sfm_agent_certificate=/viom/certs/sfm_agent.cert.pem --sfm_agent_privatekey=/viom/certs/sfm_agent.private.key --subCA_certificate=/viom/certs/intermediate.cert.pem --rootCA_certificate=/viom/certs/ca.cert.pem
The certificates are imported on the agents automatically.
Follow the instructions and provide the appropriate input at the prompts that the command displays.
You may encounter certain situations that you can address as follows:
The certificate import process restarts all the VIOM services on the Management Server and the xprtld service on all the managed hosts. After the certificate is successfully imported, if a managed host does not yet use the new certificate, check whether that host is registered on multiple Management Servers. If so, unconfigure the managed host from the Management Servers other than the one on which this new certificate was installed, and then restart the xprtld service on the host.
The certificate cannot be imported on the managed hosts that are on VIOM 7.3 or an earlier version. Upgrade such hosts to VIOM 8.0 or a later supported version (refer to the Veritas InfoScale Operations Manager Hardware and Software Compatibility Lists document), and then run the command to import the certificate again.
The certificate cannot be imported on managed hosts that are unreachable from the Management Server. After the import process is complete, address the connectivity issue for the managed hosts that were unreachable. Then, add the managed hosts to the Management Server again; the new certificate gets automatically installed on the managed hosts.