Arctera InfoScale™ Operations Manager 9.0 Installation and Configuration Guide
- Section I. Installing and configuring Arctera InfoScale Operations Manager
- Planning your Arctera InfoScale Operations Manager installation
- About Arctera InfoScale Operations Manager
- Downloading Arctera InfoScale Operations Manager 9.0
- Using the product documentation
- Host considerations for installing Arctera InfoScale Operations Manager
- Typical Arctera InfoScale Operations Manager deployment configuration
- Arctera InfoScale Operations Manager 9.0 installation overview
- Choosing a Management Server host
- Choosing the managed hosts
- System requirements
- Installing, upgrading, and uninstalling Arctera InfoScale Operations Manager
- Packages included in Arctera InfoScale Operations Manager
- About installing Management Server
- Verifying Management Server installation on Linux
- Verifying Management Server installation on Windows
- Configuring Arctera InfoScale Operations Manager on Linux and Windows
- Implementing US Executive Order (EO) requirements
- Configuring Arctera InfoScale Operations Manager Management Server and Agents in FIPS mode on Linux
- Configuring service groups using CLI script
- Configuring Arctera InfoScale Operations Manager Management Server on Linux using CLI
- Importing third-party certificates for xprtld
- About installing managed host
- Verifying managed host installation on UNIX
- Verifying managed host installation on Windows
- About upgrading the Management Server
- About backing up and restoring Arctera InfoScale Operations Manager data
- Taking regular backups of Arctera InfoScale Operations Manager data on Linux
- Backing up Arctera InfoScale Operations Manager data on Linux before upgrading to version 9.0
- Restoring backed up data on Linux
- Taking regular backups of Arctera InfoScale Operations Manager data on Windows
- Backing up Arctera InfoScale Operations Manager data on Windows before upgrading to version 9.0
- Restoring backed up data on Windows
- About upgrading managed hosts to Arctera InfoScale Operations Manager 9.0
- Verifying the version of Management Server in the console
- Verifying the version of a managed host in the console
- Uninstalling Management Server on Linux
- Uninstalling Management Server on Windows
- Uninstalling managed host on UNIX
- Uninstalling managed host on Windows
- Configuring Arctera InfoScale Operations Manager in a high availability and disaster recovery environment
- Configuring the high availability feature in Arctera InfoScale Operations Manager
- Configuring a new Arctera InfoScale Operations Manager installation in high availability environment
- Prerequisites for configuring a new Management Server in high availability environment
- Performing initial configuration of Management Server in HA environment
- Creating the base service groups for HA configuration
- Creating the base service groups for CFS HA configuration
- Completing the configuration of a Management Server installation in HA environment
- Configuring an existing Arctera InfoScale Operations Manager installation in high availability environment
- Configuring a new Arctera InfoScale Operations Manager installation in high availability environment
- Configuring CMS HA on Linux using Command Line (CLI)
- Configuring Management Server in one-to-one DR environment
- Configuring Arctera InfoScale Operations Manager in high availability and disaster recovery environment
- About upgrading the high availability configurations
- About upgrading the high availability and disaster recovery configurations
- Removing the high availability configuration
- Configuring the high availability feature in Arctera InfoScale Operations Manager
- Installing and uninstalling Arctera InfoScale Operations Manager add-ons
- About deploying Arctera InfoScale Operations Manager add-ons
- Downloading a Arctera InfoScale Operations Manager add-on
- Uploading a Arctera InfoScale Operations Manager add-on to the repository
- Installing a Arctera InfoScale Operations Manager add-on
- Uninstalling a Arctera InfoScale Operations Manager add-on
- Removing a Arctera InfoScale Operations Manager add-on from the repository
- Canceling deployment request for a Arctera InfoScale Operations Manager add-on
- Installing a Arctera InfoScale Operations Manager add-on on a specific managed host
- Uninstalling a Arctera InfoScale Operations Manager add-on from a specific managed host
- Enabling a Arctera InfoScale Operations Manager add-on on a specific managed host
- Disabling a Arctera InfoScale Operations Manager add-on from a specific managed host
- Refreshing the repository
- Restarting the web server
- Planning your Arctera InfoScale Operations Manager installation
- Section II. Setting up the Management Server environment
- Basic Arctera InfoScale Operations Manager tasks
- Adding and managing hosts
- Overview of host discovery
- Overview of agentless discovery
- About agentless discovery using the Control Host
- About agentless discovery of remote hosts
- Prerequisites for agentless configuration
- How agentless discovery of a UNIX or Linux host works
- How agentless discovery of a Windows host works
- Requirements for agentless discovery of UNIX hosts
- Requirements for agentless discovery of Windows hosts
- Requirements for deep array discovery for agentless hosts
- Commands that require the root access for agentless discovery of UNIX hosts
- Using the privilege control software with agentless discovery of UNIX hosts
- SSH configuration requirements for agentless discovery
- About installing OpenSSH on a UNIX host
- Adding the managed hosts to Management Server using an agent configuration
- Adding the managed hosts to Management Server using an agentless configuration
- Adding Agentless hosts to the Management Server using Profile
- Adding managed hosts to Management Server using the Auto Configure (gendeploy.pl) script
- Editing the agentless host configuration
- Refreshing the details of the managed host
- Removing managed hosts from the Management Server domain
- Setting up user access
- About managing authentication brokers and authentication domains in the Arctera InfoScale Operations Manager domain
- Adding Lightweight Directory Access Protocol or Active Directory-based authentication on Management Server
- Unconfiguring Lightweight Directory Access Protocol or Active Directory configuration from the authentication broker
- Configuring LDAP using CLI
- Configuring Single Sign-On in Arctera InfoScale Operations Manager
- Enabling the authentication domain
- Disabling the authentication domain
- About predefined roles in Arctera InfoScale Operations Manager
- About Organizations, objects, and roles in Arctera InfoScale Operations Manager
- Assigning permissions to user groups for a perspective
- Modifying permissions assigned to user groups for a perspective
- Deleting permissions assigned to user groups on a perspective
- Restricting users or user groups from accessing the Arctera InfoScale Operations Manager console
- Example: Managing user access in Arctera InfoScale Operations Manager using Organizations and existing user groups
- Setting up fault monitoring
- About alerts and rules
- Creating rules in the Management Server perspective
- Editing rules in the Management Server perspective
- Deleting rules in the Management Server perspective
- Enabling rules in the Management Server perspective
- Disabling rules in the Management Server perspective
- About faults and risks
- Suppressing faults in the Management Server perspective
- Restoring a suppressed fault in the Management Server perspective
- Suppressing a fault definition in the Management Server perspective
- Restoring a suppressed fault definition in the Management Server perspective
- Setting up virtualization environment discovery
- About the virtualization technologies supported
- About Control Hosts in Arctera InfoScale Operations Manager
- Requirements for discovering vCenter and ESX servers using Arctera InfoScale Operations Manager
- About near real-time discovery of VMware events
- Setting up near real-time discovery of VMware events
- Configuration settings for VMware vCenter discovery
- Requirements for discovering the Solaris zones
- Requirements for discovering Solaris Logical domains
- Requirements for discovering logical partitions
- Requirements for Microsoft Hyper-V virtualization discovery
- Requirements for Kernel-based Virtual Machine (KVM) virtualization discovery
- Adding a virtualization server
- Editing a virtualization discovery configuration
- Refreshing a virtualization discovery configuration
- Removing a virtualization discovery configuration
- Configuring performance metering for a VMware vCenter server
- Disable performance metering for a VMware vCenter server
- Deploying hot fixes, packages, and patches
- About deploying Arctera InfoScale Operations Manager hot fixes
- About deploying maintenance release packages and patches
- About deploying base release packages
- Downloading a hot fix, package, or patch
- Uploading a Arctera InfoScale Operations Manager hot fix or package to the repository
- Installing a Arctera InfoScale Operations Manager hot fix, package, or patch
- Removing a hot fix, package, or patch from the repository
- Canceling deployment request for a hot fix, package, or patch
- Installing a Arctera InfoScale Operations Manager hot fix on a specific managed host
- Configuring Management Server settings
- Configuring the Management Server settings
- Configuring SMTP settings for email notifications
- Configuring SNMP trap settings for alert notifications
- Configuring the proxy server settings
- Configuring two-factor authentication (2FA)
- Setting the period for retaining the alert and the task logs in the database
- Configuring Web server settings
- Setting the generation time for subscribed reports
- Configuring advance authorization settings
- Enabling or disabling policy signatures for the data center
- Forwarding audit logs
- Setting up extended attributes
- Viewing information on the Management Server environment
- Viewing the details of an add-on, hot fix, package, or patch on SORT website
- Viewing the hosts configured in the Management Server domain
- Viewing the details of the authentication broker and the domains associated with the broker
- Viewing faults in the Management Server perspective
- Viewing the faults definitions
- Viewing details of alert logs
- Viewing the details of rules
- Viewing the details of active users logged in to Management Server
- Viewing the Management Server settings
- Viewing the list of extended attributes
- Viewing audit information for Management Server
- Viewing task information for the data center
- Viewing or exporting a list of available policy signatures
- Appendix A. Troubleshooting
- Management Server (MS)
- Arctera InfoScale Operations Manager processes running on Management Server for Linux
- Arctera InfoScale Operations Manager services running on Management Server for Windows
- Commands to start and stop the Arctera InfoScale Operations Manager processes on Management Server on Linux
- Commands to start and stop the Arctera InfoScale Operations Manager processes on Management Server on Windows
- Management Server log file locations on Linux
- Management Server log file locations on Windows
- Managed host (MH)
- Arctera InfoScale Operations Manager processes running on managed host on Unix/Linux
- Arctera InfoScale Operations Manager services running on managed host on Windows
- Commands to start and stop Arctera InfoScale Operations Manager processes on managed host on UNIX/Linux
- Managed host log files
- Agentless driver log files
- Gathering information for troubleshooting
- Management Server (MS)
- Index
Configuring Arctera InfoScale Operations Manager Management Server and Agents in FIPS mode on Linux
The Federal Information Processing Standards (FIPS) 140-2 standard (commonly referred as FIPS mode) specifies the security requirements for cryptographic modules. The U.S. federal government has set an encryption standard for its non-military agencies, contractors, and service providers who work with the U.S. government must also follow FIPS. Hence, it is mandatory to configure and enable the FIPS 140-2 standard.
You can configure and enable FIPS mode for Arctera InfoScale Operations Manager Management Server and Agents. By default, FIPS-compliant mode is turned off when the Arctera InfoScale Operations Manager Management Server platform is installed. However, you can turn on FIPS mode for one or more nodes in your deployment. Configuration of Arctera InfoScale Operations Manager to run in FIPS mode includes the following sequence of process:
Enabling the FIPS mode on Arctera InfoScale Operations Manager Management Server (installed on Linux)
Enabling the FIPS mode on the third-party components that are used in Arctera InfoScale Operations Manager (Tomcat, Java)
Enabling the FIPS mode on Arctera InfoScale Operations Manager Agents (Linux, Solaris, and AIX)
FIPS mode can be enabled only with a fresh installation of Arctera InfoScale Operations Manager Server on a Linux system. Configuration of an existing Arctera InfoScale Operations Manager to run in FIPS mode is not supported in this release.
FIPS mode can be enabled only on Agents running on Linux, Solaris, or AIX. In this release, agents that are running on other operating systems cannot be configured in FIPS mode.
To verify if OpenSSL is installed, run the /usr/bin/openssl version command.
To enable FIPS mode on fresh installation of Arctera InfoScale Operations Manager Management Server on Linux
- Perform a fresh installation of Arctera InfoScale Operations Manager Management Server on Linux.
- Open the
VRTSatlocal.confconfiguration file that is located at/opt/VRTSsfmcs/sec/bin/. - Under the Security\Authentication\Client section, enable the FIPS mode as follows:
[Security\Authentication\Client] "FipsMode"=dword:00000001 "ConnectTimeout"=dword:00000014
- Open a browser and configure Arctera InfoScale Operations Manager Management Server.
- Once the Arctera InfoScale Operations Manager Management Server configuration is successful, you may open the
VRTSatlocal.confconfiguration file that is located at/var/opt/VRTSsfmcs/sec/root/.VRTSat/profile/and verify if the "FipsMode"=dword:00000001 is set.
To enable FIPS mode on Tomcat and Java components used in Arctera InfoScale Operations Manager
- Create a trusted Java KeyStore (JKS) for the Tomcat web server with imported certificates provided by a trusted Certificate Authority. For more information, see https://www.veritas.com/support/en_US/article.100026835
- Back up the following files:
/opt/VRTSsfmcs/webgui/jre/conf/security/java.security/opt/VRTSsfmcs/webgui/tomcat/conf/server.xml
- Copy and overwrite the following files as follows:
cp /opt/VRTSsfmcs/webgui/jre/conf/security/java.security.fips /opt/VRTSsfmcs/webgui/jre/conf/security/java.securitycp/opt/VRTSsfmcs/webgui/tomcat/conf/server.xml.fips /opt/VRTSsfmcs/webgui/tomcat/conf/server.xmlcp /opt/VRTSsfmcs/webgui/tomcat/bin/setenv.sh.fips /opt/VRTSsfmcs/webgui/tomcat/bin/setenv.sh
- Edit the server.xml that is located at
/opt/VRTSsfmcs/webgui/tomcat/conf/and add the CMS hostname (FQDN) in the Connector tag and Connector > SSLHostConfig tag respectively as follows:defaultSSLHostConfigName="<FQDN>"hostName="<FQDN>"
- Convert the Java KeyStore (JKS) to the BC FIPS Keystore (BCFKS) format using the following command:
/opt/VRTSsfmcs/webgui/jre/bin/keytool -importkeystore -srckeystore .keystore -srcstoretype pkcs12 -deststoretype BCFKS -destkeystore .keystore -srcstorepass changeit -deststorepass changeit -providerclass com.safelogic.cryptocomply.jcajce.provider.CryptoComplyFipsProvider -J--module-path=/opt/VRTSsfmcs/webgui/jre/lib/ccj-3.0.1.jar -J--add-modules=ccj -J--add-exports=java.base/sun.security.provider=ccj -J--add-exports=java.base/sun.security.internal.spec=ccj
Note:
To verify the conversion of JKS to BCFKS use the following command: /opt/VRTSsfmcs/webgui/jre/bin/keytool -list -keystore /opt/VRTSsfmcs/webgui/tomcat/cert/.keystore -storepass changeit -storetype BCFKS -providername CCJ -providerpath "/opt/VRTSsfmcs/webgui/jre/lib/ext/ccj-3.0.1.jar" -providerclass com.safelogic.cryptocomply.jcajce.provider.CryptoComplyFipsProvider
- Restart Arctera InfoScale Operations Manager web server using the following command:/opt/VRTSsfmcs/bin/vomsc --restart web
To enable FIPS mode on Arctera InfoScale Operations Manager Agents running on Linux, Solaris, AIX
- Open Arctera InfoScale Operations Manager Management Server in a browser.
- Add Linux, Solaris, or AIX Agents having Arctera InfoScale Operations Manager version 8.0, 8.0.2 to Arctera InfoScale Operations Manager Management Server.
The FIPS mode can be enabled only on Agents running on Linux, Solaris, or AIX having Arctera InfoScale Operations Manager version 8.0 and 8.0.2
Note:
In this release, agents that are running on other operating systems cannot be configured in FIPS mode.