Page History
...
The server installation CLI described above, assumes it can use non-secured protocols such as telnet, and can transfer the communication encryption key as clear text over the network. If this is a problem, you can install the server using a secure CLI. The secured installation uses existing security protocols and methods such as blowfish and SSH to ensure that the communication encryption keys are safely copied to the target server. It’s possible that the secured server installation might require more manual action items than non-secure server CLI installation. You can use one of the following methods to perform secured server installation:• Remote
- Remote Automatic mode
...
- Local mode
Remote Automatic mode
This mode may be used only if the target server is a UNIX server that runs SSH (secured shell).1. Prepare
- Prepare the server parameters file and save it to the
...
- <precise_
...
- root> folder on the main Precise FocalPoint.
For more information, see Table 2-8 on page 22. Mandatory parameters for this installation method are:
server-machine-secured-protocol-server-name true server-machine-install-encrypted-password-server-name
server-machine-installation-folder-server-name
server-machine-flavor-server-name
server-machine-install-user-server-name
You must not supply:
server-machine-security-clear-password-server-name
...
- On the main Precise FocalPoint, run the following command from
...
- <precise_
...
- root> folder:
Windows
...
- infra\bin\psin_cli.bat
-i3-user <user_name>
{-i3-encrypted-password
...
- <encrypted_
...
- password> | -i3-clear-password
...
- <clear_
...
- password>}
-action setup
-parametersfile <server_parameters_file_path>
UNIX ./infra/bin/psin_cli.sh
-i3-user <user_name>
{-i3-encrypted-password
...
- <encrypted_
...
- password> | -i3-clear-password
...
- <clear_
...
- password>}
-action setup
-parametersfile <server_parameters_file_path>
...
Info |
---|
Precise supports most of the common SSH for UNIX. If you are unable to install using the automatic mode, try the Local mode below. |
Local mode
Use this mode for Windows server or when your server does not have SSH installed.1. Prepare
- Prepare server parameters file. For more information, see Table 2-8 on page 22.
Mandatory parameters for this installation are:
server-machine-secured-protocol-server-name true
...
On the main Precise FocalPoint server, run the following command from the
...
<precise_
...
root> folder:
Windows
...
infra\bin\psin_cli.bat
-i3-user <user_name>
{-i3-encrypted-password
...
<encrypted_
...
password> | -i3-clear-password
...
<clear_
...
password>}
-action secure-crypt-keys
-ba-secure-clear-password
...
<security_
...
password>
UNIX ./infra/bin/psin_cli.sh
-i3-user <user_name>
{-i3-encrypted-password
...
<encrypted_
...
password> | -i3-clear-password
...
<clear_
...
password>}
-action secure-crypt-keys
-ba-secure-clear-password
...
<security_
...
password>
The command will generate a key file on the Precise FocalPoint server, under the products/i3fp/security/keys/ folder.
Table 2-
...
9 Local mode
...
Element Descriptions i3-
...
user See Authenticate to CLI Utility on page 8. i3-encrypted-
...
password See Authenticate to CLI Utility on page 8.
...
action always secure-crypt-keys
Mandatory: Yes
ba-secure-encrypted-
...
password Password used to encrypt the communication key, up to 8 characters.
Mandatory: Yes
Alternatively the i3clear-
...
password can be used, allowing you to specify a clear password instead of an encrypted string.
...
- Copy and extract the server packages on the target server as specified in Installing Servers.
...
- Copy key file from:
products/i3fp/security/keys/keys
...
/xml
on the main Precise FocalPoint to the target server, to the./infra
folder.
...
- On the target server, run the following command from the
...
- <precise_
...
- root > folder:
Windows
...
- infra\bin\psin_infra.exe
-manual-extricate-crypt
...
- <security_
...
- password>
...
- UNIX .
...
- /infra/bin/psin_infra
-manual-extricate-crypt
...
- <security_
...
- password>
The command will extricate the security keys on the target server.
...
- On the target server, run the following command from the
...
- <precise_
...
- root> folder. For more information, see Installing Servers.
Windows
...
- infra\bin\psin_cli.bat
-i3-user <user
...
- _
...
- name>
{-i3-encrypted-password
...
- <encrypted_
...
- password> | -i3-clear-password
...
- <clear_
...
- password>}
-action setup-server
-parametersfile <server_parameters_file_path>
UNIX ./infra/bin/psin_cli.sh
-i3-user
...
- <user_
...
- name>
{-i3-encrypted-password
...
- <encrypted_
...
- password> | -i3-clear-password
...
- <clear_
...
- password>}
-action setup-server
-parametersfile <server_parameters_file_path>
Anchor | ||||
---|---|---|---|---|
|
To update the user authentication of your Precise Windows services, fill in the following authentication parameters and then run the server setup installation in edit mode.
server-machine-service-authentication-mode-server-name
server-machine-service-authentication-domain-server-name
server-machine-service-authentication-user-server-name
server-machine-service-authentication-encrypted-password-server-name
For parameter details, see Table 2-10 on page 28.
...