Linux Deployment Guide. How to deploy Network Shutdown Module for Linux
|
|
|
- Leonard Lamb
- 10 years ago
- Views:
Transcription
1 Linux Deployment Guide How to deploy Network Shutdown Module for Linux
2 1 Contents 2 Introduction To Prepare your System for Install RedHat 5.9 i386 Command RedHat 5.9 x86_64 Command RedHat 6.4 i686 Command RedHat 6.4 x86_64 Command SuSE 11 SP3 x86_64 Command Known Issues Installation and Removal Issues Kdesu not found on path Glib Errors/ Warnings Close and Cancel buttons remain enabled during file installation Installer accepts a blank or root folder path PHP Issues PHP Multiple Vulnerabilities Phpinfo.php Information Disclosure Lighttpd Issues Lighttpd Multiple Vulnerabilities Secure Socket Layer (SSL) Issues SSL Certificate Cannot Be Trusted Check for SSL Weak Ciphers Application Issues The Upgrade Check reports that the Upgrade URL is Unreachable Shutdown Delays are not respected Workarounds Turn Off the Web Server Stop Network Shutdown Module Create a Service Configuration File Replace the Service Startup Script Restart the NSM Service(s)
3 5.2 Replace the HTTPS Certificate Generate a Private Key Create an OpenSSL configuration file Generate a Certificate Signing Request Purchase a Valid SSL Certificate Configure Lighttpd to use the new Certificate
4 2 Introduction This document discusses how to install the Schneider Electric Network Shutdown Module, version 3.06 on to modern Linux operating systems. It also discusses known issues and how to address them. 3 To Prepare your System for Install Network Shutdown Module requires a few pre-requisites before installation can be attempted; these are given in Table 1. These packages are available to install through your operating system package manager. In order to ensure these packages are available to you, you may need to register your system with your OS vendor. See your Operating System documentation for details on receiving updated packages. Depending on your system configuration, your package manager may install additional packages to satisfy the dependencies of these packages. Once these packages have been installed, Network Shutdown Module can be installed using the procedure documented in the User Guide. Table 1 - Prerequisite Packages Operating System Architecture Required Packages RedHat 5.9 i386 compat-libstdc++-33 RedHat 5.9 x86_64 compat-libstdc++-33.i386 RedHat 6.4 i386 glibc gtk2 compat-libstdc++-33 libxml2 nss-softokn-freebl RedHat 6.4 x86_64 glibc.i686 gtk2.i686 compat-libstdc++-33.i686 libxml2.i686 nss-softokn-freebl.i686 SUSE 11 SP3 i386 None SUSE 11 SP3 x86_64 libstdc bit 3.1 RedHat 5.9 i386 Command From the console as root, issue the following: yum install compat-libstdc RedHat 5.9 x86_64 Command From the console as root, issue the following: yum install compat-libstdc++-33.i RedHat 6.4 i686 Command From the console as root, issue the following: 4
5 yum install glibc gtk2 compat-libstdc++-33 libxml2 nss-softokn-freebl 3.4 RedHat 6.4 x86_64 Command From the console as root, issue the following: yum install glibc.i686 gtk2.i686 compat-libstdc++-33.i686 libxml2.i686 nss-softokn-freebl.i SuSE 11 SP3 x86_64 Command From the console as root, issue the following: zipper install libstdc bit 4 Known Issues 4.1 Installation and Removal Issues Kdesu not found on path Problem: When running the installer or uninstaller as a user, the following output is produced: which: no kdesu in (/home/bunsen/bin:/usr/local/bin:/usr/bin:/bin:/usr/bin/x11:/usr/x11r6/bin:/usr/games:/usr/ lib/mit/bin:/usr/lib/mit/sbin) which: invalid option -- 'c' Fix: These warnings can be safely ignored. Problem: Running the uninstaller on SUSE Linux as a regular user prompts for the administrator password. Then the uninstaller fails to execute. Fix: Run the uninstaller as the root user. Use sudo su or log in as root before attempting to execute the nsminstaller uninstall command Glib Errors/ Warnings Problem: When running the installer or uninstaller as the root user, output similar to the following is produced: (nsm_linux_3_06_04.run:26443): GLib-GObject-WARNING **: instance of invalid noninstantiatable type `(null)' (nsm_linux_3_06_04.run:26443): GLib-GObject-CRITICAL **: g_signal_handlers_disconnect_matched: assertion `G_TYPE_CHECK_INSTANCE (instance)' failed... other lines omitted. Fix: These warnings can be safely ignored. 5
6 4.1.3 Close and Cancel buttons remain enabled during file installation. Problem: The Close (x) and Cancel buttons remain enabled during the installation wizard as it copies files to the install path. Clicking on either of these will result in the installer aborting, before all files have been installed. This can result in failures of the uninstall process in cleanly removing all Network Shutdown Module related files. Fix: Avoid clicking either the close or cancel button as files are being copied. Allow the installer to complete before attempting software removal Installer accepts a blank or root folder path. Problem: The Network Shutdown Module will accept a blank install path, or a path consisting of the root directory. In both cases the installation path will be set to the root folder. Installation will proceed successfully. On uninstall, there is a risk of deleting system files unrelated to Network Shutdown Module, as the uninstaller attempts to delete all files and subdirectories under the installation path. Fix: Ensure a subdirectory path is specified for Network Shutdown Module. 4.2 PHP Issues Network Shutdown Module 3.06 uses PHP PHP Multiple Vulnerabilities Network Shutdown Module uses a version of PHP that is affected by multiple flaws: PHP is no longer actively supported by the PHP project. PHP versions earlier than are affected by multiple flaws. Multiple Cross Site Scripting Vulnerabilities. Multiple Cookie Injection Scripting Vulnerabilities. Multiple HTML Injection Vulnerabilities Multiple Cross Site Request Forgery Vulnerabilities. Fix: Restrict access to the application. Once configuration has been completed, turn off the web server, as outlined in section Phpinfo.php Information Disclosure Problem: The following file calls the function phpinfo() which discloses potentially sensitive information to a remote attacker:../mge/networkshutdownmodule/www/phpinfo.php Fix: This file can safely be deleted. 4.3 Lighttpd Issues Network Shutdown Module 3.06 uses Lighttpd as its web server. 6
7 4.3.1 Lighttpd Multiple Vulnerabilities Network Shutdown Module uses a version of Lighttpd that is affected by multiple flaws: Lighttpd mod_userdir case sensitive comparison security bypass vulnerability. Lighttpd trailing slash information disclosure. Lighttpd slow request handling remote denial of service vulnerability. Fix: Once configuration has been completed, turn off the web server, as outlined in section Secure Socket Layer (SSL) Issues Network Shutdown Module 3.06 uses OpenSSL 0.9.7e to provide encryption services SSL Certificate Cannot Be Trusted Problem: Network Shutdown Module installs a self-signed certificate. Self signed certificates can provide encryption for HTTPS traffic, but cannot be used to verify the authenticity of the remote host, so are open to man in the middle attacks. Fix: Replace the default certificate with a trusted certificate, as outlined in section Check for SSL Weak Ciphers Problem: Network Shutdown Module supports the following relatively weak ciphers: SSL2_RC4_128_EXPORT40_WITH_MD5 : SSL_EXPORT SSL2_RC2_CBC_128_CBC_EXPORT40_WITH_MD5 : SSL_EXPORT SSL3_RSA_EXPORT1024_WITH_RC4_56_MD5 : SSL_EXPORT SSL3_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5 : SSL_EXPORT SSL3_RSA_EXPORT1024_WITH_DES_CBC_SHA : SSL_EXPORT TLS1_RSA_EXPORT1024_WITH_RC4_56_MD5 : SSL_EXPORT TLS1_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5 : SSL_EXPORT TLS1_RSA_EXPORT1024_WITH_DES_CBC_SHA : SSL_EXPORT Fix: Once configuration has been completed, turn off the web server, as outlined in section Application Issues The Upgrade Check reports that the Upgrade URL is Unreachable. Problem: The Network Shutdown Module upgrade check page reports that the Upgrade URL is unreachable. Fix: Edit the <install path>/www/libs/upgrade.inc PHP file, and replace line 26 with: $autoupgradecheckversionurl = " Refreshing the Upgrade Check page should show if an upgrade is available. 7
8 4.5.2 Shutdown Delays are not respected. Problem: The Shutdown After and Shutdown Duration values specified in the Central Shutdown Configuration of the Network Management Card are not respected by the Network Shutdown Module. For example, specifying a Shutdown After value of 3 minutes, one would expect when Utility Failure occurs, it must persist for at least 3 minutes before the attached Network Shutdown Module would begin the shutdown procedure. For Network Shutdown Module 3.06, an issue exists where these values are not respected, and shutdown will occur immediately after the UPS event occurs. There is no fix or workaround available at this time. 5 Workarounds 5.1 Turn Off the Web Server To allow the Network Shutdown Module Web Server to be enabled or disabled separately, use the procedure documented in the following subsections. Please Note: When the web server is stopped, the system tray icon will not receive updates, and will show the status, localhost: unreachable. This can safely be ignored. The system tray icon will begin receiving updates the next time the web server is enabled Stop Network Shutdown Module As the root user, issue the following command: # service mge-nsm stop Create a Service Configuration File Create a configuration file called /etc/nsm3.conf with the following contents: # Service Configuration for Network Shutdown Module 3.06 # The Network Shutdown Module Web Server is responsible for presenting the user # interface. Disabling the web server will prevent configuration changes to # Network Shutdown Module. # # To disable the web server, comment this line, or set to false. ENABLE_WEBSERVER=true #!!! WARNING!!! # The Data Acquisition Engine (DAE) monitors the UPS status and initiates shut # down based on the events configured at the user interface. Disabling the DAE 8
9 # will leave your server unprotected. # # To disable the Data Acquisition Engine, comment this line, or set to false. ENABLE_DAE=true This configuration enables both the Web Server and the Data Acquisition Engine. To disable a service, comment the line by placing a hash ( # ) in front of it, or set the value from true to false Replace the Service Startup Script. Replace the /etc/init.d/mge-nsm script, with the following contents: #! /bin/sh ################################################################################ # LSB compatible init script for the MGE UPS SYSTEMS - Network Shutdown Module # ################################################################################ ### BEGIN INIT INFO # Provides: mge-nsm # Required-Start: $network # Should-Start: # Required-Stop: # Should-Stop: # Default-Start: 3 5 # Default-Stop: # Short-Description: MGE UPS Systems - Network Shutdown Module # Description: Network Shutdown Module provide power # protection to your computer ### END INIT INFO set -e source /etc/nsm3.conf DESC="Network Shutdown Module" MGE_NSM_HOME="`cat /etc/nsm3_path`" 9
10 WEBSVR_PID_PATH="${MGE_NSM_HOME}/bin/webserver/logs/lighttpd.pid" DAE_PID_PATH="${MGE_NSM_HOME}/bin/dae/mgeDAE.pid" # Update the needed environment variables LD_LIBRARY_PATH=$MGE_NSM_HOME/lib:$MGE_NSM_HOME/bin/webserver/bin:$LD_LIBRARY_PATH export LD_LIBRARY_PATH MGE_NSM_HOME daemon_start() { if [! -z ${MGE_NSM_HOME} ]; then if [ "$ENABLE_WEBSERVER" = "true" ]; then # Start the webserver cd ${MGE_NSM_HOME}/bin/webserver/bin./lighttpd -f../conf/lighttpd.conf -m./ fi if [ "$ENABLE_DAE" = "true" ]; then # Start the Data Acquisition Engine cd ${MGE_NSM_HOME}/bin/dae./mgeDAE -start fi fi } daemon_stop() { # Stop the webserver [ -f ${WEBSVR_PID_PATH} ] && kill `cat ${WEBSVR_PID_PATH}` 2>/dev/null # Stop the Data Acquisition Engine cd ${MGE_NSM_HOME}/bin/dae./mgeDAE -stop 10
11 # workaround for hard stop # sleep 2 && killall -9 mgedae 2>&1 1>/dev/null } case "$1" in start) # echo "Starting $DESC." daemon_start ;; stop) # echo "Stopping $DESC." daemon_stop ;; restart) # echo "Restarting $DESC." daemon_stop sleep 2 daemon_start ;; *) echo "$DESC:" echo "Usage: $0 {start stop restart}" >&2 exit 3 ;; esac exit Restart the NSM Service(s) Issue the following command: # service mge-nsm start Depending on the configuration given in the /etc/nsm3.conf, the new startup script will selectively start the enabled services. 11
12 5.2 Replace the HTTPS Certificate To replace the self-signed certificate with one signed by a trusted Certificate Authority, use the following procedure. In this process we will use the following file names for the various files needed (you may change these as you wish): server.key: A private key file. server.csr: A certificate signing request file. server.crt: The web server certificate file. intermediate.crt: The CA provided intermediate certificate trust path Generate a Private Key. Begin by creating a private key file, using openssl as shown here: # openssl genrsa -out server.key 2048 Generating RSA private key, 2048 bit long modulus e is (0x01001) Create an OpenSSL configuration file. Save the following to a file called openssl.cnf. Replace values in braces with values appropriate to your location and server. [req] default_bits=2048 default_keyfile=server.key distinguished_name=req_distinguished_name prompt=no [req_distinguished_name] C={ISO3166 two character country code} ST={state or province} L={Locality; generally city} O={Organisation Company Name} OU={Organisation Unit typically certificate type or brand} CN={Common Name typically the fully qualified local host name} 12
13 address={optional address, remove this line if unused} Generate a Certificate Signing Request. Create a certificate Signing Request (server.csr) file using openssl as shown here: # openssl req new key server.key out server.csr config openssl.cnf No output is given unless an error occurs. All going well, the server.csr file will be created based on the values given in the openssl.cnf file Purchase a Valid SSL Certificate Details may vary here as you interact with your trusted Certificate Authority and how they produce certificates. Typically they will ask for the contents of the server.csr file and using this they will produce a server certificate (server.crt) file for you. Save this file to the server host. When asked which type of certificate to produce, choose that which is appropriate for ApacheSSL/mod_ssl, which Network Shutdown Module is compatible with. Your Certificate Authority will also make available an intermediate CA bundle, which contains any root and intermediate certificates needed to authenticate your new certificate. Save this file also to the server host, (e.g. intermediate.crt) Configure Lighttpd to use the new Certificate. Copy the server.key, server.crt, and intermediate.crt files to /usr/local/mge/networkshutdownmodule/bin/webserver/bin, or to your custom install path. Concatenate the server.key and newly created server.crt file together (the order is not important). # cat server.key server.crt > server.pem For added security, change the owner and permissions for these files to root: # chown root:root *.pem *.key *.csr *.crt # chmod 600 *.pem *.key *.csr *.crt Edit /usr/local/mge/networkshutdownmodule/bin/webserver/conf/lighttpd.conf and modify the HTTPS configuration as follows: $SERVER[ socket ] == :4680 { } ssl.engine = enable ssl.pemfile = server.pem ssl.ca-file = intermediate.crt Save this file and restart the web server for settings to take effect: 13
14 # /etc/init.d/mge-nsm restart Using a browser to connect to the Network Shutdown Module user interface over https on port 4680, will present the new Certificate Authority signed SSL certificate. ** End of Document ** 14
Domino and Internet. Security. IBM Collaboration Solutions. Ask the Experts 12/16/2014
Domino and Internet Ask the Experts 12/16/2014 Security IBM Collaboration Solutions Agenda Overview of internet encryption technology Domino's implementation of encryption Demonstration of enabling an
Application Note AN1502
Application Note AN1502 Generate SSL Certificates PowerPanel Business Edition User s Manual Rev. 1 2015/08/21 Rev. 13 2013/07/26 Content Generating SSL Certificates Overview... 3 Obtain a SSL Certificate
SecuritySpy Setting Up SecuritySpy Over SSL
SecuritySpy Setting Up SecuritySpy Over SSL Secure Sockets Layer (SSL) is a cryptographic protocol that provides secure communications on the internet. It uses two keys to encrypt data: a public key and
Sun Java System Web Server 6.1 Using Self-Signed OpenSSL Certificate. Brent Wagner, Seeds of Genius October 2007
Sun Java System Web Server 6.1 Using Self-Signed OpenSSL Certificate Brent Wagner, Seeds of Genius October 2007 Edition: 1.0 October 2007 All rights reserved. This product or document is protected by copyright
Exercises: FreeBSD: Apache and SSL: SANOG VI IP Services Workshop
Exercises Exercises: FreeBSD: Apache and SSL: SANOG VI IP Services Workshop July 18, 2005 1. 2. 3. 4. 5. Install Apache with SSL support Configure Apache to start at boot Verify that http and https (Apache)
Security Workshop. Apache + SSL exercises in Ubuntu. 1 Install apache2 and enable SSL 2. 2 Generate a Local Certificate 2
Security Workshop Apache + SSL exercises in Ubuntu Contents 1 Install apache2 and enable SSL 2 2 Generate a Local Certificate 2 3 Configure Apache to use the new certificate 4 4 Verify that http and https
EventTracker Windows syslog User Guide
EventTracker Windows syslog User Guide Publication Date: September 16, 2011 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com Introduction This document is prepared to help user(s)
Enterprise SSL Support
01 Enterprise SSL Support This document describes the setup of SSL (Secure Sockets Layer) over HTTP for Enterprise clients, servers and integrations. 1. Overview Since the release of Enterprise version
Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0
Technical Note Replacing vcenter Server 4.0 Certificates VMware vsphere 4.0 Certificates are automatically generated when you install vcenter Server and ESX/ESXi. These default certificates are not signed
Browser-based Support Console
TECHNICAL PAPER Browser-based Support Console Mass deployment of certificate Netop develops and sells software solutions that enable swift, secure and seamless transfer of video, screens, sounds and data
INSTALL ZENTYAL SERVER
GUIDE FOR Zentyal Server is a small business server based on Ubuntu s LTS server version 10.04 and the ebox platform. It also has the LXDE desktop installed with Firefox web browser and PCMAN File manager.
Encrypted Connections
EMu Documentation Encrypted Connections Document Version 1 EMu Version 4.0.03 www.kesoftware.com 2010 KE Software. All rights reserved. Contents SECTION 1 Encrypted Connections 1 How it works 2 Requirements
Replacing VirtualCenter Server Certificates VMware Infrastructure 3
Technical Note Replacing VirtualCenter Server Certificates VMware Infrastructure 3 This technical note provides information about replacing the default certificates supplied with VirtualCenter Server hosts.
SWITCHBOARD SECURITY
SSLCer t i fic at e Cr eat i on SWITCHBOARD SECURITY The Switchvox Switchboard uses https which is more secure than http. https requires a security certificate to be installed or for each user to allow
Scenarios for Setting Up SSL Certificates for View
Scenarios for Setting Up SSL Certificates for View VMware Horizon 6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a
HOWTO. Configure Nginx for SSL with DoD CAC Authentication on CentOS 6.3. Joshua Penton Geocent, LLC [email protected].
HOWTO Configure Nginx for SSL with DoD CAC Authentication on CentOS 6.3 Joshua Penton Geocent, LLC [email protected] March 2013 Table of Contents Overview... 1 Prerequisites... 2 Install OpenSSL...
Red Hat Linux Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate
Red Hat Linux Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate Copyright. All rights reserved. Trustis Limited Building 273 New Greenham Park Greenham Common Thatcham
MassTransit 6.0 Enterprise Web Configuration for Macintosh OS 10.5 Server
MassTransit 6.0 Enterprise Web Configuration for Macintosh OS 10.5 Server November 6, 2008 Group Logic, Inc. 1100 North Glebe Road, Suite 800 Arlington, VA 22201 Phone: 703-528-1555 Fax: 703-528-3296 E-mail:
Obtaining SSL Certificates for VMware Horizon View Servers
Obtaining SSL Certificates for VMware Horizon View Servers View 5.2 View Composer 5.2 This document supports the version of each product listed and supports all subsequent versions until the document is
NSi Mobile Installation Guide. Version 6.2
NSi Mobile Installation Guide Version 6.2 Revision History Version Date 1.0 October 2, 2012 2.0 September 18, 2013 2 CONTENTS TABLE OF CONTENTS PREFACE... 5 Purpose of this Document... 5 Version Compatibility...
Apache, SSL and Digital Signatures Using FreeBSD
Apache, SSL and Digital Signatures Using FreeBSD AfNOG 2007 Unix System Administration April 26, 2007 Hervey Allen Network Startup Resource Center Some SSL background Invented by Netscape for secure commerce.
Online Backup Client User Manual Linux
Online Backup Client User Manual Linux 1. Product Information Product: Online Backup Client for Linux Version: 4.1.7 1.1 System Requirements Operating System Linux (RedHat, SuSE, Debian and Debian based
LoadMaster SSL Certificate Quickstart Guide
LoadMaster SSL Certificate Quickstart Guide for the LM-1500, LM-2460, LM-2860, LM-3620, SM-1020 This guide serves as a complement to the LoadMaster documentation, and is not a replacement for the full
Creating and Managing Certificates for My webmethods Server. Version 8.2 and Later
Creating and Managing Certificates for My webmethods Server Version 8.2 and Later November 2011 Contents Introduction...4 Scope... 4 Assumptions... 4 Terminology... 4 File Formats... 5 Truststore Formats...
Cloud Services. Introduction...2 Overview...2. Security considerations... 2. Installation...3 Server Configuration...4
Contents Introduction...2 Overview...2 Security considerations... 2 Installation...3 Server Configuration...4 Management Client Connection...4 General Settings... 4 Enterprise Architect Client Connection
SSL Interception on Proxy SG
SSL Interception on Proxy SG Proxy SG allows for interception of HTTPS traffic for Content Filtering and Anti Virus, and for Application Acceleration. This document describes how to setup a demonstration
Managing the SSL Certificate for the ESRS HTTPS Listener Service Technical Notes P/N 300-011-843 REV A01 January 14, 2011
Managing the SSL Certificate for the ESRS HTTPS Listener Service Technical Notes P/N 300-011-843 REV A01 January 14, 2011 This document contains information on these topics: Introduction... 2 Terminology...
Generating and Installing SSL Certificates on the Cisco ISA500
Application Note Generating and Installing SSL Certificates on the Cisco ISA500 This application note describes how to generate and install SSL certificates on the Cisco ISA500 security appliance. It includes
1. Product Information
ORIXCLOUD BACKUP CLIENT USER MANUAL LINUX 1. Product Information Product: Orixcloud Backup Client for Linux Version: 4.1.7 1.1 System Requirements Linux (RedHat, SuSE, Debian and Debian based systems such
Network-Enabled Devices, AOS v.5.x.x. Content and Purpose of This Guide...1 User Management...2 Types of user accounts2
Contents Introduction--1 Content and Purpose of This Guide...........................1 User Management.........................................2 Types of user accounts2 Security--3 Security Features.........................................3
Obtaining SSL Certificates for VMware View Servers
Obtaining SSL Certificates for VMware View Servers View 5.1 View Composer 3.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Installing Dspace 1.8 on Ubuntu 12.04
Installing Dspace 1.8 on Ubuntu 12.04 This is an abridged version of the dspace 1.8 installation guide, specifically targeted at getting a basic server running from scratch using Ubuntu. More information
How To Run A Password Manager On A 32 Bit Computer (For 64 Bit) On A 64 Bit Computer With A Password Logger (For 32 Bit) (For Linux) ( For 64 Bit (Foramd64) (Amd64 (For Pc
SafeNet Authentication Client (Linux) Administrator s Guide Version 8.1 Revision A Copyright 2011, SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document
CHAPTER 7 SSL CONFIGURATION AND TESTING
CHAPTER 7 SSL CONFIGURATION AND TESTING 7.1 Configuration and Testing of SSL Nowadays, it s very big challenge to handle the enterprise applications as they are much complex and it is a very sensitive
Laboratory Exercises VI: SSL/TLS - Configuring Apache Server
University of Split, FESB, Croatia Laboratory Exercises VI: SSL/TLS - Configuring Apache Server Keywords: digital signatures, public-key certificates, managing certificates M. Čagalj, T. Perković {mcagalj,
EMC Data Protection Search
EMC Data Protection Search Version 1.0 Security Configuration Guide 302-001-611 REV 01 Copyright 2014-2015 EMC Corporation. All rights reserved. Published in USA. Published April 20, 2015 EMC believes
Apache Security with SSL Using Ubuntu
Apache Security with SSL Using Ubuntu These materials are licensed under the Creative Commons Attribution-Noncommercial 3.0 Unported license (http://creativecommons.org/licenses/by-nc/3.0/) Some SSL background
Protect your CollabNet TeamForge site
1 Protect your CollabNet TeamForge site Set up SELinux If SELinux is active on the machine where your CollabNet TeamForge site is running, modify it to allow the services that TeamForge requires. This
RecoveryVault Express Client User Manual
For Linux distributions Software version 4.1.7 Version 2.0 Disclaimer This document is compiled with the greatest possible care. However, errors might have been introduced caused by human mistakes or by
Spectrum Technology Platform. Version 9.0. Spectrum Spatial Administration Guide
Spectrum Technology Platform Version 9.0 Spectrum Spatial Administration Guide Contents Chapter 1: Introduction...7 Welcome and Overview...8 Chapter 2: Configuring Your System...9 Changing the Default
Secure IIS Web Server with SSL
Secure IIS Web Server with SSL EventTracker v7.x Publication Date: Sep 30, 2014 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com Abstract The purpose of this document is to help
Unifying Information Security. Implementing TLS on the CLEARSWIFT SECURE Email Gateway
Unifying Information Security Implementing TLS on the CLEARSWIFT SECURE Email Gateway Contents 1 Introduction... 3 2 Understanding TLS... 4 3 Clearswift s Application of TLS... 5 3.1 Opportunistic TLS...
LAB :: Secure HTTP traffic using Secure Sockets Layer (SSL) Certificate
LAB :: Secure HTTP traffic using Secure Sockets Layer (SSL) Certificate In this example we are using apnictraining.net as domain name. # super user command. $ normal user command. X replace with your group
Use Enterprise SSO as the Credential Server for Protected Sites
Webthority HOW TO Use Enterprise SSO as the Credential Server for Protected Sites This document describes how to integrate Webthority with Enterprise SSO version 8.0.2 or 8.0.3. Webthority can be configured
SETTING UP RASPBERRY PI FOR TOPPY FTP ACCESS. (Draft 5)
SETTING UP RASPBERRY PI FOR TOPPY FTP ACCESS (Draft 5) 1 INTRODUCTION These notes describe how I set up my Raspberry Pi to allow FTP connection to a Toppy. Text in blue indicates Linux commands or file
CA Performance Center
CA Performance Center Single Sign-On User Guide 2.4 This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred to as the Documentation ) is
2 Downloading Access Manager 3.1 SP4 IR1
Novell Access Manager 3.1 SP4 IR1 Readme May 2012 Novell This Readme describes the Novell Access Manager 3.1 SP4 IR1 release. Section 1, Documentation, on page 1 Section 2, Downloading Access Manager 3.1
Online Backup Linux Client User Manual
Online Backup Linux Client User Manual Software version 4.0.x For Linux distributions August 2011 Version 1.0 Disclaimer This document is compiled with the greatest possible care. However, errors might
Microsoft IIS 4 Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate
Microsoft IIS 4 Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate Copyright. All rights reserved. Trustis Limited Building 273 New Greenham Park Greenham Common Thatcham
>copy openssl.cfg openssl.conf (use the example configuration to create a new configuration)
HowTo - PxPlus SSL This page contains the information/instructions on SSL Certificates for use with PxPlus Secure TCP/IP-based applications such as the PxPlus Web Server, the PxPlus Application Server
Cloud Services. Introduction...2 Overview...2 Simple Setup...2
Contents Introduction...2 Overview...2 Simple Setup...2 Requirements... 3 Installation... 3 Test the connection... 4 Open from another workstation... 5 Security considerations...6 Installation...6 Server
Online Backup Client User Manual
For Linux distributions Software version 4.1.7 Version 2.0 Disclaimer This document is compiled with the greatest possible care. However, errors might have been introduced caused by human mistakes or by
NETASQ SSO Agent Installation and deployment
NETASQ SSO Agent Installation and deployment Document version: 1.3 Reference: naentno_sso_agent Page 1 / 20 Copyright NETASQ 2013 General information 3 Principle 3 Requirements 3 Active Directory user
Setup Guide Access Manager 3.2 SP3
Setup Guide Access Manager 3.2 SP3 August 2014 www.netiq.com/documentation Legal Notice THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT ARE FURNISHED UNDER AND ARE SUBJECT TO THE TERMS OF A LICENSE
Creating Certificate Authorities and self-signed SSL certificates
Creating Certificate Authorities and self-signed SSL certificates http://www.tc.umn.edu/-brams006/selfsign.html Creating Certificate Authorities and self-signed SSL certificates Following is a step-by-step
Configuring TLS Security for Cloudera Manager
Configuring TLS Security for Cloudera Manager Cloudera, Inc. 220 Portage Avenue Palo Alto, CA 94306 [email protected] US: 1-888-789-1488 Intl: 1-650-362-0488 www.cloudera.com Notice 2010-2012 Cloudera,
Go to Policy/Global Properties/SmartDashboard Customization, click Configure. In Certificates and PKI properties, change host_certs_key_size to 2048
Checkpoint R71 to R71.3 You will see below that the openssl script uses a 2048 bit key which is correct for most CA's, however the default for R71.x is to provide a 1024 bit key which the script won't
Crypto Lab Public-Key Cryptography and PKI
SEED Labs 1 Crypto Lab Public-Key Cryptography and PKI Copyright c 2006-2014 Wenliang Du, Syracuse University. The development of this document is/was funded by three grants from the US National Science
LAB :: Secure HTTP traffic using Secure Sockets Layer (SSL) Certificate
LAB :: Secure HTTP traffic using Secure Sockets Layer (SSL) Certificate In this example we are using df-h.net as domain name. # super user command. $ normal user command. X replace with your group no.
Cybozu Garoon 3 Server Distributed System Installation Guide Edition 3.1 Cybozu, Inc.
Cybozu Garoon 3 Server Distributed System Installation Guide Edition 3.1 Cybozu, Inc. Preface Preface This guide describes the features and operations of Cybozu Garoon Version 3.1.0. Who Should Use This
Online Backup Client User Manual
Online Backup Client User Manual Software version 3.21 For Linux distributions January 2011 Version 2.0 Disclaimer This document is compiled with the greatest possible care. However, errors might have
User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream
User Manual Onsight Management Suite Version 5.1 Another Innovation by Librestream Doc #: 400075-06 May 2012 Information in this document is subject to change without notice. Reproduction in any manner
User and Reference Manual
User and Reference Manual User & Reference Manual All rights reserved. No parts of this work may be reproduced in any form or by any means - graphic, electronic, or mechanical, including photocopying,
PowerChute TM Network Shutdown Security Features & Deployment
PowerChute TM Network Shutdown Security Features & Deployment By David Grehan, Sarah Jane Hannon ABSTRACT PowerChute TM Network Shutdown (PowerChute) software works in conjunction with the UPS Network
Installing and Configuring vcenter Multi-Hypervisor Manager
Installing and Configuring vcenter Multi-Hypervisor Manager vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.1 This document supports the version of each product listed and supports all subsequent
White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3
White Paper Fabasoft Folio 2015 Update Rollup 3 Copyright Fabasoft R&D GmbH, Linz, Austria, 2016. All rights reserved. All hardware and software names used are registered trade names and/or registered
Oracle Mobile Security Suite Workshop. Installation
Oracle Mobile Security Suite Workshop Installation The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any
DoD Public Key Enablement (PKE) Quick Reference Guide. Securing Apache HTTP with mod_ssl for Linux
DoD Public Key Enablement (PKE) Quick Reference Guide Securing Apache HTTP with mod_ssl for Linux Contact: [email protected] URL: https://www.us.army.mil/suite/page/474113 This guide provides instructions
FERMILAB CENTRAL WEB HOSTING SINGLE SIGN ON (SSO) ON CWS LINUX WITH SAML AND MOD_AUTH_MELLON
FERMILAB CENTRAL WEB HOSTING SINGLE SIGN ON (SSO) ON CWS LINUX WITH SAML AND MOD_AUTH_MELLON Contents Information and Security Contacts:... 3 1. Introduction... 4 2. Installing Module... 4 3. Create Metadata
Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2)
Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2) Hyper-V Manager Hyper-V Server R1, R2 Intelligent Power Protector Main
Self Signed Certificates
TECH NOTE 003 Self Signed Certificates X.509 Certificate Creation Using Easy-Rsa with OpenVPN www.westermo.com page 1 AIM This Tech Note will show how to create X.509 certificates with easy-rsa in OpenVPN
Dell UPS Local Node Manager USER'S GUIDE EXTENSION FOR MICROSOFT VIRTUAL ARCHITECTURES Dellups.com
CHAPTER: Introduction Microsoft virtual architecture: Hyper-V 6.0 Manager Hyper-V Server (R1 & R2) Hyper-V Manager Hyper-V Server R1, Dell UPS Local Node Manager R2 Main Operating System: 2008Enterprise
PMOD Installation on Linux Systems
User's Guide PMOD Installation on Linux Systems Version 3.7 PMOD Technologies Linux Installation The installation for all types of PMOD systems starts with the software extraction from the installation
FirstClass Synchronization Services Install Guide
FirstClass Synchronization Services Install Guide 12.035 Product Released: 2014-11-04 Install Guide Revised: 2014-10-30 Contents 1 Component Information:... 3 2 Install Instructions... 3 2.1 Windows Install
webmethods Certificate Toolkit
Title Page webmethods Certificate Toolkit User s Guide Version 7.1.1 January 2008 webmethods Copyright & Document ID This document applies to webmethods Certificate Toolkit Version 7.1.1 and to all subsequent
Secure Traffic Inspection
Overview, page 1 Legal Disclaimer, page 2 Secure Sockets Layer Certificates, page 3 Filters, page 4 Policy, page 5 Overview When a user connects to a website via HTTPS, the session is encrypted with a
HP OpenView Adapter for SSL Using Radia
HP OpenView Adapter for SSL Using Radia Radia SSL Adapter Guide Software Version: 2.0 for the UNIX and Windows operating systems Manufacturing Part Number: T3424-90064 August 2004 Copyright 2004 Hewlett-Packard
CERTIFICATE-BASED SINGLE SIGN-ON FOR EMC MY DOCUMENTUM FOR MICROSOFT OUTLOOK USING CA SITEMINDER
White Paper CERTIFICATE-BASED SINGLE SIGN-ON FOR EMC MY DOCUMENTUM FOR MICROSOFT OUTLOOK USING CA SITEMINDER Abstract This white paper explains the process of integrating CA SiteMinder with My Documentum
Zend Server Amazon AMI Quick Start Guide
Zend Server Amazon AMI Quick Start Guide By Zend Technologies www.zend.com Disclaimer This is the Quick Start Guide for The Zend Server Zend Server Amazon Machine Image The information in this document
KMIP installation Guide. DataSecure and KeySecure Version 6.1.2. 2012 SafeNet, Inc. 007-012120-001
KMIP installation Guide DataSecure and KeySecure Version 6.1.2 2012 SafeNet, Inc. 007-012120-001 Introduction This guide provides you with the information necessary to configure the KMIP server on the
Kaspersky Security Center Web-Console
Kaspersky Security Center Web-Console User Guide CONTENTS ABOUT THIS GUIDE... 5 In this document... 5 Document conventions... 7 KASPERSKY SECURITY CENTER WEB-CONSOLE... 8 SOFTWARE REQUIREMENTS... 10 APPLICATION
PowerPanel Business Edition Installation Guide
PowerPanel Business Edition Installation Guide For Automatic Transfer Switch Rev. 5 2015/12/2 Table of Contents Introduction... 3 Hardware Installation... 3 Install PowerPanel Business Edition Software...
ez Agent Administrator s Guide
ez Agent Administrator s Guide Copyright This document is protected by the United States copyright laws, and is proprietary to Zscaler Inc. Copying, reproducing, integrating, translating, modifying, enhancing,
Prerequisites and Configuration Guide
Prerequisites and Configuration Guide Informatica Support Console (Version 2.0) Table of Contents Chapter 1: Overview.................................................... 2 Chapter 2: Minimum System Requirements.................................
FileMaker Server 14. FileMaker Server Help
FileMaker Server 14 FileMaker Server Help 2007 2015 FileMaker, Inc. All Rights Reserved. FileMaker, Inc. 5201 Patrick Henry Drive Santa Clara, California 95054 FileMaker and FileMaker Go are trademarks
Avira Update Manager User Manual
Avira Update Manager User Manual Table of contents Table of contents 1. Product information........................................... 4 1.1 Functionality................................................................
MAMP 3 User Guide! March 2014 (c) appsolute GmbH!
MAMP 3 User Guide March 2014 (c) appsolute GmbH 1 I. Installation 3 1. Installation requirements 3 2. Installing and upgrading 3 3. Uninstall 3 II. First Steps 4 III. Preferences 5 Start/Stop 5 2. Ports
Release Notes for Version 1.5.207
Release Notes for Version 1.5.207 Created: March 9, 2015 Table of Contents What s New... 3 Fixes... 3 System Requirements... 3 Stonesoft Appliances... 3 Build Version... 4 Product Binary Checksums... 4
How to Order and Install Odette Certificates. Odette CA Help File and User Manual
How to Order and Install Odette Certificates Odette CA Help File and User Manual 1 Release date 24.02.2014 Contents Preparation for Ordering an Odette Certificate... 3 Step 1: Prepare the information you
Installation and Administration Guide
www.novell.com/documentation Installation and Administration Guide Novell Kanaka for Mac Version 2.8.2 November 3, 2015 Legal Notices Condrey Corporation makes no representations or warranties with respect
ViMP 3.0. SSL Configuration in Apache 2.2. Author: ViMP GmbH
ViMP 3.0 SSL Configuration in Apache 2.2 Author: ViMP GmbH Table of Contents Requirements...3 Create your own certificates with OpenSSL...4 Generate a self-signed certificate...4 Generate a certificate
Online Backup Client User Manual Mac OS
Online Backup Client User Manual Mac OS 1. Product Information Product: Online Backup Client for Mac OS X Version: 4.1.7 1.1 System Requirements Operating System Mac OS X Leopard (10.5.0 and higher) (PPC
Online Backup Client User Manual Mac OS
Online Backup Client User Manual Mac OS 1. Product Information Product: Online Backup Client for Mac OS X Version: 4.1.7 1.1 System Requirements Operating System Mac OS X Leopard (10.5.0 and higher) (PPC
STEP 4 : GETTING LIGHTTPD TO WORK ON YOUR SEAGATE GOFLEX SATELLITE
STEP 4 : GETTING LIGHTTPD TO WORK ON YOUR SEAGATE GOFLEX SATELLITE Note : Command Lines are in red. Congratulations on following all 3 steps. This is the final step you need to do to get rid of the old
How to Order and Install Odette Certificates. Odette CA Help File and User Manual
How to Order and Install Odette Certificates Odette CA Help File and User Manual 1 Release date 28.07.2014 Contents Preparation for Ordering an Odette Certificate... 3 Step 1: Prepare the information you
Novell Sentinel Log Manager 1.2 Release Notes. 1 What s New. 1.1 Enhancements to Licenses. Novell. February 2011
Novell Sentinel Log Manager 1.2 Release Notes February 2011 Novell Novell Sentinel Log Manager collects data from a wide variety of devices and applications, including intrusion detection systems, firewalls,
Secure Messaging Server Console... 2
Secure Messaging Server Console... 2 Upgrading your PEN Server Console:... 2 Server Console Installation Guide... 2 Prerequisites:... 2 General preparation:... 2 Installing the Server Console... 2 Activating
Installing and Configuring vcloud Connector
Installing and Configuring vcloud Connector vcloud Connector 2.7.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Setting Up SSL on IIS6 for MEGA Advisor
Setting Up SSL on IIS6 for MEGA Advisor Revised: July 5, 2012 Created: February 1, 2008 Author: Melinda BODROGI CONTENTS Contents... 2 Principle... 3 Requirements... 4 Install the certification authority
HP ProLiant Essentials Vulnerability and Patch Management Pack Release Notes
HP ProLiant Essentials Vulnerability and Patch Management Pack Release Notes Supported platforms... 2 What s new in version 2.1... 2 What s new in version 2.0.3... 2 What s new in version 2.0.2... 2 What
