Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP Application Discovery Getting Started Guide Version 3.0.00 > Chapter 2 Configuring Components

Complete Certificate Exchange

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

Application Discovery uses Secure Sockets Layer (SSL) certificates to authenticate and secure data transmission between Application Discovery agents and the Application Discovery server. Once Application Discovery components are installed, the accompanying certificate information for Application Discovery server and for Application Discovery agent must be exchanged to allow the server and agents to recognize legitimate transmissions.

The Application Discovery server automatically attempts to exchange certificates with a managed system when Application Discovery agent is started with the following command:

Using HP SIM to Complete Certificate Exchange

  1. Initiate certificate exchange by selecting Configure ->Configure VSE Agents->Exchange AD Agent Certificates from the HP SIM top menu.

  2. Select the HP-UX systems where you want the exchange to occur using the HP SIM system selection list. Click Apply.

  3. Verify the system selection and click Next.

  4. A description is displayed of the action about to take place. When you are sure that you want to exchange certificates so that the Application Discovery agent can begin reporting data to the server, click Run now to complete the certificate exchange.

NOTE: If you find that you are unable to exchange certificates from within HP SIM, check the following:
  • That you have the correct permissions associated with your login ID.

  • That the targeted managed node is authorized to accept remote commands from HP SIM.

    To set the correct SSH configuration that authorizes the acceptance of remote commands, type the following command on the CMS:

    mxagentconfig -a -n managed_system -u login -p password
    

    where managed_system is the name of the target system for which you want to enable remote communication, login is the user name on the managed system, and password is the password of that user on the managed system.

Completing Certificate Exchange from the Command Line

From the command line, you can exchange certificates with one or more managed hosts.

  1. Log in as root on the system hosting the CMS.

  2. Enter the following command:

    amgr_remote_config -a -n system_name -u root

    To configure multiple hosts, add -n system_name for each host to be configured.

    By default, amgr_remote_config uses Secure Shell (SSH) to complete this action securely across the network.

  3. You might be prompted to provide a password for the specified user (root) for each system login. You must supply the password in order to proceed.

    Once the login is accomplished, the CMS sends its SSL certificate to the agent on the managed host, and the agent supplies its SSL certificate to the CMS. Application Discovery agents can now transfer data securely to the CMS, and the CMS can authenticate the transmission.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2006-2007 Hewlett-Packard Development Company, L.P.