Top
ServerView Resource Orchestrator Cloud Edition V3.4.0 Reference Guide (Command/XML)
FUJITSU Software

5.4 rcxadm authctl

Name

[Windows Manager]
Installation_folder\SVROR\Manager\bin\rcxadm authctl - user authentication directory service connection settings

[Linux Manager]
/opt/FJSVrcvmr/bin/rcxadm authctl - user authentication directory service connection settings


Format

rcxadm authctl register {-host hostname|-ip ip_address} [-port port] -base base_dn -bind bind_dn [-method {SSL|PLAIN}] {-passwd password|-passwd_file password_file} [-auth {serverview|ldap}]
rcxadm authctl unregister
rcxadm authctl show
rcxadm authctl modify {-host hostname|-ip ip_address} [-port port] -base base_dn -bind bind_dn [-method {SSL|PLAIN}] {-passwd password|-passwd_file password_file} [-auth {serverview|ldap}]
rcxadm authctl export
rcxadm authctl diffcert
rcxadm authctl refreshcert -alias alias
rcxadm authctl sync

Description

rcxadm authctl is the command to operate the connection information of the directory server that retains user authentication information.

Only OS administrators can execute this command.

When using the following subcommands, stop the manager prior to command execution:

Subcommands

register

Registers directory server connection information with Resource Orchestrator.
When directory server connection information is registered, user authentication is performed in the directory service. When executing this command, the directory server is not connected.
This command cannot be used when multiple sets of directory server connection information are registered.

unregister

Deletes the connection information of directory servers registered with Resource Orchestrator. User information registered in the directory server is not deleted; the connection information is only deleted from Resource Orchestrator.
This command cannot be used when multiple sets of directory server connection information are registered.

modify

Modifies the connection information of directory servers registered with Resource Orchestrator.
This command cannot be used when multiple sets of directory server connection information are registered.

show

The registered directory server connection information is displayed in the following format.

host1: Host name or IP address
host2: Host name or IP address
port: Port_number
base: base_dn
bind: Administrative_user_DN
method: Encryption_communication_method
auth: Authentication_method

When directory server connection information for only one server is registered, only one host name (or IP address) is displayed.

export

Migrates the information from a directory server used with Resource Orchestrator V2.3.0, to the management information of Resource Orchestrator.

When user information is being managed using a directory service or Single Sign-On is performed with Resource Orchestrator V2.3.0, this task must be done before migration.

Migrate the following information to the management information:

  • User group information and the users belonging to it

  • Role definition

  • Scope and role of access

  • Resource information under the orchestration tree (the names and tree structure)

diffcert

Compares the certificates registered with ServerView Operations Manager and the Resource Orchestrator manager, and when the following difference exists, that certificate is displayed using a different name.

  • Certificates that exist in the ServerView Operations Manager keystore, but not in the Resource Orchestrator manager's keystore

  • Certificates that exist in the ServerView Operations Manager keystore and the Resource Orchestrator manager's keystore, but have conflicting fingerprints

This command cannot be used for the following configurations:

  • ServerView Operations Manager has not been installed.

Difference of the CA certificate (keystore) is displayed using alias in the following format:

svs_cms
ldaphost.fujitsu.com

refreshcert

Imports the certificate of ServerView Operations Manager corresponding to the specified alias into Resource Orchestrator.

Specify the alias displayed by the diffcert command.

This command cannot be used for the following configurations:

  • ServerView Operations Manager has not been installed

If a root CA certificate has been registered with ServerView Operations Manager, specify that root CA certificate.

To import the server certificate, specify the alias for the following certificate:

  • Server certificate of ServerView Operations Manager

  • Server certificate of the directory server to be used

    This is unnecessary when using the directory service provided with ServerView Operations Manager.

Note

The certificate is imported using the specified alias. The existing certificate is deleted in the following cases:

  • There is a certificate which has the same alias

  • There is a certificate which has the same content as the certificate to be imported

Point

When executing the command, create a copy of the keystore (truststore-cacerts) file for Resource Orchestrator in the following format. When a file with the same name already exists, it will be overwritten.

[Windows Manager]

  • Source File

    Installation_folder\SVROR\Manager\runtime\jre6\lib\security\cacerts

  • Destination File

    Installation_folder\SVROR\Manager\runtime\jre6\lib\security\cacerts.org

[Linux Manager]

  • Source File

    /opt/FJSVrcvmr/runtime/jre6/lib/security/cacerts

  • Destination File

    /opt/FJSVrcvmr/runtime/jre6/lib/security/cacerts.org

sync

Synchronizes the directory server connection settings of Resource Orchestrator with those of ServerView Operations Manager.

This command cannot be used for the following configurations:

  • ServerView Operations Manager has not been installed.


Options

-host hostname

Specify the host name for the directory server to register using an FQDN or an IP address.

-ip ip

Specify the IP address of the directory server to register. This option is for compatibility. Use the -host option.

-port port (optional)

Specify the port number of the directory server to register. When omitted, the following port numbers are regarded as having been specified using the -method value.

SSL   : 636
PLAIN : 389
-base base_dn

Specify the search base of the directory server to register in DN format.

-bind bind_dn

Specify the administrative privilege user name of the directory server to register in DN format.

-method {SSL|PLAIN} (optional)

Specify the encryption communication method to use with the directory server to register. Specify one of following.

If this option is omitted, "SSL" is specified. If PLAIN is specified, encryption is not performed.

  • SSL

  • PLAIN

-passwd password

Specify the password for the administrative privilege user of the directory server to register.

-passwd_file password_file

Specify the administrative privilege user name of the directory server to register.

-alias alias

Specify the alias of the certificate to import into the CA certificate of Resource Orchestrator.

When using blank spaces or symbols in the specified string, enclose the whole string in double quotes ( " ).

An alias which contains double quotes ( " ) as character elements cannot be specified for this command. Remove any double quotes (") included in the alias before executing this command.


Requirements

Permissions

Refer to "5.1.2 Roles and Available Operations" in the "Design Guide CE".

Location

Admin server


Example

Exit Status

This command returns the following values:

0

The command executed successfully.

non-zero

An error has occurred.