Secure Shell (SSH) in HP SIM

12
Note:
You must restart
HP
SIM
a
fter making changes to the Windows
Administrator user name.
Add this user account to HP SIM with full
-
configuration
-
rights and authorizations on all systems,
including the CMS, using the
Options
Security
Users
and
Authorizations
menu or the following
com
mand:
>
mxuser
a MyDomain
\
AlternateAdmin
-
p full
C Administrator
Note:
If you run the
mxuser
command, you must assign the appropriate
authorizations to the user by running the
mxauth
command.
You must also authorize t
his user account for SSH access on
the managed system: it must be added to
the passwd file and be set up for user, host or
password
authentication. Running the Configure or
Repair Agents tool with this user name will set up the system appropriately. Decide which method to
use by referring t
o the
Configuration steps
section.
Configuration steps
When HP SIM is initially installed on the CMS system, SSH is configured in the following way:
If installing on Windows:
1.
OpenSSH is installed, with the special version of Cy
gwin
.
2.
The name of the administrator account (which might have been renamed from
Administrator) is saved
.
3.
The installing user and administrator are added to the
passwd
file (in
C:
\
Program
Files
\
OpenSSH
\
etc
)
.
4.
The installing user and administrator are configu
red for user public key
authentication
.
5.
The administrator is configured for the SSH bypass feature
.
If installing on Linux or HP
-
UX
:
1.
SSH should be preinstalled from the operating system
2.
The root user is configured for user public key authentication
3.
The roo
t and Administrator users are configured for the SSH bypass feature
You can install
OpenSSH on managed systems that run SSA tools.
You can
install OpenSSH
on
a
Windows system
in the following ways
:
Using the Install OpenSSH tool
The Install OpenSSH tool
i
s perhaps the easiest way to deploy OpenSSH to a Windows
managed system. The tool runs the OpenSSH installation, adds both the user specified and
the administrator user to the
passwd
file, and then configures these users for public key
authentication from
the CMS. This tool is only available on a CMS that runs on Windows
.
You can deploy
the OpenSSH only to Windows management systems.
Separate OpenSSH Install