Chat now with support
Chat mit Support

Privilege Manager for Unix 7.1.1 - Administration Guide

Introducing Privilege Manager for Unix Planning Deployment Installation and Configuration Upgrade Privilege Manager for Unix System Administration Managing Security Policy The Privilege Manager for Unix Security Policy Advanced Privilege Manager for Unix Configuration Administering Log and Keystroke Files InTrust Plug-in for Privilege Manager for Unix Troubleshooting Privilege Manager for Unix Policy File Components Privilege Manager for Unix Variables
Variable names Variable scope Global input variables Global output variables Global event log variables PM settings variables
Privilege Manager for Unix Flow Control Statements Privilege Manager for Unix Built-in Functions and Procedures
Environment functions Hash table functions Input and output functions LDAP functions LDAP API example List functions Miscellaneous functions Password functions Remote access functions String functions User information functions Authentication Services functions
Privilege Manager for Unix programs Installation Packages

pmsrvinfo

Syntax
pmsrvinfo [--csv] | -v
Description

Use the pmsrvinfo command to display information about the group in either human readable or CSV format. You can run this program on any server in the policy group.

Options

pmsrvinfo has the following options.

Table 86: Options: pmsrvinfo
Option Description
--csv Displays information in .CSV format, instead of human readable output.

-v

Displays the Privilege Manager for Unix version number and exits.

Examples
# pmsrvinfo
Policy Server Configuration: 
---------------------------- 
Privilege Manager for Unix version   : 6.0.0 (nnn) 
Listening port for pmmasterd daemon    : 12345 
Comms failover method                  : random 
Comms timeout(in seconds)              : 10 
Policy type in use                     : pmpolicy 
Group ownership of logs                : pmlog 
Group ownership of policy repository   : pmpolicy 
Policy server type                     : primary 
Primary policy server for this group   : adminhost1 
Group name for this group              : adminGroup1 
Location of the repository             :
file:////var/opt/quest/qpm4u/.qpm4u/.repository/pmpolicy_repos/trunk 
Hosts in the group                     : adminhost1 adminhost2

pmstatus

Syntax
pmstatus [-v] [-p <port>] [-h <hostname>] [-f <hostfile>] [-o <outfile>]
Description

The pmstatus program checks connectivity between Privilege Manager for Unix and pmlocald and pmmasterd on the specified hosts. You must specify at least one host, using either the -h or -f option.

Options

pmstatus has the following options.

Table 87: Options: pmstatus
Option Description
-f <hostfile> Specifies the name of a file containing a list of hosts to check.
-h <hostname> Specifies the name of the host to check. -h supercedes -f if you specify both options.
-o <outfile> Writes status information to the specified file.
-p <port> Specifies an alternative port to use when checking for connectivity with pmmasterd.

-v

Displays version information for the pmstatus program.

Examples

The following is an example of the output from pmstatus, if the command is directed at a host that is contactable and that contains Privilege Manager for Unix components:

[root@sdfbs02p linux-intel]# ./pmstatus -h sdfbs07p 
Master process on sdfbs07p:12345 responded 
Agent process on sdfbs07p:12346 responded 

The following is an example of the output from pmstatus, if the command is directed at a host that is contactable, but does not contain any Privilege Manager for Unix components:

[root@sdfbs02p linux-intel]# ./pmstatus -h sdfbs07p 
pmstatus5.0.2 (006): 3003 Could not connect to a master daemon for sdfbs07p 
No master process responded on sdfbs07p:12345 
pmstatus5.0.2 (006): 3001 Connection to pmlocald on sdfbs07p failed: Connection refused 
No agent process responded on sdfbs07p:12346 

pmsum

Syntax
pmsum /<full_path_name>
Description

Use pmsum to generate a checksum of the named file. The output it produces can be used in a policy with the runcksum variable. If the requested binary/command does not match the checksum, it rejects the command.

Options

pmsum has the following options.

Table 88: Options: pmsum
Option Description

-v

Prints the version number of Privilege Manager for Unix and exits.

Examples
# pmsum /bin/ls 
5591e026 /bin/ls
Related Topics

runcksum

pmsysid

Syntax
pmsysid [-i] | -v
Description

The pmsysid command displays the Privilege Manager for Unix system ID.

Options

pmsysid has the following options.

Table 89: Options: pmsysid
Option Description
-i Shows the system host name and IP address.

-v

Displays the Privilege Manager for Unix version and exits.

Verwandte Dokumente

The document was helpful.

Bewertung auswählen

I easily found the information I needed.

Bewertung auswählen