Enable agent daemon command line options: |
none |
Enter:
- -e <logfile> to use the error log file identified by <logfile>.
- -m to only accept connections from the policy server daemon on the specified host. (Use multiple -m options to specify more than one host.)
- -s to send error messages to syslog. none to assign no options.
- These command-line options override the syslog and pmlocaldlog options configured in the pm.settings file.
|
Enable client daemon? |
YES |
Enter No |
Configure host components to communicate with remote hosts through firewall? |
NO |
Enter Yes |
Enable Privilege Manager for Unix shells (pmksh, pmsh, pmcsh, pmbash)? |
YES
That is, you want to use a Privilege Manager for Unix shell to control or log Privilege Manager for Unix sessions, regardless of how the user logs in (telnet, ssh, rsh, rexec). |
Enter No if you do NOT want to add the Privilege Manager for Unix shells to the system. That is, you do not want to use the Privilege Manager for Unix shells as a login shell. |
Add the entries to the /etc/services file? |
YES |
Enter No
You must add service entries to either the /etc/services file or the NIS services map. |
Edit list of policy servers with which this agent can communicate? |
none |
Enter valid policy server names to add to the list. |
Indicate if the list is correct |
YES |
Enter No |
Policy Server daemon port # |
12345 |
Enter a port number |
Specify the agent daemon port number: |
12346 |
Enter a port number for the agent to communicate with the policy server. |
Specify a range of local port numbers for this host to connect to other defined Privilege Manager for Unix hosts across a firewall? |
NO |
Enter Yes, then enter:
- Minimum reserved port (600-1024). (Default is 600.)
- Maximum reserved port (600-1024). (Default is 1024.)
|
Allow short host names? |
YES |
Enter No to use fully qualified host names instead. |
Configure Kerberos on your network? |
NO |
Enter Yes, then enter:
- Policy server principal name. (Default is host.)
- Local principal name. (Default is host.)
- Directory for replay cache. (Default is /var/tmp.
- Path for the Kerberos configuration files. (Default is /etc/opt/quest/vas/vas.conf.)
- Full pathname of the Kerberos keytab file. (Default is /etc/opt/quest/vas/host.keytab.
|
Specify encryption level:
See Encryption for details. |
AES |
Enter one of these encryption options:
|
Enable certificates? |
NO |
Enter Yes, then answer:
Generate a certificate on this host? (Default is NO.)
Enter Yes and specify a passphrase for the certificate.
Once configuration of this agent is complete, swap and install keys for each host in your system that need to communicate with this host.
See Swap and install keys for details. |
Activate the failover timeout? |
YES |
Enter No, then assign the failover timeout in seconds.
Default: 10 seconds |
Assign the failover timeout |
10 |
Enter a timeout value in seconds |
Select random policy server |
YES |
Enter No |
Send errors reported by agent to syslog? |
YES |
|
Store errors reported by the agent daemon in /var/log/pmlocald.log? |
YES |
Enter No, then enter a location. |
Store errors reported by the run agent in /var/log/pmrun.log? |
YES |
Enter No, then enter a location. |