Chat now with support
Chat with Support

Safeguard Authentication Services 4.1.5 - Management Console for Unix Administration Guide

One Identity Privileged Access Suite for Unix Introducing One Identity Management Console for Unix Installing Management Console for Unix Preparing Unix Hosts Working with Host Systems Managing Local Groups Managing Local Users Active Directory Integration Authentication Services Integration Privilege Manager Integration Reporting Setting Preferences Security Troubleshooting Tips
Auto Profile Issues Active Directory Issues Auditing and Compliance Cannot Create a Service Connection Point Check Authentication Services Agent Status Commands Not Available CSV or PDF Reports Do Not Open Database Port Number Is Already in Use Elevation Is Not Working Hosts Do Not Display Import File Lists Fakepath Information Does Not Display in the Console Java Applet Failures License Info in Report is not Accurate Out of Memory Error Post Install Configuration Fails on Unix or Mac Privilege Manager Feature Issues Profile Task Never Completes questusr Account was Deleted Readiness Check Failed Recovering From a Failed Upgrade Reports Are Slow Reset the Supervisor Password Running on a Windows 2008 R2 Domain Controller Service Account Login Fails Setting Custom Configuration Settings Single Sign-on (SSO) Issues JVM Memory Tuning Suggestions Start/Stop/Restart Management Console for Unix Service Tool Bar Buttons Are Not Enabled UID or GID Conflicts
System Maintenance Command Line Utilities Web Services Database Maintenance

Enable SSO for Remote Browser Clients

In order for remote browser clients to log onto the mangement console using SSO, Management Console for Unix requires that the web browser 'delegate' the user's credentials to the server. Therefore, you must enable the Management Console for Unix server for delegation.

To enable the Management Console for Unix server for delegation

  1. Open Active Directory Users and Computers.

  2. Navigate to the container in the domain on which the computer where Management Console for Unix is running resides.

    For example, if the console is installed on a domain controller, navigate to <DomainName> | Domain controllers and find the computer object.

  3. In the details pane, right-click the computer object and click Properties.

  4. Open the Delegation tab, select Trust this computer for delegation to any service (Kerberos only) and click OK to save your selection and close the properties.

Note: In Active Directory, computer objects have a property that gets set when you select Trust this computer for delegation to any service (Kerberos only). SSO will not work if delegation is not enabled on the server.

For the delegation changes to take effect in Active Directory, you may need to reboot the client.

JVM Memory Tuning Suggestions

If you are experiencing performance degradation due to heavy demand from web service calls, simultaneous report generation, multiple browser connection querying, and so forth, One Identity recommends that you increase the JVM memory.

To tune JVM memory

  1. Open the custom.cfg file for editing.

    (See Setting Custom Configuration Settings for general information about customizing configuration settings for the mangement console.)

  2. Set the initial or start memory size using the -Xms variable and the maximum memory size using the -Xmx variable. For example:

    -Xms512m

    -AND-

    -Xmx512m

    where "512m" specifies 512MB of memory or "1g" specifies 1GB of memory.

    Note: 1024MB is the default memory requirement.

    One Identity recommendations:

    • For each 1,000 application database records (hosts, uses, groups, group memberships), increase the JVM memory by 20MB to support 1 to 3 simultaneous web browser connections.
    • For each 1,000 records, increase the memory by 30MB to support 3 to 5 simultaneous web browser connections.
    • Do not allocate more memory than you have; the console will fail to load.

    These suggested specifications depend on your reporting demands. If you create more than two or three reports simultaneously, increase the memory specification.

    For further information on specific settings refer to <install_directory>/jvmargs.cfg

    These values are used for the JVM heap which reserves memory for the server and its database. Increasing the amount of memory available can improve performance, but increasing it too much can have a detrimental effect in the form of longer pauses for full garbage collection runs. Setting -Xms and -Xmx to the same value increases predictability by removing the most important sizing decision from the virtual machine. On the other hand, the virtual machine cannot compensate if you make a poor choice. Be sure to increase the memory as you increase the number of processors, since allocation can be parallelized. JVM heaps greater than 1.5 Gbytes require a 64-bit JVM. Anything more than that will cause the service to not start.

    Numbers can include 'm' or 'M' for megabytes, 'k' or 'K' for kilobytes, and 'g' or 'G' for gigabytes. For example, 32k is the same as 32768. Unless you have problems with pauses, try granting as much memory as possible.

    For further reading on garbage collection tuning refer to http://java.sun.com/docs/hotspot/gc5.0/gc_tuning_5.html and for additional VM options refer to http://java.sun.com/javase/technologies/hotspot/vmoptions.jsp

  3. Save the custom.cfg file.

  4. Restart the Management Console for Unix service.

    (See Start/Stop/Restart Management Console for Unix Service for details about restarting the Management Console for Unix Service.)

Start/Stop/Restart Management Console for Unix Service

Depending on the platform you are using, use the corresponding procedure to start, stop, or restart the Management Console for Unix service (mcu_service).

Linux or Solaris Machines

To stop, start, or restart the Management Console for Unix service (mcu_service) on a Linux/Solaris machine

  1. Log onto the machine as root user.
  2. At the root prompt, enter one of the following commands:

    To stop and restart the service automatically:

    /etc/init.d/mcu_service restart

    To stop the service and unload it:

    /etc/init.d/mcu_service stop

    To load the service and start it:

    /etc/init.d/mcu_service start
Related Documents