Configuration
Setting Up the
If no IP address or host name is found, you are asked if you want to create the bundle anyway; no entry is placed in the temporary file.
If multiple IP addresses are found, no entry is placed in the temporary file; the bundle is created without comment.
When the System Manager is started later, any entries in the temporary file are added to the host list table, displayed on the Host Manager screen.
The following is an example of entering the names of your host systems, run on administration host adminsys for agent hosts myhost1 and myhost2. It prompts for each host name (or IP address). Press
$ IDS_genAgentCerts
==> Be sure to run this script on the IDS Administration host.
Generate keys for which host? myhost1
Generating key pair and certificate request for IDS Agent on myhost1....
Signing certificate for IDS Agent on myhost1...
Certificate package for IDS Agent on myhost1 is /var/opt/ids/tmp/myhost1.tar.Z
Next hostname (^D to quit)? myhost2
Generating key pair and certificate request for IDS Agent on myhost2....
Signing certificate for IDS Agent on myhost2...
Certificate package for IDS Agent on myhost2 is /var/opt/ids/tmp/myhost2.tar.Z
Next hostname (^D to quit)? myhost3
Host name "myhost3" unknown. DNS lookup failed.
Do you still wish to create a certificate [N]/Y? n
Generating key pair and certificate request for IDS Agent on 15.27.43.6....
Signing certificate for IDS Agent on 15.27.43.6...
Certificate package for IDS Agent on 15.27.43.6 is /var/opt/ids/tmp/15.27.43.6.tar.Z
Next hostname (^D to quit)?
************************************************************
*Successfully created agent certificates for the following
*hosts:
*myhost1
*myhost2
*15.27.43.6
*
*Certificate public keys are valid for 700 days and are
*1024 bits in size.
22 | Chapter 2 |