scom2012 监控linux,SCOM 2012, WSMan, and Unix/Linux Computer Discovery

本文详细介绍了SCOM2012如何使用WS-Management(WSMan)协议进行Linux/UNIX计算机的监控。通过基本认证,SCOM传递用户名/密码对进行身份验证,所有监测操作都基于WSMan这个跨平台管理的SOAP协议。同时,文章强调了证书在安全连接和身份验证中的关键作用,SCOM管理服务器在发现UNIX/Linux代理时,会使用自己的证书签署代理证书,形成安全的通信链路。
摘要由CSDN通过智能技术生成

SCOM 2012, WSMan, and Unix/Linux Computer Discovery

01/12/2016

2 分钟可看完

本文内容

Summary

System Center Operations Manager (SCOM) Linux/UNIX monitoring uses WS-Management/WSMan “basic authentication” on an ongoing basis – i.e., it passes a username/password pair to the Linux computer, and the Linux computer authenticates that username/password using the PAM.  If you disable “basic authentication” on the SCOM management server, it’s not going to work.  Other potential WinRM authentication choices are not implemented for SCOM monitoring of Linux/UNIX, see https://msdn.microsoft.com/en-us/library/aa384295(v=vs.85).aspx.

What is WS-Management?

WS-Management (or WSMan) is the core protocol used in UNIX/Linux monitoring.   WSMan is a SOAP-based protocol for cross-platform management.   All monitoring operations (e.g. enumerating CIM providers for data on file systems, memory, etc, execution of commands/scripts for monitoring, executing log file reads for monitoring) are implemented over WSMan.   As WSMan is a web service protocol, the OpenPegasus-based CIMOM functions as a secure web server (user credentials are authenticated through PAM).  This is where the agent certificate comes in to play.

How Does SCOM use WSMan?

The UNIX/Linux agent certificate is used to secure the WSMan connection using SSL and provide authentication for the remote agent host. When the Operations Manager UNIX/Linux agent is installed, it generates a certificate (using openssl) at the path:  /etc/opt/microsoft/ssl.  The file name of the certificate is scx-host-.pem and the corresponding private key is named scx-key.pem.   The agent actually looks for the certificate at /etc/opt/microsoft/scx/ssl/scx.pem, which is initially configured as a symbolic link pointing to scx-host-.pem.

When a Management Server discovers a UNIX/Linux agent, the server uses its certificate to sign the agent certificate, acting like a standalone Certificate Authority.  In the discovery process, this actually involves securely transferring the certificate from the agent to the Management Server, signing it, copying it back to the agent, and restarting the agent daemon.   See http://blogs.msdn.com/b/wmi/archive/2009/03/23/how-to-use-wsman-config-provider-for-certificate-authentication.aspx

In summary, SCOM uses WSMan and certificates to securely communicate between Management Server and the Unix/Linux Agent.

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值