Avamar: Administrer sessionssikkerhedsindstillinger fra CLI

Summary: Denne artikel beskriver, hvordan du administrerer sikkerhedsindstillingerne for Avamar-sessionen fra kommandolinjeværktøjet.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

BEMÆRK: Ved enhver ændring af sessionssikkerhedsindstillingerne kræves en MCS-genstart!


Forudgående kontrol

Det er bedste praksis at udføre følgende, før du ændrer indstillingerne for sessionssikkerhed.

  • Stop alle sikkerhedskopieringer, replikering, og sørg for, at der ikke kører vedligeholdelse (kontrolpunkt/hfscheck/affaldsindsamling).
  • Kontroller, at der er et gyldigt kontrolpunkt tilgængeligt på Avamar.



Oversigt over

Følgende script, der er installeret på alle Avamar-servere, bruges til at administrere indstillingerne for sessionssikkerhed.
Kør scriptet som root-bruger.

enable_secure_config.sh


Vis de aktuelle indstillinger:

enable_secure_config.sh --showconfig

Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="false"
"secure_agent_feature_on"                               ="false"
"session_ticket_feature_on"                             ="false"
"secure_agents_mode"                                    ="unsecure_only"
"secure_st_mode"                                        ="unsecure_only"
"secure_dd_feature_on"                                  ="false"
"verifypeer"                                            ="no"

Client and Server Communication set to Default (Workflow Re-Run) mode with No Authentication.
Client Agent and Management Server Communication set to unsecure_only mode.
Secure Data Domain Feature is Disabled.


I eksemplet ovenfor er sessionssikkerhed deaktiveret.

Der er fire mulige understøttede konfigurationer:

  1. Disabled
  2. Blandet-Single
  3. Godkendt-enkelt
  4. Godkendt-dobbelt

Deaktiveret

Følgende output viser indstillingerne for deaktiveret tilstand.

Kommando:
enable_secure_config.sh --showconfig

Output:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="false"
"secure_agent_feature_on"                               ="false"
"session_ticket_feature_on"                             ="false"
"secure_agents_mode"                                    ="unsecure_only"
"secure_st_mode"                                        ="unsecure_only"
"secure_dd_feature_on"                                  ="false"
"verifypeer"                                            ="no"

Client and Server Communication set to Default (Workflow Re-Run) mode with No Authentication.
Client Agent and Management Server Communication set to unsecure_only mode.
Secure Data Domain Feature is Disabled.

Sådan indstiller du sessionssikkerhedsindstillinger til deaktiveret:

Kommando:
enable_secure_config.sh --enable-all --undo

Output:
#########################  #########################
#########################  #########################
Disabling Avamar Security Features
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Hvis indstillingerne er ændret, skal MCS genstartes.


Blandet-Single

Følgende output viser indstillingerne for blandet enkelttilstand.

Kommando:
enable_secure_config.sh --showconfig

Output:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="mixed"
"secure_st_mode"                                        ="mixed"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="no"

Client and Server Communication set to Mixed mode with One-Way/Single Authentication.
Client Agent and Management Server Communication set to mixed mode.
Secure Data Domain Feature is Enabled.

Sådan indstiller du sessionssikkerhedsindstillinger til Mixed-Single:

Command:
enable_secure_config.sh --enable-all

Output:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Kommando:
avmaint config --ava verifypeer=no

Output:
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<gsanconfig verifypeer="yes"/>

Hvis indstillingerne er ændret, skal MCS genstartes.


Godkendt-enkelt

Følgende output viser indstillingerne for godkendt enkelttilstand.

Kommando:
enable_secure_config.sh --showconfig

Output:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="secure_only"
"secure_st_mode"                                        ="secure_only"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="no"

Client and Server Communication set to Authenticated mode with One-Way/Single Authentication.
Client Agent and Management Server Communication set to secure_only mode.
Secure Data Domain Feature is Enabled.

Sådan indstiller du indstillinger for sessionssikkerhed til Authenticated-Single:

Command:
enable_secure_config.sh --enable-secure-all

Output:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Kommando:
avmaint config --ava verifypeer=no

Output:
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<gsanconfig verifypeer="yes"/>

Hvis indstillingerne er ændret, skal MCS genstartes.


Godkendt-dobbelt

Følgende output viser indstillingerne for godkendt dobbelttilstand.

Kommando:
enable_secure_config.sh --showconfig

Output:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="secure_only"
"secure_st_mode"                                        ="secure_only"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="yes"

Client and Server Communication set to Authenticated mode with Two-Way/Dual Authentication.
Client Agent and Management Server Communication set to secure_only mode.
Secure Data Domain Feature is Enabled.

Sådan indstiller du sessionssikkerhedsindstillinger til Authenticated-Dual:

Command:
enable_secure_config.sh --enable-secure-all

Output:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Hvis indstillingerne er ændret, skal MCS genstartes.


Bemærk

Brug følgende kommandoer til at genstarte MCS og sikkerhedskopieringsprogrammet som administratorbruger:
mcserver.sh --restart --force
dpnctl start sched

Affected Products

Avamar
Article Properties
Article Number: 000222234
Article Type: How To
Last Modified: 12 Dec 2025
Version:  8
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.