Ooops, no root ssh and no GUI console

    In my previous post, I talked about a change to ssh_config to allow SGD to run X apps from a locked down server. Another thing I encountered during the same install was that the root user was not allowed ssh or any access to the system outside of direct console access. And since there was no graphics card in this server, I could therefore not use the SGD GUI admin tools. Makes it a tad more difficult to add or change apps and other SGD admin tasks, particularly for those not as comfortable with command line interfaces (CLI).
    Since by default the root user of the OS is used to administer SGD, the way around this is to create another user, and add them to the 'global' group. The easiest way to do that is through the GUI interface, but since I already ruled that out, here are some CLI commands to get the job done. Login via ssh using a non-root user, then su to root in order to run the commands.
    First, create a Solaris user. In this case, I used 'sgdadmin' for this task, created as follows, although don't feel obligated to use my method:

    useradd -c "SGD Admin" -d /export/home/sgdadmin -m sgdadmin

    And now to the SGD configuration, via CLI commands. The first line adds the Solaris user 'sgdadmin' to SGD as a person object, the second adds the new person object to the 'global' group, thus allowing it to administer SGD.

    /opt/tarantella/bin/tarantella object new_person --name ".../_ens/o=organization/cn=sgdadmin" --surname none --user sgdadmin

    /opt/tarantella/bin/tarantella role add_member --role global --member ".../_ens/o=organization/cn=sgdadmin"

    The tricky part of this is the _ens format for SGD objects, used to identify the new person object. These commands are based on using the default installation directory for SGD, so modify them accordingly if you have installed SGD in a location other than the default of /opt/tarantella.
    As long as those commands executed without error, you should now be able to login to the SGD GUI as 'sgdadmin' and get access to the Configuration Wizard and Object Manager, regardless of whether you are on the SGD server or not.
Comments:

Post a Comment:
Comments are closed for this entry.
About

Think Thin is a collection of bloggers that work with Oracle's Virtual Desktop portfolio of products.

Search

Archives
« August 2015
SunMonTueWedThuFriSat
      
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
     
Today