Appendix
Reference Card and Glossary
Events
VISULOX Service Events
|
Type |
Event |
Description |
Event variable |
|---|---|---|---|
|
Login |
Multiple login failures detected |
Default warning setting for failed login attempts: 5 per minute, 20 per hour and 50 per day |
multipleloginfailures |
|
Login |
Access PIN accepted |
Login with Access PIN accepted |
2faPinAccepted |
|
Login |
Access PIN requested |
Access PIN for login requested |
2faPinRequested |
|
Login |
Access PIN rejected |
Access PIN was rejected |
2faPinRejected |
|
Login |
OTP requested |
One Time Passcode for login requested |
otpRequested |
|
Login (Webtop) |
Logged out by supervisor |
Application session ended by supervisor via VISULOX Cockpit |
webtopSessionEndedByAdmin |
|
Application |
Application started |
Application session has been started with session controller |
sessionControllerStarted |
|
Application |
Application started (uncontrolled) |
Application session has been started without session controller |
sessionUncontolledStarted |
|
Application |
Application ended |
Application session ended |
sessionControllerEnded |
|
Application |
Session locked |
Application session locked |
lock |
|
Application |
Session unlocked |
Application session unlocked |
unlock |
|
Application |
Session locked by supervisor |
Application session locked by supervisor via VISULOX Cockpit |
lockedbyadmin |
|
Application |
Session unlocked by supervisor |
Application session unlocked by supervisor via VISULOX Cockpit |
unlockedbyadmin |
|
Application |
Ended by supervisor |
Application session ended by supervisor via VISULOX Cockpit |
sessionEndedByAdmin |
|
Application |
Message sent |
Message from supervisor is sent via Cockpit to the user |
message |
|
Application |
Accepted by user |
Message, recording, etc. acknowledged by the user |
accept |
|
Application |
Rejected |
Recording rejected by user |
reject |
|
Notification |
Notification sent |
A notification was sent based on the selected script |
scriptsend |
|
Access |
Access will expire |
Warning, that access to applications will expire soon |
|
|
Access |
User request |
Access requested by the user |
accessRequestedByUser |
|
Application |
Remark by user |
Session annotation created by the user |
annotationByUser |
|
Application |
Remark by supervisor |
Annotation created by the supervisor in the VISULOX Cockpit for the session |
annotationBySupervisor |
|
Cooperation |
Assistance request |
Request for a cooperation |
assistrequested |
|
Cooperation |
Assist observe |
Assist mode switched to observe |
assistobserve |
|
Cooperation |
Assist interact |
Assist mode switched to interact |
assistinteract |
|
Cooperation |
Assist Standby |
Assist mode switched to standby |
assiststandby |
|
Cooperation |
Dual Control |
Dual Control cooperation started |
dualcontrol |
|
Cooperation |
Assistance closed |
Cooperation closed |
assistclosed |
|
Recording |
Manual recording |
Manual recording of the session started by the supervisor via VISULOX Cockpit |
sessionManuallyRecordingStarted |
|
Recording |
Recording stopped |
Manual recording stopped by the supervisor via VISULOX Cockpit |
sessionManuallyRecordingStopped |
|
Recording |
Recording started by Policy |
Predefined recording started by Application Policy |
sessionRecordingStarted |
|
Keyboard control |
In use |
Input changed to this user |
inputFocusChanged |
|
Keyboard control |
Inputline |
The user entered a line of characters |
keyboardControlInputline |
|
Keyboard control |
Responsible |
Input changed to this user |
inputResponsibility |
|
Keyboard control |
Idle |
Keyboard idle |
InputFocusIdle |
|
Keyboard control |
Keyboard control started |
Keyboard input detection started |
keyboardControlStarted |
|
Keyboard control |
Keyword detected |
Keyword detected by keystroke detection control |
keywordDetected |
|
Checkout |
Checkout |
Session checkout via Cockpit |
checkout |
|
Checkout |
Checkout with keystrokes |
Checkout of the session information in a ZIP file with displayed keystrokes |
checkoutwithkeystrokes |
|
Checkout |
Report in browser |
Report created via Cockpit and displayed in browser |
reportGeneratedByGuiBrowser |
|
Checkout |
Report via eMail |
Report created via Cockpit and sent via eMail |
reportGeneratedByGuiEmail |
|
Checkout |
Player started |
Browser-based player started via Cockpit |
player |
|
Checkout |
Player with keystrokes started |
Browser based player with displayed keystrokes started |
playerwithkeystrokes |
|
System |
Auto accepted |
Accepted automatically by the system |
autoaccept |
|
System |
Auto rejected |
Rejected automatically by the system |
autoreject |
|
System |
Object created |
A VISULOX object has been created |
objectNew |
|
System |
Object copied |
A VISULOX object has been copied |
objectCopied |
|
System |
Object changed |
A VISULOX object has been changed |
objectChanged |
|
System |
Object deleted |
A VISULOX object has been deleted |
objectDeleted |
|
System |
Object attached |
A VISULOX object has been attached |
objectAttached |
|
System |
Object detached |
A VISULOX object has been detached |
objectDetached |
|
File Transfer |
Synced to folder |
Files synchronized with the folder |
syncput |
|
File Transfer |
Synced to Transit Zone |
Files synchronized with the Transit Zone |
syncget |
|
File Transfer |
Transfer to server |
File transferred from Transit Zone to the application server via SFTP/FTP |
ftput |
|
File Transfer |
Transfer to Transit Zone |
File transferred from application server to the Transit Zone via SFTP/FTP |
ftget |
|
File Transfer |
Upload (internal web page) |
File uploaded via internal web page |
webput |
|
File Transfer |
Download (internal web page) |
File downloaded via internal web page |
webget |
|
File Transfer |
Upload |
File uploaded from client into Transit Zone |
userput |
|
File Transfer |
Download |
File transferred from Transit Zone to the client |
userget |
|
File Transfer |
File checked |
Transferred file has been checked |
checked |
|
File Transfer |
Approved |
Transferred file has been approved |
approved |
|
File Transfer |
File rejected |
File rejected after check |
rejected |
|
File Transfer |
Pending |
File not approved yet |
pending |
|
File Transfer |
Conditionally accepted |
File accepted depending on endpoint rules |
tmpaccepted |
VISULOX PORTAL Service Events
|
Type |
Event |
Description |
Event variable |
|---|---|---|---|
|
Server |
Server started |
Server has been started / details |
serverStart |
|
Server |
Server stopped |
Server was stopped / details |
serverStop |
|
Server |
SSL started |
VISULOX PORTAL Security SSL has been started |
securitySSLStart |
|
Server |
SSL stopped |
VISULOX PORTAL Security SSL has been stopped |
securitySSLStop |
|
Login |
Login rejected |
VISULOX PORTAL login was rejected for the user / details |
loginResultRejected |
|
Login |
Login ambigious |
Login information ambiguous, common name needed |
loginResultAmbiguous |
|
Login |
Anonymous login not supported |
Login failed, Anonymous login not supported |
loginResultAnonymous |
|
Login |
Unresolveable user |
Login failed, unresolvable user |
loginResultUnresolveable |
|
Workspace |
Workspace opened |
Workspace session has been started / details |
webtopSessionStartedDetails |
|
Workspace |
Workspace closed |
Workspace session has been stopped / details |
webtopSessionEndedDetails |
|
Application |
Application session started |
Application session has been started / details |
sessionStartedDetails |
|
Application |
Application session stopped |
Application session was stopped / details |
sessionEndedDetails |
|
VISULOX PORTAL Object |
Object modified |
VISULOX PORTAL object has been changed |
modifySuccess |
|
VISULOX PORTAL Object |
Object created |
A new VISULOX PORTAL object was created |
createSuccess |
|
VISULOX PORTAL Object |
Object create failed |
Creating an VISULOX PORTALobject failed |
createFailure |
|
VISULOX PORTAL Object |
Rename successful |
VISULOX PORTAL object renamed successfully |
renameSuccess |
|
VISULOX PORTAL Object |
Object deleted |
An VISULOX PORTAL object was deleted |
deleteSuccess |
Script Interface & Variables
Available script categories
|
Category |
Used as |
|---|---|
|
Notification |
These action scripts can be chosen, where application notifications are used (Application Policy). |
|
Pin |
These action scripts deliver information for the Multi Factor Authentication (Login Policy). |
|
Report |
These are report actions scripts. |
|
Validate |
These action scripts can be chosen for validation. |
|
* |
These action scripts are available everywhere scripts can be used. The setup provides one script in this category,
|
Notification script variables (examples)
The following list contains some useful examples for script variables.
To get the complete list of available variables for a certain action script, the dump script should be used.
|
Variable |
Description |
|---|---|
|
VLXFULLNAME |
Full name of the user |
|
VLXSURNAME |
Surname of the user |
|
VLXEMAIL |
eMail address of the user |
|
VLXSMS |
SMS address of the user |
|
VLXOWNER |
Owner of the application |
|
VLXGROUPLIST |
Group list |
|
VLXUSERPROFILE |
Profile of the user |
|
VLXPIN |
PIN for Multi Factor Authentication |
|
VLXPIN_FMT |
Formatted PIN for Multi Factor Authentication |
|
VLXPIN_SEQUENCE |
Sequence number for PIN |
|
VLXPIN_EXPIRATIONTIME |
Expiration time with date for the PIN |
|
VLXPIN_LIFETIME |
Lifetime for the PIN |
|
VLXPIN_TEXT |
PIN text |
|
VLXACCESSPOIN |
Access Point |
|
VLXCREATETIME |
Creation time |
|
VLXLOG |
Path to logs |
|
VLXLOGINUSER |
Logged in user |
|
VLXMANAGER |
Manager of the user |
|
VLXOBJECT |
Name of the object |
|
VLXOWNERID |
Owner ID |
|
VLXOWNERSHORT |
Short name of the owner |
|
VLXPOLICY |
VISULOX policy |
|
VLXREMOTEIP |
Remote IP |
|
VLXSMS |
SMS of the user |
|
VLXLISTHASH |
Hash |
|
VLXCLIENTIP |
Client IP address |
|
VLXLANG |
Language |
|
VLXSESSIONHOST |
Host, where the session was started |
|
VLXCREATETIME_FMT |
Time of creation (readable) |
|
VLXSESSIONSTARTTIME |
Start time of the sesssion |
|
VLXSESSIONDURATION |
Duration of the session |
|
VLXSESSIONDURATION_FMT |
Duration of the session (readable) |
|
VLXSESSIONENDTIME |
Endtime of the session |
|
VLXSESSIONENDTIME_FMT |
Endtime of the session (readable) |
|
VLXAPPLICATION |
Application name |
|
VLXRECIPENT |
Recipient |
|
VLXTICKETID |
Ticket ID of the user |
|
VLXLOGINSCRIPT |
Login script |
|
VLXAPPLICATIONUSER |
User of the application |
|
VLXBADWORD |
Detected keyword in Keyboard recording |
|
VLXEVENTINFO |
Event info |
|
VLXCREATEDBY |
Created by |
|
VLXCREATEDBYSHORT |
Short name of creator |
See also:
Exit Codes
In the following table all VISULOX Exit Codes are listed with a short description and the meaning of the code.
|
Exit code |
Short description |
Comment |
|
0 |
SUCCESS |
Success |
|
1 |
FAILURE |
Failure |
|
2 |
WARNING |
Warning |
|
3 |
REJECT |
Policy |
|
4 |
ACCEPT |
Policy |
|
5 |
PASSON |
Policy |
|
6 |
APPLY |
Policy |
|
7 |
EXCLUDE |
Policy |
|
8 |
APPROVAL |
Rule |
|
9 |
ALLOW |
Rule |
|
10 |
ALLOWSPONTAN |
Rule |
|
11 |
ALLOWENDPOINT |
Transit rule matches, but endpoint has to be taken into account |
|
12 |
DENY |
Deny action |
|
13 |
DENYTOOLARGE |
Transit: file is too large |
|
14 |
DENYDIRECTION |
Transit: file can not be transferred in this direction |
|
15 |
DENYFORENDPOINT |
Transit: file cannot be handled with this endpoint |
|
16 |
DENYVIRUS |
Transit: file has a virus |
|
17 |
DENYEMPTY |
Transit: file is empty |
|
18 |
DENYPASSON |
Transit: script denies Passon |
|
19 |
NOMATCHPOLICY |
Policy |
|
20 |
USAGE |
Command line usage error |
|
21 |
DATAERR |
Data format error |
|
22 |
NOINPUT |
Cannot open input |
|
23 |
UNKNOWNUSER |
User unknown |
|
24 |
UNKNOWNHOST |
Host name unknown |
|
25 |
UNAVAILABLE |
Service unavailable |
|
26 |
SOFTWARE |
Internal software error |
|
27 |
LICENSE |
License error |
|
28 |
OSERR |
System error (e.g. can't fork) |
|
29 |
OSFILE |
Critical OS file missing |
|
30 |
CANTCREAT |
Can't create (user) output file |
|
31 |
IOERR |
Input/output error |
|
32 |
TEMPFAIL |
Temp failure; user is invited to retry |
|
33 |
PROTOCOL |
Remote error in protocol |
|
34 |
NOPERM |
Permission denied |
|
35 |
CONFIG |
Configuration error |
|
36 |
INIT |
Initialization error |
|
37 |
SCRIPTERROR |
Script execution with error |
|
38 |
DATABASE |
Error during database interaction |
|
39 |
TIMEOUT |
Timeout |
|
40 |
REGISTRATION |
Error on registration |
|
41 |
XAUTH |
Error on setting x11 cookie |
|
42 |
ZMQERROR |
ZeroMQ error |
|
43 |
CRYPTOERROR |
Crypto error |
|
44 |
STARTREJECTED |
Start rejected |
|
45 |
ALREADYRUNNING |
Program already running |
|
46 |
NOTIMPLEMENTED |
Not implemented |
|
47 |
UNDEFINED |
Operation has no defined state yet |
|
48 |
EXHAUSTED |
No resource available anymore |
|
49 |
LOOKUP |
Item not found |
|
50 |
EMPTY |
Unexpected empty result |
|
51 |
RESTART |
Restarting... |
|
52 |
RETRY |
Try again |
|
53 |
OLDREQUEST |
Received reply to a previous request |
|
54 |
TRANSPORT |
Error in transport layer |
|
55 |
QUORUM |
No etcd leader |
|
56 |
ACCESSPOINTCHECK |
Access validation |
|
57 |
BUSY |
Resource temporarily unavailable |
|
100 |
ACCESSREQUEST |
Access Policy Request |
|
200 |
DISABLED |
LDAP cannot get data, because the datasource is disabled |
|
210 |
APPROVALPASSON |
Rule |
|
1000 |
INFO |
Info line in integrity test |
Command Line Parameter
VISULOX Command
visulox <command> [<command-specific args>]
During installation /usr/sbin/visulox is created, which makes it possible to execute the VISULOX Service Command without using the whole path.
Available parameters
|
Command |
Description |
Additional commands / args |
|---|---|---|
|
addon |
Command Line Interface to VISULOX Addons |
cmdconnect, cmdguard, ftclient, host, script, template |
|
admin |
Manage the VISULOX Administration |
cockpit, action, message, region, timeprofile |
|
archive |
Manage VISULOX Archive Node |
-node <>, -set |
|
assignments |
Check assignments in policies and applications |
app, datastore, policy |
|
attach |
Attach a node to the VISULOX Cluster |
<hostname>, -location, -zone |
|
cluster |
Builds a VISULOX Cluster |
data, layout, build -f <> | -template |
|
cockpit |
Start of the VISULOX Cockpit |
title <>, lang <>, roles <>, grant <>, groupaccess <>,owner <>, ksr, cdm, kiosk, personal |
|
config |
Manage the VISULOX configuration |
accesspoint, datasources, dump, edit, env, list, locations,logo, mynodename, rebuild, reset, vap |
|
database |
Query the VISULOX Database |
list, backup, restore, fields, query, integrity, rename <>, node <>, table <>, timeout <> |
|
datasource |
Manage the VISULOX Datasources |
add, check, copy, delete, edit, list |
|
detach |
Detach a node from the VISULOX Cluster |
server <>, timeout <> |
|
end2end |
VISULOX end2end check |
off, on, status |
|
etcd |
Manage ETCD instances |
benchmark, client, del, get, instance, member, node, put, test |
|
export |
Export from VISULOX |
events, files, sessions |
|
integrity |
VISULOX Integrity-Check |
sys, lib, cmd, users, portal, ulimit, store, recorder, datasources, license |
|
license |
Manage the VISULOX License |
list, replace, test, usage (-component <users|sessions|recorders|hostcontrols> -unit <week|month|year>) |
|
log |
Query VISULOX log database |
since <>, until <>, logleve <>l, follow |
|
online |
VISULOX online status |
getpin, fields (list available fields), -i (ignore case), -object <> (owner or group mask), -application <>, -fields <>, sortby <> (sort by field) |
|
otp |
Manage the VISULOX OTP configuration |
check <>, key, reset <>, set <> |
|
passcache |
Manage the VISULOX Passcache |
list, fields, edit, delete |
|
ping |
Ping local master or designated worker |
id <> (outdated) |
|
policy |
Command line interface to the VISULOX Policies |
external, login, internal, access, application, transit |
|
portal |
Attach / detach VISULOX Service from VISULOX PORTAL Service
(See also: VISULOX PORTAL ATTACH Command) |
array, config, discover, drop, admin, mode, etc (see: VISULOX-PORTAL Command) visulox portal --help shows all available VISULOX PORTAL and VISULOX commands. With visulox portal admin -user <unixuser> a Unix user can be activated as VISULOX Portal Admin
|
|
pwdmgmt |
Manage / list account passwords |
expired, mustchange, notify <>, warn |
|
report |
Command line interface to VISULOX Report |
title <>, mctitle <>, name <>, type <>, xslt <>, metadata <>, query <>, tframe <>, -from<>. -to <>, sql <>, lang <>, filename <>, mailto <>, mailsubject <>, maildescription <>, maildescriptionfile <>, archive <> |
|
reset |
Reset local cluster state |
|
|
restart |
Restart VISULOX Service (locally) Use with caution, all sg, sc and scx will be stopped. |
-service <>, -timeout <> |
|
start |
Start VISULOX Service (locally) |
debug |
|
status |
Query VISULOX status |
diskfree, features, load, monitor, next, servers, services, sessions, uptime, usage, users, workers, server <>, serverfilter <>, print, fields <> |
|
stop |
Stop VISULOX Service (locally) |
id <> |
|
store |
Manage the VISULOX store |
attach, changed, detach, disable, enable, extras, get, migrate, missing, next, put, status, slot <> |
|
support |
Gather information for support (-info: short report) |
directory <>, sys, dump, etc, rt, logs, net, integrity, config, tta |
|
transit |
Command line interface to VISULOX Transit Zone (list, import) |
list, import, owner, path, rtime |
|
version |
Display versions of installed VISULOX packages |
|
With -help or -? the detailed options for a basic command can be displayed.
If more parameters are needed for a command, the available options are always displayed by entering the basic command.
General commands
|
Parameter |
Description |
|---|---|
|
-format <value> |
Format of output (text,xml,csv,json,tcl) / Default: <text> |
|
-log <value> |
Set loglevel to error, verbose, info or debug / Default: <> |
|
-verbose |
More messages on stdout |
|
-run |
Run an operation (use only on application request) |
|
-stdin |
Get arguments from stdin |
|
-- |
Forcibly stop option processing |
|
-help / -? |
Display commands |
Usage
The following examples show the usage of the VISULOX Service Command:
visulox status
visulox license
visulox license replace -file <path to license file>
visulox status sessions
visulox online
visulox database query -sql "select vlxapplication from external_applications WHERE vlxapplicationgroups = '' AND vlxapplicationusers = ''" -format csv -raw
visulox transit import -path /tmp/file.txt -owner "o=Tarantella System Objects/cn=TestUser"
visulox transit list -owner "o=Tarantella System Objects/cn=TestUser"
visulox detach <vlx-node.domain>
VISULOX PORTAL ATTACH Command
visulox portal attach [<command-specific args>]
During installation /usr/sbin/visulox is created, which makes it possible to execute the VISULOX Service Command without using the whole path.
Available parameters
|
Command |
Description |
|---|---|
|
-all |
Install all (default) |
|
-portal |
Modify VISULOX PORTAL only, write configuration |
|
-examples |
setup examples |
|
-attach |
Attach VISULOX Service to VISULOX PORTAL Service
|
|
-expect |
Install expect script only |
|
-webtop |
Install webtop script only |
|
-jspconfig |
Create VISULOX JSP configuration file |
|
-apacheport <value> |
Local port to address Apache. If empty, discovered by webservice configuration <> |
|
-externalport <value> |
External port to address Apache. If empty, discovered by httpd.conf <> |
|
-serviceonline <value> |
Enable/disable Webtop Enhancements <true> |
|
-adminuser <value> |
UNIX user for the VISULOX webservice user in VISULOX PORTAL<vlxwebservice>
|
|
-adminuid <value> |
User ID for the VISULOX admin user in VISULOX PORTAL <610>
|
|
-adminpwd <value> |
Password for the VISULOX admin user in VISULOX PORTAL <generate> |
|
-adminou <value> |
OrgUnit for Webservice user cn=<host name>/<adminou> <> |
|
-version <value> |
Force VISULOX PORTAL version <> |
General commands
|
Parameter |
Description |
|---|---|
|
-format <value> |
Format of output (text,xml,csv,json,tcl) / Default: <text> |
|
-verbose |
More messages on stdout |
|
-run |
Run an operation (use only on application request) |
|
-- |
Forcibly stop option processing |
|
-help / -? |
Display commands |
Usage
The following examples show the usage of the attach command:
visulox portal attach
This command checks if login-ens is enabled. If this is the case a local user vlxwebservice (610) with group ttaserv (500) was added to the system. A password was also generated and stored secure.
VISULOX-PORTAL Command
visulox-portal <command> [<command-specific args>]
During installation /usr/sbin/visulox-portal is created, which makes it possible to execute the VISULOX PORTAL Service Command without using the whole path.
Available parameters
|
Command |
Description |
|---|---|
|
array |
Creates and manages arrays of VISULOX PORTAL servers |
|
config |
Edits array-wide and server-specific configuration |
|
discover |
Discover available resources |
|
drop |
Drop discovered resources |
|
emulatorsession |
Lists and controls emulator sessions |
|
gateway |
Manipulates the VISULOX GATEWAY store |
|
help |
Displays this list of commands |
|
info |
Shows status information for the local server |
|
object |
Manipulates objects in the datastore |
|
passcache |
Manipulates the password cache |
|
restart |
Restarts VISULOX PORTAL services |
|
role |
Configures role occupants and their extra webtop links |
|
security |
Controls security services, manages certificates |
|
serverrename |
Change the server's peer or external DNS name |
|
service |
Edits service object configuration |
|
start |
Starts VISULOX PORTAL services |
|
status |
Shows the current status of VISULOX PORTAL array members |
|
stop |
Stops VISULOX PORTAL services |
|
tokencache |
Manipulates the token cache |
|
version |
Displays versions of installed VISULOX PORTAL packages |
|
webserver |
Controls the VISULOX PORTAL Web Server |
|
webtopsession |
Lists and controls webtop sessions |
With visulox-portal <subcommand> --help the detailed options for a command can be displayed.
If more parameters are needed for a command, the available options are always displayed by entering the basic command.
Usage
The following examples show the usage of the VISULOX-PORTAL Command:
visulox-portal status
visulox-portal version
visulox-portal webtopsession list
visulox-portal array list
visulox-portal array join --primary <hostname> --secondary <hostname>
VISULOX-GATEWAY Command
visulox-gateway <command> [<command-specific args>]
During installation /usr/sbin/visulox-gateway is created, which makes it possible to execute the VISULOX GATEWAY Command without using the whole path.
Available parameters
|
Command |
Description |
|---|---|
|
start |
Start VISULOX GATEWAY |
|
stop |
Stop VISULOX GATEWAY |
|
restart |
Restart VISULOX GATEWAY |
|
config |
Configuration options: create, list, edit, enable, disable |
|
server |
Server options: add, add-array, remove, list, list-array |
|
status |
Show VISULOX GATEWAY status |
|
version |
Show VISULOX GATEWAY version |
|
sslcert |
Export, print sslcert |
|
sslkey |
Import, export sslkey |
|
cert |
Export the VISULOX GATEWAY certificate |
|
clientcert |
Import, list, remove clientcert |
|
key |
Import private key and its corresponding certificate |
|
patch |
Add, remove, list VISULOX GATEWAY patches |
|
connection |
List connections |
|
support |
VISULOX Gateway Support Report |
With visulox-gateway <subcommand> --help the detailed options for a command can be displayed.
If more parameters are needed for a command, the available options are always displayed by entering the basic command.
Usage
The following examples show the usage of the VISULOX-GATEWAY Command:
visulox-gateway status
visulox-gateway version
visulox-gateway server list
visulox-gateway config list
visulox-gateway server add-array --name osgd --serverurl <https://fqdn of the primary portal server>
Integrity-Check
The Integrity-Check is started automatically during installation of VISULOX to make sure, that all requirements are met for a properly running system.
However Integrity-Check can also be used in an already running environment for diagnose purpose.
Integrity-Check can be started via the visulox command:
visulox integrity
In the quiet mode no shell output and no log entries in /tmp/visulox-integrity.log are written.
Only the Integrity-Check exit code will be returned:
visulox integrity -quiet
Available Integrity-Check commands
|
Command |
Description |
|---|---|
|
-sw |
Check of online software status |
|
-vlx |
Check the VLX Services and cluster ports |
|
-sys |
Check the system environment |
|
-lib |
Check for missing libs |
|
-cmd |
Check command for missing libraries |
|
-disk |
Check disk |
|
-users |
Check VISULOX transit users |
|
-portal |
Check the VISULOX PORTAL Service |
|
-cert |
Check certificates within VISULOX and VISULOX PORTAL |
|
-store |
Check store |
|
-recorder |
Check recorder |
|
-datasources |
Check datasources |
|
-assignments |
Check datastore assignments and dynamic applications |
|
-license |
Check license |
|
-policies |
Check policies (VISULOX must be online) |
|
-index |
Check index |
|
-scripts |
Check scripts |
|
-x11forward |
Check x11forward |
|
-gate |
Check gate config |
|
|
Check mail configuration |
General commands
|
Command |
Description |
|---|---|
|
-format <value> |
Format of output (text,xml,csv,json,tcl) <text> |
|
-verbose |
More messages on stdout |
|
-- |
Forcibly stop option processing |
|
-help |
Print this message |
|
-? |
Print this message |
Usage
visulox integrity
Please wait ....
Integrity-Check: amitego engineering - in house license / beta2-3.1.1 / 2016-07-12 12:46:32 UTC
-----------------------------------------------------------------------------------
| option | cat | info | returnCode |
-----------------------------------------------------------------------------------
| -license | check | Evaluation | WARNING(2) |
| -sys | Script /opt/visulox/tools/filecheck.sh | not configured | WARNING(2) |
| -sys | Script /opt/visulox/tools/event.sh | not configured | WARNING(2) |
| -portal | 5.60 Warnings | see logfile | WARNING(2) |
-----------------------------------------------------------------------------------
ExitCode: WARNING
Check the warnings. For more information see /tmp/visulox-integrity.log
Only warnings and errors are displayed by default. All Integrity checks can be shown with the -verbose parameter.
visulox integrity -portal
---------------------------------------------------------------------------
| option | cat | info | returnCode |
---------------------------------------------------------------------------
| -portal | core | PORTAL 5.60 | SUCCESS(0) |
| -portal | connect | yes | SUCCESS(0) |
| -portal | webtop | ok | SUCCESS(0) |
| -portal | var | security-xsecurity ok | SUCCESS(0) |
| -portal | var | xpe-maxsessions ok | SUCCESS(0) |
| -portal | var | xpe-maxusers ok | SUCCESS(0) |
| -portal | role | administrator is root | WARNING(2) |
| -portal | array | P: mp-vlx32-ol7.tbsol.de | SUCCESS(0) |
| -portal | security-gateway | mp-vlx32-ol7.tbsol.de is good | SUCCESS(0) |
---------------------------------------------------------------------------
visulox integrity -cert
-------------------------------------------------------------------------------------------------
| option | cat | info | returnCode |
-------------------------------------------------------------------------------------------------
| -cert | SSL-CERT | issuer = /C=de/ST=de/O=amitego/CN=test.tbsol.de | SUCCESS(0) |
| -cert | SSL-CERT | subject = test.tbsol.de | SUCCESS(0) |
| -cert | SSL-CERT | serial = EA8628EF3B3A7F44 | SUCCESS(0) |
| -cert | SSL-CERT | from = 2016-12-16 09:12 | SUCCESS(0) |
| -cert | SSL-CERT | until = 2017-12-16 09:12 | SUCCESS(0) |
| -cert | SSL-CERT | remain = 360d 21h | SUCCESS(0) |
| -cert | PEER-CERT | issuer = /CN=mp-ol6u3-devel.tbsol.de CA Cert | SUCCESS(0) |
| -cert | PEER-CERT | subject = test.tbsol.de CA Cert | SUCCESS(0) |
| -cert | PEER-CERT | serial = 9F3D8E05D8800F22 | SUCCESS(0) |
| -cert | PEER-CERT | from = 2013-07-15 12:20 | SUCCESS(0) |
| -cert | PEER-CERT | until = 2023-07-13 12:20 | SUCCESS(0) |
| -cert | PEER-CERT | remain = 2395d 23h | SUCCESS(0) |
| -cert | SSL-CA | issuer = /C=de/ST=de/O=amitego/CN=test.tbsol.de | SUCCESS(0) |
| -cert | SSL-CA | subject = test.tbsol.de | SUCCESS(0) |
| -cert | SSL-CA | serial = EA8628EF3B3A7F44 | SUCCESS(0) |
| -cert | SSL-CA | from = 2016-12-16 09:12 | SUCCESS(0) |
| -cert | SSL-CA | until = 2017-12-16 09:12 | SUCCESS(0) |
| -cert | SSL-CA | remain = 360d 21h | SUCCESS(0) |
-------------------------------------------------------------------------------------------------
Integrity check with the parameter -cert shows the status of the both VISULOX PORTAL certificates. PEER-CERT and SSL-CERT.
The serials can be displayed on the local VISULOX GATEWAY with the command visulox-gateway server list and have to match with the serials of the VISULOX PORTAL certificates.
Integrity check shows a warning, when the lifetime is lower than 30 days or an error when the lifetime is expired.
visulox integrity -disk
Please wait ...Integrity-Check: VISULOX EVALUATION / xdevelopment / development
------------------------------------------------------------------------------------------
| option | cat | info | returnCode |
------------------------------------------------------------------------------------------
| -disk | Diskspace | ok in base (base threshold at 2.0GB has 39.67GB) | SUCCESS(0) |
| -disk | Diskspace | ok in var (var threshold at 5.0GB has 39.67GB) | SUCCESS(0) |
| -disk | Diskspace | ok in data (data threshold at 20.0GB has 39.67GB) | SUCCESS(0) |
| -disk | Diskspace | ok | SUCCESS(0) |
| -disk | DB Partition | ok fileserver.tbsol.de:/home/users/xxx | SUCCESS(0) |
| -disk | DB Partition | needs atleast 157.30MB - has 39.67GB | SUCCESS(0) |
------------------------------------------------------------------------------------------
ExitCode: SUCCESS
Among the checks also the diskspace for the database is checked. VLX_DATADIR must have at least 2.5 of size of the database available because VACUUM creates a copy of the database.
For example: a 4GB database needs 6 GB free diskspace. The diskspace is checked with integriy check.
Troubleshooting
-
VISULOX PORTAL connect failure
On servers, where VISULOX Service is installed together with VISULOX PORTAL Service, the connection to the VISULOX PORTAL Service can be checked with a small tool:/opt/visulox/lib/utils/sgd.tcl check Check connections --------------------------------------------------------------------------------------------------------------------------- | scottasessionid | scottasessionowner | --------------------------------------------------------------------------------------------------------------------------- | test-ol6u5.tbsol.de:1434362892796:1108252004568201775 | {.../_ens/o=Tarantella System Objects/ou=Visulox/cn=test-ol6u5} | ---------------------------------------------------------------------------------------------------------------------------
The following command reinstalls the necessary VISULOX PORTAL Service components on the server and mostly fixes connection errors:visulox portal attach -
VISULOX PORTAL Service warnings
More details can be found in visulox-integrity.log. The Java tuning values should be adjusted for the environment.
Mostly, the following settings will be adequate:-
tuning-jvm-initial: 1024
-
tuning-jvm-max: 2048
-
tuning-jvm-scale: 150
-
Adjust the values, with:
visulox-portal config edit --tuning-jvm-initial 2048
visulox-portal config edit --tuning-jvm-max 2048
visulox-portal config edit --tuning-jvm-scale 150
The following VISULOX PORTAL Service default values should also be checked:
-
-
sessions-timeout-always
-
sessions-timeout-session
-
webtop-session-idle-timeout
-
Changes of VISULOX PORTAL Service configurations is known to VISULOX after "visulox portal attach -portal".
-
"Administrator is root" warning
The warning can be disabled by adding a new administrator to VISULOX PORTAL:
useradd <name of the new portal administrator> passwd <name of the new portal administrator>visulox-portal object edit --name "/o=tarantella system objects/cn=administrator" --user adminvisulox portal attachDoing a VISULOX Integrity-Check again, the warning has disappeared. root can be removed from the administrators list.
-
event.sh and filecheck.sh missing
The files event.sh.template and filecheck.sh.template in /opt/visulox/tools/ must be copied to event.sh and filecheck.sh, if needed.
The correct permission (0550 / vlx:vlxgroup) has to be set as well for these files.
cd /opt/visulox/tools cp events.sh.tmplate events.sh cp filecheck.sh.template filecheck.sh chown vlx: events.sh filecheck.sh chmod 0550 events.sh filecheck.sh
Glossary
|
Expression |
Description |
|
3PA |
Third Party Authentication / 3rd Party Authentication |
|
Access Branding |
With Access Branding it is possible to display different login page designs for different users according to their access point. |
|
Access Management |
Enhanced VISULOX Concept for administrating the access of users |
|
AD |
Active Directory |
|
AIP |
Adaptive Internet Protocol: Client communication protocol from the VISULOX PORTAL Service |
|
Ambiguous login |
The situation where an authentication mechanism has found more than one match for a user and cannot distinguish between them without further information from the user |
|
Annotation |
A short text, that can be entered before a recorded session is confirmed, during a recorded session or in VISULOX Cockpit / Archive for closed sessions |
|
API |
Application Programming Interface |
|
Application server |
A server which provides applications, that can be accessed via the VISULOX PORTAL |
|
Application session |
See: emulator session |
|
Args |
The arguments an application is started with |
|
Assist / Assistance |
See: Assisting Cooperation |
|
Assisting cooperation |
Within the VISULOX Cockpit, the user can select an application and press assist to join the application. The owner of the application selects the cooperation mode |
|
Chapter |
A chapter equals 20 minutes film of a recorded session |
|
CLI |
Command Line Interface |
|
CMD |
The command / path an application is started with |
|
Cooperation |
When two or more users are watching or working with the same application in realtime on their own desktop |
|
Cooperation master |
The user, who has started the application (owner) will be the master of this application in a Cooperation |
|
Cooperation member |
A user, who is not owner of an application and who is not able to switch the cooperation modes |
|
Cooperation modes |
On hold: Member is assigned to a Cooperation, but does not participate Observe: Member is able to watch the Cooperation application, but can not interact Interact: Member can interact with the application |
|
CP |
Short form for Cooperation |
|
Datastore |
Internal VISULOX PORTAL Service database, where all defined objects (users, hosts, applications) are stored. A VISULOX PORTAL Array replicates the datastore between all members simultaneously |
|
DMZ |
Demilitarized zone (Perimeter zone) |
|
DSI |
Directory Service Integration |
|
Dual Control |
Cooperation enforcing a real four-eye-principle |
|
ELU |
Extended License Usage - When ELU has expired, its not possible to start more recorders or display more users than allowed under MD / Status, max users / recorders |
|
Emulator session |
The running session, when an application is started with the Workspace on an application server |
|
Expect script |
VISULOX PORTAL connection script started during the launch of an application |
|
External DNS name |
The name by which an VISULOX PORTAL Server is known to a client device. A VISULOX PORTAL Server can have multiple external DNS names. |
|
File Exchange |
File Transfer web access for transferring files between a client and the Transit Zone for users without access to the VISULOX PORTAL |
|
File Transfer Client |
VISULOX Component for transferring files securely from Transit Zone to application servers and back |
|
Film |
Summary of the recorded chapters |
|
Forced authentication |
When VISULOX PORTAL prompts for a user name or password, by displaying an authentication dialog box
|
|
FQDN |
Fully Qualified Domain Name - The full name of a system, containing its hostname and its domain name.
|
|
Group Access |
Group Access is used to define an Access Policy for a specific list of users. This is needed when users are working together in a project and the project is represented by a group object in the repository |
|
Host object |
Host objects can be assigned to File Transit, Command Guard and Command Connect groups. |
|
Host Connect |
See: VISULOX Command Connect / VISULOX Command Guard |
|
IAR |
Intelligent Array Routing |
|
ICA |
Independent Computing Architecture: Client communication protocol from Citrix |
|
Integrity-Check |
Tool to check the VISULOX components and services |
|
Internal / external message |
The VISULOX Service supplies an external message for the login page and an internal message for the user's Workspace |
|
Kiosk mode |
VISULOX PORTAL display mode, where an application is displayed in full-screen |
|
LDAP |
Lightweight Directory Access Protocol |
|
LDAPS |
Lightweight Directory Access Protocol over SSL. Used for secure connections to an LDAP directory. |
|
LID |
Short form for License ID - Contains the date, the license started |
|
Management Console |
See: VISULOX Cockpit |
|
MFA |
Multi Factor Authentication |
|
Native Client |
A VISULOX PORTAL component that can be installed on client devices. The client maintains communication with the VISULOX PORTAL Server and is required to run applications
|
|
NEP |
Short form for Network Entry Point |
|
Network Entry Point |
See: RIP |
|
NFS |
Network File System |
|
Notifications |
Implemented notification system for access, Workspace / File Transfer and emulator sessions in the VISULOX Services |
|
Object |
A self-contained entity, defined by a number of attributes and values. VISULOX PORTAL Objects have different types, such as an X application.
|
|
One Time Passcode |
The One Time Passcode is used for authentication and will become invalid after usage. A provided OTP is based on a secret key and the time via a smartphone APP |
|
Organization object |
A VISULOX PORTAL Object used to represent the top level of an organizational hierarchy.
|
|
Organizational hierarchy |
The collection of objects in the VISULOX PORTAL Datastore, descending from one or more organization or domain component objects. Represents the collection of people, application servers, and applications within an organization. |
|
Organizational unit object |
A VISULOX PORTAL Object used to distinguish different departments, sites, or teams in an organizational hierarchy. Organizational unit (OU) objects can be contained in an organization or domain component object. Organizational unit objects have an OU= naming attribute |
|
OTP |
Short form for One Time Passcode |
|
Peer DNS name |
The name by which an VISULOX PORTAL Server is known to other VISULOX PORTAL Servers in the same array |
|
Primary server |
The VISULOX PORTAL Server that acts as the authoritative source for global information, and maintains the definitive copy of the VISULOX PORTAL Datastore |
|
RDP |
Remote Desktop Protocol: Client communication protocol from Microsoft |
|
Remote IP |
Remote IP address, the information, from where a client request is coming |
|
Report |
The VISULOX Service is collecting data about workspacesessions, emulatorsessions, recordings and cooperations. The information can be clearly arranged in reports. In VISULOX Cockpit a variety of possible reports can be created on several pages |
|
Resume |
To redisplay an application session that has been suspended. See also: suspend |
|
RIP |
Short form for Remote IP address |
|
RVA |
Remote Vendor Access |
|
S & M |
Short form for Support and Maintenance |
|
Secondary server |
An array member that is not the primary server. The primary server replicates information to secondary servers. |
|
Session |
The VISULOX PORTAL generates a session for any X11 or RDP application, which has an unique session ID |
|
SIEM |
Security Information and Event Management |
|
SOX |
Short form for Sarbanes-Oxley Act |
|
SSL certificate |
A digital passport that establishes credentials on the web. In VISULOX PORTAL Service, allows client devices to trust the identity of a VISULOX PORTAL Server |
|
Suspend |
To pause an application session. A suspended application is not closed, it can be resumed. See also: resume |
|
TAP |
Short form for Temporary Access PIN, part of the Multi Factor Authentication (MFA) |
|
TCC |
Short form for Tarantella Client Component: Component for login into the VISULOX PORTAL via Native Client |
|
TCL |
Programming Language. Most of the VISULOX products are based on TCL |
|
Temporary Access PIN |
VISULOX method for the Multi Factor Authentication (MFA) |
|
TFN |
Tarantella Full Naming, X.500 format to address a VISULOX PORTAL object |
|
Transit Zone |
Zone, where files are transferred from/to application servers/clients |
|
VAP |
Short form for Virtual Access Point |
|
Virtual Access Point |
VISULOX method to get an independent URL of the VISULOX Access Nodes for reliability and Workspace balancing |
|
VISULOX Access Node |
Node running the VISULOX PORTAL Service and the VISULOX Service |
|
VISULOX Base |
Single VISULOX Node |
|
VISULOX Cluster |
Two or more VISULOX Nodes, that are joined together because of scalability, redundancy and load balancing |
|
VISULOX Cockpit |
Central VISULOX application to control sessions, access, recording, cooperations and to generate reports |
|
VISULOX Command Connect |
VISULOX component, which provides the possibility to connect to multiple hosts and to open an X-Client on these hosts. The connection method can be SSH, RDP or telnet. Former: Host Connect |
|
VISULOX Command Guard |
VISULOX component, which provides the possibility to connect to multiple hosts and to open an X-Client on these hosts Command Guard has command level controls for the application. It allows and denies the usage of certain commands by the user Additionally server side scripts can be issued either to multiple endpoints or to a single one |
|
VISULOX Common Access Platform |
The whole environment, that is built with the VISULOX GATEWAY, VISULOX Portal Service, VISULOX Service and databases |
|
VISULOX Data |
VISULOX Database and VISULOX Filestore |
|
VISULOX Filestore |
File system which stores the films. 5 MByte per user and per hour. Recommended for VISULOX is a local disk with 150-250 GB, for VISULOX Archive Node depending on the lifetime of films, up to x TB on a NAS/SAN storage |
|
VISULOX GATEWAY |
The VISULOX GATEWAY is a proxy server designed to be deployed in front of a VISULOX PORTAL Array in a demilitarized zone (DMZ). This enables the VISULOX PORTAL Array to be located on the internal network of an organization. Additionally, all connections can be authenticated in the DMZ before any connections are made to the VISULOX PORTAL servers in the array.
|
|
VISULOX Host Connect |
See: VISULOX Command Connect |
|
VISULOX Hotfix |
Tool to check the software status in the cluster, backup and apply hotfixes |
|
VISULOX keystroke recording
|
In this recording mode all user keyboard interactions are registered and can be checked for unwanted entries (analyzing engine) |
|
VISULOX Node |
Node running the VISULOX Service to control sessions, films and recorders |
|
VISULOX PAM |
VISULOX Privileged Access Management |
|
VISULOX PORTAL Array |
Two or more VISULOX Access Nodes, that are joined together because of scalability, redundancy and load balancing |
|
VISULOX PORTAL Benchmark |
Tool to create a defined number of demo-users, who log into the VISULOX PORTAL and start recorded applications automatically. All settings can be configured easily within a GUI |
|
VISULOX PORTAL Console |
Web-based management console for the VISULOX PORTAL Service (Former: Administration Console) |
|
VISULOX PORTAL Web Server |
A pre-built web server installed and configured along with the VISULOX PORTAL Service, contains Apache, mod_ssl for HTTPS support, and Tomcat for Java Servlet and JSP support |
|
VISULOX PORTAL Web Services |
An API collection that allows developers to build their own applications to work with the VISULOX PORTAL Service. The APIs can be used to authenticate users, launch applications, and interact with the VISULOX PORTAL Datastore |
|
VISULOX Revision Server
|
VISULOX Node which replicates the production database into Revision Server database and transfers the films from the production filestore into the Revision Server filestore (also known as Archive Server) |
|
VISULOX Service Group |
See: VISULOX Cluster |
|
VISULOX Short Support Report |
A Short Support Report to send via eMail created with visulox support -info. The Short Support Report should be sent to the VISULOX Support Team every time a new Support Request is opened |
|
VISULOX Support Report |
Package generated by the visulox support command, containing all information, necessary for support |
|
VISULOX Transit Area |
File Transfer component embedded in the Workspace to transfer files between client and Transit Zone |
|
VISULOX Transit Mapping |
To setup the VISULOX Transit Zone on Unix application servers, that are not a VISULOX Node, an RPM file is available for installation. |
|
VISULOX Videolog Player |
Player to view the recorded films inside the VISULOX Cockpit or checked out films in a browser |
|
VISULOX Webservice User |
Each VISULOX Service needs this user in the datastore to read the webservices on the VISULOX Access Nodes. The VISULOX webservice user has to be setup once in the datastore |
|
VISULOX_Setup.xls |
Excel-sheet, which has to be filled out in the planning phase by the responsible project leader, together with the amitego consultant |
|
vlxMode |
VISULOX variable set in the VISULOX PORTAL Console |
|
VLX Password SelfService |
Active Directory (AD) and Oracle Unified Directory (OUD) users are able to change their password by themselves with this appliction assigned. |
|
Webtop |
In the current version, the Webtop is called the Workspace. A Workspace is the term used to describe a user's applications, documents, and desktops. See: Workspace |
|
WM |
Short form for Window Manager |
|
Workspace |
The Workspace is displayed after logging into the VISULOX PORTAL. It is a special web page, that lists the applications that are assigned to the user |
|
Workspace balancing |
VISULOX load balancing mechanism including a virtual access point |
|
Workspace session |
The running session, after a user has logged into the VISULOX PORTAL via browser or Native Client |
|
X11 forwarding |
The process of forwarding, or tunneling, the windows of a remotely started X application to a client desktop |
|
X Window System |
A distributed window system for UNIX platform operating systems, based on the X11 protocol. Also called X11, or X Windows |
|
X.509 certificate |
See: SSL certificate |