One Identity Safeguard for Privileged Sessions 6.0 Series User manual

OneIdentitySafeguardforPrivileged
Sessions6.0
InstallationGuide

Copyright 2020 One Identity LLC.
ALL RIGHTS RESERVED.
Thisguidecontainsproprietaryinformationprotectedbycopyright.Thesoftwaredescribedinthisguide
isfurnishedunderasoftwarelicenseornondisclosureagreement.Thissoftwaremaybeusedorcopied
onlyinaccordancewiththetermsoftheapplicableagreement.Nopartofthisguidemaybereproduced
ortransmittedinanyformorbyanymeans,electronicormechanical,includingphotocopyingand
recordingforanypurposeotherthanthepurchaser’spersonalusewithoutthewrittenpermissionof
OneIdentityLLC.
TheinformationinthisdocumentisprovidedinconnectionwithOneIdentityproducts.Nolicense,
expressorimplied,byestoppelorotherwise,toanyintellectualpropertyrightisgrantedbythis
documentorinconnectionwiththesaleofOneIdentityLLCproducts.EXCEPTASSETFORTHINTHE
TERMSANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,
ONEIDENTITYASSUMESNOLIABILITYWHATSOEVERANDDISCLAIMSANYEXPRESS,IMPLIEDOR
STATUTORYWARRANTYRELATINGTOITSPRODUCTSINCLUDING,BUTNOTLIMITEDTO,THE
IMPLIEDWARRANTYOFMERCHANTABILITY,FITNESSFORAPARTICULARPURPOSE,ORNON-
INFRINGEMENT.INNOEVENTSHALLONEIDENTITYBELIABLEFORANYDIRECT,INDIRECT,
CONSEQUENTIAL,PUNITIVE,SPECIALORINCIDENTALDAMAGES(INCLUDING,WITHOUT
LIMITATION,DAMAGESFORLOSSOFPROFITS,BUSINESSINTERRUPTIONORLOSSOF
INFORMATION)ARISINGOUTOFTHEUSEORINABILITYTOUSETHISDOCUMENT,EVENIF
ONEIDENTITYHASBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.OneIdentitymakesno
representationsorwarrantieswithrespecttotheaccuracyorcompletenessofthecontentsofthis
documentandreservestherighttomakechangestospecificationsandproductdescriptionsatany
timewithoutnotice.OneIdentitydoesnotmakeanycommitmenttoupdatetheinformation
containedinthisdocument.
Ifyouhaveanyquestionsregardingyourpotentialuseofthismaterial,contact:
OneIdentityLLC.
Attn:LEGALDept
4PolarisWay
AlisoViejo,CA92656
RefertoourWebsite(http://www.OneIdentity.com)forregionalandinternationalofficeinformation.
Patents
OneIdentityisproudofouradvancedtechnology.Patentsandpendingpatentsmayapplytothis
product.Forthemostcurrentinformationaboutapplicablepatentsforthisproduct,pleasevisitour
websiteathttp://www.OneIdentity.com/legal/patents.aspx.
Trademarks
OneIdentityandtheOneIdentitylogoaretrademarksandregisteredtrademarksofOneIdentity
LLC.intheU.S.A.andothercountries.ForacompletelistofOneIdentitytrademarks,pleasevisit
ourwebsiteatwww.OneIdentity.com/legal.Allothertrademarksarethepropertyoftheir
respectiveowners.
Legend
WARNING: A WARNING icon highlights a potential risk of bodily injury or property
damage, for which industry-standard safety precautions are advised. This icon is
often associated with electrical hazards related to hardware.
CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if
instructions are not followed.
SPSInstallationGuide
Updated-February2020
Version-6.0

Contents
Preface 5
Summaryofcontents 5
Introduction 6
Package contents inventory 7
One Identity Safeguard for Privileged Sessions Hardware Installation
Guide 8
InstallingtheSPShardware 8
InstallingtwoSPSunitsinHAmode 11
Hardware specifications 12
OneIdentitySafeguardforPrivilegedSessions(SPS)T1 12
OneIdentitySafeguardforPrivilegedSessions(SPS)T4 13
OneIdentitySafeguardforPrivilegedSessions(SPS)T10 14
OneIdentitySafeguardforPrivilegedSessions(SPS)Appliance3000 15
OneIdentitySafeguardforPrivilegedSessions(SPS)Appliance3500 16
One Identity Safeguard for Privileged Sessions Software Installation Guide18
InstallingtheSPSsoftware 18
One Identity Safeguard for Privileged Sessions VMware Installation Guide 21
InstallingSPSunderVMwareESXi/ESX 21
LimitationsofSPSunderVMware 22
One Identity Safeguard for Privileged Sessions Hyper-V Installation Guide 24
LimitationsofSPSunderHyper-V 24
InstallingSPSunderHyper-V 25
Installing One Identity Safeguard for Privileged Sessions as a Kernel-
based Virtual Machine 27
InstallingSPSasaKernel-basedVirtualMachine 27
LimitationsofSPSunderKVM 28
Deploying One Identity Safeguard for Privileged Sessions from the Azure
Marketplace 30
Prerequisites 30
SPS 6.0 Installation Guide
3

Limitations 31
DeployOneIdentitySafeguardforPrivilegedSessionsfromtheMicrosoftAzure
Marketplace 33
HighAvailabilityandredundancyinMicrosoftAzure 35
Redundancy 35
HighAvailability 35
Virtual appliance maintenance 36
ModifyingthedisksizeofaSPSvirtualappliance 36
About us 37
Contactingus 37
Technicalsupportresources 37
SPS 6.0 Installation Guide
4

1
Preface
WelcometotheOneIdentitySafeguardforPrivilegedSessions6.0InstallationGuide.
ThisdocumentdescribeshowtosetuptheOneIdentitySafeguardforPrivilegedSessions
(SPS)hardware,andhowtoinstallSPSoncertifiedhardwareorasavirtualappliance.
Summary of contents
IntroductionprovidesbackgroundinformationanddescribesthemainpurposeoftheOne
IdentitySafeguardforPrivilegedSessionsInstallationGuide.
PackagecontentsinventoryliststhecontentsofthepackageyoureceivewiththeOne
IdentitySafeguardforPrivilegedSessions(SPS).
OneIdentitySafeguardforPrivilegedSessionsHardwareInstallationGuidedescribeshow
tosetuptheSPShardware.
HardwarespecificationsdescribesthehardwarespecificationsoftheSPSappliance.
OneIdentitySafeguardforPrivilegedSessionsSoftwareInstallationGuidedescribeshow
toinstallSPSoncertifiedhardware.
OneIdentitySafeguardforPrivilegedSessionsVMwareInstallationGuidedescribeshowto
installSPSasaVMwarevirtualappliance.
OneIdentitySafeguardforPrivilegedSessionsHyper-VInstallationGuidedescribeshowto
installOneIdentitySafeguardforPrivilegedSessions(SPS)asaHyper-Vvirtualappliance.
InstallingOneIdentitySafeguardforPrivilegedSessionsasaKernel-basedVirtualMachine
describeshowtoinstallOneIdentitySafeguardforPrivilegedSessions(SPS)asaKernel-
basedVirtualMachine.
DeployingOneIdentitySafeguardforPrivilegedSessionsfromtheAzureMarketplace
describeshowtoinstallOneIdentitySafeguardforPrivilegedSessions(SPS)fromthe
MicrosoftAzureMarketplace.
SPS 6.0 Installation Guide
Preface
5

2
Introduction
Theaimofthisguideistoprovidedetailed,step-by-stepinstructionsonhowtosetupand
installOneIdentitySafeguardforPrivilegedSessionsonunpackingitandanysubsequent
occasionsthatmightrequirethere-installationoftheproduct.
NotethatthecontentsofthisdocumentwerepreviouslyincludedintheAdministration
Guide.Thisstandaloneguidewascreatedto:
lImprovehowinformationisorganizedintheOneIdentitySafeguardforPrivileged
Sessionsdocumentationset.
lMakeiteasierforuserstofindinformationrelevanttotheirroles,context,andhow
theyusetheproduct.
SPS 6.0 Installation Guide
Introduction
6

3
Package contents inventory
Carefullyunpackallservercomponentsfromthepackingcartons.Thefollowingitems
shouldbepackagedwiththeOneIdentitySafeguardforPrivilegedSessions:
lAOneIdentitySafeguardforPrivilegedSessionsappliance,pre-installedwiththe
latestOneIdentitySafeguardforPrivilegedSessionsfirmware.
lOneIdentitySafeguardforPrivilegedSessionsaccessorykit,includingthefollowing:
lOne Identity Safeguard for Privileged Sessions 6.0 Packaging Checklist
(this document).
lGPLv2.0license.
lRackmounthardware(dependingonappliancetype).
lPowercable.
ThedefaultBIOSandIPMIpasswordsareinthedocumentation.
SPS 6.0 Installation Guide
Package contents inventory
7

4
One Identity Safeguard for
Privileged Sessions Hardware
Installation Guide
ThisdocumentdescribeshowtosetuptheOneIdentitySafeguardforPrivilegedSessions
(SPS)hardware.Refertothefollowingdocumentsforstep-by-stepinstructions:
lSafeguard Sessions Appliance 3000:seetheSC113 Chassis Series User's Manual,
Chapter 6: Rack Installation,availableonlineat
https://www.supermicro.com/manuals/chassis/1U/SC113.pdf.
lSafeguard Sessions Appliance 3500:seetheSuperServer 1029U-T Series User's
Manual, Chapter 2: Server Installation,availableonlineat
https://www.supermicro.com/manuals/superserver/1U/MNL-1973.pdf.
lFordetailsonhowtoinstallasingleSPSunit,seeInstallingtheSPShardware.
lFordetailsonhowtoinstallatwoSPSunitsinhighavailabilitymode,seeInstalling
twoSPSunitsinHAmode.
Installing the SPS hardware
ThefollowingdescribeshowtoinstallasingleSPSunit.
To install a single SPS unit
1. UnpackSPS.
2. (Optional)InstallSPSintoarackwiththesliderails.Sliderailsareavailableforall
SPSappliances.
3. Connectthecables.
a. ConnecttheEthernetcablefacingyourLANtotheEthernetconnectorlabeled
as1.Thisisphysicalinterface1ofSPS.Thisinterfaceisusedfortheinitial
configurationofSPS,andformonitoringconnections.(Fordetailsonthe
rolesofthedifferentinterfaces,see"Networkinterfaces"inthe
AdministrationGuide.)
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
8

b. (Optional)TouseSPSacrossmultiplephysical(L1)networks,youcanconnect
additionalnetworksusingphysicalinterface2(Ethernetconnector2)and
physicalinterface3(Ethernetconnector3).
c. Connect an Ethernet cable that you can use to remotely support the SPS
hardware to the IPMI interface of SPS. For details, see the following
documents:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMI
User'sGuide.
CAUTION:
Connect the IPMI before plugging in the power cord. Failing to
do so will result in IPMI failure.
CAUTION: SECURITY HAZARD!
The IPMI interface, like all out-of-band management interfaces,
has known vulnerabilities that One Identity cannot fix or have
an effect on. To avoid security hazards, One Identity
recommends that you only connect the IPMI interface to well-
protected, separated management networks with restricted
accessibility. Failing to do so may result in an unauthorized
access to all data stored on the SPS appliance. Data on the
appliance can be unencrypted or encrypted, and can include
sensitive information, for example, passwords, decryption keys,
private keys, and so on.
For more information, see Best Practices for managing servers
with IPMI features enabled in Datacenters.
NOTE:
TheadministratorofSPSmustbeauthorizedandabletoaccesstheIPMI
interfaceforsupportandtroubleshootingpurposesincasevendor
supportisneeded.
ThefollowingportsareusedbytheIPMIinterface:
lPort623(UDP):IPMI(cannotbechanged)
lPort5123(UDP):floppy(cannotbechanged)
lPort5901(TCP):videodisplay(configurable)
lPort5900(TCP):HID(configurable)
lPort5120(TCP):CD(configurable)
lPort80(TCP):HTTP(configurable)
d. (Optional)ConnecttheEthernetcableconnectingSPStoanotherSPSnodeto
theEthernetconnectorlabeledas4.Thisisthehighavailability(HA)interface
ofSPS.(Fordetailsontherolesofthedifferentinterfaces,see"Network
interfaces"intheAdministrationGuide.)
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
9

e. (Optional)TheSafeguardSessionsAppliance3500isequippedwithadual-port
SFP+interfacecardlabeledAandB.Optionally,connectasupportedSFP+
moduletotheseinterfaces.
NOTE:
Foralistofcompatibleconnectors,seeLinuxBaseDriverfor10Gigabit
IntelEthernetNetworkConnection.NotethatSFPtransceiversencoded
fornonIntelhostsmaybeincompatiblewiththeIntel82599EBhost
chipsetfoundinSPS.
4. Poweronthehardware.
5. ChangetheBIOSpasswordontheOneIdentitySafeguardforPrivilegedSessions.
ThedefaultpasswordisADMINorchangeme,dependingonyourhardware.
6. ChangetheIPMIpasswordontheOneIdentitySafeguardforPrivilegedSessions.
ThedefaultpasswordisADMINorchangeme,dependingonyourhardware.
NOTE:
EnsurethatyouhavethelatestversionofIPMIfirmwareinstalled.Youcan
downloadtherelevantfirmwarefromtheOneIdentityKnowledgebase.
TochangetheIPMIpassword,connecttotheIPMIremoteconsole.
NOTE:
IfyouencounterissueswhenconnectingtotheIPMIremoteconsole,addthe
DNSnameortheIPaddressoftheIPMIinterfacetotheexceptionlist
(whitelist)oftheJavaconsole.Fordetailsonhowtodothis,seetheJavaFAQ
entrytitledHowcanIconfiguretheExceptionSiteList?.
7. Followingboot,SPSattemptstoreceiveanIPaddressautomaticallyviaDHCP.Ifit
failstoobtainanautomaticIPaddress,itstartslisteningforHTTPSconnectionson
the192.168.1.1IPaddress.
ToconfigureSPStolistenforconnectionsonacustomIPaddress,completethe
followingsteps:
a. AccessSPSfromthelocalconsole,andloginwithusernamerootand
passworddefault.
b. SelectShells > Core shellintheConsoleMenu.
c. ChangetheIPaddressofSPS:
ifconfig eth0 <IP-address> netmask 255.255.255.0
Replace<IP-address>withanIPv4addresssuitableforyourenvironment.
d. Setthedefaultgatewayusingthefollowingcommand:
route add default gw <IP-of-default-gateway>
Replace<IP-of-default-gateway>withtheIPaddressofthedefaultgateway.
e. Typeexit,thenselectLogoutfromtheConsoleMenu.
8. ConnecttotheSPSwebinterfacefromaclientmachineandcompletetheWelcome
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
10

Wizardasdescribedin"TheWelcomeWizardandthefirstlogin"inthe
AdministrationGuide.
NOTE:
TheAdministrationGuideisavailableontheSafeguardforPrivilegedSessions
Documentationpage.
Installing two SPS units in HA mode
ThefollowingdescribeshowtoinstallSPSwithhighavailabilitysupport.
To install SPS with high availability support
1. ForthefirstSPSunit,completeInstallingtheSPShardware.
2. ForthesecondSPSunit,completeSteps1-3ofInstallingtheSPShardware.
3. ConnectthetwounitswithanEthernetcableviatheEthernetconnectorslabeledas4.
4. Poweronthesecondunit.
5. ChangetheBIOSandIPMIpasswordsonthesecondunit.Thedefaultpasswordis
ADMINorchangeme,dependingonyourhardware.
6. ConnecttotheSPSwebinterfaceofthefirstunitfromaclientmachineandenable
thehighavailabilitymode.NavigatetoBasic Settings > High Availability .Click
Convert to Cluster,thenreloadthepageinyourbrowser.
7. ClickReboot Cluster.
8. Waituntiltheslaveunitsynchronizesitsdisktothemasterunit.Dependingonthe
sizeoftheharddisks,thismaytakeseveralhours.Youcanincreasethespeedofthe
synchronizationviatheSPSwebinterfaceatBasic Settings > High Availability
> DRBD sync rate limit.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
11

5
Hardware specifications
TheOneIdentitySafeguardforPrivilegedSessions(SPS)appliancesarebuiltonhigh
performance,energyefficient,andreliablehardwarethatareeasilymountedintostandard
rackmounts.
ThefollowingsectionsprovidedetailedinformationofSPSappliances.
One Identity Safeguard for Privileged
Sessions (SPS) T1
Unit:1
Number of disk slots:2(internalonly)
Redundant PSU:0
Mainboard:X8SIL-F
Chipset:Intel3420
NIC:
l2xIntel®82574LGigabitEthernetController
l1xSupermicroAOC-SG-i2DualGbEPCI-Ex4
IPMI:NuvotonWPCM450,SMT(Latestver.:3.16)
CPU:1xIntelXeonX34302.4GHzQuad
RAM:2x4GBSamsungDDR3-1600ECC/UnbufferedSTD
HDD:2xSeagateConstellationES.31TBSATAIII
RAID:SoftwareRAID
RAID type:RAID1
Chassis (H x W x D):43mmx426mmx356mm(1U)
Chassis (H x W x D):1,7"x16,8"x14,0"(1U)
Chassis:SuperChassis512-200B
SPS 6.0 Installation Guide
Hardware specifications
12

Weight:7,7kg/17lbs
Wattage IDLE:50Watt
Wattage LOAD:243Watt
System MTBF (h):42216hours
Electrical:100-240V,60-50Hz,4-2Amp
Operating temperature:10°Cto35°C
Non-operating temperature:-40°Cto70°C
Humidity range:8%to90%
Non-operating humidity:5%to95%
Compliant to:CE,cCSAus,FCC,VCCI-A
Linktomanufacturerdocumentation
One Identity Safeguard for Privileged
Sessions (SPS) T4
Unit:1
Number of disk slots:4
Redundant PSU:1
Mainboard:X9SPU-F
Chipset:IntelC216ExpressPCH
NIC
l2xIntel®82574LGigabitEthernetController
l1xSupermicroAOC-SG-i2DualGbEPCI-Ex4
IPMI:NuvotonWPCM450RA0BX,SMT(Latestver.:3.38)
CPU:1xIntelXeonE3-1275v23.5GHzQuad
RAM:2x4GBSamsungDDR3-1600ECC/UnbufferedSTD
HDD:4xSeagateConstellationES.32TBSATAIII
RAID:
lLSIMegaRAIDSAS9271-4iSGL
l+LSILSIiBBU09BBU
RAID type:RAID10
Chassis (H x W x D): 43mmx437mmx650mm
Chassis: (H x W x D)1,7"x17,2"x25,6"
Chassis:SuperChassis815TQ-R500UB
SPS 6.0 Installation Guide
Hardware specifications
13

Weight:16,5kg/38lbs
Wattage IDLE:60Watt
Wattage LOAD:547Watt
System MTBF (h):69667hours
Electrical:100-240V,60-50Hz,6.2-2.6Amp
Operating temperature:10°Cto35°C
Non-operating temperature:-40°Cto70°C
Humidity range:8%to90%
Non-operating humidity:5%to95%
Compliant to:CE,cCSAus,FCC,VCCI-A
Linktomanufacturerdocumentation
One Identity Safeguard for Privileged
Sessions (SPS) T10
Unit:2
Number of disk slots:12
Redundant PSU:1
Mainboard:X9DRW-7TPF+
Chipset:Intel®C602J
NIC:
l1xIntel®82599DualPort10GSFP+
l1xIntel®i350DualPortGigabitEthernet
l1xSupermicroAOC-SG-i2DualGbEPCI-Ex4
IPMI:NuvotonWPCM450BMC,SMT(Latestver.:3.39)
CPU:2xIntelXeonE5-2630v22.6GHz
RAM:8x4GBSamsungDDR3-1600ECC/UnbufferedSTD
HDD:13xSeagateConstellation.2SAS1TB2.5"
RAID:
lLSI2208(1GBcache)
l+SupermicroBTR-0022L-LSI00279BBU
l+ChenbroCK22803Expander
RAID type:RAID50
Chassis (H x W x D):89mmx437mmx684mm
SPS 6.0 Installation Guide
Hardware specifications
14

Chassis (H x W x D):3,5"x17,2"x26,93"
Chassis:SuperChassis219A-R920WB
Weight:23,6kg/52lbs
Wattage IDLE:106Watt
Wattage LOAD:987Watt
System MTBF (h):36683hours
Electrical:100-240V,50-60Hz,11-4.5Amp
Operating temperature:10°Cto35°C
Non-operating temperature:-40°Cto70°C
Humidity range:8%to90%
Non-operating humidity:5%to95%
Compliant to:CE,cCSAus,FCC,VCCI-A
Linktomanufacturerdocumentation
One Identity Safeguard for Privileged
Sessions (SPS) Appliance 3000
Unit:1U
Drive Bays:8x2.5
Redundant PSU:Yes
NIC:4x1GBase-TEthernetports
IPMI:version2.0
CPU:IntelXeonE3-12753.60Ghz4Core
Memory:2x16GB
HDD:4x2TB
RAID:LSIMegaRAIDSAS9361-4i
RAID Type:RAID5
Usable Storage:6TB
Chassis (W x H x D):17.2"x1.7"x23.5"(437x43x650mm)
Weight:35lbs(15.9kg)
Wattage IDLE / LOAD:N/A
Electrical:500WRedundantAC-DCPowerSupplies
Operating Temperature:5°Cto35°C(41°Fto95°F)
Non-operating Temperature:-40°Cto60°C(-40°Fto140°F)
Humidity Range:8%to90%(non-condensing)
SPS 6.0 Installation Guide
Hardware specifications
15

Non-operating Humidity:5%to95%(non-condensing)
Compliant to:CE,cCSAus,FCC,VCCI-A
Linktomanufacturerdocumentation
List of appliance ports
1. Redundantpowersupplies
2. Serialport
3. 2xUSBports
4. 2xUSBports
5. 2xRJ45GbEEthernetports
6. VGAport
7. 4x1GBase-TEthernetports
8. DedicatedIPMILANport
One Identity Safeguard for Privileged
Sessions (SPS) Appliance 3500
Unit:1U
Drive Bays:10x2.5
Redundant PSU:Yes
NIC:
l2x1GBase-TEthernetports
l2x10GBase-TEthernetports
IPMI:version2.0
CPU:2xIntelXeonSilver41102.1Ghz8Core
Memory:8x8GB
HDD:8x2TB+1HotSpare
RAID:
SPS 6.0 Installation Guide
Hardware specifications
16

lLSIAvagoCacheVaultPowerModule02(CVPM02)Kit
l1xBroadcomMegaRAIDSAS9361-16i+
RAID Type:RAID50
Usable Storage:12TB
Chassis (W x H x D):17.2"x1.7"x28.5"(437x43x724mm)
Weight:41lbs(18.6kg)
Wattage IDLE / LOAD:N/A
Electrical:750WRedundantAC-DCPowerSupplies
Operating Temperature:10°Cto35°C(50°F~95°F)
Non-operating Temperature:-40°Cto60°C(-40°Fto140°F)
Humidity Range:8%to90%(non-condensing)
Non-operating Humidity:5%to95%(non-condensing)
Compliant to:CE,cCSAus,FCC,VCCI-A
Linktomanufacturerdocumentation
NOTE:TheOneIdentitySafeguardforPrivilegedSessions(SPS)Appliance3500is
equippedwithadual-port10Gbitinterface.ThisinterfacehasSFP+connectors(notRJ-
45)labeledAandB,andcanbefoundrightoftheLabel1and2Ethernetinterfaces.If
youwantfastercommunication,forexample,incaseofhighdataload,youcanconnect
uptotwo10GSFP+transceivers.Thesetransceiversarenotshippedwiththeoriginal
packageandhavetobepurchasedseparately.
List of appliance ports
1. Redundantpowersupplies
2. 2xRJ4510GbEEthernetports
3. 2x3.0USBports
4. DedicatedIPMILANport
5. Serialport
6. VGAport
7. 2x1GBase-TEthernetports
8. 2xSFP+10GbEports
SPS 6.0 Installation Guide
Hardware specifications
17

6
One Identity Safeguard for
Privileged Sessions Software
Installation Guide
ThisdocumentdescribeshowtoinstalltheOneIdentitySafeguardforPrivileged
Sessions(SPS)softwareonacertifiedhardware.Thelistofcertifiedhardwareis
availableatOneIdentity.
NotethatinstallingandreinstallingSPScantakealongtime,especiallyforaHAcluster.
Therearenosupportedworkaroundsforreducingthenecessarydowntime.OneIdentity
recommendstestingSPSinavirtualenvironment,andusingphysicalhardwareonlyfor
verifyingHAfunctionalityandmeasuringperformance.
Installing the SPS software
ThefollowingdescribeshowtoinstallanewSPSonaserver.
Prerequisites:
When installing SPS on a physical hardware, make sure that you use a One Identity-
supported appliance, and that every hard disk required for the particular appliance is
inserted. Installing SPS without the required number of hard disks can cause
erroneous behavior.
To install a new SPS on a server
1. LogintoyoursupportportalanddownloadthelatestOneIdentitySafeguardfor
PrivilegedSessionsinstallationISOfile.Notethatyouneedtohavepartneraccess
todownloadOneIdentitySafeguardforPrivilegedSessionsISOfiles.Ifyouarea
partnerbutdonotseetheISOfiles,youcanrequestpartneraccesswithin
supportportal.
2. MounttheISOimage,orburnittoaCD-ROM.
3. ConnectyourcomputertotheIPMIinterfaceofSPS.Fordetails,seethefollowing
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
18

documents:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMIUser'sGuide.
4. Powerontheserver.
5. LogintotheIPMIwebinterface,andboottheOneIdentitySafeguardforPrivileged
SessionsinstallationCDontheserverusingavirtualCD-ROM.Fordetails,seethe
followingdocuments:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMIUser'sGuide.
6. WhentheOneIdentitySafeguardforPrivilegedSessionsinstallerstarts,select
Installer,pressEnter,andwaituntiltheserverfinishesthebootprocess.
TIP:
Fortestingpurposes,youcanspeedupinstallationattheexpenseofslowing
downRAIDsynchronization.AddthefollowingkernelparametertoInstallerin
GRUB:
lazy_itable_init=true
Thisoptiondefersfullfilesysteminitialization,requiringthekerneltofinishit
duringRAIDsynchronization,whichslowsthatprocessdownconsiderably.This
isnotrecommendedinaproductionenvironment.
7. InstallingSPSwillcompletelydeletethecontentsoftheharddisks.If youwant
toproceedinstallingSPS,enterYEStostarttheinstallationprocess.Dependingon
thesizeofthedisks, theinstallationprocesstakes fromafewminutestoan
hourtocomplete.
CAUTION:
Hazard of data loss All data on the disks will be deleted.
8. Theinstallerdisplaysthefollowingmessage:Waiting for RAID sync...,andstarts
tosynchronizethedisksofSPS.
lYouarerecommendedtowaituntilthesynchronizationfinishes.RAID
synchronizationisatwo-stepprocess,theprogressoftheactivestepis
indicatedontheprogressbar.Waituntilbothstepsarecompleted.Notethat
thissynchronizationtakesseveralhours,dependingonthesizeofthehard
disks(about8hoursontheaverage).
lToskiptheRAIDsynchronization,pressCtrl+Alt+DeletetorebootSPS.Note
thatthesystemwillautomaticallyperformthesynchronizationafterthefirst
boot,butinthiscasetheprocesswilltakeseveraldays.
9. Whentheinstallationisfinished,theInstallation finished successfullymessageis
displayed.Unmounttheinstallationmedia,thenpressCtrl+Alt+DeletetorebootSPS.
WaituntilthesystemrebootsanddisplaystheIPaddressitacceptsmanagement
connectionson.
10. If you are installing the slave node of a SPS cluster, skip this step.EntertheIP
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
19

addressdisplayedinthepreviousstepintoyourbrowserandverifythattheWelcome
WizardoftheOneIdentitySafeguardforPrivilegedSessionsisavailable.(Ifyou
havetocreateanaliasIPaddressforyourcomputerthatfallsintothe
192.168.1.0/24subnet(forexample192.168.1.10),see"TheinitialconnectiontoOne
IdentitySafeguardforPrivilegedSessions(SPS)"intheAdministrationGuide.)
NOTE:
Fordetailsonthesupportedwebbrowsersandoperatingsystems,see
"Supportedwebbrowsersandoperatingsystems"intheAdministrationGuide.
Figure 1: The Welcome Wizard
11. Poweroffthesystem.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
20
This manual suits for next models
5
Table of contents
Other One Identity Network Hardware manuals
Popular Network Hardware manuals by other brands

NEXTIVITY
NEXTIVITY SHIELD MegaFi quick start guide

ZyXEL Communications
ZyXEL Communications NSA-210 Support notes

Panasonic
Panasonic i-pro WJ-NT304 operating instructions

Airspan
Airspan AirHarmony-4000 installation guide

D-Link
D-Link ShareCenter Pulse DNS-320 user manual

GL Communications
GL Communications PacketExpert SA PXE104 Quick install guide