One Identity Safeguard for PrivilegedSessions 6.0 User manual

OneIdentitySafeguardforPrivileged
Sessions6.0
InstallationGuide

Copyright 2019 One Identity LLC.
ALL RIGHTS RESERVED.
Thisguidecontainsproprietaryinformationprotectedbycopyright.Thesoftwaredescribedinthisguide
isfurnishedunderasoftwarelicenseornondisclosureagreement.Thissoftwaremaybeusedorcopied
onlyinaccordancewiththetermsoftheapplicableagreement.Nopartofthisguidemaybereproduced
ortransmittedinanyformorbyanymeans,electronicormechanical,includingphotocopyingand
recordingforanypurposeotherthanthepurchaser’spersonalusewithoutthewrittenpermissionof
OneIdentityLLC.
TheinformationinthisdocumentisprovidedinconnectionwithOneIdentityproducts.Nolicense,
expressorimplied,byestoppelorotherwise,toanyintellectualpropertyrightisgrantedbythis
documentorinconnectionwiththesaleofOneIdentityLLCproducts.EXCEPTASSETFORTHINTHE
TERMSANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,
ONEIDENTITYASSUMESNOLIABILITYWHATSOEVERANDDISCLAIMSANYEXPRESS,IMPLIEDOR
STATUTORYWARRANTYRELATINGTOITSPRODUCTSINCLUDING,BUTNOTLIMITEDTO,THE
IMPLIEDWARRANTYOFMERCHANTABILITY,FITNESSFORAPARTICULARPURPOSE,ORNON-
INFRINGEMENT.INNOEVENTSHALLONEIDENTITYBELIABLEFORANYDIRECT,INDIRECT,
CONSEQUENTIAL,PUNITIVE,SPECIALORINCIDENTALDAMAGES(INCLUDING,WITHOUT
LIMITATION,DAMAGESFORLOSSOFPROFITS,BUSINESSINTERRUPTIONORLOSSOF
INFORMATION)ARISINGOUTOFTHEUSEORINABILITYTOUSETHISDOCUMENT,EVENIF
ONEIDENTITYHASBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.OneIdentitymakesno
representationsorwarrantieswithrespecttotheaccuracyorcompletenessofthecontentsofthis
documentandreservestherighttomakechangestospecificationsandproductdescriptionsatany
timewithoutnotice.OneIdentitydoesnotmakeanycommitmenttoupdatetheinformation
containedinthisdocument.
Ifyouhaveanyquestionsregardingyourpotentialuseofthismaterial,contact:
OneIdentityLLC.
Attn:LEGALDept
4PolarisWay
AlisoViejo,CA92656
RefertoourWebsite(http://www.OneIdentity.com)forregionalandinternationalofficeinformation.
Patents
OneIdentityisproudofouradvancedtechnology.Patentsandpendingpatentsmayapplytothis
product.Forthemostcurrentinformationaboutapplicablepatentsforthisproduct,pleasevisitour
websiteathttp://www.OneIdentity.com/legal/patents.aspx.
Trademarks
OneIdentityandtheOneIdentitylogoaretrademarksandregisteredtrademarksofOneIdentity
LLC.intheU.S.A.andothercountries.ForacompletelistofOneIdentitytrademarks,pleasevisit
ourwebsiteatwww.OneIdentity.com/legal.Allothertrademarksarethepropertyoftheir
respectiveowners.
Legend
WARNING: A WARNING icon highlights a potential risk of bodily injury or property
damage, for which industry-standard safety precautions are advised. This icon is
often associated with electrical hazards related to hardware.
CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if
instructions are not followed.
SPSInstallationGuide
Updated-September2019
Version-6.0

Contents
Preface 5
Summaryofcontents 5
Introduction 6
Package contents inventory 7
One Identity Safeguard for Privileged Sessions Hardware Installation
Guide 8
InstallingtheSPShardware 8
InstallingtwoSPSunitsinHAmode 11
Hardware specifications 12
One Identity Safeguard for Privileged Sessions Software Installation Guide14
InstallingtheSPSsoftware 14
One Identity Safeguard for Privileged Sessions VMware Installation Guide 17
InstallingSPSunderVMwareESXi/ESX 17
LimitationsofSPSunderVMware 18
One Identity Safeguard for Privileged Sessions Hyper-V Installation Guide 20
LimitationsofSPSunderHyper-V 20
InstallingSPSunderHyper-V 21
Installing One Identity Safeguard for Privileged Sessions as a Kernel-
based Virtual Machine 23
InstallingSPSasaKernel-basedVirtualMachine 23
LimitationsofSPSunderKVM 24
Deploying One Identity Safeguard for Privileged Sessions from the Azure
Marketplace 26
Prerequisites 26
Limitations 27
DeployOneIdentitySafeguardforPrivilegedSessionsfromtheMicrosoftAzure
Marketplace 29
HighAvailabilityandredundancyinMicrosoftAzure 31
Redundancy 31
SPS 6.0 Installation Guide 3

1
Preface
WelcometotheOneIdentitySafeguardforPrivilegedSessions6.0InstallationGuide.
ThisdocumentdescribeshowtosetuptheOneIdentitySafeguardforPrivilegedSessions
(SPS)hardware,andhowtoinstallSPSoncertifiedhardwareorasavirtualappliance.
Summary of contents
IntroductionprovidesbackgroundinformationanddescribesthemainpurposeoftheOne
IdentitySafeguardforPrivilegedSessionsInstallationGuide.
PackagecontentsinventoryliststhecontentsofthepackageyoureceivewiththeOne
IdentitySafeguardforPrivilegedSessions(SPS).
OneIdentitySafeguardforPrivilegedSessionsHardwareInstallationGuidedescribeshow
tosetuptheSPShardware.
HardwarespecificationsdescribesthehardwarespecificationsoftheSPSappliance.
OneIdentitySafeguardforPrivilegedSessionsSoftwareInstallationGuidedescribeshow
toinstallSPSoncertifiedhardware.
OneIdentitySafeguardforPrivilegedSessionsVMwareInstallationGuidedescribeshowto
installSPSasaVMwarevirtualappliance.
OneIdentitySafeguardforPrivilegedSessionsHyper-VInstallationGuidedescribeshowto
installOneIdentitySafeguardforPrivilegedSessions(SPS)asaHyper-Vvirtualappliance.
InstallingOneIdentitySafeguardforPrivilegedSessionsasaKernel-basedVirtualMachine
describeshowtoinstallOneIdentitySafeguardforPrivilegedSessions(SPS)asaKernel-
basedVirtualMachine.
DeployingOneIdentitySafeguardforPrivilegedSessionsfromtheAzureMarketplace
describeshowtoinstallOneIdentitySafeguardforPrivilegedSessions(SPS)fromthe
MicrosoftAzureMarketplace.
SPS 6.0 Installation Guide
Preface
5

2
Introduction
Theaimofthisguideistoprovidedetailed,step-by-stepinstructionsonhowtosetupand
installOneIdentitySafeguardforPrivilegedSessionsonunpackingitandanysubsequent
occasionsthatmightrequirethere-installationoftheproduct.
NotethatthecontentsofthisdocumentwerepreviouslyincludedintheAdministration
Guide.Thisstandaloneguidewascreatedto:
lImprovehowinformationisorganizedintheOneIdentitySafeguardforPrivileged
Sessionsdocumentationset.
lMakeiteasierforuserstofindinformationrelevanttotheirroles,context,andhow
theyusetheproduct.
SPS 6.0 Installation Guide
Introduction
6

3
Package contents inventory
Carefullyunpackallservercomponentsfromthepackingcartons.Thefollowingitems
shouldbepackagedwiththeOneIdentitySafeguardforPrivilegedSessions:
lAOneIdentitySafeguardforPrivilegedSessionsappliance,pre-installedwiththe
latestOneIdentitySafeguardforPrivilegedSessionsfirmware.
lOneIdentitySafeguardforPrivilegedSessionsaccessorykit,includingthefollowing:
lOne Identity Safeguard for Privileged Sessions 6.0 Packaging Checklist
(this document).
lGPLv2.0license.
lRackmounthardware(dependingonappliancetype).
lPowercable.
ThedefaultBIOSandIPMIpasswordsareinthedocumentation.
SPS 6.0 Installation Guide
Package contents inventory
7

4
One Identity Safeguard for
Privileged Sessions Hardware
Installation Guide
ThisdocumentdescribeshowtosetuptheOneIdentitySafeguardforPrivilegedSessions
(SPS)hardware.Refertothefollowingdocumentsforstep-by-stepinstructions:
lSafeguard Sessions Appliance 3000:seetheSC113 Chassis Series User's Manual,
Chapter 6: Rack Installation,availableonlineat
https://www.supermicro.com/manuals/chassis/1U/SC113.pdf.
lSafeguard Sessions Appliance 3500:seetheSuperServer 1029U-T Series User's
Manual, Chapter 2: Server Installation,availableonlineat
https://www.supermicro.com/manuals/superserver/1U/MNL-1973.pdf.
lFordetailsonhowtoinstallasingleSPSunit,seeInstallingtheSPShardware.
lFordetailsonhowtoinstallatwoSPSunitsinhighavailabilitymode,seeInstalling
twoSPSunitsinHAmode.
Installing the SPS hardware
ThefollowingdescribeshowtoinstallasingleSPSunit.
To install a single SPS unit
1. UnpackSPS.
2. (Optional)InstallSPSintoarackwiththesliderails.Sliderailsareavailableforall
SPSappliances.
3. Connectthecables.
a. ConnecttheEthernetcablefacingyourLANtotheEthernetconnectorlabeled
as1.Thisisphysicalinterface1ofSPS.Thisinterfaceisusedfortheinitial
configurationofSPS,andformonitoringconnections.(Fordetailsonthe
rolesofthedifferentinterfaces,see"Networkinterfaces"inthe
AdministrationGuide.)
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
8

b. (Optional)TouseSPSacrossmultiplephysical(L1)networks,youcanconnect
additionalnetworksusingphysicalinterface2(Ethernetconnector2)and
physicalinterface3(Ethernetconnector3).
c. Connect an Ethernet cable that you can use to remotely support the SPS
hardware to the IPMI interface of SPS. For details, see the following
documents:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMI
User'sGuide.
CAUTION:
Connect the IPMI before plugging in the power cord. Failing to
do so will result in IPMI failure.
CAUTION: SECURITY HAZARD!
The IPMI interface, like all out-of-band management interfaces,
has known vulnerabilities that One Identity cannot fix or have
an effect on. To avoid security hazards, One Identity
recommends that you only connect the IPMI interface to well-
protected, separated management networks with restricted
accessibility. Failing to do so may result in an unauthorized
access to all data stored on the SPS appliance. Data on the
appliance can be unencrypted or encrypted, and can include
sensitive information, for example, passwords, decryption keys,
private keys, and so on.
For more information, see Best Practices for managing servers
with IPMI features enabled in Datacenters.
NOTE:
TheadministratorofSPSmustbeauthorizedandabletoaccesstheIPMI
interfaceforsupportandtroubleshootingpurposesincasevendor
supportisneeded.
ThefollowingportsareusedbytheIPMIinterface:
lPort623(UDP):IPMI(cannotbechanged)
lPort5123(UDP):floppy(cannotbechanged)
lPort5901(TCP):videodisplay(configurable)
lPort5900(TCP):HID(configurable)
lPort5120(TCP):CD(configurable)
lPort80(TCP):HTTP(configurable)
d. (Optional)ConnecttheEthernetcableconnectingSPStoanotherSPSnodeto
theEthernetconnectorlabeledas4.Thisisthehighavailability(HA)interface
ofSPS.(Fordetailsontherolesofthedifferentinterfaces,see"Network
interfaces"intheAdministrationGuide.)
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
9

e. (Optional)TheSafeguardSessionsAppliance3500isequippedwithadual-port
SFP+interfacecardlabeledAandB.Optionally,connectasupportedSFP+
moduletotheseinterfaces.
NOTE:
Foralistofcompatibleconnectors,seeLinuxBaseDriverfor10Gigabit
IntelEthernetNetworkConnection.NotethatSFPtransceiversencoded
fornonIntelhostsmaybeincompatiblewiththeIntel82599EBhost
chipsetfoundinSPS.
4. Poweronthehardware.
5. ChangetheBIOSpasswordontheOneIdentitySafeguardforPrivilegedSessions.
ThedefaultpasswordisADMINorchangeme,dependingonyourhardware.
6. ChangetheIPMIpasswordontheOneIdentitySafeguardforPrivilegedSessions.
ThedefaultpasswordisADMINorchangeme,dependingonyourhardware.
NOTE:
EnsurethatyouhavethelatestversionofIPMIfirmwareinstalled.Youcan
downloadtherelevantfirmwarefromtheOneIdentityKnowledgebase.
TochangetheIPMIpassword,connecttotheIPMIremoteconsole.
NOTE:
IfyouencounterissueswhenconnectingtotheIPMIremoteconsole,addthe
DNSnameortheIPaddressoftheIPMIinterfacetotheexceptionlist
(whitelist)oftheJavaconsole.Fordetailsonhowtodothis,seetheJavaFAQ
entrytitledHowcanIconfiguretheExceptionSiteList?.
7. Followingboot,SPSattemptstoreceiveanIPaddressautomaticallyviaDHCP.Ifit
failstoobtainanautomaticIPaddress,itstartslisteningforHTTPSconnectionson
the192.168.1.1IPaddress.
ToconfigureSPStolistenforconnectionsonacustomIPaddress,completethe
followingsteps:
a. AccessSPSfromthelocalconsole,andloginwithusernamerootand
passworddefault.
b. SelectShells > Core shellintheConsoleMenu.
c. ChangetheIPaddressofSPS:
ifconfig eth0 <IP-address> netmask 255.255.255.0
Replace<IP-address>withanIPv4addresssuitableforyourenvironment.
d. Setthedefaultgatewayusingthefollowingcommand:
route add default gw <IP-of-default-gateway>
Replace<IP-of-default-gateway>withtheIPaddressofthedefaultgateway.
e. Typeexit,thenselectLogoutfromtheConsoleMenu.
8. ConnecttotheSPSwebinterfacefromaclientmachineandcompletetheWelcome
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
10

Wizardasdescribedin"TheWelcomeWizardandthefirstlogin"inthe
AdministrationGuide.
NOTE:
TheAdministrationGuideisavailableontheSafeguardforPrivilegedSessions
Documentationpage.
Installing two SPS units in HA mode
ThefollowingdescribeshowtoinstallSPSwithhighavailabilitysupport.
To install SPS with high availability support
1. ForthefirstSPSunit,completeInstallingtheSPShardware.
2. ForthesecondSPSunit,completeSteps1-3ofInstallingtheSPShardware.
3. ConnectthetwounitswithanEthernetcableviatheEthernetconnectorslabeledas4.
4. Poweronthesecondunit.
5. ChangetheBIOSandIPMIpasswordsonthesecondunit.Thedefaultpasswordis
ADMINorchangeme,dependingonyourhardware.
6. ConnecttotheSPSwebinterfaceofthefirstunitfromaclientmachineandenable
thehighavailabilitymode.NavigatetoBasic Settings > High Availability .Click
Convert to Cluster,thenreloadthepageinyourbrowser.
7. ClickReboot Cluster.
8. Waituntiltheslaveunitsynchronizesitsdisktothemasterunit.Dependingonthe
sizeoftheharddisks,thismaytakeseveralhours.Youcanincreasethespeedofthe
synchronizationviatheSPSwebinterfaceatBasic Settings > High Availability
> DRBD sync rate limit.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hardware Installation Guide
11

5
Hardware specifications
OneIdentitySafeguardforPrivilegedSessionsappliancesarebuiltonhighperformance,
energyefficient,andreliablehardwarethatareeasilymountedintostandardrackmounts.
Product Redundant
PSU
Processor Memory Capacity RAID IPMI
SPST-1 No Intel(R)
Xeon(R)
X3430@
2.40GHz
2x4GB 2x1TB SoftwareRAID Yes
SPST-4 Yes Intel(R)
Xeon(R)E3-
1275V2@
3.50GHz
2x4GB 4x2TB LSIMegaRAID
SAS9271-4iSGL
Yes
SPST-10 Yes 2xIntel(R)
Xeon(R)E5-
2630V2@
2.6GHz
8x4GB 13x1TB LSI2208(1GB
cache)
Yes
Safeguard
Sessions
Appliance
3000
Yes 1xIntel
XeonE3-
1275
3.60GHz
8Core
2x16
GB
4x2TB
NLSAS
LSIMegaRAID
SAS9361-4i
Single
Yes
Safeguard
Sessions
Appliance
3500
Yes 2xIntel
XeonSilver
41102.1Ghz
8Core
(=16Core)
8x8GB 9x2TB
NLSAS
1xBroadcom
MegaRAIDSAS
9361-16i+LSI
Avago
CacheVault
PowerModule02
(CVPM02)Kit
Yes
Table 1: Hardware specifications
TheSafeguardSessionsAppliance3500isequippedwithadual-port10Gbitinterface.This
interfacehasSFP+connectors(notRJ-45)labeledAandB,andcanbefoundrightofthe
SPS 6.0 Installation Guide
Hardware specifications
12

Label1and2Ethernetinterfaces.Ifyouwantfastercommunication,forexample,incase
ofhighdataload,youcanconnectuptotwo10Gbitnetworkcards.Thesecardsarenot
shippedwiththeoriginalpackageandhavetobepurchasedseparately.
SPS 6.0 Installation Guide
Hardware specifications
13

6
One Identity Safeguard for
Privileged Sessions Software
Installation Guide
ThisdocumentdescribeshowtoinstalltheOneIdentitySafeguardforPrivileged
Sessions(SPS)softwareonacertifiedhardware.Thelistofcertifiedhardwareis
availableatOneIdentity.
NotethatinstallingandreinstallingSPScantakealongtime,especiallyforaHAcluster.
Therearenosupportedworkaroundsforreducingthenecessarydowntime.OneIdentity
recommendstestingSPSinavirtualenvironment,andusingphysicalhardwareonlyfor
verifyingHAfunctionalityandmeasuringperformance.
Installing the SPS software
ThefollowingdescribeshowtoinstallanewSPSonaserver.
Prerequisites:
When installing SPS on a physical hardware, make sure that you use a One Identity-
supported appliance, and that every hard disk required for the particular appliance is
inserted. Installing SPS without the required number of hard disks can cause
erroneous behavior.
To install a new SPS on a server
1. LogintoyoursupportportalanddownloadthelatestOneIdentitySafeguardfor
PrivilegedSessionsinstallationISOfile.Notethatyouneedtohavepartneraccess
todownloadOneIdentitySafeguardforPrivilegedSessionsISOfiles.Ifyouarea
partnerbutdonotseetheISOfiles,youcanrequestpartneraccesswithin
supportportal.
2. MounttheISOimage,orburnittoaCD-ROM.
3. ConnectyourcomputertotheIPMIinterfaceofSPS.Fordetails,seethefollowing
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
14

documents:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMIUser'sGuide.
4. Powerontheserver.
5. LogintotheIPMIwebinterface,andboottheOneIdentitySafeguardforPrivileged
SessionsinstallationCDontheserverusingavirtualCD-ROM.Fordetails,seethe
followingdocuments:
ForSafeguardSessionsAppliance3000and3500,seetheX9SMTIPMIUser'sGuide.
6. WhentheOneIdentitySafeguardforPrivilegedSessionsinstallerstarts,select
Installer,pressEnter,andwaituntiltheserverfinishesthebootprocess.
TIP:
Fortestingpurposes,youcanspeedupinstallationattheexpenseofslowing
downRAIDsynchronization.AddthefollowingkernelparametertoInstallerin
GRUB:
lazy_itable_init=true
Thisoptiondefersfullfilesysteminitialization,requiringthekerneltofinishit
duringRAIDsynchronization,whichslowsthatprocessdownconsiderably.This
isnotrecommendedinaproductionenvironment.
7. InstallingSPSwillcompletelydeletethecontentsoftheharddisks.If youwant
toproceedinstallingSPS,enterYEStostarttheinstallationprocess.Dependingon
thesizeofthedisks, theinstallationprocesstakes fromafewminutestoan
hourtocomplete.
CAUTION:
Hazard of data loss All data on the disks will be deleted.
8. Theinstallerdisplaysthefollowingmessage:Waiting for RAID sync...,andstarts
tosynchronizethedisksofSPS.
lYouarerecommendedtowaituntilthesynchronizationfinishes.RAID
synchronizationisatwo-stepprocess,theprogressoftheactivestepis
indicatedontheprogressbar.Waituntilbothstepsarecompleted.Notethat
thissynchronizationtakesseveralhours,dependingonthesizeofthehard
disks(about8hoursontheaverage).
lToskiptheRAIDsynchronization,pressCtrl+Alt+DeletetorebootSPS.Note
thatthesystemwillautomaticallyperformthesynchronizationafterthefirst
boot,butinthiscasetheprocesswilltakeseveraldays.
9. Whentheinstallationisfinished,theInstallation finished successfullymessageis
displayed.Unmounttheinstallationmedia,thenpressCtrl+Alt+DeletetorebootSPS.
WaituntilthesystemrebootsanddisplaystheIPaddressitacceptsmanagement
connectionson.
10. If you are installing the slave node of a SPS cluster, skip this step.EntertheIP
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
15

addressdisplayedinthepreviousstepintoyourbrowserandverifythattheWelcome
WizardoftheOneIdentitySafeguardforPrivilegedSessionsisavailable.(Ifyou
havetocreateanaliasIPaddressforyourcomputerthatfallsintothe
192.168.1.0/24subnet(forexample192.168.1.10),see"TheinitialconnectiontoOne
IdentitySafeguardforPrivilegedSessions(SPS)"intheAdministrationGuide.)
NOTE:
Fordetailsonthesupportedwebbrowsersandoperatingsystems,see
"Supportedwebbrowsersandoperatingsystems"intheAdministrationGuide.
Figure 1: The Welcome Wizard
11. Poweroffthesystem.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Software Installation Guide
16

7
One Identity Safeguard for
Privileged Sessions VMware
Installation Guide
ThistutorialdescribesthepossibilitiesandlimitationsofinstallingOneIdentitySafeguard
forPrivilegedSessions(SPS)6.0asavirtualapplianceunderaVMwareESXiserver.
Installing SPS under VMware ESXi/ESX
ThefollowingdescribeshowtoinstallanewSPSunderVMware ESXi or ESX.
To install a new SPS under VMware ESXi or ESX
1. CreatethevirtualmachineforSPSusingthefollowingsettings.Notethatthese
settingsaresuitableforevaluationpurposes.TotestSPSundersignificantload,
contactOneIdentityforrecommendations.
lGuestoperatingsystem:Linux/Ubuntu 64-bit
lAllocatememoryforthevirtualmachine.SPSrequiresaminimumof4GiB(8
GiBisrecommended)ofmemory.Therecommendedsizeforthememory
dependsontheexactenvironment,butconsiderthefollowing:
lThebasesystemrequires4GiBofmemory.
lSPSrequiresabout1-5MiBofmemoryforeveryactiveconnection,
dependingonthetypeoftheconnection—graphicalprotocolsrequire
morememory.
lTheharddiskcontrollermustbeLSI Logic Parallel.
lDonotuseRAIDfortheharddisk,usethedataduplicationfeaturesofyour
virtualenvironmentinstead.Thatway,asingleharddiskissufficientforthe
system.Ifyouneedtousethebuilt-inRAIDsupportofSPSforsomereason,
usetwoharddisks,andSPSwillautomaticallyusetheminsoftwareRAID.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions VMware Installation Guide
17

CAUTION:
Hazard of data loss When you install or reinstall SPS in a virtual
environment, always create new hard disks. Using existing hard
disks can cause unexpected behavior and operational problems.
lConfigureafixedsizediskwithatleast20GiBspace.About10GiBis
requiredforthebasesystem,theremainingdiskspaceisusedtostore
data.Toincreasetheinitialdisksize,seeModifyingthedisksizeofaSPS
virtualappliance.
l
NOTE:
SPSwillusethenetworkcardwiththelowestPCIIDaseth0(Physical
interface 1),thecardwiththesecondlowestPCIIDaseth1(the
Physical interface 2),andsoon.Insomecases,thismightdifferfrom
thelabelsintheVMWaremanagementinterface,forexample,itis
possiblethateth0willbelabeledasNetwork adapter 4,andasaresult,
theSPSWelcomeWizardwillnotbeavailableonNetwork adapter 1.
SPSrequiresatleastonenetworkcard(preferablyVMXNET3)tofunction.
Configurationscanuseupto6networkcards.
NOTE:
Thefourth(eth3)networkcardisreservedforHighAvailabilitymodeby
default.Therefore,makesureyouenable,butdonotattach,thefourth
(eth3)networkcardtoanetwork.
2. Aftercreatingthevirtualmachine,editthesettingsofthemachine.Setthe
followingoptions:
a. UnderOptions > VMware ToolsenabletheShutdown, Suspend, Reset
options,otherwisetheSPSadministratorwillnotbeabletoaccessthese
functionsfromtheSPSwebinterface.
b. UnderOptions > Boot optionsenabletheForce BIOS Setupoption.Thisis
requiredtobeabletocheckthesystemtime(andmodifyitifneeded)before
installingSPS.
3. LogintoyoursupportportalanddownloadthelatestOneIdentitySafeguardfor
PrivilegedSessionsinstallationISOfile.NotethatyouneedtohavepurchasedSPS
asavirtualapplianceorhavepartneraccesstodownloadOneIdentitySafeguardfor
PrivilegedSessionsISOfiles.IfyouareapartnerbutdonotseetheISOfiles,you
canrequestpartneraccesswithinsupportportal.
4. MounttheISOimageandbootthevirtualmachine.Followtheon-screeninstructions
toinstallSPS.
Limitations of SPS under VMware
Thefollowinglimitationsapplytorunningversion6.0ofSPSunderVMware:
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions VMware Installation Guide
18

lSPScanbeinstalledunderthefollowingVMwareversions:
lVMwareESXi5.5orlater.
lVMwareESXi6.0orlater.
lVMwareESXi6.5orlater.
lSPScanonlyusefixeddiskspaceassignedtothevirtualhost,itisnotpossibletouse
on-demanddiskallocationscenarios.Toincreasethesizeofthevirtualdisk,see
ModifyingthedisksizeofaSPSvirtualapplianceonpage32.
lIfHighAvailability(HA)operationmodeisrequiredinavirtualenvironment,usethe
HAfunctionprovidedbythevirtualenvironment.
lHardware-relatedalertsandstatusindicatorsofSPSmaydisplayinaccurate
information,forexample,displaydegradedRAIDstatus.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions VMware Installation Guide
19

8
One Identity Safeguard for
Privileged Sessions Hyper-V
Installation Guide
ThistutorialdescribesthepossibilitiesandlimitationsofinstallingOneIdentitySafeguard
forPrivilegedSessions(SPS)6.0asavirtualapplianceunderaHyper-Vserver.
Limitations of SPS under Hyper-V
Version6.0ofSPShasnospecialsupportforrunningunderHyper-V.Whilethebasic
functionalityofSPSisnotaffectedbyrunningasavirtualappliance,thefollowing
limitationsapply:
lIfHighAvailability(HA)operationmodeisrequiredinavirtualenvironment,usethe
HAfunctionprovidedbythevirtualenvironment.
lHardware-relatedalertsandstatusindicatorsofSPSmaydisplayinaccurate
information,forexample,displaydegradedRAIDstatus.
lWhenrunningSPSunderMicrosoftHyper-V,ensurethatthenetworkinterfacesare
actuallyconnectedtothenetwork.WhenrunningunderHyper-V,SPSindicateson
theBasic Settings > Network > Ethernet linkspagethatthereisalinkevenif
thenetworkinterfaceisconfiguredandenabled,butnotconnectedtothenetwork.
lWhenrebootingSPSinHyper-V,thefollowingcriticalerrormessagemayappearin
theeventlogoftheHyper-Vhost:
<Virtual machine name> was reset because an unrecoverable error occurred on a
virtual processor that caused a triple fault.
Thisisnormal,thereisnoproblemwithSPS.Fordetails,seeTriplefaultineventlog
showsresetofLinuxvirtualmachines.
SPS 6.0 Installation Guide
One Identity Safeguard for Privileged Sessions Hyper-V Installation Guide
20
This manual suits for next models
3
Table of contents
Other One Identity Server manuals
Popular Server manuals by other brands

DMP Electronics
DMP Electronics eBox-3300 user manual

Dell
Dell PowerEdge R910 Getting started with

D-Link
D-Link Epress EtherNetwork DP-301P+ Quick installation guide

Gigabyte
Gigabyte G293-S45-AAP1 user manual

HPE
HPE Apollo 2000 Gen10 Plus System Product End-of-Life Disassembly Instructions

Vivotek
Vivotek VS2402 Quick installation guide