Changes for page Unix Agent installieren

Last modified by Sabrina V. on 2026/10/08 10:44

From version 8.1
edited by Steffi F
on 2026/03/30 13:39
Change comment: There is no comment for this version
To version 19.1
edited by Sabrina V.
on 2026/10/08 10:44
Change comment: There is no comment for this version

Summary

Details

Page properties
Author
... ... @@ -1,1 +1,1 @@
1 -XWiki.SF
1 +XWiki.SV
Content
... ... @@ -1,27 +1,31 @@
1 1  {{aagon.floatingbox/}}
2 2  
3 3  (% class="wikigeneratedid" %)
4 -The Unix Agent is the completely renewed and technically revised further development of the Linux and Mac agents. The agent can be deployed and installed without Python using a supplied Client Command. The inventory data is transmitted to the ACMP Server in full and updated.
4 +The Unix Agent is the completely renewed and technically revised further development of the Linux and Mac agents. The agent can be deployed and installed without Python using a supplied Client Command. The inventory data is transmitted to the acmp Server in full and updated.
5 5  
6 6  {{aagon.infobox}}
7 -If you use Unix clients that are not connected to the network, you can inventory them using the [[Unix Offline Scanner>>doc:ACMP.69.Arbeiten mit der ACMP Console.Clients erfassen.Offline Scanner.WebHome||anchor="“HRunUnixOfflineScanner”"]].
7 +If you use Unix clients that are not connected to the network, you can inventory them using the [[Unix Offline Scanner>>doc:ACMP.610.Arbeiten mit der ACMP Console.Clients erfassen.Offline Scanner.WebHome||anchor="“HRunUnixOfflineScanner”"]].
8 8  {{/aagon.infobox}}
9 9  
10 +{{aagon.versionierungsbox}}
11 +Please note that the assignment of a maintenance window profile to containers with Unix agents is only supported in its full form starting with aesb version 1.12. Additionally, creating a maintenance window profile is possible starting with acmp version 6.9.
12 +{{/aagon.versionierungsbox}}
13 +
10 10  = Installation requirements =
11 11  
12 12  There are several requirements for you and your system for installing the Unix Agent.
13 13  
14 -=== Requirements for your knowledge of ACMP ===
18 +=== Requirements for your knowledge of acmp ===
15 15  
16 16  * You have a basic understanding of how to configure SICS.
17 -* You know how to import Client Commands into ACMP.
21 +* You know how to import Client Commands into acmp.
18 18  * You know how to execute Client Commands.
19 19  
20 20  === Requirements for your environment ===
21 21  
22 -* ACMP is installed.
26 +* acmp is installed.
23 23  * SICS is installed on a server.
24 -* The ACMP Server is connected to SICS.
28 +* The acmp Server is connected to SICS.
25 25  * SICS users are allowed to access the public API.
26 26  
27 27  === Requirements for your MacOS and Linux systems ===
... ... @@ -35,11 +35,33 @@
35 35  * Linux and MacOS Clients must be able to reach SICS via Rest (any firewalls must allow port 3950).
36 36  * Firewall settings for SICS must be customizable if necessary.
37 37  
42 +{{aagon.infobox}}
43 +Please note that the Unix Agent has been advanced with additional scanners in acmp version 6.10. The System Scanner requires certain packages for this purpose, which must be installed or downloaded on Linux environments.
44 +
45 +The Unix Agent reads the TPM information from the physical devices and then populates certain fields (e.g., “TPM enabled,” “TPM on,” or “TPM manufacturer”) with the corresponding values.
46 +
47 +You will need the following packages:
48 +**TPM:**
49 +
50 + „tpm-tools“ for TPM 1.2 Chips
51 + -„tpm2-tools“ for TPM 2.0 Chips
52 +
53 +**Login History:**
54 +
55 + „util-linux“
56 +
57 +Execute these packages in the terminal.
58 +__Example__: For Ubuntu 24.04, the installation commands would be as follows:
59 +„sudo apt install tpm-tools“
60 +„sudo apt install tpm2-tools“
61 +„sudo apt install util-linux“
62 +{{/aagon.infobox}}
63 +
38 38  = Installation with the Client Command =
39 39  
40 -An existing SICS connection to the ACMP server is required to install the Unix Agent. If you have not yet configured a SICS connection, you must do so first. Instructions for configuring the SICS connection can be found in the section [[Configuring the SICS connection>>doc:AESB.19.AESB installieren, konfigurieren und aktualisieren.SICS-Verbindung konfigurieren.WebHome]].
66 +An existing SICS connection to the acmp server is required to install the Unix Agent. If you have not yet configured a SICS connection, you must do so first. Instructions for configuring the SICS connection can be found in the section [[Configuring the SICS connection>>doc:AESB.111.AESB installieren, konfigurieren und aktualisieren.SICS-Verbindung konfigurieren.WebHome]].
41 41  
42 -The Unix Agent is installed using a Client Command in ACMP. To do this, the Client Command must first be imported and released.
68 +The Unix Agent is installed using a Client Command in acmp. To do this, the Client Command must first be imported and released.
43 43  
44 44  {{aagon.warnungsbox}}
45 45  Installing the Unix Agent stops and removes the Linux Agent.
... ... @@ -51,15 +51,19 @@
51 51  
52 52  The file for the required Client Command of the Unix Agent is named as in the following example:
53 53  
54 -{{{ACMP Unix Agent verteilen & Inventory__{1F5A4238-731B-44B6-84F0-3EFB8F2D3222}.sim}}}
80 +{{{acmp Unix Agent verteilen & Inventory__{1F5A4238-731B-44B6-84F0-3EFB8F2D3222}.sim}}}
55 55  
56 -For information on how to import and release a Client Command in ACMP, refer to the section [[Create Client Commands>>doc:ACMP.67.ACMP-Solutions.Client Commands.Client Command erstellen.WebHome||anchor="HImport"]] .
82 +For information on how to import and release a Client Command in acmp, refer to the section [[Create Client Commands>>doc:ACMP.610.ACMP-Solutions.Desktop Automation.Client Commands.Client Command erstellen.WebHome||anchor="HImport"]].
57 57  
84 +{{aagon.warnungsbox}}
85 +To ensure that clients are properly detected and can be managed, you must use a version of the Unix Agent that is compatible with your acmp version. Otherwise, your Linux and macOS clients will not be detected as manageable clients.
86 +{{/aagon.warnungsbox}}
87 +
58 58  === Execute Client Command ===
59 59  
60 60  After you have released the Client Command, you can execute it.
61 61  
62 -In the ACMP Console, navigate to Client Commands > Execute. Then double-click to select the Client Command for the Unix Agent.
92 +In the acmp Console, navigate to Client Commands > Execute. Then double-click to select the Client Command for the Unix Agent.
63 63  
64 64  In the dialog window that opens, click the //Execute// button. The Client Command interface opens, where you can configure the installation of the Unix Agent.
65 65  
... ... @@ -71,7 +71,7 @@
71 71  
72 72  === SSH credentials ===
73 73  
74 -The Unix Agent is transferred to the target computers via SSH; valid user data must be entered accordingly. Unlike the Linux Agent, the Unix Agent transfers the scan data directly to the ACMP Server.
104 +The Unix Agent is transferred to the target computers via SSH; valid user data must be entered accordingly. Unlike the Linux Agent, the Unix Agent transfers the scan data directly to the acmp Server.
75 75  
76 76  {{aagon.warnungsbox}}
77 77  The user whose user data is specified as SSH credentials for the installation must be created on each of the target computers and have “sudo” rights (superuser do) there.
... ... @@ -83,10 +83,26 @@
83 83  
84 84  === Specify SICS credentials ===
85 85  
86 -To install the Unix Agent on the target computers, you must specify your SICS session data. The specified endpoint must be in the format //wss:~/~/ipaddress:port//. Please note that all target computers must have access to this endpoint. You assigned the continuing user data to the operator during the AESB installation.
116 +To perform the installation of the Unix Agent on the target computers, you must enter your SICS session data.
87 87  
88 -You can also specify multiple fallback SICS connections in the tabs. If the primary SICS connection fails and cannot be used, an attempt is made to establish a connection to another defined SICS and to carry out the transfer via one of the fallback connections. The list of fallback SICS connections is used continuously, starting with fallback SICS #1, until a connection to one of the defined fallback SICS connections can be established or there are no more fallback connections in the list.
118 +**SICS user**
89 89  
120 +For the SICS user, you can create an aesb user with minimal permissions. This user must be created in the aesb console. For more info, see the section [[managing aesb users>>https://doc.aagon.com/bin/view/AESB/111/Workspaces/Benutzer/#HBenutzerverwalten]].
121 +
122 +**SICS server**
123 +
124 +The endpoint must be specified in the format “wss:~/~/server:port”, for example:
125 +
126 +* wss:~/~/ipaddress:port
127 +* wss:~/~/hostname:port
128 +* wss:~/~/FQHN:port (Fully Qualified Host Name)
129 +
130 +Please note that all target computers require access to this endpoint. You assigned the additional user credentials for the operator during the aesb installation.
131 +
132 +**SICS Fallbacks**
133 +
134 +In the tabs, you can specify multiple fallback SICS connections. If the primary SICS connection fails and cannot be used, the system will attempt to establish a connection to another defined SICS and perform the transfer via one of the fallback connections. The list of fallback SICS connections is used continuously, starting with Fallback SICS #1, until a connection to one of the defined fallback SICS connections has been established or there are no continuing fallback connections remaining in the list.
135 +
90 90  {{aagon.infobox}}
91 91  If the connection to one of the defined fallback SICS could be established successfully, the connection is maintained until the next restart.
92 92  {{/aagon.infobox}}
... ... @@ -97,7 +97,7 @@
97 97  
98 98  **Enable logging**
99 99  
100 -By selecting the //Enable logging// option, you can load the logs to your machine (or the machine with the ACMP Console) after installation or execution. Enabling logging is already available at this point in the Client Command and can be useful, as errors may occur during installation or execution as Inventory One-Time-Scan.
146 +By selecting the //Enable logging// option, you can load the logs to your machine (or the machine with the acmp Console) after installation or execution. Enabling logging is already available at this point in the Client Command and can be useful, as errors may occur during installation or execution as Inventory One-Time-Scan.
101 101  
102 102  **One-time scan**
103 103  
... ... @@ -105,11 +105,11 @@
105 105  
106 106  **Agent installation**
107 107  
108 -To install the Unix Agent as a permanent resource, you can execute the agent in the //Agent Installation// mode. The Unix Agent is now transferred to the target computer and registered as a service. Following installation, the agent starts automatically and obtains its configuration from ACMP within 10 minutes. The agent is now entered as a client in ACMP and contains the basic client details. The execution file can be found under the path: ##/usr/local/sbin/aagon/ACMPUnixAgent/##
154 +To install the Unix Agent as a permanent resource, you can execute the agent in the //Agent Installation// mode. The Unix Agent is now transferred to the target computer and registered as a service. Following installation, the agent starts automatically and obtains its configuration from acmp within 10 minutes. The agent is now entered as a client in acmp and contains the basic client details. The execution file can be found under the path: ##/usr/local/sbin/aagon/ACMPUnixAgent/##
109 109  
110 110  The agent also uses another directory to store various resources that are relevant to the agent. This directory can be found under the path:## /etc/aagon/ACMPUnixAgent/##
111 111  
112 -The Agent Tasks templates are used to execute the scanners. These can be used in exactly the same way as with the ACMP Windows Agent (Container). The following jobs are currently taken into account within the Agent Tasks:
158 +The Agent Tasks templates are used to execute the scanners. These can be used in exactly the same way as with the acmp Windows Agent (Container). The following jobs are currently taken into account within the Agent Tasks:
113 113  
114 114  * System scanner
115 115  * Software scanner
... ... @@ -163,7 +163,7 @@
163 163  
164 164  ----
165 165  
166 -**Symptom:** After distributing the Unix Agent using the Client Command, the Unix client does not appear in ACMP.
212 +**Symptom:** After distributing the Unix Agent using the Client Command, the Unix client does not appear in acmp.
167 167  
168 168  **Cause:** An error occurred during the execution of the Client Command, but was not immediately apparent due to the settings.
169 169  
... ... @@ -170,11 +170,11 @@
170 170  **Action:** In the properties of the Client Command in the plugin //Options //in the Combobox //Show console log// enable the option //Only on errors// and confirm the
171 171  dialog with //OK//. After executing the Client Command again, a console log should now be displayed in the event of an error, which may provide information about the cause of the problem.
172 172  
173 -If the Unix systems still do not appear in ACMP, there may be many reasons for this. It is therefore recommended to activate logging for the agent and the SICS. Then go through the chain from start to end.
219 +If the Unix systems still do not appear in acmp, there may be many reasons for this. It is therefore recommended to activate logging for the agent and the SICS. Then go through the chain from start to end.
174 174  
175 175  ----
176 176  
177 -**Symptom:** After distributing the Unix Agent using the Client Command, the Unix client does not appear in ACMP. The error “Invalid input detected: endpoint” is displayed in the SmartInspect log.
223 +**Symptom:** After distributing the Unix Agent using the Client Command, the Unix client does not appear in acmp. The error “Invalid input detected: endpoint” is displayed in the SmartInspect log.
178 178  
179 179  **Cause:** An error occurred during the connection to SICS because the protocol may not have been prefixed during the connection. You can see this in the SmartInspect log in the row //Application settings//: ##“SicsEndpoint: <AESB-SICS-NAME_IP>:3950”##
180 180  
... ... @@ -210,31 +210,31 @@
210 210  
211 211  ----
212 212  
213 -**Symptom:** The Unix Agent is running, but the corresponding Unix client does not appear in an ACMP query.
259 +**Symptom:** The Unix Agent is running, but the corresponding Unix client does not appear in an acmp query.
214 214  
215 -**Cause:** The SICS cannot forward the scan data of the Unix Agent to the ACMP Server because the connection is not available.
261 +**Cause:** The SICS cannot forward the scan data of the Unix Agent to the acmp Server because the connection is not available.
216 216  
217 -**Action:** Check in the ACMP Console settings whether the SICS connection of the ACMP Server is still working (in the ACMP Server / SICS connection plugin) and whether the checkbox for SICS users to access the public API is activated. Further information on this problem can be found in the log of the ACMP Server or the Unix Agent.
263 +**Action:** Check in the acmp Console settings whether the SICS connection of the acmp Server is still working (in the acmp Server / SICS connection plugin) and whether the checkbox for SICS users to access the public API is activated. Further information on this problem can be found in the log of the acmp Server or the Unix Agent.
218 218  
219 219  ----
220 220  
221 -**Symptom:** The Unix client appears in an ACMP query, but no scan data is available.
267 +**Symptom:** The Unix client appears in an acmp query, but no scan data is available.
222 222  
223 -**Cause:** During installation, the system waits between 2 and 10 minutes until the scan settings for this Unix client are retrieved by sending a request to the ACMP Server.
269 +**Cause:** During installation, the system waits between 2 and 10 minutes until the scan settings for this Unix client are retrieved by sending a request to the acmp Server.
224 224  
225 225  **Action: **If necessary, wait a little longer until the scan data has been loaded. If no scan data appears after significantly more than 10 minutes, you should enable logging for all components involved and check the entire chain from start to end for errors.
226 226  
227 227  = **Updating the Unix Agent** =
228 228  
229 -Updating the Unix Agent is done in the same way as its [[installation via a Client Command.>>https://doc.aagon.com/bin/view/ACMP/69/Arbeiten%20mit%20der%20ACMP%20Console/Clients%20erfassen/Unix%20Agent%20installieren/?language=en#HInstallationwiththeClientCommand]]
275 +Updating the Unix Agent is done in the same way as its [[installation via a Client Command.>>||anchor="HInstallationwiththeClientCommand"]]
230 230  
231 -In this process, the agent is redistributed and installed on the target systems via the ACMP Console. The transfer takes place via SSH using the appropriate permissions. During execution, the existing agent is replaced by the current version and reconfigured as a service.
277 +In this process, the agent is redistributed and installed on the target systems via the acmp Console. The transfer takes place via SSH using the appropriate permissions. During execution, the existing agent is replaced by the current version and reconfigured as a service.
232 232  
233 -The agent then starts automatically and takes over the existing communication with the ACMP Server.
279 +The agent then starts automatically and takes over the existing communication with the acmp Server.
234 234  
235 235  = Administration of Linux and MacOS Clients =
236 236  
237 -Previously, clients running Linux or macOS could only be detected and inventoried with the Unix Agent. They could not, however, be administered, and no shell scripts or jobs could be executed on these clients. Now, newly detected Linux and macOS clients can be managed if inventoried using the Unix Agent. This also enables the automated, time-controlled execution of Unix scripts as jobs. For more info, see the section [[Unix Scripts>>doc:ACMP.68.ACMP-Solutions.Desktop Automation.Unix Scripts.WebHome]].
283 +Previously, clients running Linux or macOS could only be detected and inventoried with the Unix Agent. They could not, however, be administered, and no shell scripts or jobs could be executed on these clients. Now, newly detected Linux and macOS clients can be managed if inventoried using the Unix Agent. This also enables the automated, time-controlled execution of Unix scripts as jobs. For more info, see the section [[Unix Scripts>>doc:ACMP.610.ACMP-Solutions.Desktop Automation.Unix Scripts.WebHome]].
238 238  
239 239  (% class="box infomessage" %)
240 240  (((
© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community