Radia - General Discussions

 
 
Anthony Davies
Publish a UEFI Windows 8.1 64bit image > 4GB

I am trying to publish a Windows 8.1 64bit image captured from a UEFI boot machine, but the uploaded WIM file is 6.2GB and the RADIA publisher will not publish it (It only publishes 4GB of the file).
I have tried manually splitting the image using DISM but, although this publishes OK, the subsequent download fails as the UEFIInstall.cmd that runs imagex on the target device is incorrect; it acts as though there is only one WIM file rather than two.
So, I either need a publisher that publishes > 4GB or a version of OSCapture , winpe_x64.wim and wpe-x64-810_0000n.tgz that supports split images.

We are running HPCA 8.10 with CP3 and the UEFI support code from HPCA 9.1.

Any ideas?

Tony Davies (HP)

1 0
Vinod Kumar
Linux Proxy Preloads

Hi,

Can anyone suggest what would be the best practice for preloading the Linux Proxy servers? Using External Policy

regards,
Vinod

0 0
Michael Conwell
CAE Satellite Updates using the Console

After manually upgrading a 100 server infrastructure with the 8.10.0003 patch, why isn't there functionality in the RCA console to import a Satellite patch to the Core and execute the stage it to the satellites and remotely install it on the satellites?

You would have to have it done in stages: 1. Import the patch 2. Stage the patch to the satellite 3. Execute the patch. In my mind, the staging should be done in advance of installation and it should be done so in a fashion that it doesn't flood the WAN while it copies to the Satellite. Execution needs to be done separately due to the possible scheduling restrictions imposed by a Change Management system.

Also, patches shouldn't require manual installation for desired components. If I need the 8.10.0003 patch PLUS the OS Management components, I should be able to select this from the console and then have the system update itself when I tell it too.

Supression of Reboots would be a necessary component.

Centralized reporting of success, failure, pending-reboots, etc. would be needed.

It is long past time to giving us this feature for maintaining our RCA infrastructure.

1 1
Vinod Kumar
ZOBJCID

During the migration from 7.8 to 9.1, if the ZOBJCID changes while importing the instances will it trigger an update on the client for the particular instances?

Regards,
Vinod

1 0
Jesse Swensen
SAPSTATS and HSAPSTATS tables in the RDBMS

I would like to better understand the use of these two tables. I understand HSAPSTATS is the history table for SAPSTATS. But how is the SAPSTATS table populated and with what information?

3 1
John Edmondson
9.1 Client upgrade package contains a zstop that does not work with v7.9 clients.

In the service RCA_AGENT_0910_UPGRADE_WIN
(which comes with 9.1 media for client upgrade purposes)
contains a zstop for client version which is EDMGETV(ZMASTER,ZPKGRELI)>='V0910.20140131'
unfortunately, the version in ZPKGRELI for version 7.9.x (we have 7.9.6 and 7.9.8 clients) shows as
V796.20120220
V7 is NOT less than V09 and so the zstop takes effect, and the package does not install.

Before we reinvent the wheel to fix it..Has anyone already run into this and if so how did you deal with it?

2 2
Andres Alpizar
HPCA Core v 8.1: Reporting changes PRIMARY.SECURITY even when there were not changes.

Question

In Client Automation Enterprise (CAE), when running a dmabatch to sync the core with satellites, sometimes some changes are reflected for the PRIMARY.SECURITY Domain in the sync.log, even this domain is not in use.

Example:

ADD PRIMARY.SECURITY.FILE.AXXX

ADD PRIMARY.SECURITY.FILE.AXXX

ADD PRIMARY.SECURITY.FILE.AXXX

REP PRIMARY.SECURITY.PACKAGE.XXX

REP PRIMARY.SECURITY.PACKAGE.XXX

REP PRIMARY.SECURITY.PACKAGE.XXX

Answer

Everytime  the core server/ tomcat server is restarted, the default packages(SCAP, Vulnerability)  gets published into CSDB even though they already been published.

And  if this is done the first time dmasync just after the restart ,these logs gets generated though there is no usage or change of the security domain.

 This can be verify with below steps.

1) On core machine stop all the services except the Configuration Server and DCS service.

2) Run a dmabatch sync from satellite, and check logs. The logs will not contain any of primary.security domain changes as no default package data is published to core CSDB.

3) Start the core service/tomcat service and than do the dmabatch. the logs will have primary.security domain changes.

 This process is part of the design and this a expected behavior.

 

To avoid these repeated logs ,the promotion of the default paakcges should be stopped.

This can be achceived by:

 

1)Once these packages gets published into CSDB, If these packages gets removed from the priming folder, these promote will not happen again and again.

 

2) Stop tomcat server -2) Take backup of the <CA-installed dir>\VulnerabilityServer\content\priming\services

3) Remove the content from the <CA-installed dir>\VulnerabilityServer\content\priming\services folder.

4) Start tomcat server

0 2
Vinod Kumar
Subnet Information

Is the data of Subnet information available under Satellite Management in the Radia Console stored in the Portal Open LDAP Directory ? If so which class or container have those information ?

 

Regards,

Vinod

1 0
Vinod Kumar
Satellite Management - Server Details

Hi,

Why does the Operations and Configuration tab does not show up for each Satellite servers under RCA console?

Browsing under Satellite Management for each satellite server there are different tabs available like Summary, Properties, Cache, Server Pools, Locations, Reporting, Operations and Configurations tab. We get an error while selecting Operations and Configuration tab alone ?

Screenshot attached.

Regards,

Vinod

1 1
Vinod Kumar
SSL Configuration

Hi,

Is there a way we can secure only specific components with SSL? Like we want the enable SSL only for Portal, Reporting Server, Enterprise Manager (Tomcat) and OS Manager only and not for other modules in Core/Satellite ?

Could we configure individual components? Modify only

  1. RCA.RMP.rc under Portal

  2. RRS.CFG under Reporing

  3. RCA.OSM.rc under OS Manager

Regards,

Vinod

0 0
Vinod Kumar
NVMDR Error Logs

Hi,

Under which circumstances the following messages are seen under NVDMR logs?

NVD4012I 31122013 01:49:39   Initializing    --- Logons are disabled -- sending <retry in 999 min> response

Is it during DMA sync process or any other process? I can see the Active tasks is just 12 (TASK Limit is set to 125 in edmprof.dat) so Pushbacks are ruled out.

Any insights ?

Regards,

vinod

 

5 0
Andres Alpizar
How to delete running jobs from the Core Console using table QRTZ_JOB_DETAILS.

Question

In Client Automation Enterprise (CAE),it is not possible to delete running jobs using the Core Console or the Enterprise Manager. How can these jobs be deleted and removed from the Console's Current Jobs list?

Answer

If that does not work,  In a Core & Satellite environment,these job executions can be deleted by doing the following:

  1. Open a command prompt and navigate to <HPCA>\database\bin.
  2. Run mysql.exe -u ope -p ope.
  3. Type ope and press Enter.
  4. Run a SQL command to delete the running job executions.

To delete the parent job, not an individual job execution,copy its ID and run:

delete from QRTZ_JOB_DETAILS where JOB_NAME=X; (Where X is the ID for the parent job and ";" is used to commit the command).

. This will delete the parent job and all job executions under it. 

3 0
Vinod Kumar
Sap Management

Hi,

In Core/Satellite model, we have an option in RMP.CFG to enable/disable the SAP Automatic Management. If enabled it does two things 

  1. Create SAP instances for any new Satellite server added in the environment

  2. Create RPS_ User account under PRDMAINT.POLICY.USER class

 

So is there a way we can disable the user creation only and not the SAP instance creation ?

 

Regards,

Vinod

7 1
Vinod Kumar
Add device to Satellite Group

How do we add a device to the satellite management group to install the Satellite on the device ? Under RCA Console, there is an option available to add devices to the Server group. But when selected it does not display the device list. 

 

Regards,

Vinod

1 0
Vinod Kumar
Internet Managed Clients

Team,

Again any best practice document available to manage the internet managed clients with 9.x ? This is something which we really wants to see how we can manage them. I did read briefly about how it can be managed in the PDF but it is not really sufficient information available.

 

Regards,

Vinod

3 0
Vinod Kumar
Branch Cache

Team,

Is there any best practice available to use the branch cache technology along with Radia or any third part tool recommended ?

Regards,

Vinod

2 2
Salish Gopi
Secure Communication failure in RCA

There could be various reasons for secure communication failure in an environment.

1.Expired certificates

2.SSL port not enabled

3.Signed certificate is not set

4.Host name mismatch

Solution:

1.If you discover that the certificate is expired ,on the RCA core or satellite servers use the current version of certificate generation utility to create new certificates, new keystore and trust store files.

2.Verify that the correct port is enabled. You can use telnet command for verify the same.

3.Make sure that signed certificate is set.

4.The form of the hostname simple or FQDN must also match.

For example, if you use the certificate generation utility to create certificates using this command:

Cert_mgr create signed –hostname coreserver.rcas.local

You must use the following URL to create the SSL connection:

https://coreserver.rcas.local:SSLport/console

Where SSL port is the SSL port configured on coreserver.rcas.local

0 0
Salish Gopi
How to Recover,Export and Import the OpenLDAP database

To Recover the OpenLDAP database:

1.Stop the RCA Directory service service.

2.Open the command prompt and navigate to the directory

<InstallDir>\Directoryservice.

3.Run the following command:

db_recover -cef –h database\rmp

 

To Export the OpenLDAP database:

1.Stop the RCA Directory service service.

2.Open the command prompt and navigate to the directory

<InstallDir>\Directoryservice.

3.Run the following command:

slapcat –f slapd.conf –l openldapP.ldif

 

To Import the OpenLDAP database:

1.Stop the RCA Directory service service.

2.Rename the existing rmp folder.(<InstallDir>\Directoryservice\Database\rmp)

3.Create a new rmp folder.

4.Copy the DB_CONFIG file from the existing rmp folder to the new folder.

5.Open the command prompt and navigate to the directory <InstallDir>\Directoryservice.

6.Run the following command:

Slapadd –f slapd.conf –l openldapP.ldif

7.Restart the directory services.

0 2
Fazahath Baig
Refresh DTM Schedules on Targets after CORE Schedules

If you modify the schedule for a DTM job on the HPCA Core server, you must also refresh that schedule on each target device. You can do this by creating a job using the Refresh DTM Job Schedules sample job action template.

By default, there is a DTM_DAILY_TIMER in the Configuration Server Database (CSDB) that can be entitled to a managed device to instruct its agent to perform a synchronization with its Core server once a day or job information.

A Refresh DTM Schedules job provides another way to schedule the synchronization with the Core server. For example, a Refresh DTM Schedules job can be created to ask agents to synchronize with the Core server every 12 hours for job information.

To the agent of a target device, this Refresh DTM Schedules job will be run just as any other agent job – such as a Software Connect – when the job timer expires.

Note: Before you can successfully run a Refresh DTM Schedules job on a client device, the

HPCA Agent on that client must have performed a prior connect operation to the HPCA Core

server.

0 0
Andres Alpizar
Radia v 9.0 User Capabilities Error with AD User when logging.

When logging in the Radia Console v.9.0, with an Active Directory (AD) user, a screen saying "E*rror Retrieving Capabilities*" is shown.

This happens because the account used to log in is in a different organization unit (OU), container (cn)  or groups than the one specified in the Authentication Group DN when creating the Directory Service, so please try to have the user in just one OU,CN or group.

If it is necessary for the user to be on several OU, CN, groups please contact PSL Support

0 1
Vinod Kumar
Client Agent data to Core

Hi,

In 9.x Core Satellite Architecture - What kind of information would be send from Client Agent to the Core? Like we are not doing any OSM connects so what other information would be send. Can this be tracked ?

Regards,

Vinod

 

6 1

Top Contributors