Installing WAPT Server on CentOS7¶
Configuring the CentOS/ RedHat server¶
In order to install a fresh CentOS7 machine (virtual or physical) without graphical interface (choose minimal installation), please refer to official CentOS documentation. This documentation is also valid for Redhat7 initial installation.
Configuring network parameters¶
The different parameters presented below are not specific to WAPT; you may adapt them as required for your environment.
Modify the following files in order to get a proper naming (FQDN) and network addressing strategy.
In the following example:
Configuring the name of WAPT Server¶
The short name of the WAPT Server must not be longer than 15 characters (the limit is due to sAMAccountName restriction in Active Directory).
The name of the WAPT Server must be a FQDN, that is to say it has both the server name and the DNS suffix.
/etc/hostnamefile and write the FQDN of the server;
# /etc/hostname du waptserver srvwapt.mydomain.lan
/etc/hostsfile, be sure to put both the FQDN and the short name of the server;
# /etc/hosts du waptserver 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 ::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 10.0.0.10 srvwapt.mydomain.lan srvwapt
on the line defining the DNS server IP address, be sure to have the IP of the server (not 127.0.0.1), then the FQDN, then the short name;
do not change the line with
Configuring the IP address of the WAPT Server¶
/etc/sysconfig/network-scripts/ifcfg-eth0file and define a static IP address. The name of the file can be different, like
# /etc/sysconfig/network-scripts/ifcfg-eth0 du serveur wapt TYPE="Ethernet" BOOTPROTO="static" NAME="eth0" ONBOOT="yes" IPADDR=10.0.0.10 NETMASK=255.255.255.0 GATEWAY=10.0.0.254 DNS1=10.0.0.1 DNS2=10.0.0.2
apply the network configuration by rebooting the machine with a
after reboot, configure the system language in English in order to have non-localized logs for easier searching of common errors;
localectl set-locale LANG=en_US.utf8 localectl status
check that the machine clock is on time (with NTP installed), and that SELinux and the firewall are enabled;
yum list installed | grep ntp service ntpd status date sestatus systemctl status firewalld
If the NTP package is not installed.
yum install ntp systemctl enable ntpd.service systemctl start ntpd
update CentOS7 and set up the EPEL repository;
yum update yum install epel-release wget sudo
The server is now ready. You may now go on to the next step and install WAPT on your CentOS/ RedHat.
Installing the WAPT Server on CentOS / RedHat¶
The upgrade procedure is different from installation. For upgrade, please refer to Upgrading the WAPT Server.
Installing the WAPT Server runs a few steps:
configuring the repositories;
installing additional Linux packages;
installing and provisioning the PostgreSQL database;
post-configuring the WAPT Server;
Configuring RPM repositories and installing WAPT and PostgreSQL packages¶
The configuration of repositories for WAPT Enterprise and WAPT Discovery Edition differs. Make sure to choose the right one!
During installation, you may be asked for the kerberos realm. Just press Enter to skip this step.
Follow this procedure for getting the right packages for the WAPT Enterprise Edition. For WAPT Discovery Edition please refer to the next block.
To access WAPT Enterprise resources, you must use the username and password provided by our sales department.
Replace user and password in the deb parameter to access WAPT Enterprise repository.
cat > /etc/yum.repos.d/wapt.repo <<EOF [wapt] name=WAPT Server Repo baseurl=https://user:email@example.com/entreprise/centos7/wapt-2.0/ enabled=1 gpgcheck=1 EOF
Follow this procedure for getting the right packages for the WAPT Discovery Edition. For WAPT Enterprise Edition please refer to the previous block.
WAPT Discovery will be release later in April. For the free version, refer to wapt-1.8 documentation https://www.wapt.fr/en/doc-1.8/
Installing the WAPT Server packages¶
wget -q -O /tmp/tranquil_it.gpg "https://wapt.tranquil.it/centos7/RPM-GPG-KEY-TISWAPT-7"; rpm --import /tmp/tranquil_it.gpg yum install epel-release yum install postgresql96-server postgresql96-contrib tis-waptserver tis-waptsetup cabextract
initialize the PostgreSQL database and activate the services:
sudo /usr/pgsql-9.6/bin/postgresql96-setup initdb sudo systemctl enable postgresql-9.6 waptserver nginx sudo systemctl start postgresql-9.6 nginx
For post-configuration to work properly, you must first have properly configured the hostname of the WAPT server. To check, use the command echo $(hostname) which must return the DNS address that will be used by WAPT agents on client computers.
This post-configuration script must be run as root.
run the script:
click on Yes to run the postconf script:
do you want to launch post configuration tool? < yes > < no >
choose a password for the SuperAdmin account of the WAPT server (minimum length is 10 characters);
Please enter the wapt server password (min. 10 characters) ***************** < OK > < Cancel >
confirm the password;
Please enter the server password again: ***************** < OK > < Cancel >
choose the authentication mode for the initial registering of the WAPT agents;
choice #1 allows to register computers without authentication. The WAPT server registers all computers that ask;
choice #2 activates the initial registration based on kerberos. (you can activate it later);
choice #3 does not activate the kerberos authentication mechanism for the initial registering of machines equipped with WAPT. The WAPT server will require a login and password for each machine registering with it;
WaptAgent Authentication type? -------------------------------------------------------------------------- (*) 1 Allow unauthenticated registration ( ) 2 Enable kerberos authentication required for machines registration. Registration will ask for password if kerberos not available ( ) 3 Disable kerberos but registration require strong authentication -------------------------------------------------------------------------- < OK > < Cancel >
select OK to start WAPT Server;
Press OK to start waptserver < OK >
select Yes to configure Nginx;
Do you want to configure nginx? < Yes > < No >
fill in the FQDN of the WAPT server;
FQDN for the WAPT server (eg. wapt.acme.com) --------------------------------------------- wapt.mydomain.lan --------------------------------------------- < OK > < Cancel >
select OK and a self-signed certificate will be generated, this step may take a long time …
Generating DH parameters, 2048 bit long safe prime, generator 2 This is going to take a long time .......................................+...............................+...
Nginx is now configured, select OK to restart Nginx:
The Nginx config is done. We need to restart Nginx? < OK >
The post-configuration is now finished.
Postconfiguration completed. Please connect to https://wapt.mydomain.lan/ to access the server. < OK >
Listing of post-configuration script options:
Configures Nginx so that port 80 is permanently redirected to 443
Your WAPT server is now ready. You may go to the documentation on installing the WAPT console!!