DISA STIG Distribution Installation
#Overview
A DISA STIG compliant single-node Gluu Server Linux package is available only or RHEL 8. This deployment does not use a chroot container. Follow the instructions below:
- Install the Linux package
- Start the Server and log in to the container
- Run the setup script
- Sign in via browser
- Disable Gluu repositories
#Prerequisites
Make sure the target server or VM meets all minimum requirements specified in the VM Preparation Guide.
SELinux must be set to permissive in /etc/selinux/config
#Instructions
#Install the package
The Gluu Server will create its file system under /root/ and will be installed under /opt. File size and minimum requirements remain the same as the host.
Run the following commands:
wget https://repo.gluu.org/rhel/Gluu-rhel8.repo -O /etc/yum.repos.d/Gluu.repowget https://repo.gluu.org/rhel/RPM-GPG-KEY-GLUU -O /etc/pki/rpm-gpg/RPM-GPG-KEY-GLUUrpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-GLUUyum clean allyum install gluu-serverAfter installation, the gluu-server package needs to be excluded from automatic updates with the following command.
yum versionlock gluu-server#Start the server and log in
This distribution of the Gluu Server does not use a chroot container and must be started using a different process from other distributions.
Run the following commands:
TBD
#Run the setup script
Configuration is completed by running the setup script. This generates certificates, salt values, and renders configuration files. Run the script with the following commands:
cd /install/community-edition-setup./setup.pySee the Setup Script Documentation for more detail on setup script options.
#Sign in via browser
Wait about 10 minutes in total for the server to restart and finalize its configuration. After that period, sign in via a web browser. The username will be admin and your password will be the ldap_password you provided during installation.
#Disable Gluu Repositories
To prevent involuntary overwrites of the currently deployed instance (in case a newer version of the same package is found during regular OS updates), disable the previously added Gluu repositories after initial installation.
Edit /etc/yum.repos.d/Gluu.repo so that the enabled=1 clause is changed to enabled=0
#Backups
Sometimes things go wrong! It can be difficult to troubleshoot issues if the steps to reproduce the issue are not clearly documented. This is why we always recommend creating backups of your Gluu Server.
#Uninstallation
Run the following commands:
/sbin/gluu-serverd disable/sbin/gluu-serverd stopyum remove gluu-server rm -rf /opt/gluu-server.save#Support
Please review the Gluu support portal. There are many existing tickets about troubleshooting installation issues. If there is no similar existing public issue, register for an account and open a new ticket.
If your organization needs guaranteed responses, SLAs, and priority access to the Gluu support and development team, consider purchasing one of our VIP support contracts.
