OpenPegasus WBEM Services for Linux
Go to file
2014-09-01 15:55:43 +02:00
.gitignore Update to upstream version 2.12.1 2013-03-31 15:40:32 +01:00
access.conf port from RHEL-4; upgrade to 2.5 2005-10-03 17:56:03 +00:00
cimprovagt-wrapper.sh Add cimprovagt wrapper for possibility of confining providers in SELinux, update README.RedHat.Security accordingly, add provider specific wrapper example 2012-12-18 13:43:09 +01:00
cmpiOSBase_OperatingSystemProvider-cimprovagt.example Add cimprovagt wrapper for possibility of confining providers in SELinux, update README.RedHat.Security accordingly, add provider specific wrapper example 2012-12-18 13:43:09 +01:00
generate-certs Fix Pegasus service regenerates SSL certificates on every start 2014-08-12 12:40:10 +02:00
pegasus_arch_alternatives Port to ppc64le architecture 2014-03-18 12:07:38 +01:00
pegasus_rpm_build_env.sh Port to ppc64le architecture 2014-03-18 12:07:38 +01:00
pegasus-2.5.1-pam-wbem.patch - Use password-auth common PAM configuration instead of system-auth 2009-09-16 18:59:02 +00:00
pegasus-2.5.1-warnings.patch fix bug 190432; fix upstream bugs 4955 4956 4968 4978 4983 4984 4986 5017 2006-05-03 00:13:59 +00:00
pegasus-2.6.0-cimuser.patch changed %build section 2007-03-21 10:13:24 +00:00
pegasus-2.7.0-no_snmp_tests.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.7.0-PIE.patch Update to upstream version 2.11.0 2011-05-19 15:50:06 +02:00
pegasus-2.9.0-cmpi-provider-lib.patch Update to upstream version 2.11.0 2011-05-19 15:50:06 +02:00
pegasus-2.9.0-local-or-remote-auth.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.9.0-no-rpath.patch Update to upstream version 2.12.0 2012-10-09 11:22:20 +02:00
pegasus-2.9.0-redhat-config.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.9.0-sparc.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.9.1-getpagesize.patch Update to upstream version 2.9.2, Cleanup the spec file, use upstream Makefile 2010-11-03 15:15:38 +01:00
pegasus-2.10.0-dont-strip.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.10.0-sparc-posix-lock.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.12.0-cimmofl-allow-experimental.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.12.0-empty_arrays.patch Fix getPropertyAt() returns Null instead of empty array (patch by Jan Safranek) 2013-01-08 14:32:11 +01:00
pegasus-2.12.0-null_value.patch Fix CMPI enumGetNext function to change CMPI Data state from default CMPI_nullValue to CMPI_goodValue when it finds and returns next instance correctly, Enable processing of ExecQuery operations 2012-10-24 14:16:56 +02:00
pegasus-2.12.0-schema-version-and-includes.patch Use Experimental DMTF CIM schema version 2.38.0 2013-09-05 15:45:19 +02:00
pegasus-2.13.0-build-fix.patch Update to upstream version 2.13.0 2013-09-03 12:30:53 +02:00
pegasus-2.13.0-CMGetKey-data-type-fix.patch Fix cmpi: CMGetKey() returns wrong data type for some data types 2014-07-01 12:46:51 +02:00
pegasus-2.13.0-enable-subscriptions-for-nonprivileged-users.patch Allow unprivileged users to subscribe to indications, Remove packages which are part of the minimum build environment from BR 2014-01-08 10:09:14 +01:00
pegasus-2.13.0-PG_ComputerSystem.CreationClassName.patch Fix PG_ComputerSystem to have correct CreationClassName value 2013-10-24 14:39:14 +02:00
pegasus-2.13.0-SSLGeneration.patch Increase security of generating SSL certificates 2014-09-01 15:55:43 +02:00
pegasus-2.13.0-wrong-embedded-instances-from-cimom-callback.patch Fixed wrong instances from CIMOM callback 2014-08-05 16:15:57 +02:00
README.RedHat.Security Add cimprovagt wrapper for possibility of confining providers in SELinux, update README.RedHat.Security accordingly, add provider specific wrapper example 2012-12-18 13:43:09 +01:00
README.RedHat.SSL update to 2.9.0 2009-06-16 12:09:03 +00:00
rpm_build_env Port to ppc64le architecture 2014-03-18 12:07:38 +01:00
sources Use Experimental DMTF CIM schema version 2.38.0 2013-09-05 15:45:19 +02:00
tog-pegasus.service Wait for the slpd.service in the systemd unit file 2014-03-12 14:59:51 +01:00
tog-pegasus.spec Increase security of generating SSL certificates 2014-09-01 15:55:43 +02:00
tog-pegasus.tmpfiles Use %%ghost for /var/run/tog-pegasus 2011-03-22 12:39:44 +01:00

              Red Hat SSL configuration for tog-pegasus
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   The Red Hat tog-pegasus package is built with support for SSL
   (the Secure Socket Layer).
   Note: the upstream documentation for SSL is located here:
   /usr/share/doc/tog-pegasus-%{version}/PegasusSSLGuidelines.htm
   However, because the upstream documentation for SSL is not up-to-date
   (it was last updated in March, 2006, around the time of the
   OpenPegasus-2.5.1 release), nor accurate, we are providing this short
   description of how to configure SSL, as well as how it should be used.

 Hard-Coded Build-Time Constants:
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Here is the list of constants which are hard-coded during build time:

   PEGASUS_CONFIG_DIR = /etc/Pegasus

   PEGASUS_PEM_DIR = $(PEGASUS_CONFIG_DIR)
                  (= /etc/Pegasus)

   PEGASUS_SSL_KEY_FILE = file.pem
   PEGASUS_SSL_KEY_FILE_PATH = $(PEGASUS_PEM_DIR)/$(PEGASUS_SSL_KEY_FILE)
                  (= /etc/Pegasus/file.pem)
   o Contains the private key for the CIM Server SSL Certificate.

   PEGASUS_SSL_CERT_FILE = server.pem
   PEGASUS_SSL_CERT_FILE_PATH = $(PEGASUS_PEM_DIR)/$(PEGASUS_SSL_CERT_FILE)
                             (= /etc/Pegasus/server.pem)
   o Contains the CIM Server SSL Certificate.

   PEGASUS_SSL_TRUSTSTORE = client.pem
   PEGASUS_SSL_CLIENT_TRUSTSTORE = $(PEGASUS_PEM_DIR)/$(PEGASUS_SSL_TRUSTSTORE)
                                (= /etc/Pegasus/client.pem)
   PEGASUS_SSL_SERVER_TRUSTSTORE = $(PEGASUS_PEM_DIR)/cimserver_trust
                                (= /etc/Pegasus/cimserver_trust)
   o Specifies the location of the OpenSSL truststore. Consistent with the
     OpenSSL implementation, a truststore can be either a file or directory.
     If the truststore is a directory, then all certificates within the
     directory are considered trusted.

   PEGASUS_SSL_SERVER_CRL = $(PEGASUS_PEM_DIR)/crl
                         (= /etc/Pegasus/crl)
   o This is where the CRL (Certificate Revocation List) store resides.

 Tips Following Package Installation:
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   o CIM Server default SSL certificates are generated when you run the
     tog-pegasus daemon (for example, by issuing the command
     "service tog-pegasus start") for the first time, which includes the
     following files, which are created in /etc/Pegasus: client.pem, file.pem,
     server.pem and ssl.cnf.
     Important: simply running the "cimserver" binary (/usr/sbin/cimserver)
     does NOT create the certificates or abovementioned files.
     Note: if you want to use your own certificates, simply overwrite the ones
     in /etc/Pegasus.

   o to enable/disable HTTPS port 5989 (the official WBEM secure port),
     use cimconfig.

   o the wbemcli command (from the sblim-wbemcli package)
     uses /etc/Pegasus/client.pem by default (see man wbemcli).