Restricting Access to the AppInternals License Server

Categories:
Solution Number:
S26048
Last Modified:
2015-04-23
Issue

Any users with access to the desktop of the License Server can access and configure Appinternals Licenses. The following steps can be used to restrict user access for license operations.

Solution

You can restrict the users of a license server from performing license operations by creating a user authorization file called:
user_auth

To restrict access for server administration create a file named:
admin_auth

In these files you list machine-user pairs that are allowed to receive licenses from that server. A license server with a user_auth or admin_auth file will grant access only to those machine-user pairs listed in the file. If you do not create a user_auth or admin_auth, any user from any machine can obtain licenses and run applications.

To restrict granting of Licenses with a user_auth file:
A. Create a text file with the name user_auth and place it on the license server for which you want to specify users, in the same directory as the license file:
-  Windows:
\OPNET_License

- Linux:
/opt/OPNET_license/

B. Add machine-user pairs to the file using the following format:
machine_name username

You can use a plus sign (+) to mean any user or any machine, as shown in the following example:
engineering_machine root  js_box jsmith  ww_NT wwilson + hhoover engineering_test +

The example shows that the following permissions are granted:
engineering_machine root
* root on engineering_machine can perform license operations

js_box jsmith
* jsmith can perform operations when logged into js_box

ww_NT wwilson
* wwilson can perform operations when logged into ww_NT

+ hhoover
* hhoover can perform operations when logged into any machine

engineering_test +
* any user can perform operations when logged into engineering_test

C. After adding or editing a user authorization file, you must do one of the following things to make it take effect:
-  In the License Manager, choose Tools > Refresh Server Authorization Files.
-  Stop and restart the license server


To restrict access for server administration:
1. Create a text file with the name admin_auth and place the file in:
-  Windows:
\OPNET_License

- Linux:
/opt/OPNET_license/

2. Add machine-user pairs to the file using the format shown in step B above

3. After adding or editing a user authorization file, you must do one of the following things to make it take effect:
-  In the License Manager, choose Tools > Refresh Server Authorization Files.
-  Stop and restart the license server

Note: This file specifies machines and users. Only the users listed, when logged into the machines listed, can perform server administration operations on that server. The following operations are restricted:
* Add License
* Revoke License (however, users who are already using licenses can always revoke their own licenses)
* Change Maintenance Expiration
* Change License Expiration
* Deregister License
* Clear License File
* Update System Date
* Start Server
* Stop Server
 

Attachments
NOTICE: Riverbed® product names have changed. Please refer to the Product List for a complete list of product names.
Can't find an answer? Create a case