r1soft and ASL

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
getsolidstate
Forum User
Forum User
Posts: 60
Joined: Mon Jun 11, 2012 1:10 pm
Location: usa

r1soft and ASL

Unread post by getsolidstate »

Hi guys,
I'm trying to install R1soft CDP but it seems we are having some issues.
Are there any known problems between the two?
Could it be that R1soft does not like the ASL kernels? If so, how can we go about this?
breun
Long Time Forum Regular
Long Time Forum Regular
Posts: 2813
Joined: Sat Aug 20, 2005 9:30 am
Location: The Netherlands

Re: r1soft and ASL

Unread post by breun »

Helping might be easier if you explain what 'some issues' are exactly.

One thing I can think of: I think R1soft wants to install a custom kernel module. By default ASL does not allow loading kernel modules at runtime (see ALLOW_kmod_loading in the ASL configuration), so you might need to build the kernel module en and reboot the server so it gets loaded at boot time or allow loading kernel modules at runtime, but that means disabling one of the security features of ASL.

See the ASL FAQ here.
Lemonbit Internet Dedicated Server Management
getsolidstate
Forum User
Forum User
Posts: 60
Joined: Mon Jun 11, 2012 1:10 pm
Location: usa

Re: r1soft and ASL

Unread post by getsolidstate »

yes R1soft does install a custom kernel module.
unfortunately, i'm not sure how to load it according to the FAQ.
would be nice if someone can walk me through this.
i don't even know where r1soft kernel module is.
Imaging
Forum Regular
Forum Regular
Posts: 346
Joined: Sat Sep 25, 2010 2:46 pm

Re: r1soft and ASL

Unread post by Imaging »

Which version of the agent is in use?

We've gotten the CDP2 and CDP4 agents to work with the ASL kernel so may be able to provide some pointers (assuming you are trying to install the agent of course and not the CDP server).
getsolidstate
Forum User
Forum User
Posts: 60
Joined: Mon Jun 11, 2012 1:10 pm
Location: usa

Re: r1soft and ASL

Unread post by getsolidstate »

yes, it's for installing the agent:
r1soft-cdp-enterprise-agent-4.2.1-17820
r1soft-setup-4.2.1-17820
r1soft-cdp-agent-4.2.1-17820
r1soft-cdp-async-agent-2-6-4.2.1-17820

and the cdp server is the CDP v3.

imaging, how did you get yours to work, as i thought ASL disables kernel module loading?
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Re: r1soft and ASL

Unread post by BruceLee »

are you sure you want the enterprise and standard agent installled at the same time?
so which version do you want to install? advanced version?

short description:
update to at least gradm package (2.9.1-12)
disable kernel module protection in asl
https://www.atomicorp.com/wiki/index.ph ... s_with_ASL
install r1soft. install the asl kernel headers and devel packages and follow the build process of r1soft.
Some links:
http://wiki.r1soft.com/display/CDP3/Lin ... om+Kernels
http://wiki.r1soft.com/display/CDP3/Bui ... nel+Module

check that its loaded before 99 in your rc level
reboot.check that its working
you should also re-enable asl kernel module protection again.
reboot.
breun
Long Time Forum Regular
Long Time Forum Regular
Posts: 2813
Joined: Sat Aug 20, 2005 9:30 am
Location: The Netherlands

Re: r1soft and ASL

Unread post by breun »

Loading the module at runtime will fail, but I guess it should load after a reboot? That way you wouldn't need to disable the protection temporarily (and reboot twice).
Lemonbit Internet Dedicated Server Management
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Re: r1soft and ASL

Unread post by BruceLee »

hmm...thats the way I got it working in a test env. But I might be wrong and did more than I needed. :)
Imaging
Forum Regular
Forum Regular
Posts: 346
Joined: Sat Sep 25, 2010 2:46 pm

Re: r1soft and ASL

Unread post by Imaging »

Bruce:

That's the same procedure we followed but we didn't disable the protection. We made sure it loads before 99 in rc (used 98) so it would load before ASL locks the kernel. It loaded fine after a reboot without us having to disable/enable the protection.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: r1soft and ASL

Unread post by mikeshinn »

Thats most secure option. If you set it to load before 99, and just reboot you're good to go.
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Re: r1soft and ASL

Unread post by BruceLee »

thanks for the updates. good to know that there is a better and more secure way than the one I did.
BruceLee
Forum Regular
Forum Regular
Posts: 879
Joined: Sat Mar 28, 2009 6:58 pm
Location: Germany

Re: r1soft and ASL

Unread post by BruceLee »

one question came in my mind...
wouldnt ASL stop the kernel module creation/building?
I think I disabled it for that reason.
breun
Long Time Forum Regular
Long Time Forum Regular
Posts: 2813
Joined: Sat Aug 20, 2005 9:30 am
Location: The Netherlands

Re: r1soft and ASL

Unread post by breun »

ASL won't stop compilers from working.
Lemonbit Internet Dedicated Server Management
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: r1soft and ASL

Unread post by mikeshinn »

wouldnt ASL stop the kernel module creation/building?
No, as Breun said, ASL doesnt prevent compilers from running.
User avatar
CRServers
Forum User
Forum User
Posts: 54
Joined: Wed Jul 04, 2012 7:44 am
Location: Costa Rica

Re: r1soft and ASL

Unread post by CRServers »

I had the same problems with the Idera agent over the ASL kernel.
I happen to find the solution here:
http://vrblog.eu/encountered-issues/run ... ernel.html
I hope it helps others.
Regards,
Rodrigo Fernández
Image
http://www.crservers.com
Post Reply