# Introduction - User Manual

LCC® - Linux Control Center is a powerful centralized management solution for Linux servers. Developed to facilitate administration and provide visibility into tasks executed in the Linux environment, LCC is the perfect tool for small teams looking to perform administration tasks in a centralized, automated, and efficient manner. With LCC, you can reduce the chances of human error and gain total control over your corporate environment.

The creation of LCC has its roots in the complexity of managing package updates, implementing patches, maintaining activity history, and the operations team's requirement to efficiently and effectively communicate the execution of these tasks and their impacts to management.

**Main features:**

* **Agentless** - no agents need to be installed on remote servers
* **Automatic network discovery** for server inclusion
* **Package management**
* **Vulnerable package identification**
* **User account management**
* **File management**
* **Service administration**
* **Script and playbook execution**
* **Scheduling**
* **Alerts**
* **Creation of restore points in virtualizers**
* **Diverse integrations**
* **High availability** (cluster mode)
* **Reports**

**Architecture:**

&#x20; ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/en/images/fluxo-lcc-completo.png)\
&#x20;
------

**Contact us**

Website: <https://linuxcontrolcenter.com.br>

Quick Start: <https://docs.linuxcontrolcenter.com.br/quick-start>

Forum: <https://forum.linuxcontrolcenter.com.br>

Docs: <https://docs.linuxcontrolcenter.com.br>

Instagram: <https://instagram.linuxcontrolcenter.com.br>

Telegram: <https://telegram.linuxcontrolcenter.com.br>

Commercial Email: <comercial@7dev.net.br>

Support Email: <suporte@7dev.net.br>

Phone: [(61) 99883-9004](tel:+5561998839004)

Whatsapp: [(61) 99883-9004](https://wa.me/5561998839004?text=Ol%C3%A1!%20Vi%20seu%20contato%20na%20p%C3%A1gina%20de%20documenta%C3%A7%C3%A3o%20do%20Linux%20Control%20Center!)


# Requirements


# Server Requirements

The tables below indicate the minimum software and hardware requirements for the Linux Control Center.

{% hint style="warning" %}
**Note:** It is not necessary to pre-install any software requirements. The LCC installation script automatically handles the installation of all dependencies.
{% endhint %}

### Hardware Requirements

|   CPU   |  RAM | Disk Space |
| :-----: | :--: | :--------: |
| 4 Cores | 8 GB |   200 GB   |

### Software Requirements

|   Operating System  |        Docker       |     Database    |
| :-----------------: | :-----------------: | :-------------: |
| Debian 12 amd64-bit | Docker Engine 23.x+ | PostgreSQL 15.x |

{% hint style="warning" %}
For 'All-in-One' installations, where all components (Console, Worker, and Alert & Report) are installed on the same server, consider all traffic rules with the same server as the source. For installations with dedicated servers for each service, refer to the **Source** and **Destination** columns in the tables below for each component.
{% endhint %}

### External Access Requirements

|               Source              |             Destination            |   Port  | Protocol |
| :-------------------------------: | :--------------------------------: | :-----: | :------: |
| Console / Worker / Alert & Report | download.linuxcontrolcenter.com.br | TCP/443 |   HTTPS  |
| Console / Worker / Alert & Report |           deb.debian.org           |  TCP/80 |   HTTP   |
| Console / Worker / Alert & Report |         download.docker.com        | TCP/443 |   HTTPS  |
| Console / Worker / Alert & Report |     customer-portal.lcc7.online    | TCP/443 |   HTTPS  |
|          Console / Worker         |          cloud.tenable.com         | TCP/443 |   HTTPS  |
|              Console              |       7vulndb-api.lcc7.online      | TCP/443 |   HTTPS  |

### Internal Access Requirements

|     Source     |        Destination        |          Port          |    Protocol    |
| :------------: | :-----------------------: | :--------------------: | :------------: |
|     Worker     |          Console          |         TCP/443        |      HTTPS     |
| Alert & Report |          Database         |        TCP/5432        |       TCP      |
|     Worker     |    Hosts managed by LCC   | Defined by environment | SSH/WinRM/ICMP |
|     Console    |       vCenter / ESXi      | Defined by environment |   HTTP/HTTPS   |
|     Worker     | BeyondTrust Password Safe |           De           |                |


# Client Requirements

The table below indicates the minimum software requirements that clients need to be managed by Linux Control Center.

### Client Distribution Requirements

|       Distribution       |                                                                                                                                                                  Release                                                                                                                                                                  |
| :----------------------: | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: |
|        Alma Linux        |                                                                                                                                                    <p>Alma Linux 8<br>Alma Linux 9</p>                                                                                                                                                    |
|          Debian          |                                                                                                                                     <p>Debian 8<br>Debian 9<br>Debian 10<br>Debian 11<br>Debian 12</p>                                                                                                                                    |
|          Fedora          |                                                                                                                                                                 Fedora 37                                                                                                                                                                 |
|          CentOS          |                                                                                                                                  <p>CentOS Linux 7 (Core)<br>CentOS Linux 8 (Core)<br>CentOS Stream 9</p>                                                                                                                                 |
|         openSUSE         |                                                                                                                                              <p>openSUSE 13<br>openSUSE 14<br>openSUSE 15</p>                                                                                                                                             |
|  Oracle Enterprise Linux |                                                                                                                         <p>Oracle Enterprise Linux 7<br>Oracle Enterprise Linux 8<br>Oracle Enterprise Linux 9</p>                                                                                                                        |
| Red Hat Enterprise Linux |                                                                                                                       <p>Red Hat Enterprise Linux 7<br>Red Hat Enterprise Linux 8<br>Red Hat Enterprise Linux 9</p>                                                                                                                       |
|           Rocky          |                                                                                                                                                         <p>Rocky 8<br>Rocky 9</p>                                                                                                                                                         |
|          Ubuntu          |                                                                                                                                                    <p>Ubuntu 20.04<br>Ubuntu 22.04</p>                                                                                                                                                    |
|           Mint           | <p>Linux Mint 19.x (Tara)<br>Linux Mint 19.1 (Tessa)<br>Linux Mint 19.2 (Tina)<br>Linux Mint 19.3 (Tricia)<br>Linux Mint 20.x (Ulyana)<br>Linux Mint 20.1 (Ulyssa)<br>Linux Mint 20.2 (Uma)<br>Linux Mint 20.3 (Una)<br>Linux Mint 21 (Vanessa)<br>Linux Mint 21.1 (Vera)<br>Linux Mint 21.2 (Victoria)<br>Linux Mint 21.3 (Virginia)</p> |

***

### Client Software Requirements

|                   Software                  |                                                                        Version                                                                       |
| :-----------------------------------------: | :--------------------------------------------------------------------------------------------------------------------------------------------------: |
|                    Python                   |                                                         <p>2.7 or higher<br>3.6 or higher</p>                                                        |
| Ciphers enabled and supported for SSH login | <p>3des-cbc<br>aes128-cbc<br>aes192-cbc<br>aes256-cbc<br>aes128-ctr<br>aes192-ctr<br>aes256-ctr<br>aes128-gcm<br>aes256-gcm<br>chacha20-poly1305</p> |
|                     Sudo                    |                                                                   1.8.31 or higher                                                                   |
|                     SSH                     |                                                                Key-based login enabled                                                               |


# Quick Start

## Overview

Understanding how the LCC® - Linux Control Center works is an essential step to ensure a successful implementation and an efficient onboarding process in your environment.

In this Quick Start guide, we will cover the basic operation of the tool, as well as the initial steps that should be performed right after installing the LCC.

## Basic Operation of LCC

LCC is an orchestration solution for Linux systems. It features a Web Console through which commands can be sent to the Worker module, which is responsible for executing various user-requested actions. Additionally, LCC includes an Alert & Report module that generates alerts and detailed logs of all actions performed via the Console or by the Worker, providing a comprehensive and centralized view of all executed operations.

The essential step for the LCC onboarding process is importing the Hosts to be managed into the database. This task can be performed using the **Discover** feature or by importing **Managed Assets** through integration with **BeyondTrust PasswordSafe**. Only after importing the Linux Hosts will the LCC be able to execute all available Actions.

* It is possible to handle Microsoft Windows Hosts, which are treated as **Unmanaged Hosts**, with limited actions restricted to executing **PowerShell** scripts via **WinRM**.

## How to Request a Community License

LCC® - Linux Control Center offers a **Community License** that allows free usage of the LCC, limiting only the number of managed hosts, which is set to **25 hosts total**.

1. Visit <https://start.linuxcontrolcenter.com.br>, fill in your information correctly, read, and agree to the **Terms and Conditions of Use** of LCC.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3185dff63588a16b6fbc7ec7dcdd5ff2813a4f9e%2Ftela_de_licenca.png?alt=media)

{% hint style="info" %}
You will then receive the **UUID** and **Password** for the Community License in the registered email.

If you do not receive the email, check your Spam folder or contact the support team via the **Contact Us** channels at <https://docs.linuxcontrolcenter.com.br>.
{% endhint %}

## How to Install LCC

### Install Tutorial

1. After receiving your Community License, follow the step-by-step installation guide available at:

   <https://docs.linuxcontrolcenter.com.br/setup-install>

### Establishing Trust Between Console and Worker

1. Right after installation, it is necessary to accept the Worker to enable the execution of Actions.
2. Log in to LCC with the user **7dev** and password **7dev**.

* The URL should follow this pattern: https\:// \[IP or Hostname]/console/

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-974731bf7c9d5334205865cd252e24a19635d8e9%2Flogin_lcc.png?alt=media)

1. Check the **Terms of Use** box and click **Accept**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-faee517b210776011e63626f47c841281a932773%2Faceite_termos%20de%20uso.png?alt=media)
2. Click on **Config**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
3. Click on **Worker**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cd65fda9af58f4b015594beb0bc963576b9eda30%2Fbotao_worker.png?alt=media)
4. Click on **Actions**, then select **Trust**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d291783e31af1fedf9c271cf99572853a9c257f8%2Ftrust_worker.png?alt=media)
5. The status will change to **Accepted**, indicating that the LCC is ready for use!

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f944d6e8626b8f33a6a66b8f50b7d3ba231d85cc%2Fworker_aceito.png?alt=media)

## Recommended First Tasks After Installing LCC

### Run Discover

* After accepting the Worker, the next task to perform is **Discover**.
* Check the technical details of running **Discover** at the link below:

<https://docs.linuxcontrolcenter.com.br/discover_lcc>

### Check Packages for Available Updates

* The recommended Action to run is **Package Check Update**, which checks for available package updates, making it easier to update all managed Hosts.
* To execute this Action, follow the steps in the link below:

<https://docs.linuxcontrolcenter.com.br/host-actions/package-check-update>


# Setup and Installation

## Requirements

Server and Client requirements: <https://docs.linuxcontrolcenter.com.br/requirements>\
Community License requested at: <https://start.linuxcontrolcenter.com.br>

* The **Community License** is free and includes all features enabled, with a limitation of managing up to **25 hosts**.

For organizations that require support for a larger number of devices, we recommend purchasing the **Enterprise License**. Contact us at <https://linuxcontrolcenter.com.br/contato/> for more information and to learn how to scale your operations efficiently.

## Overview

The installation of the Linux Control Center is done via a Bash script. The entire installation process is automated, requiring only the configuration of a few variables.

## Purpose

This manual aims to demonstrate the step-by-step process of installing the LCC using the installation script.

## LCC Installation

### Installation Script

{% hint style="warning" %}
**Note:** It is not necessary to manually install any software dependencies. The LCC installation script automatically installs all required dependencies.
{% endhint %}

1. Copy the script below by clicking the **Copy** button.

```
#!/bin/bash
address=""
db_name=""
db_user=""
db_pass=""
redis_pass=""
license_uuid=""
license_password=""
tag_version="stable"

#download lcc-cli

rm -rf lcc-cli-*.tar.gz 2> /dev/null

wget https://download.linuxcontrolcenter.com.br/repository/public/lcc-cli-stable.tar.gz

# untar lcc-cli
tar -xzvf lcc-cli-stable.tar.gz

# make /opt/lcc/bin directory
mkdir -p /opt/lcc/{bin,etc}

# move lcc-cli to /opt/lcc/bin
mv lcc-cli-stable /opt/lcc/bin/lcc-cli

# make lcc-cli executable
chmod +x /opt/lcc/bin/lcc-cli

rm -rf /usr/local/bin/lcc-cli 2> /dev/null

ln -s /opt/lcc/bin/lcc-cli /usr/local/bin/lcc-cli

cat > /opt/lcc/etc/database.yml <<EOF
db_name: ${db_name}
db_user: ${db_user}
db_pass: ${db_pass}

EOF

cat > /opt/lcc/etc/console.yml <<EOF
balancer_url: https://${address}
site_url: https://${address}
node_url: https://${address}
node_sequence: 1
db_name: ${db_name}
db_user: ${db_user}
db_pass: ${db_pass}
db_host: ${address}
db_port: 5432
threads: 10
redis_pass: ${redis_pass}

EOF

cat > /opt/lcc/etc/worker.yml <<EOF
console_url: https://${address}
console_uuid_server: ${license_uuid}
node_url: https://127.0.0.1
work_threads: 10
self_threads: 3

EOF

cat > /opt/lcc/etc/alert_report.yml <<EOF
db_name: ${db_name}
db_user: ${db_user}
db_pass: ${db_pass}
db_host: ${address}
db_port: 5432
redis_pass: ${redis_pass}
threads: 3

EOF

cat > /opt/lcc/etc/license.yml <<EOF
license_uuid: ${license_uuid}
license_password: ${license_password}

EOF

cat > /opt/lcc/etc/version.yml <<EOF
tag_version: $tag_version

EOF

lcc-cli database --install
lcc-cli console --install
lcc-cli worker --install
lcc-cli alert-report --install

exit 0
```

### Script Configuration

1. Access the host where LCC will be installed using the **root** user in the terminal.
2. Create a file with a **.sh** extension and paste the script content.

   Example: `nano script-install.sh`
3. Configure the variables as described below:
   * **address=" "** → Domain (FQDN) or IPv4 address of the host used to access the Console.<br>
   * **db\_name="lcc"** → Keep the default database name for easier management.<br>
   * **db\_user=" "** → Enter a username for the database.<br>
   * **db\_pass=" "** → Enter a password for the database.<br>
   * **redis\_pass=" "** → Enter a password for Redis.<br>
   * **license\_uuid=" "** → Enter the license UUID.<br>
   * **license\_password=" "** → Enter the license password.<br>
   * **tag\_version="stable"** → Keep the **stable** tag to install the latest stable version of LCC.<br>
4. See the example in the image below:

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-81296d737890574055f2eb99cf64978a344dde31%2Fconfigurando_variaveis.png?alt=media)
5. Save the script changes:

* Keyboard shortcut to save (nano): `ctrl + o`
* Keyboard shortcut to exit (nano): `ctrl + x`

### Script Permissions and Execution

1. Add execute permission to the script with the command:

   Command: `chmod +x script-install.sh`

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d05234e9fef85850b9ab2527913bd7e0869421e7%2Fchmod_script.png?alt=media)
2. Em seguida, execute o script e escolha o idioma digitando o número correspondente para leitura da EULA.

   Command: `./script-install.sh`

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d7bf1fb0dee31b8f118ebd10253e34a5b8efaf84%2Fidioma_licenca.png?alt=media)
3. Read the EULA and agree by pressing Enter.
4. Confirm acceptance of the EULA by typing yes and pressing Enter, then type y to start the LCC installation.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-caf14a0f3b41ede88a844d0046d5d20b2ea4e762%2Faceitando_instalacao.png?alt=media)
5. The terminal will become available once the installation is complete.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7bcef3301c6e9d84809bac8c74b4b74ec72ec0df%2Finstalacao_concluida.png?alt=media)

### First Login to LCC

1. Access the LCC URL in the following format:

   https\:// ip-address ou Hostname/console/
2. Enter the default credentials and click LOG IN:

   * *Username: 7dev*
   * *Password: 7dev*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c6f30cd5743037573225b162b4fcea817c8c3026%2Ftela_login.png?alt=media)
3. Accept the Terms of Use and log in.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-faee517b210776011e63626f47c841281a932773%2Faceite_termos%20de%20uso.png?alt=media)

### Establishing Trust Between Console and Worker

1. Right after installation, it is necessary to establish trust between the Console and the Worker to enable the execution of Actions.
2. Click on **Config**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
3. Click on **Worker**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cd65fda9af58f4b015594beb0bc963576b9eda30%2Fbotao_worker.png?alt=media)
4. Click on **Actions**, then click **Trust**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d291783e31af1fedf9c271cf99572853a9c257f8%2Ftrust_worker.png?alt=media)
5. The status will change to **Accepted**, indicating that the LCC is ready for use!

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f944d6e8626b8f33a6a66b8f50b7d3ba231d85cc%2Fworker_aceito.png?alt=media)


# Dashboard

## Dashboard

The Linux Control Center Dashboard displays various information to the user at a glance.

## Hosts and Packages Overview

The first section, Hosts and Packages Overview, shows key information about the Hosts so that the administrator can take action based on what is displayed.

* **Hosts**: Total number of hosts managed by LCC
* **Packages**: Lists all packages from all Hosts discovered by LCC.
* **Updatable Hosts**: Hosts that have packages available for update.
* **Updatable Packages**: Number of packages available to be updated.
* **Host Alerts**: Hosts that have packages with alerts.
* **Package Alerts**: Number of packages with vulnerability alerts.

### Updated Packages Chart

This chart displays the number of packages updated by LCC over time, with each update date properly recorded. If needed, you can easily download the chart by clicking the 3-line button located in the upper-right corner of the chart and choosing the desired format, available in SVG, PNG, and CSV.

### Packages with Alerts

* This chart displays all packages identified as vulnerable, either through the 7 Vulndb API or through integrations with Tenable Security Center and Tenable Cloud Security.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-648806effeb61cff21ba590f6c8173acf15f7a17%2Fdashboard-pacotes.png?alt=media)

### Packages with Pending Updates

This chart shows the total number of packages available for update, along with the respective dates when the checks were performed. You can also download this report.

### Actions Performed

This chart displays the total number of all actions performed in the Linux Control Center, along with the respective dates. As with the previous charts, it is possible to download it.

### Host Actions

* This table shows only the Actions related to hosts, such as Package Update, for example. These Actions can also be checked in the general queue by clicking the **Actions Working** button at the top of the page, where these and all other Actions already performed by LCC are listed.
* By clicking the **Expand** button on the desired action row, you can view the detailed output logs of that Action.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-54e63757c2424f4d5b93995152d94822111bbbcf%2Fdashboard-action-performed.png?alt=media)

### Alerts

* This table displays specific actions performed in the LCC by a user, such as removing a host from an integration or attempts to access an LCC page by an unauthenticated user.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-577e6bd83beb63c7399fe04ffd7118306c94f544%2Fdashboard-alerts.png?alt=media)


# Discover


# Linux Control Center Discover

## Requirements

Linux Control Center = 2.10.X or higher

Client Requirements = <https://docs.linuxcontrolcenter.com.br/requirements/client-requirements>

## Purpose

* This document aims to explain how the LCC Discover works, providing step-by-step instructions, use cases, and solutions to common issues.

## Overview

* LCC Discover is the first task that should be executed after installing the Linux Control Center. Running Discover allows automated importing of network hosts. Discover does not require installing any agents on the hosts, only SSH access is needed.
* To ensure optimal functionality, Discover is divided into 5 steps, each executed independently. See the description of each step below.

**Host Ping**

* This is the first step to find active hosts on the network. It sends pings to all addresses within the configured CIDR. When LCC receives a ping response, it reads the TTL (Time to Live) value to identify the operating system associated with the IP address.
* All IPs that respond to the ping are recorded in the **IPs Alive** list during execution to be processed in the next steps. If a host blocks ping requests, it may still be found in the next steps.

**Search SSH Port**

* This step helps when the administrator does not know the SSH port of the target hosts. Discover scans all 65,535 TCP ports to detect which one is running SSH. Enabling this option will significantly increase execution time. Adjust **Time Out** settings in **Config Execution**, as explained in section 13 of this guide.

**Test Credentials**

* Correct credential input is crucial. These credentials are tested in the **Test Credentials** step. If credentials are incorrect, LCC will not be able to import the hosts.
* If multiple credentials are provided, Discover will use the first one that succeeds in privilege escalation on a host, and then return to the first credential for the next host.

**Import Hosts**

* In this step, the host has already been identified and credentials validated. LCC connects to the host and enumerates information such as installed packages, package versions, and more for management in the LCC web console.
* For Discover to succeed, the user provided must have permission to create a local account (`lcc.local`) on the remote server.

**PAM**

* This step integrates with BeyondTrust Password Safe to authenticate hosts using credentials stored in the vault integrated with LCC.

## Privilege Escalation

* Understanding privilege escalation is essential for configuring credentials correctly. Below is a summary of each privilege escalation method.

**sudo without password**

* The user in the **Username** field must have permission to escalate directly to root without a password. Only the **Password** for the username is required.

**sudo with password**

* The **Username** must have sudo privileges, but both the user password and the **Privilege Escalation Password** (typically root's password) are needed.

**None**

* This option is used when the SSH user has sufficient permissions for account creation and SSH key configuration (typically the `root` user).

**su -**

* Logs in with the **Username**, then switches to the privileged user set in **Privilege Escalation Username** using the **Privilege Escalation Password**.

## Running Discover

### Discover with Local Credentials

1. Click **Discover** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-21bb326d248deb72da73eeb3e6c0db2766f81d0e%2Fdiscover_dashboard.png?alt=media)
2. Click **ADD**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-35ed26e6f8bf1af20703c3aa18a02bbb388e237b%2Fadd_discover.png?alt=media)
3. Enter a name in the **Name** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fdbd62c6143ec006bfb339a503a4a64f69bfbf2b%2Fname_discover.png?alt=media)
4. Click **+** in the **Credentials** section.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-886e8cb4507576142799c1990b82cd2fa721f610%2Fadd_credentials.png?alt=media)
5. Fill in the credential fields:
   * **Name:** Identifier for the credential.<br>
   * **Auth Type:** SSH authentication method (**Password** or **Key**).<br>
   * **Username:** SSH user.<br>
   * **Password:** SSH user password.<br>
   * **Privilege Escalation:** Select the escalation method.<br>
   * **Privilege Escalation Username:** (If required) Privileged user with permission to create accounts and modify sudoers.<br>
   * **Privilege Escalation Password:** (If required) Password for the privileged user.
6. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a4d83565300a3a508ce7a0456a790630f15aae4b%2Fsave_credential.png?alt=media)
7. Click **+** in the **CIDRs** section.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-17a71e141ae29f94ab5e9a32ff0e9f972c224dbe%2Fadd_cidr.png?alt=media)
8. Enter a **Name** for the CIDR range.
9. Enter the IP range in **CIDR** format.
10. Click **Save**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c4368ce80a480a810b86306144cc855432439c44%2Fcird_name.png?alt=media)
11. Click **+** in the **Ports** section.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c478c9f67edf27641679ff0db647aafc0bc16744%2Fadd_port.png?alt=media)
12. Enter the SSH port number in the **Port** field and click **Save**.

    * This is the SSH port Discover will use to connect.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b8b824fede22cbe80064a4e93534b303780ea2d7%2Fports.png?alt=media)
13. Check **Search SSH Port** if the SSH port is unknown. If enabled, do not fill the **Port** field and adjust **TimeOut** settings as explained in [Search SSH Port](#search-ssh-port).

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b3abc11c21a3348d97bc4d729981ca6ab4a959cd%2Fsearch_ssh_port.png?alt=media)
14. Verify all fields and click **Save**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9f220f83202f4753a302c6cbf69e749518192659%2Fsave_discover.png?alt=media)
15. Click **Actions** > **Run Discover**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-22a84793355cb6097ef7f4f7ad3ef103f7202d1d%2Frun_discover.png?alt=media)
16. Confirm by clicking **YES**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-411325fa89762cb2b8125927f6564782a84feeef%2Fconfirmar_execucao.png?alt=media)
17. Monitor progress by clicking **Actions Working**. Wait until the status shows **Processed**, indicating completion.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-883096556e2212cf752bad52e4b2b6d813233c34%2Factions%20working.png?alt=media)

### Discover with BeyondTrust Password Safe Integration

* Follow this guide to run Discover using credentials from BeyondTrust Password Safe:

<https://docs.7dev.net.br/adding-hosts/beyondtrust-password-safe-api>

## Credential Use Cases

### Discover with Root User

* Logs in directly as `root`. The **PermitRootLogin** option must be enabled on the hosts' SSH server.

**Username:** root\
**Password:** root password\
**Privilege Escalation:** **none**

Example:

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9355c66463c4704a74c7d5e17cf53cd9bd0a3a67%2Froot_user.png?alt=media)

### Discover with Non-Privileged User

* Logs in with a regular user and escalates to root using **su -**.

**Username:** non-privileged user\
**Password:** user password\
**Privilege Escalation:** **su -**\
**Privilege Escalation Username:** root\
**Privilege Escalation Password:** root password

Example:

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5effe11a42b380991194448ff37a8b9b3db75be5%2Fsu_escalonation.png?alt=media)

### Discover with Privileged User (sudo without password)

* Uses a sudo user configured with **NOPASSWD**.

**Username:** sudo user\
**Password:** user password\
**Privilege Escalation:** **sudo without password**

Example:

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-19716150fc0978640c28741984e0312ff8600ae7%2Fsudo_without_password.png?alt=media)

### Discover with sudo and password

* Uses a sudo user requiring the root password for privilege escalation.

**Username:** sudo user\
**Password:** user password\
**Privilege Escalation:** **sudo with password**\
**Privilege Escalation Password:** root password

Example:

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1b0f5ad4f4668631f1882dd6722e8d9df43b2ef7%2Fsudo_with_password.png?alt=media)

### SSH Key Authentication

* Uses SSH keys instead of passwords.

> ⚠️ **Warning:** SSH key-based authentication must be configured on all target hosts prior to running Discover. This does not interfere with privilege escalation methods.

**Username:** SSH key user\
**Auth Type:** **Key**\
**Privilege Escalation:** Select as needed\
**Private Key:** SSH private key

Example:

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3ef83903c0427c02fe897c89af2ba2c3919ae050%2Fcredential_key.png?alt=media)

## Host Identification Use Cases

### Discover CIDRs

* Define target networks using CIDR objects.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-691dc86da59daa9e9005379ca567f17369f83fc8%2Fcidr_example.png?alt=media)

* Multiple CIDRs can be used simultaneously.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d3ada3593925fec7ff8b0f6355b410200534f23d%2F2_cidr.png?alt=media)

### CIDRs Supported by LCC

| CIDR | Subnet Mask     | Available Addresses |
| ---- | --------------- | ------------------- |
| /16  | 255.255.0.0     | 65,536              |
| /17  | 255.255.128.0   | 32,768              |
| /18  | 255.255.192.0   | 16,384              |
| /19  | 255.255.224.0   | 8,192               |
| /20  | 255.255.240.0   | 4,096               |
| /21  | 255.255.248.0   | 2,048               |
| /22  | 255.255.252.0   | 1,024               |
| /23  | 255.255.254.0   | 512                 |
| /24  | 255.255.255.0   | 256                 |
| /25  | 255.255.255.128 | 128                 |
| /26  | 255.255.255.192 | 64                  |
| /27  | 255.255.255.224 | 32                  |
| /28  | 255.255.255.240 | 16                  |
| /29  | 255.255.255.248 | 8                   |
| /30  | 255.255.255.252 | 4                   |
| /31  | 255.255.255.254 | 2                   |
| /32  | 255.255.255.255 | 1                   |

### Upload CIDR via CSV

* Upload a CSV file with the structure:

name,target\
CIDR Name,IP/CIDR

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e0fab67d32e62f3daa2322defea876795e5f2dc0%2Fexemplo_upload_cidr.png?alt=media)

1. Click **Upload**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e266a0e9b9704c9d2c7c910c1acf6e632b42fd95%2Fbotao_upload.png?alt=media)
2. Click **Select File**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-86d405ef84a6d4acb150dce65ef035bf0ca30898%2Fbotao_select_file.png?alt=media)
3. Upload the file and click **Confirm**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9f253f877fb7ad95bf351381e509819dd42b4984%2Fbotao_confirm_upload.png?alt=media)

### Search SSH Port

* Discover will scan all 65,535 TCP ports to detect which one is running SSH.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-165589a40b47d17581e9b448e434e5a98729cb38%2Fsearch_ssh_casosde_uso.png?alt=media)

* Adjust the Discover Time Out as follows:

1. Click **Config** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click **Parameters**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-825b81ca437236f43fec5d1d645eaf523e699658%2Fparameters.png?alt=media)
3. Click **Discover**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-06ce4c357ee55213ed6e00a4d8e18ea571b5302b%2Fdiscover_parameters.png?alt=media)
4. Adjust timeouts as needed.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e3f856cd48bd70408a84577ff9b8c3cc9418ee93%2Fcampos_timeout.png?alt=media)

## Troubleshooting

### How to Get a Discover Report

The LCC has a Discover Execution Report feature, which includes a summary of Hosts that were found, imported, and those that encountered failures during the process. It also provides a summary of the error to help identify the failure.

1. To get a Discover report, click **Discover** in the LCC left sidebar menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6064bbe817750fce6ba49f51cb2cfdd450056438%2Fdiscover_dashboard.png?alt=media)
2. Click on the desired Discover.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-208dd5622ab9138194c06aa5a47473a3e52be6ba%2Fescolha_discover.png?alt=media)
3. Click the **Reports** tab and then click on the name of the desired Log.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3c739d97006f0b479b3e5045f829ad5ea6db98f0%2Freport_log.png?alt=media)
4. Click **Success** or **Failed** to get the summary of imported Hosts and those that failed during any step of the Discover.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bb85cd971234e3ff446880742e0da2c9d6fa227b%2Fhost_success_failed.png?alt=media)
5. Here is an example of a Discover with a Host having a **Failed** status.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4b98016d331538df25f67438f4ac873b2d4ecfca%2Fresult_failed.png?alt=media)
6. You can also download the full Log by clicking **Download** on the desired report. A .zip file will be downloaded containing the report in pdf, csv, html, and xlsx formats.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-046f4821a81fcc06eebc8a9928151bea905db04b%2Freport_discover.png?alt=media)

### Host Not Imported by Discover

* In some situations, a Host may not be imported into the LCC even with the correct configurations and credentials. This error usually occurs when a Timeout is exceeded in one of the five Discover steps.
* The first troubleshooting step is to increase the Timeout values for the Discover steps and run it again. See how to adjust the timeout settings in the topic [Search SSH Port](#search-ssh-port).

1. To identify if the host is not being imported due to a Timeout, the "Message" field in the Discover report will be empty, as shown in the image below.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c29e2b3a1cf5195f241be6f7bbca2780f71669f2%2Fdiscover_report.png?alt=media)

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4a5ae7b438417bce4c7ebd9144d7194db25abe2e%2Fdiscover_report2.png?alt=media)

### Invalid Credentials in Discover

1. Click **Logs** in the LCC left sidebar menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d3d542788d38a9551a8ce046d4a28be5dc9dd12f%2Flogs_dashboard.png?alt=media)
2. Click **Queue**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-998fc31d275589aa97a664e79b4207dcc49769e7%2Fqueue.png?alt=media)
3. All tasks executed on the Hosts within the LCC will be displayed.
4. Click **LOG** for the desired **Discover LCC**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7f9efee6ddcbe51318160c1a58e9edfcde0cc462%2Flog_discover_queue.png?alt=media)
5. Search for the phrase **invalid credentials** to display all hosts that failed the **test credentials** step.

Here are some settings that may cause an invalid credentials log:

* Root user with a command interpreter (shell) set to **/sbin/nologin**, **/bin/false**, or interpreters with similar behavior.
* Incorrect SSH login or privilege escalation credentials.
* Root user without a password configured on the Host, especially if using the privilege escalation method "su -".

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-167f31181c596b15895d366d1018f0a0456f78a4%2Finvalid_credentials.png?alt=media)

1. Searching for the IP address of a desired Host will display all Discover steps related to that address. You can view details of each step by clicking **Expand**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c0ecfa9561ab0549059fe106a92531964bcd3c11%2Finvalid_credentials_ip.png?alt=media)
2. For more details on which credential is incorrect, open the Discover Report following the steps in <#how-to-get-a-discover-report>. This example uses the privilege escalation method "su -".

* Example of incorrect SSH Login credentials: "invalid/incorrect password".

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-040ae4fe397a669b52afd87c2ad6ec86f2972f53%2Fsenha_loginssh_errada.png?alt=media)
* Example of incorrect Root password: "incorrect su password".

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e8d13d6dc40527a59565077f21aa41493de80ee9%2Fsenha_root_errada.png?alt=media)

## Log Interpretation

### Log Analysis in the Queue

The LCC offers an intuitive log screen with features that make reading and analysis easier, such as keyword search capability.

1. Click **Logs** in the LCC left sidebar menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d3d542788d38a9551a8ce046d4a28be5dc9dd12f%2Flogs_dashboard.png?alt=media)
2. Click **Queue**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-998fc31d275589aa97a664e79b4207dcc49769e7%2Fqueue.png?alt=media)
3. All actions executed on the Hosts within the LCC will be displayed.
4. Click **Log** for the desired action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7f9efee6ddcbe51318160c1a58e9edfcde0cc462%2Flog_discover_queue.png?alt=media)
5. In the log window, you can get details by clicking **Expand** and download it by clicking **Download**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3322a13b93a3879fe548dcfd474696ae3da0a2f9%2Flog_discover_janela.png?alt=media)

### Discover Step Analysis

Each of the five Discover execution steps is also logged and can be reviewed during or after the Discover run.

1. Search for the word **progress** in the Log search field.
2. Several logs will be displayed, each representing part of the execution of one Discover step.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f635ca498d49a007e3c8365532f4504e5927b7e1%2Fphase_logs.png?alt=media)
3. Click **Expand** to read more details about the logs for the steps at the moment Discover was running.
4. Interpret the Discover steps:

   **Phase 1 - Ping:** Sends a Ping to all hosts based on the CIDR mask defined in the Discover.

   **Phase 2 - Search SSH Port:** Checks if the port defined in Discover is open or performs a port scan on all 65,535 TCP ports of all CIDR hosts to find the SSH port if the Search SSH Port option is enabled.

   **Phase 3 - Test Credentials:** Tests the credentials on all hosts.

   **Phase 4 - Import:** Imports the host into the LCC after passing all previous steps.

   **Phase 5 - PAM:** This step imports hosts without going through the Ping and Search SSH Port steps because the host is imported using a BeyondTrust Password Safe credential.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-296828f1b0ab6f263b0e66d464df6ad431b7a7b9%2Fphase_detalhes.png?alt=media)


# BeyondTrust Password Safe

## Requirements

* BeyondInsight 22.X or higher.
* Linux Control Center 2.10 or higher.
* API registration key.
* API account and group with correct permissions.
* The *Managed Account* used by the Linux Control Center must be API-enabled and must exist in the *Managed System*.

## Overview

BeyondTrust Password Safe is an enterprise password management software that provides complete control and accountability over all privileged (and non-privileged) accounts within an organization.

Through this integration, it is possible to perform scans using privileged credentials managed by Password Safe.

## BeyondTrust Environment Setup

{% hint style="warning" %}
It is recommended that the managed account be dedicated to the Linux Control Center.
{% endhint %}

{% hint style="danger" %}
All *Assets* to be imported into the Linux Control Center must be added to BeyondInsight Password Safe through a *Discovery Scan* to ensure data integrity for proper import. The same applies to the *Managed System*, meaning it must be created from an *Asset* along with its respective *Managed Accounts*.
{% endhint %}

### API Registration in Password Safe

1. Access the BeyondInsight Console.
2. Go to **Configuration** > **General** > **API Registrations**.
3. Click **Create New API Registration** and select **API Key Policy**.
4. Provide a name for the API registration and click **Create API Registration**.
5. You must add an Authentication/IP rule for the address of your *Linux Control Center Worker* instance. If there are multiple workers installed in the network, all *Workers* IP addresses must be listed.

   * On the *Details* page, click *Add Authentication Rule*.
   * Select *Single IP Address* from the dropdown at the top right.
   * Select the *IP Rule* option.
   * Enter the IP address.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7e5e373e17a548131adbfb6e690aae3ec8218edb%2Fimage%20\(39\).png?alt=media)
6. Disable *Multi-Factor Authentication*.
7. Click *Update Registration* on the Details page.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-77778696e465fff07c70d634188cce024fee2410%2Fimage%20\(88\).png?alt=media)

### New Local User Account in BeyondInsight

A user account and a group must be configured for the Linux Control Center.

1. In the BeyondInsight Console, go to **Configuration** > **Role Based Access** > **User Management**.
2. Click the **Users** tab.
3. Click **Create New User** and select **Create a New User**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-63635521fff1427755754ca8d1749700307004f3%2Fimage%20\(42\).png?alt=media)
4. Enter user details such as identification and credentials.
5. Click *Create User*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e021089a0322c3403bcca482f7048f2935b2d559%2Fimage%20\(94\).png?alt=media)

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0d0b49b14711cacb0cba70ca17393f2d686197d0%2Fimage%20\(95\).png?alt=media)

### New Local Group in BeyondInsight

1. Follow the steps to create a new local group and enable the necessary features and *Smart Groups*:
2. In the BeyondInsight Console, go to **Configuration** > **Role Based Access** > **User Management**. Click the **Groups** tab.
3. Click **Create New Group** and select **Create a New Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4153d14f1069bf61d8d2a9d1c2b1376d70aa1db2%2Fimage%20\(49\).png?alt=media)
4. Provide the group name and description, then click **Create Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d2abedefdcd2b7b8dc3581d05ce4411a8f2e1144%2Fimage%20\(91\).png?alt=media)
5. Check the box next to the newly created group, then click the three dots to the right of the group and select **View Group Details**.
6. In **Group Details**, select **Features**.
7. On the **Features** page, locate features by selecting **All Features** in the Show dropdown. Select **Feature Name** in the **Filter By** dropdown, then type the feature name in the **Feature Name** field. The following features must be enabled:

   * Asset Management
   * Attribute Management
   * Password Safe Account Management
   * Password Safe System Management

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5ab24c1f6c93eefc84cb1a53800f4737d0193346%2Fimage%20\(43\).png?alt=media)
8. The features listed above must be assigned **Read Only** permissions. Click the three dots to the right of each feature and select **Assign Permissions Read Only**.
9. In **Group Details**, select **Smart Groups**.
10. On the **Smart Groups Permissions** page, locate **Smart Groups** by selecting **All Smart Groups** in the Show dropdown. Select **Smart Group Name** in the **Filter By** dropdown, then type the Smart Group name in the **Smart Group Name** field. The target managed Smart Group must be enabled.
11. Smart Groups must be assigned **Full Control** permissions. Click the three dots to the right of the Smart Group and select **Assign Permissions Full Control**.
12. The target Smart Group must have *Requestor, Approver, and Credential Manager* selected as roles. Click the three dots to the right of the Smart Group and select **Edit Password Safe Roles**.
13. Check the box **Requestor** and select an access policy from the **Access Policy for Requestor** dropdown. This policy applies to the managed account used for integration.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6ecd768e2eb53a49c9049af51ec61ef13e865e34%2Fimage%20\(103\).png?alt=media)

{% hint style="warning" %}
The Linux Control Center requires an **Access Policy** configured with **View Password** permission and **Auto Approve** enabled. It is also recommended to enable **"Allow multi-day checkout of accounts"** to avoid possible denied requests near the end of the day.
{% endhint %}

14. Click **Save Roles**.
15. To add the previously created user to the group:
    * Go to **Configuration > Role Based Access > User Management > Groups**.
    * Click the three dots to the right of the new group and select **View Group Details**.
    * In **Group Details**, select **Users**.
    * Select **Users Not Assigned** in the Show dropdown.
    * In the **Filter by** dropdown, select **Username**. Type the username in the **Username** field.
    * Check the box next to the username and click **Assign User**.
16. Finally, assign the **API registration** created for the integration to this group:

    * Go to **Configuration > Role Based Access > User Management > Groups**.
    * Click the three dots to the right of the group and select **View Group Details**.
    * In **Group Details**, select **API Registrations**. A list of API registrations will be displayed.
    * Check the box next to the API registration created under **API Registration**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9db1ab64ecd6525533dab0a7a1487e3a6bb32afe%2Fimage%20\(46\).png?alt=media)

### Managed Account Used by the Linux Control Center

1. In the **BeyondInsight Console**, go to **Managed Accounts.**
2. In the **Filter by** dropdown, select **Account**. Enter the account name in the **Account** field.
3. Click the three dots to the right of each entry and select **Edit Account**. In **Account Settings**, ensure that **API Enabled** is checked.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-37642b866ae614b4b0daa5cfbf874775591a40a9%2Fimage%20\(50\).png?alt=media)

## Integration with Linux Control Center

Set up the integration with the Linux Control Center after completing the setup in your BeyondTrust Password Safe environment.

1. In the Linux Control Center, go to **Config**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f570451f9e9e9ca31fa03e70d2d579135e9627af%2Fbotao_config.png?alt=media)
2. Click **BeyondTrust**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4c6f63278032ba0530bc1a3ad607ba014ee7e26f%2Fbotao_beyondtrust.png?alt=media)
3. Click **Password Safe**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4c52640671251f4410a5b9114436ceda38c1b83b%2Fbotao_passwordsafe.png?alt=media)
4. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-49c520bc541b0f9ec87c7eaef430f82f08b5f133%2Fbotao_create.png?alt=media)
5. Provide all necessary settings to authenticate with the Password Safe API, such as **API Base URL, API Auth Key, API Auth Username, API Auth Password**, and the **Managed Account** to be used by the Linux Control Center.
6. Select the **Privilege Escalation** field based on the chosen account permissions.
7. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-53bc2e4d0317cd6f35eafd4bbca8c7715c59ca58%2Fformulario_ps.png?alt=media)
8. After saving, click the created integration, click **Actions**, and run **Test Connection With Safe API** to validate communication with BeyondInsight.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-451e1cf94da2cd2293c8170c9fc24a9c20f1cba0%2Fbotao_test_api.png?alt=media)

   If the connection fails, go to **BeyondInsight > Configuration > User Audit options** and review the connection details.

### Get Assets Info

1. The **Get Assets Info** option queries all **Smart Group Assets** linked to the **User Group** of the **API Auth Username** used.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f24d5aa417fdbdfa3826c600c393f82fe7e5e1de%2Fdiagrama_discover_bt.png?alt=media)
2. Click **Actions** and execute **Get Assets Info**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f15fda1d14feb127eca8e65b86962e3cbf0fedeb%2Fget_assets_info.png?alt=media)
3. Confirm the action by clicking **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dc5f437ef298908f1ce6cd2de045b795d27ee19d%2Fconfirm_action.png?alt=media)
4. A new job will be created in **Logs > Queue** on the left menu with the **"Get Smart Groups"** action from the User Group belonging to the **Auth Username API**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-22432bc00cfde76e7caea2463ac8b48f40c66b25%2Fimage%20\(75\).png?alt=media)
5. Once the job is completed, all Assets will be available for the **Import Asset** action.

### Import Assets

1. To list the Assets available for import into the Linux Control Center, go to **Config > Integrations > BeyondTrust > Password Safe**, click the created integration, and then click **Import Assets**.
2. Select the assets to be imported through the **Import Assets** process and click **Send**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cfa3e16386302a3fc5b4329599f47f1d7c1c54a7%2Fimage%20\(77\).png?alt=media)
3. A new action called **Import Assets** will be created. In this action, the Linux Control Center will attempt to connect to each selected Asset using the provided Managed Account to verify it can connect using the managed account and the password retrieved from Password Safe.
4. After validation, the Linux Control Center will start a new job with the **Photography** action for each imported host, collecting host information such as hostname, kernel version, IPv4 address, MAC address, SSH port, operating system version, and other details.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-683303ab247bf3cb7f8ed8da27bfe067e1de0f4a%2Fimage%20\(66\).png?alt=media)
5. When **Import Assets Info** successfully reaches the **Processed** state in the Queue menu, go to the **Hosts** option in the left menu and verify that the assets were correctly imported into the Linux Control Center using the BeyondTrust authentication method.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-56f5e2fef2c1a3e42d4afd4b74b1e112c017ea82%2Fimage%20\(67\).png?alt=media)


# Host Actions


# Get Info

## Requirements

Linux Control Center version 2.10.X or higher

## Overview

The **Get Info** action is a key function within the system, responsible for retrieving general information from hosts and storing it in the LCC console. This action is essential to ensure that machine data remains current and accurate.

The Get Info action runs in a chained manner. This means that whenever an action that modifies the host’s operating system configuration is executed (such as installing a package), the Get Info action automatically runs right after the previous action is completed. This ensures that the information displayed in the LCC remains reliable and up-to-date. As a result, the integrity and accuracy of the LCC’s data are maintained.

## Purpose

This document aims to explain the purpose and functionality of the **Get Info** action in the Linux Control Center (LCC).

## Running the Get Info Action

1. Click on **Hosts** from the left-hand menu in the LCC.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select one or more hosts by checking the box next to the hostname, then click the **Actions** button at the top of the page, or click the **Actions** button on the desired host’s row.
3. After clicking **Actions**, select **Get Info**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-aecadad180bd4f1b0ab97286f1352fb06df44530%2Faction_get_info.png?alt=media)
4. Click **Yes** to confirm execution.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5825bb16121d76b15c76d4486251545e7fab7804%2Fconfirma_get_info.png?alt=media)
5. Open the host where the action was sent and click **Actions History**. The Get Info action is identified as *Photography*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
6. Wait for the *Photography* actions to reach the **Processed** status.

   ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/hosts_actions/account_del/lista_history_getinfo.png)


# Package Check Update

## Requirements

* Linux Control Center 2.10.X or higher

## Overview

Linux Control Center (LCC) has the **Package Check Update** feature, which facilitates version management of all packages on environment hosts. The **Package Check Update** action connects to the remote repositories already configured on the target hosts, looking for metadata about packages with available updates. After retrieving the metadata, the Linux Control Center checks the current packages on the machine in its database, and if there is a newer version based on the received metadata, it will be marked as **"Upgradable"**.

## Objective

The purpose of this document is to demonstrate how to use the **Package Check Update** action in LCC.

## Running Package Check Update

1. In the left side menu of LCC, click on **Hosts**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Check one or more boxes for the desired hosts and click the **Actions** button.
3. Select the **Package Check Update** action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2d83639ad0aa46d0736b8bb4479b57c63d445f98%2Fbotao_actions_hosts.png?alt=media)
4. Confirm the action by clicking **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e2dff1e8a24ce57db5ddfd13fe98bc05ecf4dea5%2Fconfirma_acao_check_update.png?alt=media)
5. Open the host where you sent the **Package Check Update** action and click **Actions History**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b3f76fdbc5ff6a28a7b28109f9673a91572a9142%2Ftela_general_seta_actions.png?alt=media)
6. Wait for the *Package Check Update* and *Photography* actions to reach the **Processed** status.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1711d542b783458cb4c1d3530ffa1dacc25262ca%2Faction_finalizada_history.png?alt=media)

{% hint style="info" %}
The *Photography* action is responsible for retrieving information about packages, user accounts, and various data from the host and inserting it into the LCC database. This is how LCC displays detailed and accurate information.
{% endhint %}

1. After the action completes successfully, go back to the **General** screen.
2. Click **Show Packages**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a6a2e64b8966fc954856bd43d137a33cf7508d05%2Ftela_general_host.png?alt=media)
3. To finish, check the **Packages Updatable** box to filter all packages available for update.

* The icon inside the red circle indicates that the package has an update available from the repository.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cc48189d12d41530a3d71d4cf1df8105cc8c73a6%2Findicador_pacote_atualizavel.png?alt=media)


# Package Update

## Requirements

* Linux Control Center 2.10.X or higher

## Overview

The **Package Update** action updates all packages on a host or a group of hosts in LCC. This action allows you to keep all packages across your infrastructure fully updated in an extremely simple way.

## Objective

The purpose of this document is to demonstrate how to use the **Package Update** action in LCC.

## Updating Packages on Hosts

{% hint style="info" %}
You must run a **Package Check Update** before executing the **Package Update** action. If the check was done more than one week ago, it is recommended to run **Package Check Update** again before performing the update.
{% endhint %}

* Follow the guide at the link below to run **Package Check Update**:
* <https://docs.linuxcontrolcenter.com.br/en/host-actions/package_check_update>

1. In the left menu of LCC, click on **Hosts**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select one or more hosts by checking the boxes, then click the **Actions** button.
3. Select the **Package Update** action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ca3df217304ebac17227b955315a180e67b899a2%2Fbotao_package_update.png?alt=media)
4. Confirm the action by clicking **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c47ee1c4ba13fb02e46d3f241054c455705bf8b3%2Fconfirma_atualizacao.png?alt=media)
5. Open the host where the action was executed and click **Actions History**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b3f76fdbc5ff6a28a7b28109f9673a91572a9142%2Ftela_general_seta_actions.png?alt=media)
6. Wait for the actions *Package Update*, *Package Check Update*, and *Photography* to reach the **Processed** status.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f33d1962580e60c1d838d704a2f356d6923b1b2b%2Fhistory_package_update.png?alt=media)
7. Once the action is completed successfully, return to the **General** screen.
8. Click **Show Packages**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a6a2e64b8966fc954856bd43d137a33cf7508d05%2Ftela_general_host.png?alt=media)
9. Finally, check the **Packages Updatable** box. You should now see that there are no packages available for update.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7fa0ee502cdeeb3b391c7cd787f349d3c8a388f1%2Flista_atualizada.png?alt=media)


# Package Vulnerable Update

## Requirements

* Linux Control Center 2.10.X or higher

## Overview

The **Package Vulnerable Update** action updates packages that were identified as vulnerable from a scan performed by the **7 Vulndb API** of LCC or through integration with **Tenable Security Center** or **Tenable Vulnerability Manager**.

## Objective

The purpose of this document is to demonstrate how to use the **Package Vulnerable Update** action in LCC.

## Identifying Vulnerable Packages with 7 Vulndb API

{% hint style="info" %}
In order for LCC to identify which package is vulnerable due to being outdated, it is necessary to run the **7 Vulndb API scan**.
{% endhint %}

\- Follow the step-by-step guide at the link below to run \*\*7 Vulndb API\*\*:\
\-

## Updating Vulnerable Packages

1. In the left menu of LCC, click on **Hosts**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select one or more hosts.
3. Click the **Actions** button at the top of the page and execute the **Package Vulnerable Update** action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c70c6d392430dd6d05cc029a734d541273a6578%2Fseta_package_vulnerable_update.png?alt=media)
4. Confirm the action by clicking **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-97e137a0cdb9f5b507b146255b65cc9af6f0ac85%2Fconfirma_vulnerable_update.png?alt=media)
5. Open the host where the action was executed and click **Actions History**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b3f76fdbc5ff6a28a7b28109f9673a91572a9142%2Ftela_general_seta_actions.png?alt=media)
6. Wait for the actions *Package Vulnerable Update*, *Package Check Update*, and *Photography* to reach the **Processed** status.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-11c4c8549c996472c10c702e9fe93b743504c6a3%2Factions_history_vulnerable_update.png?alt=media)
7. With this action, some vulnerabilities that can be mitigated simply by updating packages will no longer pose a risk to your environment!

Based on this information, it is possible to implement some security measures such as:

* Update the package
* Proactive monitoring
* Freeze the package version until the version issue is investigated
* Vulnerability management
* Backup and recovery

Although not limited to these, these measures aim to mitigate potential vulnerabilities and promote a safer environment.


# Package Hold

## Version

* Linux Control Center = 2.10.X or higher

## Requirements

* Hosts must be previously configured in the LCC database

## Overview

* This guide provides information and step-by-step instructions to configure **Package Hold** in the Linux Control Center.

## Objective

* Mark packages with the **"Hold"** flag to ensure they remain at their current version.

{% hint style="info" %}
If there are packages marked as *Hold* on the host before importing it into LCC, it will be necessary to mark them again as "Hold" in the LCC console after import.

The *Hold* configuration follows the relationship of **Host X Package**, preventing the package from being modified regardless of which LCC package management action is performed.
{% endhint %}

## Package Hold on Hosts

1. To add packages to the Hold list of a host, go to the **Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a262fa19677789ebc50a8a179d979f2c42cee928%2Fbotao_hosts.png?alt=media)
2. Click on the row of the desired host and open the **General** tab.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f47b5611bf344cbd8052d017f2e00dade2e505d6%2Fguia_general.png?alt=media)
3. Select the packages in the **Packages available to hold** table and move them to the right table using the arrow button.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-35a7192ed227dbb3d9531f46521e22ca3df390d9%2Fpacotes_selecionados.png?alt=media)
4. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1d04989d8689e2e6903a9d5a7556d41ce62724b4%2Fbotao_save.png?alt=media)
5. Done! From now on, any package management action performed on this host will respect the packages configured as **"Hold"**, meaning those packages will not be modified.

## Package Hold on Host Groups

1. To apply the Hold configuration to a host group, go to the **Host Groups** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ea99f939aa1d5955172532bf7e51ea8590a50df1%2Fhost_groups.png?alt=media)
2. Click **Manual**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c7b80084633f49d8c7bed9230d2b6128a09a7faf%2Fbotao_manual.png?alt=media)
3. Click on the desired group.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-20b6fa96bd6e7d6e0475c5ea529b8063452a54bc%2Ftela_com_grupo.png?alt=media)
4. Scroll down to the **Packages** table, select the packages from the left table, and move them to the **Packages in the group** table on the right using the arrow button.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-669ea5447a40e7136cd95c26dd4226fb8e5e75d0%2Fpacotes_selecionados_grupo.png?alt=media)
5. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1cff60c085ee25ed7c8559e11d6f83d9e42f24e9%2Fbotao_save_grupo.png?alt=media)
6. Done! From now on, any package management action performed on this host group will respect the packages configured as **"Hold"**, meaning those packages will not be modified.

## Package Hold Persist

* This setting prevents the package from being modified even if the command is executed directly on the terminal of the hosts managed by LCC.

1. Click **Config**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-800e5f2e8c1268ec5dfc13cc7b16e4f533ad922c%2Fbotao_config.png?alt=media)
2. Click **Parameters**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-825b81ca437236f43fec5d1d645eaf523e699658%2Fparameters.png?alt=media)
3. Click **Ansible**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c91fe5264fd4b80ad17885b648a85444a0ce05b9%2Fbotao_ansible.png?alt=media)
4. Check the option **Package Hold Persist** and click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-70c2094d9a404205ff79efa6564c06d59bb28e7b%2Fbotao_hold_persist.png?alt=media)


# Package Install

## Version

* Linux Control Center = 2.10.X or higher

## Requirements

* Hosts must be previously configured in the LCC database.

## Overview

* This guide provides information and step-by-step instructions to install packages on hosts managed by the Linux Control Center (LCC).

## Objective

The Linux Control Center (LCC) offers an efficient feature for package installation, allowing you to install packages on a previously created host group or by selecting hosts at the time of installation. This functionality simplifies the process, enabling users to perform large-scale installations, either by typing the desired package name to install from the repository or by uploading packages directly through the LCC console.

* For installation on a large number of hosts, we recommend creating groups to organize the hosts according to your environment's needs. This way, LCC offers better control and convenience for large-scale package installation.
* To create a host group, follow the guide at the link below:

<https://docs.linuxcontrolcenter.com.br/hosts-group>

### Installing Packages on Hosts

* This option provides greater agility for installing packages on a small number of hosts or on a single host, making it ideal for quick day-to-day operations.

1. Click **Hosts** in the left menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a532dd47faff1b1fe76d7a00c2c713eaa58248a6%2Fhosts_dashboard.png?alt=media)
2. Select the desired hosts by checking the **Hostname** boxes and click **Actions** at the top of the page.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-545ee7e775f49875362bfabf82c7351f78314c02%2Fselecionando-hosts.png?alt=media)
3. If you want to install on only one host, click **Actions** on that host's row (uncheck any other selected hosts if necessary).
4. Click **Package Install**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-94085dfffe98135c176b6f0b93a8c5ce19b02f85%2Factions_package_install.png?alt=media)
5. Type the name of the package you wish to install in the **Insert packages** field.
6. Click **ADD**, or if needed, upload the package file by clicking the **Upload File** button.
7. Click **Yes** and LCC will proceed with the installation.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b4f86810eb79320e84f3e68b3ce757f874b0f4ba%2Finsert_packege_actions.png?alt=media)


# Package Remove

## Requirements

* Linux Control Center = 2.10.X or higher

## Overview

The **Package Remove** action allows you to uninstall packages across your entire Linux host infrastructure in an extremely simple way.

## Objective

The purpose of this manual is to demonstrate how to use the **Package Remove** action in LCC.

## Removing Packages from Hosts

{% hint style="info" %}
LCC does not provide a way to revert this action. Make a snapshot of the host using your environment's tools or through LCC's integration with VMware or Nutanix.
{% endhint %}

1. In the left menu of LCC, click on **Hosts**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select the desired hosts and click the **Actions** button at the top of the page.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4012b221286e1e81066ff6374c813cddf1dd66e7%2Factions-topo-da-pagina.png?alt=media)
3. If you want to remove the package from only one host, click **Actions** on that host's row.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1f372e5c4ef6fe6fea81b7036884e364f149fb55%2Factions-linha-do-host.png?alt=media)
4. Click the **Package Remove** action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5e247c503197f47b6b043f2f9224d6046d33af9e%2Faction_remove.png?alt=media)
5. Choose the package you want to remove in the **Insert Package** field and click **ADD** to add it to the removal list. You can also remove multiple packages simultaneously.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-64b5c83b3ffaa1ce14cc3d3273e63213b080f8b4%2Fadd_package.png?alt=media)
6. Click **Yes**, and the action will be executed shortly.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-261d0fee591ef073d5ea7c95b5c0a65f2c9592ed%2Fbotao_yes.png?alt=media)
7. Click **Actions Working** to monitor the status of the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f261de33a415bffa01b1b5128cd675b520465128%2Fbotao_actions_working.png?alt=media)
8. A **Photography** action will be automatically executed after the **Package Remove** action reaches the **Processed** and **Success** status. In case of an error, a **Photography** will also be executed to ensure the integrity of the host data displayed in the console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-eaa9a4393fea0e7d9644669558cdaba79ee1390b%2Faction_executada.png?alt=media)


# Account Add

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The purpose of the Linux Control Center (LCC) Account Add action is to add an account to a host using credentials managed in the LCC database.

## Objective

The purpose of this document is to demonstrate the step-by-step process for executing the LCC Account Add action.

## Adding Host Accounts

You must have at least one credential previously configured in the LCC database according to the step-by-step instructions in the link below:

<https://docs.linuxcontrolcenter.com.br/managing-accounts/adicionando-contas-host>

1. Click on **Hosts** in the left side menu of the LCC

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select 1 or more hosts by checking the box next to the Hostname and click on the Actions button of the page type, or click on the Actions button in the desired host row.
3. After clicking on Actions, click on the **Account Add** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5fa69a676eb5e61c4b847594e2d5d7ccf96505b5%2Fseta_botao_account_add.png?alt=media)
4. Search for the account name in the **Insert Accounts** field to make selection easier.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-aed6f900a7de6164644de43291bc7bb42c51b9e7%2Fescolher_conta.png?alt=media)
5. Click **Yes** to confirm the inclusion of the account in the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-04d68fb387c06d16d92c677cdf7f99f72a22dd19%2Fconfirma_add_account.png?alt=media)
6. Open the host where you sent the action and click on **Actions History**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
7. Wait for the *Account Add* and *Photography* actions to have the status **Processed**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-966782012c1be921d71734fd1868de0a50e6ad0c%2Faccount_history.png?alt=media)
8. After the actions are successfully completed, click on **Account** and you will be able to see the account successfully inserted.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-12104808fcae34602f95cfc183cbde8b526ac54c%2Faccount_list.png?alt=media)

### Credential Permission Level in Sudoers

1. You can edit the permission level of the Host's Sudoers account on the **Account** screen.
2. Click the button indicated by the red arrow and choose the type of permission you want.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-04edf43015b2b0549fe23cb95cb147d1f26672ab%2Fsudo_edit.png?alt=media)


# Account Del

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The purpose of the Linux Control Center (LCC) Account Del action is to delete local accounts from Hosts managed by the LCC.

## Objective

This document is intended to demonstrate the step-by-step process for executing the LCC Account Del action.

## Deleting a Host Account

{% hint style="warning" %}
If removing the account results in its unlinking from all hosts, it will be deleted from the LCC Console.
{% endhint %}

1. Click **Hosts** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select 1 or more hosts by checking the box next to the Hostname and click the Actions button for the page type, or click the Actions button for the desired host row.
3. After clicking on Actions, click on the **Account Del** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-272bf842ddc21fefd517e1582b948933693b1119%2Fseta_botao_account_del.png?alt=media)
4. Search for the account name in the **Insert Accounts** field to make selection easier.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d306773f7b4c6f2fcd5a339fb5a12c2c556fe1bb%2Fescolher_conta_del.png?alt=media)
5. Click on **Yes** to confirm deletion of the account on the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c92a36e8925d1d9205379f9e68d8abde235f1010%2Fconfirma_del_account.png?alt=media)
6. Open the host where you sent the action and click on **Actions History**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
7. Wait for the *Account Del* and *Photography* actions to have the status **Processed**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8c6ebbcaed725d02f5559a06a9407774ec88ea3e%2Faccount_history_del.png?alt=media)
8. After the actions are successfully completed, click on **Account** and you will see that the removed account is not present.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6af87e5400417763ab7eb6a54a7674432b1e280f%2Faccount_list_del.png?alt=media)


# Account Expire

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The purpose of the Linux Control Center (LCC) Account Expire action is to define local accounts as expired, enabling account control in a simple and fast way.

## Objective

The purpose of this document is to demonstrate the step-by-step process for executing the LCC Account Expire action.

## Expire Host Account

1. Click on **Hosts** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select 1 or more hosts by checking the box next to the Hostname field and click on the **Actions** button of the page type, or click on the Actions button of the desired host line. 1. After clicking on Actions, click on the **Account Expire** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-99c2f9a0a564aa233d22d464e25168dafe63d4d8%2Fseta_botao_account_expire.png?alt=media)
3. Search for the account name in the **Insert Accounts** field to make selection easier.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a0917ab6c6d380b587a0e2dfb1ebafcd6aa6ee37%2Fescolher_conta_expire.png?alt=media)
4. Click on **Yes** to confirm the account change on the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-25abbb79f1adbebf0a516b893e8b3194a4d55a6a%2Fconfirma_expire_account.png?alt=media)
5. Open the host where you sent the action and click on **Actions History**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
6. Wait for the *Account Expire* and *Photography* actions to have the status **Processed**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8c9d7133a4b692211e7a464e33663ca997366d5c%2Faccount_history_expire.png?alt=media)


# Account Lock

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The purpose of the Linux Control Center (LCC) Account Lock action is to set local accounts to "Lock", enabling account control in a simple and fast way.

## Objective

The purpose of this document is to demonstrate the step-by-step process for executing the LCC Account Lock action.

## Block Host Account

1. Click on **Hosts** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select 1 or more hosts by checking the box next to the Hostname field and click on the **Actions** button of the page type, or click on the Actions button in the desired host line. 1. After clicking on Actions, click on the **Account Lock** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-297eb67a89a0add256deabd17fd64aad3dc76b3e%2Fseta_botao_account_lock.png?alt=media)
3. Search for the account name in the **Insert Accounts** field to make selection easier.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-db31f89fa7c49ec4bf660c02febb2b370f6cbbcf%2Fescolher_conta_lock.png?alt=media)
4. Click on **Yes** to confirm the account change on the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5aedb0c05916567af319bb5dc790f516c3b25a0f%2Fconfirma_lock_account.png?alt=media)
5. Open the host where you sent the action and click on **Actions History**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
6. Wait for the *Account Lock* and *Photography* actions to have the status **Processed**


# Account UnLock

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The purpose of the Linux Control Center (LCC) Account Lock action is to set local accounts as "UnLock", enabling account control in a simple and fast way.

## Objective

The purpose of this document is to demonstrate the step-by-step process for executing the LCC Account UnLock action.

## Unlocking a Host Account

1. Click on **Hosts** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)
2. Select 1 or more hosts by checking the box next to the Hostname field and click on the **Actions** button of the page type, or click on the Actions button in the desired host row. 1. After clicking on Actions, click on the **Account UnLock** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-72dfc1463b8748c61922d3ba0bed244836143f53%2Fseta_botao_account_unlock.png?alt=media)
3. Search for the account name in the **Insert Accounts** field to make selection easier.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7faa6d16c047043bd51df1d6480d64a5f32628fa%2Fescolher_conta_unlock.png?alt=media)
4. Click on **Yes** to confirm the account change on the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e987c04423fed0ec540fa274201bb3bc431d2fc9%2Fconfirma_unlock_account.png?alt=media)
5. Open the host where you sent the action and click on **Actions History**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23fe1f130b40e1bddb458d986cc9ae465d820d3e%2Fseta_para_account_history.png?alt=media)
6. Wait for the *Account UnLock* and *Photography* actions to have the status **Processed**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-272ebe13433f8f16ffc79fe058682145f1da29c8%2Faccount_history_unlock.png?alt=media)


# File Add

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center allows you to upload and manage files from managed Hosts. The LCC file management provides greater reliability when creating backups of configuration files and more security with access permission control.

## Objective

The objective of this document is to demonstrate the step-by-step process for using the File ADD *Action*

## Add Managed File to Host

1. Access the **Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **File Add**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-59163a0dbdc5674ffdf4639219e46e10b6615324%2Ffile_add_linha_host.png?alt=media)
3. To run the Action on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **File Add**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0be13ab35e61798a74ef02d7d266dbe79370fdfa%2Ffile_add_topo.png?alt=media)
4. Click on **File Type** and choose the **Managed** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e553ff755bd5307532da5f9400ae84f62a33108a%2Ftype_managed.png?alt=media)
5. Click on **Insert File** and choose the managed file to add to the Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9410edd83f1aad8c6450690eb91f041c5869e0e3%2Finsert_file.png?alt=media)
6. Click **Yes** to start the *Action*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-32012e8e4a0d4691da1eb2f6bfaea6344cf3d9f2%2Fbotao_yes.png?alt=media)
7. Click the **Queue Working** button at the top of the page to monitor the execution of the action.

**Note:** An independent **File Add** Action will be created for each Host if it is executed on more than one Host simultaneously.

```
![](/pt-br/images/hosts_actions/file_add/actions_file_add_working.png)
```


# File Del

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center allows you to delete Managed or Unmanaged files from Hosts in the LCC database.

## Objective

The objective of this document is to demonstrate the step-by-step process for using the File Del *Action*.

## File Del

1. Access the **Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **File Del**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-402122abb13fc5dbfb5d855c997395d1d3f4a5f5%2Factions_linha.png?alt=media)
3. To execute the Action on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **File Del**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-89030e074b1c37b7c009e014550413e8ab5bccde%2Factions_topo.png?alt=media)

### Deleting a Managed File

* Deleting a Managed File generates an *Action* that uses the information from the File registry to identify the directory and file name to be used in removing the File.

1. Click on **File Type** and choose the **Managed** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e91bd9b572b4b1c48f8511870536d2f87ac4afda%2Ftype_managed.png?alt=media)
2. Click on **Insert File** and choose the managed file to add to the Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0aed9b63b43a976931e296a91716616bbaee49f0%2Finert_file_managed.png?alt=media)

### Deleting an Unmanaged File

* Deleting an Unmanaged File generates an *Action* that uses the directory and file name information entered manually.

1. Click on **File Type** and choose the **Unmanaged** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5e53a8b5609a8a52a5aa9b80299cdea5aa80ad64%2Ftype_unmanaged.png?alt=media)
2. Click on **Path** and enter the directory and full name of the file you want to delete.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-afe95ed6da9b33ac7aaaf377d38a435f972b5975%2Fnome_file_unmanaged.png?alt=media)
3. Click on **Yes** to start the *Action* and the file will be deleted from the selected Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-822b2fbae45551997fcb4a786ee60919603351c8%2Fbotao_yes_managed.png?alt=media)


# File Download

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The File Download action is used to download any file on a Host from a URL.

The LCC will connect to the Host via SSH, download it from the Link provided and save the file in the directory specified when executing the action in the Console. The entire process will be managed automatically by the LCC, regardless of the number of Hosts or Links registered.

## Objective

This document aims to demonstrate how the **File Download** Action works

## Downloading Files on Hosts

{% hint style="warning" %}
**Note:** The URL must include the file to be downloaded, because the File Download action performs a standard GET request. If the link does not point directly to the final file, the download will not be completed successfully.
{% endhint %}

1. Access the **Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **File Donwload**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-87206ba9cf03b4c7b4a9c5dc6e3cd7754c885ace%2Factions_linha_host.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **File Download**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-071676ab32e8385f87f71b8e2127a164009b263a%2Factions_topo_pagina.png?alt=media)
4. Fill in the fields as follows;

* **URL**: URL to download the file<br>
* **Destination Directory:** Full directory where the file will be saved. Ex: /tmp/

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1bed5142426d0c84f1790d2a92ea86023a7d1958%2Factions_vazia.png?alt=media)

1. If you want to download more than one file simultaneously, click the **Add More URL and Destination** button and repeat the previous step with other values.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7f2e86b2625ccd91f54c085b4ccc1b88f9da0fb0%2Faction_preenchida.png?alt=media)
2. Click **Save** after filling in the information correctly.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cbb59d7f013c19f0ece6892ebfd77bc68b8ca3a9%2Fexecute_action.png?alt=media)
3. Click the **Queue Working** button at the top of the page to monitor the execution of the action.

* **Note:** An independent **File Download** Action will be created for each Host if it is executed on more than one Host simultaneously.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6f1e2c9fb4cd206a50267c136c79b0f9e65cf6fb%2Faction_executada.png?alt=media)


# Manage Host Service

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Manage Host Service action is used to manage the services of Hosts managed by Linux Control Center.

## Objective

This document aims to demonstrate how the **Manage Host Service** Action works.

## Service Management

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **Manage Host Service**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-caee8938ecb2c7b5f979d157c4d743c2e6346cbb%2Flinha_host.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Manage Host Service**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a35607949bcb62d3b5ce0d79270aea66606e00e5%2Factions_topo.png?alt=media)
4. Click on **Services**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-68c391ae349fb4d6fad5f6bbaaebd9b6cab6d190%2Fservices_host.png?alt=media)
5. Choose the services you want to perform the action on.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-470e46e1c52353f114d0a849c8ce0719906839c8%2Fservicos_selecionados.png?alt=media)
6. Click on **Action**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-14d17eaf213ac091649a39296c9261326ec03bf2%2Fbotao_action_servico.png?alt=media)
7. Choose one of the actions to perform on the Host service, which are:

* **Start:** Starts the service on the Host.
* **Stop:** Stops the service on the Host. - **Restart:** Restarts the service on the Host.
* **Enable:** Enables the service to start automatically when the Host is turned on.
* **Disable:** Disables the service so that it does not start automatically when the Host is turned on.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-03911303119a68046e786e543871c671863b887a%2Factions_service.png?alt=media)

1. Verify that the information is correct and click **Yes** to execute the action.

   ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/hosts_actions/manage_host_service/button_yes.png)


# Host Ping

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Host Ping action is used to validate whether a Host is Up or Down by sending/responding to ICMP requests.

## Objective

The purpose of this document is to demonstrate step by step how to use the Host Ping action of the Linux Control Center.

## Running Host Ping

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the line and a desired Host and click on **Host Ping**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-70be2950aa112b07129328bab979f04cae88c275%2Fhost_ping_linha_host.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Host Ping**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2717ffd2ba84000721dbb79c9bd9ae38efd4b50e%2Factions_topo_pagina.png?alt=media)
4. Click on **Yes** to run the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3403e170d85ad62f69d08c5b7f08ea15341abd0a%2Fbotao_yes.png?alt=media)
5. Click on the **Queue Working** button at the top of the page to monitor the execution of the action.

* **Note:** An independent **Host Ping** Action will be created for each Host if the action is run on more than one Host simultaneously.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5f989ad814c66307cb1e5aef297c604dd8913600%2Factions_working.png?alt=media)

1. If the Host does not respond, the **Action Status** action will have the result **Error**, and the icon in the **Status** column on the **Hosts** screen will turn red, indicating that it is not possible to perform actions on this Host, as shown in the example below.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a283596014f692ada463253c153bb449c4692006%2Fstatus_vermelho.png?alt=media)


# Host Reboot

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The **Host Reboot** action is used to reboot Hosts from the Linux Control Center Console.

## Objective

This document aims to demonstrate step by step how to use the Host Reboot action of the Linux Control Center.

## Running Host Reboot

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **Host Reboot**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-40b82543d0c7039d5de88532dbf4664c028fd680%2Faction_linha.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Host Reboot**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d1c8f84639f836229f1f9ba5f629a29a40a29e14%2Faction_topo.png?alt=media)
4. Click on **Yes** to run the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2fe479c7a84c934e4eb5f4d03c2011c21e5eb4eb%2Fbotao_yes.png?alt=media)
5. Click on the **Queue Working** button at the top of the page to monitor the execution of the action.

* **Note:** An independent **Host Reboot** Action will be created for each Host if it is run on more than one Host simultaneously.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2dfa6e088a694259a184a0bdd0e14a9fe6f43a51%2Facao_na_fila.png?alt=media)


# Host Shutdown

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Host Shutdown action is used to shut down Hosts from the Linux Control Center Console.

## Objective

This document aims to demonstrate step by step how to use the Host Shutdown action of the Linux Control Center.

## Running Host Shutdown

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click **Actions** in the row and a desired Host and click **Host Shutdown**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-61fb9a63f868f84841ad4c37e842a8e2ed6e830f%2Factions_linha_host.png?alt=media)
3. To execute on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Host Shutdown**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c99148892bc920399c762b3c03641943b9435f5b%2Factions_topo.png?alt=media)
4. Click on **Yes** to execute the action.

* The Action will be sent to the queue and the Host will be *Shutdown*.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7f1ee0d5abddac4dd4ef49421a4085cc28e7ab68%2Fbotao_yes.png?alt=media)


# Insert Group

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Insert Group action is used to insert Hosts into Linux Control Center groups

## Objective

The purpose of this document is to demonstrate step by step how to use the Insert Group action of the Linux Control Center.

## Insert Hosts into a Group

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **Insert Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4db132142969a9efc90ff0127f36357f67a794bf%2Factions_linha.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Insert Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e6420d3f578f09ba3bdd4804e31d518bcbf0ea84%2Factions_topo.png?alt=media)
4. Click on the **Insert Group** field to choose the group in which the Hosts will be inserted.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b904e9aee6b8fbaaf102aee64e7ab41db1838b2f%2Fcampo_insert_group.png?alt=media)
5. Click on **Yes** to execute the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-102827386eb9de3e3723349dc4ff694aef0e7cd6%2Fbotao_yes.png?alt=media)
6. See that the hosts are present in the selected group.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-34b000496bcb5731b26e464e6c8120b0b2c6a763%2Fgrupo_com_hosts.png?alt=media)


# Check Vulnerability

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Check Vulnerability action is used to execute the Vulndb API vulnerability API 7 of the LCC.

## Objective

The purpose of this document is to demonstrate step by step how to use the Check Vulnerability Action of the Linux Control Center.

## Executing the Check Vulnerability

{% hint style="warning" %}
When executing this action on a Host, all packages with identified vulnerabilities will be marked. If the same package with vulnerability is installed on another Host, it will also be flagged in the Console.
{% endhint %}

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the line and a desired Host and click on **Check Vulnerability**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d247af79ed1b1164eb93e57c53ab85d6c58c1e49%2Flinha_host.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Check Vulnerability**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b929fc79940d50fd4f0b71ae2eacff360ce0096a%2Factions_topo.png?alt=media)
4. Click on **Yes** to run the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-980a2d490c024c64626e5ba5693bfa8e3c0ede13%2Fbotao_yes.png?alt=media)
5. Click on **7 VulnDB API** in the left side menu to monitor the execution of the API.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cdfef70fc4660d1fbbc848e7d8d17292862ae497%2Fbotao_7vulndbapi.png?alt=media)
6. Wait until the icon in the *Status* column displays the message **Processed**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3e87d3b39cfab1ee8977a867e95d5e6c69dd96b6%2Fapi_runnig.png?alt=media)


# Execute Custom Playbook

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Execute Custom Playbook action is used to execute custom Ansible Playbooks on Hosts that are being managed by the LCC.

## Objective

The purpose of this document is to demonstrate step by step how to use the Execute Custom Playbook action of the Linux Control Center.

## Executing Custom Ansible Playbooks

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **Execute Custom Playbook**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d9f85ab840c99c91a4f83d9336f7ac9336e0d426%2Factions_linha_host.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click **Actions** at the top of the page and click **Execute Custom Playbook**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6b7d7c07c7360a3dde0dc16644bc55710e8f6c1d%2Factions_topo.png?alt=media)
4. Choose the playbook you want to run in the **Playbooks** field

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-397282f64d0b2927e4489e2a07b6ef6a3cf104cb%2Fcampo_playbooks.png?alt=media)
5. Click **Yes** to run the playbook.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6542b246df1df2fbce997a1e858cea58ffe3f013%2Fbotao_yes.png?alt=media)


# Execute Custom Scripts

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Execute Custom Script action is used to execute custom scripts on hosts that are being managed by the LCC.

## Objective

The purpose of this document is to demonstrate step by step how to use the Execute Custom Script action of the Linux Control Center.

## Executing Custom Scripts

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired host and click on **Execute Custom Script**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c16d7755b56078efd8c3b7af6a592ff553e0e806%2Flinha_host.png?alt=media)
3. To execute on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Execute Custom Script**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-67067cc57f1e7a508c17e6c4f5d57f4d6817fe7d%2Factions_topo.png?alt=media)
4. Choose the Script you want to execute in the **Scripts** field

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-06991889c746098c9218037d320c09e788d62a71%2Fcampo_scripts.png?alt=media)
5. Click on **Yes** to execute the Script.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-120bcfbfdcd5708c54547960cfc11bf5ea1cfe73%2Fbotao_yes.png?alt=media)
6. Click on the **Queue Working** button at the top of the page to monitor the execution of the action.

* **Note:** An independent **Execute Custom Script** Action will be created for each Host if the action is executed on more than one Host simultaneously, with separate logs for each execution.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5d3b4da633a03137c80d31fdc06fa0faa9ec4937%2Factions_working.png?alt=media)


# Tenable Launch Scan

## Requirements

Linux Control Center = 2.10.X or higher\
Integration with Tenable Vulnerability Management and Sync Scans pre-configured in the Console.\
Hosts with pre-configured Nessus Agent.

## Overview

The *Tenable Launch Scan* action allows you to launch a Tenable Vulnerability Management Scan through the Linux Control Center integration.

## Objective

The purpose of this document is to demonstrate step by step how to use the **Tenable Launch Scan** action of the Linux Control Center.

## Running the Tenable Launch Scan

{% hint style="info" %}
This Action only works with the *Tenable Vulnerability Management* integration.

The LCC does not run the Scan on the selected Host, but rather the Scan previously configured in the Tenable VM environment. Make sure that the Hosts managed by the LCC are included in the Scan that will be run.
{% endhint %}

1. Go to the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Select any Host and click on **Actions** at the top of the page and click on **Tenable Launch Scan**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-647843cef8580216719456d1a3c503b2b3ebd392%2Faction_para_executar.jpg?alt=media)
3. Click on **Tenable** and choose the Tenable VM integration.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c230982968d9f936167814ed1831cd713a437bd2%2Fcampo_tenable.jpg?alt=media)
4. Click on **Scan** to select the Scan you want to run.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-54d79b0e3d3203a81ac1da3ae8f690829d245af9%2Fcampo_scan.jpg?alt=media)
5. Click **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-460e4521186cd188d978cbff2c7ec28e75b4c79f%2Fbotao_yes.jpg?alt=media)
6. Click **Agree** to confirm and execute the Action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cdab8bef6bf3bc81cc2ab5b6e1365a4aee21c873%2Fconfirmacao_agree.jpg?alt=media)
7. Click the **Queue Working** button at the top of the page to track the execution of the Action.

{% hint style="info" %}
Access the Tenable Vulnerability Management web interface to track the execution status of the Scan.
{% endhint %}

* **Note:** A single independent Tenable Launch Scan Action will be created for each Host if the action is executed on more than one Host simultaneously.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c44636d5127428e7480abea15074476d3da99f84%2Faction_working.jpg?alt=media)


# Tenable Sync Results

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Tenable Sync Results action is used to obtain the results available in the Tenable repository through the integration of the Linux Control Center with the Tenable Vulnerability Management and/or Tenable Security Center.

## Objective

The purpose of this document is to demonstrate step by step how to use the **Tenable Sync Results** action of the Linux Control Center.

## Tenable Sync Results

{% hint style="warning" %}
This Action can only be executed once every 24 hours. Before executing the *Sync Results*, check if any Scan has been performed recently to ensure that the vulnerability information is up to date.

The Action will have the **Aborted** status if it is executed again within the 24-hour period.
{% endhint %}

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **Tenable Sync Results**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-72106e59f3a89789a275d24a5d50181c802ff503%2Fbotao_linha.png?alt=media)
3. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Tenable Sync Results**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dada247752c84e7d4177393d9986aca66d5add20%2Fbotao_topo.png?alt=media)
4. Click on the **Tenable** field and choose the configured integration.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a0a70b368ad9abf7df4b40e2d8226737b2a31e26%2Fcampo_tenable.png?alt=media)
5. Click **Yes** to execute the action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e569eccb653d62d2525e0642bc7a4c5846881cab%2Fbotao_yes.png?alt=media)
6. Click the **Queue Working** button at the top of the page to monitor the execution of the action.

**Note:** A single **Tenable TSC Sync Results** Action will be executed regardless of the number of Hosts selected.

1. Note that the action has the **Processing** Status, this status indicates that the information is being transferred to the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d0bb31fdecc937759e8427a18f95a4e8fc3a440b%2Factions_processing.png?alt=media)
2. The Status will have the value **Processed** indicating that the transfer is complete.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bb57b491bfb848d30f9f97f4df522939aa11081f%2Factions_processed.png?alt=media)
3. Access the **Hosts** screen and the Risk column will have the indexes **AES, ACR and VPR**, indicating that the information was transferred correctly.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-05da50808c1b8633e2b84f1992b901a6ece5379a%2Fcoluna_risk.png?alt=media)


# Delete Hosts

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Delete action is used to delete Hosts that are being managed by the LCC.

## Objective

This document aims to demonstrate how the **Delete** Action works

## Deleting Hosts from the LCC

{% hint style="warning" %}
**Note:** If the Host is accidentally deleted, it will be necessary to import it again using **Discover** or **Import Assets** with the **BeyondTrust** integration.
{% endhint %}

1. Access the **Hosts** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click **Delete**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-393821d3a067a2b2b44f56d508f59bee5ca4e451%2Factions_linha.png?alt=media)
3. To execute on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Delete**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7b3c3a7d2580b6cb3178871272c2677e97528aa4%2Factions_topo.png?alt=media)
4. Click on **Yes** to execute the action and delete the Host from the LCC database.

* Note that the **Hosts selected to action** field displays the Host that will be deleted.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a2e488adde716c3c5fc2519a30b661afd920600f%2Fbotao_yes.png?alt=media)

1. Note that the Host **ol8-hmg** is no longer present in the Hosts list.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cc8ec158e6793ef5f0ef2fc44cff744180b834b1%2Fhost_deletado.png?alt=media)


# Host Groups

## Requirements

Linux Control Center = 2.10.X or Higher

## Overview

The main objective of the Linux Control Center (LCC) is to facilitate the administration of Linux hosts. To this end, the LCC offers the ability to create host groups, allowing the execution of several actions simultaneously on a large number of hosts, optimizing the management of the environment.

## Objective

This manual aims to demonstrate how to create groups and insert hosts to manage them through LCC Actions.

## Create Host Group Manually

1. Click **Host Groups**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a61ddfda6a8c81d38db71ecf292140e6d59ef060%2Fhosts_group_dashboard.png?alt=media)
2. Click **Manual** to select hosts and create the group manually

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-555058ef7c8cbb4c0111cf729dcaec10f8550665%2Fgrupo_manual.png?alt=media)
3. Click **ADD**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b5e05e304560fdfe99548eaf2457257443aed374%2Fadd_group.png?alt=media)
4. Type the group name in the **Host Group** line

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e324262a294267d53f5d471fa7b175f68a824b89%2Fhost_group.png?alt=media)
5. Move the desired hosts from the left table to the right table or click **Select All** to move all of them.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1f1152909bead10f1fd2654e98c7759c978d1e3d%2Fmover_grupos.png?alt=media)
6. Click **Save**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d2aa5d31d3240fe7f06f51bf60e7c590d2b03c2a%2Fsave_group_manual.png?alt=media)

## Create Group from Discover CIDR

1. Click **Hosts Group**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a61ddfda6a8c81d38db71ecf292140e6d59ef060%2Fhosts_group_dashboard.png?alt=media)
2. Click **Dynamic by CIDRs** to create a group according to the range of IP addresses registered in the CIDR field in Discover.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c912099af515290750cd780828251696717840ca%2Fcidr_group.png?alt=media)
3. Write the group name in the **Host Group** line

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c4d036d303ec9df3c743b7730be3737a727b1563%2Fgroup_name_cidr.png?alt=media)
4. Click on the **CIDR** line and choose the IP address range (Same address range defined in Discover)

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-abe5ede3ef44194f88fe2e965e9b660c19a86419%2Fcidr_select.png?alt=media)
5. Click on **ADD Another Host group** to add more than one CIDR to the group, if necessary.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2228171bdeb447dba3011ff6c6daa27ec0b55453%2Fadd_another_group.png?alt=media)
6. Click **Save**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9d21d30a5210c9dc82d27ac346517ea32d400176%2Fsave_group_cidr.png?alt=media)
7. The created group will then be listed, allowing you to execute any LCC Action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bbad82de1c02af83a1780ad6dc3830192618d1f7%2Fgrupo_criado.png?alt=media)


# Managed Account


# Create Managed Account

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center allows you to manage local accounts on Linux servers, enabling more efficient control of access to services and servers. This feature allows you to create a managed account in the LCC Console, which can be created on a remote server according to the desired sudo permission level.

## Objective

This document aims to present the step-by-step process for using the LCC account management features.

## Account Management

### Create a Managed Account for Hosts

* To create an account in the LCC Console, follow the steps below; 1. Access the LCC Click on **Accounts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c0a45022a1233460d9ae4ff9b0d9bc1e6d609c6b%2Fbotao_accounts_dashboard.png?alt=media)

1. Click on **Create**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5839d53c513235b238af4af60c259e60d09bf414%2Fbotao_create.png?alt=media)

1. Fill in the fields according to the needs of your environment.

**Name**: Account Display Name\
**username**: Account User\
**Password**: Account Password\
**Shell**: Defines which Shell the account will have when logging in\
**BeyondTrust Functional Account**: Defines whether the account will be defined as a *Functional Account* through integration with PasswordSafe in your environment.

1. Click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1323b732a7d9f7ba2023d760610a8f7c23ac0039%2Fbotao_save.png?alt=media)

1. Click on the account that was created, where you will be able to see the account information as shown in the image below;

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-62eccd976aedcf46edf414e052936bbe650bb092%2Fconta_criada.png?alt=media)

1. Click on **Account Host**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bedb8fdd15c70009190576ee8d337a9ab94ddc85%2Faccount_host.png?alt=media)

### Add Account to Host

1. Click on **ADD Host**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-62c8faabb927dce18727da13ce7e4702394f2bcc%2Fbotao_add_host.png?alt=media)

1. Choose which **Host** you want to add the account to.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3b478fb95f1fbd8ff0564edb88cab34cf5b5c6b2%2Fcampo_host.png?alt=media)

1. Choose the permission level to escalate privilege in **Sudo**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ca0244b5ad01660d6081122c292506dd2a90653d%2Fcampo_sudo.png?alt=media)

1. Click **Save** to add the account to the selected Host.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-855f52662f323f2290a9092262f629f75e6ede3d%2Fbotao_save-add-host.png?alt=media)

1. You can track the status of the **Account ADD** action in the queue by clicking on **Actions Working**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e06c72ebebd7794fd18f520cd24526a323feedef%2Faccount_working.png?alt=media)

1. Once the **Account ADD** action is complete, a **Photography** action will automatically start to update the Host information in the LCC database.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1e885de8da8d6e582374ce277e70328e2c04c12a%2Ffotografia.png?alt=media)

1. To validate that the account was created correctly, access the Host on the **Hosts** screen and click on **Accounts** and the added account will be listed.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1a23d67e6282a7af06888c5a1de3bcb8fc5be341%2Fconta_criada_no_host.png?alt=media)


# Managed Files


# Create Managed File

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

Linux Control Center allows you to standardize configuration files for managed Hosts by uploading a configuration file.

## Objective

This document aims to demonstrate step by step how to use the *Files* functionality of Linux Control Center.

## Create Managed File

### Essential Settings

1. Access the **Files** screen on the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5830d70fa5f978a6f442332e44740d9f16497cfb%2Ffile_dashboard.png?alt=media)
2. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a5cad4f66c4ffc61a31828cf5736c816d46aedbe%2Fbotao_create.png?alt=media)
3. Fill in the required fields as instructed below;

**Name:** Name to identify the file only in the LCC Console.\
**Upload File:** Field to upload the desired file.\
**Path:** Directory, Name and Extension in which it will be stored on the Host.\
**Owner:** User who will have access permissions to the file.\
**Group:** Group that will have access permissions to the file.\
**Permissions:** Level of access permission to the file.<br>

```
![](/pt-br/images/files/create_file/campos_iniciais.png)
```

### Additional Settings

* These settings allow you to create a User, Group or Directory when they do not exist on a Host where the file will be uploaded. It also allows you to create a copy of the file and move it to a desired directory if one already exists before performing the action of adding the new file to the Host.

**Create User:** Creates the user from the *Owner* field if it does not exist on the Host.\
**Create Group:** Creates the access group from the *group* field if it does not exist on the Host.\
**Create Directory:** Creates the directory to save the file from the *Path* field if it does not exist on the Host.\
**Backup:** Creates a copy with date and time if a file with the same name and extension already exists in the same *Path* directory.\
**Move Backup:** Moves the created copy to the directory entered in the *Backup Directory* field.<br>

```
![](/pt-br/images/files/create_file/campos_adicionais.png)
```

1. Click **Save** to make the file an LCC Managed File.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-83887351af7257429f57bdd9bed80a8c2859aa6e%2Fbotao_save.png?alt=media)
2. Click on Managed File to check or change the File settings.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-65bd487f2ee8a405c3070113132ca8daa7d3fae3%2Farquivo_criado.png?alt=media)
3. All fields filled in when creating the file will be displayed. You can also download it by clicking on **Download**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2502198da3f28619357f40b892d0861735d1b33%2Fbotao_download.png?alt=media)

### File Host and Content

1. Access the File created and click on *File Host*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b4475bceb8d2195c162ccffb65afa9b6bbc03649%2Ftela_file_host.png?alt=media)
2. The **ADD Host** button creates an empty row in the table, and by clicking on the arrow in the *Host* column, you will be able to choose a Host to create the file.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cffb594ffec13258bf8d1628c59469a8dd8d7884%2Fbotao_add_host.png?alt=media)
3. Click **Save** after selecting the Host to start the *File Add* Action that will include the file according to the settings.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cd9498a6edac7e2e0a258e36295200d71c22a0b2%2Fbotao_save_tela_file_host.png?alt=media)
4. This screen displays which *Hosts* the file was added to, along with the date and time it was created. The *Sync* Column indicates whether the file is synchronized with the latest version in the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3f67a3cff4e921a98b1d5406b4e7c7ed7544640d%2Farquivo_adicionado_host.png?alt=media)
5. The trash can icon button in the *Actions* column makes it easier to delete the file from the desired Host from this screen, but it is also possible to delete the file from the **Hosts** screen or from the **Host Groups** screen for a larger number of Hosts.
6. When you click this button, the *File Del* action will be started immediately and the file will be removed from the chosen Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8a0cc8dd8624c2e722ea8b910da15883a4ad7021%2Fbotao_lixeira.png?alt=media)
7. The **Content** screen displays the contents of the File in which it is saved in the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-64cdc8ddd168c5c5579ac8ca1b75c33d790eda1e%2Fcontent.png?alt=media)

## Add Managed File to Host

1. Access the **Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)
2. Click on **Actions** in the row and a desired Host and click on **File Add**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-59163a0dbdc5674ffdf4639219e46e10b6615324%2Ffile_add_linha_host.png?alt=media)
3. To execute the Action on several Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **File Add**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0be13ab35e61798a74ef02d7d266dbe79370fdfa%2Ffile_add_topo.png?alt=media)
4. Click on **File Type** and choose the **Managed** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e553ff755bd5307532da5f9400ae84f62a33108a%2Ftype_managed.png?alt=media)
5. Click **Insert File** and choose the managed file you want to add to the Host.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9410edd83f1aad8c6450690eb91f041c5869e0e3%2Finsert_file.png?alt=media)
6. Click **Yes** to start the *Action*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-32012e8e4a0d4691da1eb2f6bfaea6344cf3d9f2%2Fbotao_yes.png?alt=media)
7. Click the **Queue Working** button at the top of the page to monitor the execution of the action.

**Note:** An Action will be created.


# 7 Library


# Install Tenable Agent

## Requirements

* Hosts in the LCC database previously configured
* Host with internet access via HTTPS protocol, port TCP/443
* Nessus Agent Linking Key

## Overview

* This guide provides step-by-step instructions for using the Nessus Agent installation playbook available in the LCC 7 Library.

## Objective

* The purpose of the Install Tenable Agent playbook from the 7 Library is to facilitate the installation of the Nessus Agent, allowing mass installation on Linux hosts in an automated manner.

## Linking Key for the Nessus Agent

* The key is used during the Agent installation to associate the Host with an account in Tenable Cloud, so that the Scan result is directed to the correct location via the Web.

1. Access the website <https://cloud.tenable.com> and log in with your environment credentials.
2. Click the gear in the top right corner

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c876578db96c43011f7ef00233616be772dbb0f1%2Fcloud_homepage.png?alt=media)
3. Click **Sensors**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-185fbdbe2bbf2bf390a0ff3cc3c2dc9376c6c85b%2Fsensors.png?alt=media)
4. Click **Nessus Agents**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d731f95381e81be4682ad94c24eef3213666f987%2Fnessus_install.png?alt=media)
5. Click **ADD Nessus Agent**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-32ee669b75082381d86bb3e10957d5260eb81065%2Fadd_nessus_agent.png?alt=media)
6. Copy the **Linking Key** with the **Copy** button and save it in a text editor

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e313fe1f29f85b8a7045ace01e0ca98a5acc3857%2Fadd_nessus_agent2.png?alt=media)

## Nessus Binary Download Link Agent

* To run the playbook, you need to get the correct download link for the Nessus Agent installation package.

1. Go to the official Nessus Agent download link <https://www.tenable.com/downloads/nessus-agents?loginAttempted=true> and download the package compatible with the Linux host where the playbook will be run.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-494a5f1b917b4cf0f3805a922d224ff8836c06c7%2Fdownload_oficial_agent_page.png?alt=media)
2. Open the Download History page of your browser and right-click on the downloaded package.
3. Click **Copy Link Address**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4a8f9cb8a6a062b3db09e120cbc5cfb23cb926c2%2Flink_download.png?alt=media)
4. Save the download address along with the **Linking Key** to make the next step easier.

## Install Tenable Agent Playbook Configuration

* With the Linking Key and download address in hand, follow the steps below;

1. Click **7 Library** in the LCC left menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dbcd9b63fc9b8b4081e61966768263cfd24b93c3%2F7_library.png?alt=media)
2. Click **Sync Feed** to update the 7 Library feed
3. Click on the **Install Tenable Agent** playbook

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-18046faca6e1e833b8d5d9478a2f9a7cb87a5bcf%2Fnessus_agent.png?alt=media)
4. Click **Download** and the playbook will be saved to the LCC and available on the **Playbooks** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-eb7ae0135ceb7a9a601c05f6431d8addc1c7778e%2Fdownload_playbook.png?alt=media)
5. Click **Playbooks** in the LCC left menu and click on the **Install Tenable Agent** playbook

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-896798b88997ce4db2e4260626ee4271125aa22b%2Fplaybooks_page.png?alt=media)
6. Click **Variables**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7c33f550b18b21a15c655bbda2d0f25ccbcad3f9%2Fvariables_nessusagent_install.png?alt=media)

* Enter the values ​​of the variables; - **URL**: Enter the package download link copied in the previous step
* **PACKAGE\_TYPE**: Enter the package manager of the Linux distribution in which the playbook will be executed:
* `apt` or `rpm`
* **LINKING\_KEY**: Linking Key obtained from Tenable Cloud
* **FLAGS**: Default value:
* `--cloud`
* **BIN\_PATH**: Default value:
* `/opt/nessus_agent/sbin/nessuscli`
* **AGENT\_GROUPS**: Enter the name of the Tenable Cloud Assets group in which the Hosts will be inserted
* `/opt/nessus_agent/sbin/nessuscli`

1. Click **Save**
2. Select the playbook and click **Actions** and then **Run**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9b8c0b545e2e1346273e8f192c1642f65a537168%2Factions_playbook.png?alt=media)
3. Choose the desired **Host** or **Host Group** and click **Yes** to run the playbook.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8605c69aefeb5ce85609c69e3dae05add080936d%2Fconfirm_actions.png?alt=media)

## Installation Validation

* To validate if the installation was completed successfully;

1. Click **Dashboard** in the left side menu of the LCC and scroll down to the **Host Actions** log

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8ddef1e3de0a2866a307fc1cab1a486c0bf6b4b0%2Fdashboard_lcc.png?alt=media)
2. **Success** will appear when executed correctly and **Error** when an error occurs during the process.
3. Click **EXPAND** to read the log details.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9aaed8e9f9235d0d1db293f4d03ed60f958abbdf%2Flog_playbook.png?alt=media)


# 7 VulnDB-API

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center (LCC) has the 7vulndb-api, a constantly updated database with information about vulnerable packages from the main Linux distributions. The identification process uses the database to check for packages with vulnerabilities. Then, a scan is performed on all hosts managed by the LCC to compare and identify the presence of any package listed in the database.

## Objective

The objective of this manual is to demonstrate the step-by-step process for using the LCC's 7Vulndb vulnerability API.

## Identifying Vulnerable Packages with the 7 Vulndb API

{% hint style="warning" %}
When performing this action on a Host, all packages with identified vulnerabilities will be marked. If the same package with vulnerability is installed on another Host, it will also be flagged in the Console.
{% endhint %}

1. Access the LCC and click on **7 Vulndb API**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7cf799a5ba07fae5b63fae9cf3bd52a0ecf6907f%2Fbotao-7vuln-dashboard.png?alt=media)

1. Click on **Check Vulnerability**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ce3f11c8b18a4fcbb73707e9193e1bb67a06a853%2Fbotao-checkvulnerability-tela-api.png?alt=media)

1. The **Status** column will have the phrase ***Waiting API process:*** indicating that the API is performing the scan.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-57975a00223eeab5e590608a1c3a14578660f92c%2Fapi-processando.png?alt=media)

1. The **Status** column will have ***API awnser received:***, indicating that the scan has finished, along with the number of packages scanned.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d4b19e4dde0f77eacec72b59c8b67417d7a4264c%2Fapi-finalizada.png?alt=media)

1. These are the descriptions of the information fields on the **7 Vulndb API** screen

* **Packages request:** Total number of packages sent for analysis.
* **Packages vulnerable:** Number of packages that have some vulnerability, whether exploitable or not.
* **Request Uuid:** Request identifier.
* **Created at:** Time the analysis request was sent.
* **Updated at:** Time the analysis request was completed.

## Package Analysis Vulnerabilities

After the scan is complete, you can get more details about the vulnerabilities found in the packages.

1. Click on **Hosts** in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-100bfe54e874fce161f05d8ae0a1eda065e8d997%2Fbotao-hosts.png?alt=media)

1. Click on a desired Host and click on **CVEs**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bc9be8f6b1571159fbb04bd20ab6ea7ed34ac3d4%2Fgeneral-host.png?alt=media)

1. All **CVEs** identified in all packages will be displayed.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4a4ff8312e83ca85d7c6bbcf5524e41df5a6ec18%2Ftela-cves.png?alt=media)

1. To find the **CVE** of a specific package, change the selector from Host to Package

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b2d0db33e71e6d5187ee6ab0b62ac7dd102f60ce%2Fhost-para-packages.png?alt=media)

1. Click on **Filter Packages**

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/7vulndb_api/arrow-bottom-filter-packages.png)

1. Note that it is possible to use the **Package Vulnerable By Tenable** filter in conjunction with the **Package Vulnerable By 7Vulndb** filter
2. Select the desired filters and click on **Confirm Filter**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-059c12a693fc8c39cd52eeac0b0641cab802f205%2Fby-7vuln-by-tenable.png?alt=media)

1. This way, only the vulnerabilities related to the selected packages will be listed.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f61915589a3eaf6170f943623fe38bda1683c798%2Ffilter-packages-somente-alguns-pacotes.png?alt=media)

## Updating Vulnerable Packages

1. In the left side menu of the LCC, click on **Hosts**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)

1. Select 1 or more Hosts and click on the **Actions** button at the top of the page and execute the **Package Vulnerable Update** action.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c70c6d392430dd6d05cc029a734d541273a6578%2Fseta_package_vulnerable_update.png?alt=media)

1. Confirm the action by clicking **Yes**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-97e137a0cdb9f5b507b146255b65cc9af6f0ac85%2Fconfirma_vulnerable_update.png?alt=media)

1. Open the host that sent the action and click on **Actions History**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b3f76fdbc5ff6a28a7b28109f9673a91572a9142%2Ftela_general_seta_actions.png?alt=media)

1. Wait for the actions *Package Vulnerable update,* *Package Check Update* and *Photography* to have the status **Processed**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-11c4c8549c996472c10c702e9fe93b743504c6a3%2Factions_history_vulnerable_update.png?alt=media)

1. With this action, some vulnerabilities that can be mitigated only by updating packages will no longer be a risk to your environment!

Based on this information, it is possible to develop some security measures such as:

* Update package
* Proactive monitoring
* Freeze package version until the version situation is investigated.
* Vulnerability management
* Backup and recovery

Although not limited to these options, these measures aim to mitigate possible vulnerabilities and promote a safer environment.


# Custom Scripts

O módulo de *Script* no Linux Control Center (LCC) oferece uma maneira eficiente de automatizar a execução de scripts em hosts descobertos pelo LCC. Essa funcionalidade suporta scripts que contenham uma linha shebang ("#!") inicial, como python, bash, javascript, entre outros.

## Execução Seletiva

Os usuários têm a flexibilidade de executar scripts de duas maneiras distintas:

### 1. Execução por Host:

Ao selecionar hosts individualmente, o script será executado apenas nos hosts escolhidos pelo usuário. Essa abordagem é ideal para a execução não persistente de scripts, onde o LCC cuida do upload, execução e remoção do arquivo no sistema.

### 2. Execução por Grupo de Hosts:

A execução também pode ser estendida a grupos de hosts, proporcionando uma maneira eficaz de aplicar ações a conjuntos específicos de servidores.

## Variáveis Dinâmicas no Script

Uma característica essencial desta funcionalidade é a capacidade de inserir variáveis nos scripts. Isso permite a execução do mesmo arquivo em momentos diferentes com valores distintos, oferecendo adaptabilidade conforme necessário. O formato da variável é **${:::Nome da variável:::}**, sendo o *Nome da variável* o identificador daquela variável.

{% hint style="warning" %}
É importante notar que caso sejam escritas variáveis com o mesmo *identificador*/*nome* o LCC irá substituir o valor da ultima variável inserida pelo usuário em todas as outras. Logo é recomendado utilizar nomes diferentes caso os valores desejados de execução sejam distintos.
{% endhint %}


# Linux Scripts

## Requirements

Linux Control Center = 2.10.X or higher

## Objective

This manual aims to present all the features that the LCC Scripts module offers.

## Overview

In the Linux Control Center (LCC), the Scripts module plays an important role in administration, providing users with the ability to execute custom Scripts on hosts managed by the LCC. Using the Scripts module is similar to the Playbooks module.

Executing a Script through the LCC provides a complete view of the process, allowing you to monitor its progress in real time and generate detailed reports. In addition, the execution can be performed by the Workflow, which allows you to make dynamic decisions based on the results of each step.

## Uploading and Configuring Scripts

1. To start, access the LCC and click **Scripts** in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-84bd9077fffa7cc2bb5044eb737a1563d36664ad%2Fbotao_scripts.png?alt=media)

1. Click **Create**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e040099faad335804361a64a0acd497605e6fa52%2Fbotao_create.png?alt=media)

1. Enter a name to identify the Script in the **Name** field.
2. Click **Host Type** and choose the Script type **Windows or Linux**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1c70fa73c02945be4968f3f9630e60892c9a7507%2Fbotao_host_type.png?alt=media)

1. Fill in the **Remote Path** field with **/** at the end. This will be the directory where the Script will be saved and executed. 1. Click on **User for Execution**, which we recommend is the user **lcc.local**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6677f6f7b2810d58a26c202770eb97dd38d4bdf8%2Fuser_for_execution.png?alt=media)

1. Click on **Upload File** and choose the desired Script from your computer.
2. Note that the name of the Script will be displayed in the **Current File** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-db31c9162a0ba787a7257ef1d2bbf3b519f1a061%2Fcurrent_script.png?alt=media)

1. Click on **Save** and the Script will be saved in the LCC database.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f721fa9fcd2be1c2a8ca94014a72adb9a30b3955%2Fbotao_save.png?alt=media)

1. Click on the Script that was created and you will see the following screens:

### General Information

1. Screen that displays the date and time the Script was created, the date and time of the last change and you can also change the information in the **Name** and **Description** fields. You can also download the file by clicking **Download**, delete it by clicking **Delete** and upload a new file by clicking **Change File**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f1fae8fc3510ad6e5c456f0ed550565552d52c83%2Ftela_general.png?alt=media)

### Dynamic Variables in the Script

Similar to *Customizable Playbooks*, Scripts also have the ability to insert variables. This allows the same Script to be executed at different times with different values, offering adaptability as needed. The variable format is **${:::Variable name:::}**, where *Variable name* is the identifier of that variable.

After creating the Script with the variable in this format and uploading the file to the console, it will be possible to change its value directly through the LCC web interface whenever necessary. The updated value will be automatically saved in the Script file saved in the database.

1. See an example of implementation of this variable format

* var\_name: **${:::var\_name:::}**\*

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f99f9cfc893596b75f8ce0136bfbddaca895113e%2Ftela_variables.png?alt=media)

{% hint style="warning" %}
It is important to note that if variables are written with the same *identifier*/*name*, LCC will replace the value of the last variable entered by the user in all others. Therefore, it is recommended to use different names if the desired execution values ​​are different.
{% endhint %}

### Script Content

1. The Content screen displays the entire content of the Script. The image below shows the variable mentioned in the previous topic.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3ed55dd790c05c95bdb3336b31fe24652a35d23b%2Ftela_content.png?alt=media)

### Execution Credentials

1. On the **Credentials** screen, the LCC allows the Script to be executed with credentials other than the default *lcc.local*. It is possible to use Linux Credentials that are registered in the LCC console, Credentials from the Password Safe password vault by BeyondTrust through integration and through the LCC Hook Bridge Params functionality.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3ac6cb9e2b828ba86b3e7e1f49ccc6a6bcc872ab%2Ftela_credential1.png?alt=media)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4d2cf9e07b367199a2c42efa423d9d9fe2288e58%2Ftela_credential2.png?alt=media)

### Tenable Plugins

1. This screen makes it easy to remediate vulnerabilities identified as Tenable Plugins through integration with Tenable Vulnerability Manager and/or Tenable Security Center. Remediation is performed by running scripts from the Linux Control Center **7 Library** repository, designed to remediate specific **Tenable Plugins**.

* This example shows the *Configure SSH Ciphers and Algorithms* Script that fixes Tenable Plugin 153588.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/scripts/linux_scripts/tenable_plugins_screen.png)

## Script Execution

1. Access the **Hosts** screen

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9c491171845e4402af4a9a00d4573628cae81ae9%2Fhosts_file_download.png?alt=media)

1. Click **Actions** on the line and a desired Host and click **Execute Custom Script**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c16d7755b56078efd8c3b7af6a592ff553e0e806%2Flinha_host.png?alt=media)

1. To run on multiple Hosts simultaneously, select the desired Hosts and click on **Actions** at the top of the page and click on **Execute Custom Script**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-67067cc57f1e7a508c17e6c4f5d57f4d6817fe7d%2Factions_topo.png?alt=media)

1. Choose the Script you want to run in the **Scripts** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-06991889c746098c9218037d320c09e788d62a71%2Fcampo_scripts.png?alt=media)

1. Click on **Yes** to run the Script.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-120bcfbfdcd5708c54547960cfc11bf5ea1cfe73%2Fbotao_yes.png?alt=media)

1. Click on the **Queue Working** button at the top of the page to monitor the execution of the action.

**Note:** An independent **Execute Custom Script** Action will be created for each Host if the action is executed on more than one Host simultaneously, with separate logs for each execution.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5d3b4da633a03137c80d31fdc06fa0faa9ec4937%2Factions_working.png?alt=media)


# BeyondTrust Password Safe Secrets

This guide provides information and steps for Integration a Linux Control Center Script with BeyondTrust Password Safe Secrets.

The Secrets Safe It allows you to securely store secrets owned by developers and small groups in a controlled environment.

Through this integration it will be possible to retrieve a Secrets from BeyondTrust Password Safe and use it as a variable within a Linux Control Center Script.

## BeyondTrust Password Safe Secrets Safe Configuration

* User Group must be "Secrets Safe" feature.
* Create a Secret in Secrets Safe.
* Add Credential.

### Enabling Secrets Safe Feature

1. To enable a secrets security feature, you must edit a user group that has a user that will be used to authenticate to the BeyondTrust API.
2. Go to target user group where the user belongs, click on vertical elipse and go to View Group Details.
3. On the group page, go to Features tab and select Disabled Features on "Show" field.

   <figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-65e722675d72862e43863c11baf76e4232a421b2%2Fimage%20(106).png?alt=media" alt=""><figcaption></figcaption></figure>
4. Select the Secrets Safe feature, click on the vertical elipses and select Assign Permissions Full Control.

   <figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f0b7bad2cf0906c036a9e772fc88491e56d7a7bc%2Fimage%20(107).png?alt=media" alt=""><figcaption></figcaption></figure>
5. After these steps, the users from this groups is able to interact with Secrets Safe from BeyondInsight Password Safe API.

   <figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0f151d21f1cf31537669031a954b74a178f95d1f%2Fimage%20(109).png?alt=media" alt=""><figcaption></figcaption></figure>

### Create a Secret in Secrets Safe

1. From the left menu, click **Secrets Safe**.
2. From the Folders pane, select a folder, and then click **Add Secret** above the grid.

   <figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3c12a1719b8d7cfde09f52b34f253b7615e9129d%2Fimage%20(60).png?alt=media" alt="" width="463"><figcaption></figcaption></figure>
3. Select your secret type: **Add Credential**, **Add File**, or **Add Text**, and then fill out the form for each type as detailed in below steps.

### Add Credential

1. Enter a Title, Description, and Username.
2. Set the password:
   * Select Manual Input to manually enter a password or Select Auto Generate and select a Password Policy from the list to have a password created based on the defined policy.

     <div align="center"><figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0f83ec4ab8cec091205c386b7d9e67ae7c234153%2Fimage%20(63).png?alt=media" alt=""><figcaption></figcaption></figure></div>
3. Click Create Secret.

## Linux Control Center Script Configuration

* Ensure the BeyondTrust Password Safe integration is enabled in your Linux Control Center.
* Create a Quick BeyondTrust Credential.
* Create a Quick Windows Inventory.
* Create a Linux Control Center Script and assign Custom or Default BeyondTrust Credentials and Variables.
* Create a Workflow to execute a Custom Script for Windows/Linux.

### Quick BeyondTrust Credential

A Quick BeyondTrust Credential is a custom credential used to perform authentication on BeyondTrust Password Safe API.

1. To create a Quick BeyondTrust Credential, go to left menu Unmanaged Hosts > Quick Credentials BeyondTrust and click ADD.
2. Enter the necessary fields to perform authentication such as Name, API URL Base, API Auth Key, API Auth Username & Password and Managed Account used retrieve the Secrets. Click Save.

{% hint style="info" %}
Note that the user being used to authenticate belongs to the aforementioned group, therefore he has access to the Secrets of this group in which he has permission to interact.
{% endhint %}

<figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-aec770261d0e3d6a97c9529b5829d7410883e110%2Fimage%20(65).png?alt=media" alt=""><figcaption></figcaption></figure>

### Quick Windows Inventory

The Inventory function in Linux Control Center is the way to group information from a host such IPv4 Address, Host Type (Windows and Linux) and Port, to perform a future authentication.

A Linux Control Center Windows authentication is based on Windows Remote Management (WinRM) that allows systems to access or exchange management information over a network, the default port is 5985 over a HTTPS transport.

1. To create a Quick Windows Inventory go to **Unmanaged Hosts** > **Quick Inventory** and click **ADD**.
2. Enter a Name, Address, Port and select the host type from the droplist below (Windows or Linux).

   <figure><img src="https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f2f20c6e3083c4b8e94383170eb7f50f714f3f7a%2Fimage%20(82).png?alt=media" alt="" width="563"><figcaption></figcaption></figure>

### Create a Script

In this Script example, the following powershell template will be used:

```powershell
# Assign values to variables
$variable1 = "${:::VARIABLE1:::}"
$variable2 = "${:::VARIABLE2:::}"

# Initial text
echo "Executed By Linux Control Center - Hostname: $env:COMPUTERNAME - Date: $(Get-Date) - Time: $(Get-Date -Format HH:mm:ss)"
echo "---------------------------------------------"

# Get host information
$ipAddress = (Test-Connection -ComputerName $env:COMPUTERNAME -Count 1).IPV4Address.IPAddressToString
$hostname = $env:COMPUTERNAME
$dateTime = Get-Date

# Print information on the screen
echo "IP Address: $ipAddress"
echo "Hostname: $hostname"
echo "Date and Time: $dateTime"

# Print variable1 in plain text and base64
$base64Value1 = [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes($variable1))
echo "Variable1: $variable1"
echo "Variable1 (Base64): $base64Value1"

# Print variable2 in plain text and base64
$base64Value2 = [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes($variable2))
echo "Variable2: $variable2"
echo "Variable2 (Base64): $base64Value2"

# Final text
echo "---------------------------------------------"
echo "Executed By Linux Control Center - Hostname: $env:COMPUTERNAME - Date: $(Get-Date) - Time: $(Get-Date -Format HH:mm:ss)"

# Write on file

# Outputfile
$outputFilePath = "output_secrets.txt"

# Init
$null > $outputFilePath

# Print information on the screen and write to the output file
Add-Content -Path $outputFilePath -Value "IP Address: $ipAddress"
Add-Content -Path $outputFilePath -Value "Hostname: $hostname"
Add-Content -Path $outputFilePath -Value "Date and Time: $dateTime"

# Print variable1 in plain text and base64 and write to the output file
Add-Content -Path $outputFilePath -Value "Variable1: $variable1"
Add-Content -Path $outputFilePath -Value "Variable1 (Base64): $base64Value1"

# Print variable2 in plain text and base64 and write to the output file
Add-Content -Path $outputFilePath -Value "Variable2: $variable2"
Add-Content -Path $outputFilePath -Value "Variable2 (Base64): $base64Value2"
```

1. To create a Script, go to **Unmanaged Hosts** > **Script** and click **ADD**.
2. Enter a Name and select the Host Type field, for the powershell, it will be a Windows type. Upload the script template on the Upload File field, and Click Save.

   <figure><img src="broken://files/IdGzCwOsyT1kC2jnUKvy" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
The script's needs to a variable assigned before to start execution.
{% endhint %}

3. The Variable in the BeyondTrust Secrets Safe context, it is the retrieved Secrets from the Password Safe Secrets Safe manager. Therefore, to reveal the secrets linked to a Quick BeyondTrust Credential, click on the newly created Script object and go to the Credential tab.
   * Select which login credential will be used, if you choose BeyondTrust Default the default configuration in Config > Integrations > BeyondTrust will be used.
   * If you choose to use a Quick Credential, select BeyondTrust Custom and choose the credential. The same options is valid for the Variables field.
4. Click on Save to perform a new job with "List Secrets" action.

   <figure><img src="broken://files/XV0hnp9cLLKCBpqFZP2x" alt="" width="563"><figcaption></figcaption></figure>
5. After succesfully action, go back to Custom Script Configuration and Variables tab. Select the BeyondTrust Secret Type field and choose the Secrets Value and Secrets Type recovered by the List Secrets action.

   <figure><img src="broken://files/H5Q7kDe5ZG5ZUYFuP3DX" alt="" width="563"><figcaption></figcaption></figure>
6. Click on Save.

### Create Workflow To Execute the Script

To perform a Script Execution a script on the target Host in Quick Inventory it is necessary to create a Workflow to guide the Linux Control Center to execute.

1. From left menu, go to **Workflow** and click **ADD**.
2. On **Add Workflow** page, click on Start and select **Execute Custom Script Quick Windows**.
3. Select the **Scripts** and **Quick Inventory Windows** fields unlocked by the Execute Custom Script Quick Windows option and click **Save**.

   <figure><img src="broken://files/XcFCbiZB8PDgWx3bL56X" alt="" width="563"><figcaption></figcaption></figure>
4. Click on the newly Workflow object Actions button and click **Run** to perfom a Script Execution.
5. The Script Output is stored on home directory from the user used to perform a Script Execution on the target Host in Quick Inventory Windows.

   <figure><img src="broken://files/KoJLBPGj4ERt0V9Hl907" alt=""><figcaption></figcaption></figure>


# Custom Playbooks

## Requirements

Linux Control Center = 2.10.X or higher

## Objective

This manual aims to present all the features that the LCC Playbooks module offers.

## Overview

In the Linux Control Center (LCC), the Playbooks module plays an important role in administration, providing users with the ability to execute custom playbooks on hosts managed by the LCC.

Executing a playbook through the LCC provides a complete view of the process, allowing you to monitor progress in real time and generate detailed reports. In addition, execution can be performed by Workflow, which allows you to make dynamic decisions based on the results of each step.

## Uploading and Configuring Playbooks

1. To get started, access the LCC and click on **Playbooks** in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-625d63221879f5d8cf134ffeb7d69a46a2303e62%2Fplaybooks-menu.png?alt=media)
2. Click **Create**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e8df8e406c2fb3f0ae1ef0a0ff2ea9dfe1a2fa9f%2Fcreate_playbook.png?alt=media)
3. Enter a name to identify the playbook in the **Name** field.
4. Click **Upload File** and choose the desired playbook from your computer.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0fe513bbca35b40be10a1f2865b4352bd6e137d8%2Fnome_e_upload_playbook.png?alt=media)
5. Note that the playbook name will be displayed in the **Current File** field.
6. Click **Save** and the playbook will be saved in the LCC database.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cb2887f247d97f46a79509d0aeb618e9a57f6302%2Fsave_playbook.png?alt=media)
7. Click on the Playbook that was created and you will see the following screens:

### General Information

1. Screen that displays the date and time the playbook was created, the date and time of the last change and you can also change the information in the **Name** and **Description** fields. You can also download the file by clicking **Download**, delete it by clicking **Delete** and upload a new file by clicking **Change File**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b46821e6ddcab4ec7603413f145054df3fa90fcd%2Fgeneral_playbook.png?alt=media)

### Dynamic Variables in the Playbook

Similar to *Customizable Scripts*, playbooks also have the ability to insert variables. This allows the same playbook to be executed at different times with different values, offering adaptability as needed. The variable format is **${:::Variable name:::}**, where *Variable name* is the identifier of that variable.

After creating the playbook with the variable in this format and uploading the file to the console, it will be possible to change its value directly through the LCC web interface whenever necessary. The updated value will be automatically saved in the playbook file saved in the database.

1. See an example of implementation of this variable format

* var\_name: **${:::var\_name:::}**\*

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-df8b1a48776bf0ee68ccc4bc9307ab9d6d867cf5%2Fvariables.png?alt=media)

{% hint style="warning" %}
It is important to note that if variables are written with the same *identifier*/*name*, LCC will replace the value of the last variable entered by the user in all others. Therefore, it is recommended to use different names if the desired execution values ​​are different.
{% endhint %}

### Playbook Content

1. The Content screen displays all the playbook content. The image below shows the variable mentioned in the previous topic.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-150565af83b5f2292fd9a1014e7f3070e018aef8%2Fconteudo_playbook.png?alt=media)

### Execution Credentials

1. On the **Credentials** screen, the LCC allows the Playbook to be executed with a different credential than the default *lcc.local*. It is possible to use Linux Credentials that are registered in the LCC console, Credentials from the Password Safe password vault by BeyondTrust through integration and through the LCC Hook Bridge Params functionality.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-752b1b13546bf0f3e9ce46d066ede182c5c5c7c5%2Fcredential_playbook.png?alt=media)

### OS Release

1. This functionality allows the Playbook to be executed only on a specific Linux Distribution. 1. Click **Create**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8e650d384cf131d34be1dfe20a6b87ac55ebec59%2Fos_release_playbooks_create.png?alt=media)
2. Click **Release**, choose the Linux Distribution that the playbook will run on, and click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c22a755f4665440b159221be62f62886000bcc61%2Fsave_os_release.png?alt=media)

## Running Playbooks

1. To run the playbook, simply access the **Playbooks** screen and click on **Actions** of the desired playbook.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c1c9836531d34b2d2af33d7e2fe8e6128874cd27%2Factions_playbook.png?alt=media)
2. Click **Run**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9cee3877ea4555f98a0463466f36336b11f1d57e%2Frun_playbook.png?alt=media)
3. Choose which **Host** or **Host Group** the playbook will run on
4. Click **Yes** and the playbook will run immediately.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d802487ccfbb31054b7e0e55a32b0b10f0c52fef%2Fyes_playbook_action.png?alt=media)


# Hook Bridge


# Hook Bridge

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The LCC *Hook Bridge* is a feature that allows the automated execution of Actions on specific networks through Web requests. Each request contains an authorization **Token** that defines which Actions will be executed and on which network (CIDR). These actions are pre-configured at the time of Token creation, ensuring that only authorized *Actions* are executed.

The *Hook Bridge* is also used to facilitate integrations with the Linux Control Center. Serving as an access point, this feature allows the user to execute pre-configured actions on the LCC without needing to be logged in to the Console, while still ensuring high traceability of the flow and multiple options for monitoring the execution.

1. See the operating flow of the **Hook Bridge** with *Propagation Action* from BeyondTrust Password Safe.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5c2d7596a161de92ae0e2c67c126f7b688006cb9%2Foverview_hook_bridge.jpg?alt=media)

## Objective

The objective of this document is to provide step-by-step instructions and demonstrate the use of the **Hook Bridge** functionality of the Linux Control Center.

## Hook Bridge Token

1. Access the **Hook Bridge** screen on the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3968c8016f628e8c4d5852d59959ee777555774f%2Fhook-bridge-dashboard.png?alt=media)
2. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76758e438d7d1253808c0f8c97e23d41eae61423%2Fbotao_create.png?alt=media)
3. Fill in the **Name** field.
4. Choose the **CIDR** registered in the LCC database.

   **Name**: Name to identify the *Hook Bridge*.\
   **CIDRs**: Defines which IP address range (CIDR) the Token will have access to in order to execute the *Actions*.<br>

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-09b9097b41e4e4ae64731d38a998c7f0aa8ce652%2Fbotao_escolher_cidr.png?alt=media)
5. It is also possible to create a new **CIDR**, to do so, click on the **+** sign

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-371cf561013e2e4a872acb3adaf92dde7ccc6315%2Fbotao_criar_cidr.png?alt=media)
6. Fill in the required fields, being;

**Name:** Name to identify the *CIDR.*\
**CIDR:** Enter the IP address range followed by the network mask. Ex: 192.168.0.0/24<br>

1. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-52784e00583f928306fa33296d53f811938e4741%2Fbotao_save_cidr.png?alt=media)
2. Set the *Action* in the **Action** field

* **Action**: Defines which *Action* the *Token* will be allowed to execute.<br>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e10fe9a5013af35277db22831c30ca460b13070b%2Fcampo_action.png?alt=media)

1. Choose the *Token* login method in the *Login Type* field.

* **Login Type**: Defines the *Token* authentication type, whether it will be *Request Credential* or *System Configuration*.<br>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b41205d8124a33c5c3edcb5f99675528cc5169c5%2Fcampo_login_type.png?alt=media)
* Difference between Login Type *System Configuration* and *Request Credential*.

{% hint style="info" %}
When selecting **Request Credentials** as the login type, the request must **mandatory** contain the username and password with access permission to the target Host, along with the *Token*, serving as double authentication.

With the **System Configuration** option, the user can execute the configured Action only with the *Token* as authentication.
{% endhint %}

1. Check if the fields were filled in correctly and click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-64f3160e718c82d961f72fe7d3f8a7629b7272d3%2Fbotao_save_hook_bridge.png?alt=media)

## Request Parameters

* The *Token* serves to limit which *Action* will be executed and to perform authentication, but does not define on which *Host* the Action will be executed. To define the Host, the LCC provides some parameters that allow you to configure the request as needed.

{% hint style="info" %}
The request URL must contain Host and/or Hostname to define which Host the Action will be executed on. When only one of them is sent, the search will be performed using the parameter provided.

If both parameters are provided, the search will be performed using both. This means that if the *Hostname* is not associated with the *Host* parameter provided, the match will not be made, and the request will return an error informing what happened.
{% endhint %}

### Login Type *Request Configuration*

* See how to assemble a request with Login Type *Request Configuration*. **Note: Always use the & sign to join each argument.**

*Login Type Request Configuration Arguments:*

* **token:** Token that was generated in the LCC Console.<br>
* **username:** User used to log in to the Host.<br>
* **password:** Password used to log in to the Host.<br>
* **host:** IPV4 address of the host where the Action will be executed.<br>
* **hostname:** Hostname of the host where the Action will be executed.<br>

1. The request must start with the **IP Address** or **Hostname** of the Linux Control Center

* https\://**lcc\_ip\_or\_hostname**/

1. Then, insert the API endpoint */api/v2/hook\_bridge/request/action/*

* <https://lcc\\_ip\\_or\\_hostname/**api/v2/hook\\_bridge/request/action/>\*\*

1. After placing the endpoint, place the Hook Bridge **ID** with the **?** sign right after it. The ID is availableavailable in the Hook Bridge *ID* field.

* <https://lcc\\_ip\\_or\\_hostname/api/v2/hook\\_bridge/request/action/**1>?\*\*

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4023ee9051accedc02607eb44086d05e1f445196%2Fcampo_id.png?alt=media)

1. Set the IP address in the **host=** parameter and/or the **hostname=** of the Host where the action will be executed.

* <https://ip\\_or\\_hostname\\_of\\_lcc/api/v2/hook\\_bridge/request/action/1?**host=10.15.88.4>\*\*
* <https://ip\\_or\\_hostname\\_of\\_lcc/api/v2/hook\\_bridge/request/action/1?**hostname=lcc-ubuntu-22>\*\*

1. Define the authentication arguments **\&username=** and **\&password=** that will be responsible for logging into the server where the actions will be executed.

* <https://lcc-ip-or-hostname/api/v2/hook-bridge/request/action/1?host=10.15.88.&#x34;**\\&username=HOOKBRIDGE\\_USER\\&password=HOOKBRIDGE\\_NAME>\*\*

1. Define the *Token* of the request with the **\&token=** parameter

* The *Token* field is obtained from the **Token** field on the Hook Bridge screen.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4595e15bde27501f57b7ee870625a0f4545b6be9%2Fcampo_token.png?alt=media)
* <https://ip-ou-hostname-do-lcc/api/v2/hook-bridge/request/action/1?host=10.15.88.4\\&username=USUARIO\\_HOOKBRIDGE\\&password=SENHA\\_HOOKBDRIG&#x45;**\\&token=YfNa1UKBlMV7nLpa>\*\*

1. See the example of a complete *Request Configuration* request with the **curl** utility:

* Windows Terminal: **curl.exe -k "<https://ip-or-hostname-of-lcc/api/v2/hook-bridge/request/action/1?host=10.15.88.4\\&username=USUARIO\\_HOOKBRIDGE\\&password=SENHA\\_HOOKBDRIGE\\&token=YfNa1UKBlMV7nLpa>"**
* Linux Terminal: **curl -k "<https://ip-or-hostname-of-lcc/api/v2/hook-bridge/request/action/1?host=10.15.88.4\\&username=USUARIO\\_HOOKBRIDGE\\&password=SENHA\\_HOOKBDRIGE\\&token=YfNa1UKBlMV7nLpa>"**

### Login Type *System Configuration*

* See how to assemble a request with Login Type *System Configuration*. **Note: always use the & sign to join each of the arguments.**
* *Login Type System Configuration Arguments:*
* **token:** Token that was generated in the LCC Console.<br>
* **host:** IPV4 address of the host where the Action will be executed.<br>
* **hostname:** Hostname of the host where the Action will be executed.<br>

> Note that the only difference is that the Login Type *System Configuration* does not need the *username and password* arguments

1. The request must start with the **IP Address** or **Hostname** of the Linux Control Center

* https\://**lcc\_ip\_or\_hostname**/

1. Then, insert the API endpoint */api/v2/hook\_bridge/request/action/*

* <https://ip\\_or\\_hostname\\_of\\_lcc/**api/v2/hook\\_bridge/request/action/>\*\*

1. After setting the endpoint, set the value of the Hook Bridge **ID** with the **?** sign right after it. The ID is available in the Hook Bridge *ID* field.

* <https://ip\\_or\\_hostname\\_of\\_lcc/api/v2/hook\\_bridge/request/action/**1>?\*\*

1. Set the IP address in the **host=** parameter and/or the **hostname=** of the Host where the action will be executed.

* <https://lcc\\_ip\\_or\\_hostname/api/v2/hook\\_bridge/request/action/1?**host=10.15.88.4>\*\*
* <https://lcc\\_ip\\_or\\_hostname/api/v2/hook\\_bridge/request/action/1?**hostname=lcc-ubuntu-22>\*\*
* See an example of using both arguments simultaneously;
* <https://lcc\\_ip\\_or\\_hostname/api/v2/hook\\_bridge/request/action/1?**host=10.15.88.4\\&hostname=lcc-ubuntu-22>\*\*

1. Set the request *Token* with the **\&token=** parameter

* <https://lcc-ip-or-hostname/api/v2/hook-bridge/request/action/1?host=10.15.88.&#x34;**\\&token=YfNa1UKBlMV7nLpa>\*\*

1. See the example of a complete *System Configuration* request with the **CURL** utility:

* Windows Terminal: **curl.exe -k "<https://ip-or-hostname-of-lcc/api/v2/hook-bridge/request/action/1?host=10.15.88.4\\&token=YfNa1UKBlMV7nLpa>"**
* Linux Terminal: **curl -k "<https://ip-or-hostname-of-lcc/api/v2/hook-bridge/request/action/1?host=10.15.88.4\\&token=YfNa1UKBlMV7nLpa>"**

### *Custom Script* Action with Login Type *Script Configuration*

{% hint style="info" %}
When selecting the *Script Configuration* option, the login will be performed on the machine according to the settings registered in the *Credential* tab of the *Script*, without needing to inform the Username or Password parameter as the request arg. It is also possible to use the *Login Type* Request Credential.

This Action allows you to use only 1 script for each *Token*, and you can change it whenever necessary.
{% endhint %}

1. Click on **Action** and choose the **Custom Script** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8b863cd9b5a5a57beb5561cae7e224354e4fd4f5%2Faction_custom_script.png?alt=media)
2. Click on **Login Type** and choose the **Script Configuration** option

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5a9de286a627f5686935b37a8979cf97066072b7%2Flogin_type_script.png?alt=media)
3. Click on **Script** and define which script will be executed by the *Token*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-23d8f31c3d0ca25b1d1e38502a602884fc47f622%2Fscript_winrm.png?alt=media)
4. Click on **Save**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7f036e8b41290b2f19d0ec3694463fe18b439ad8%2Fbotao_save_custom_script.png?alt=media)

* *Arguments Login Type Script Configuration ration:*
* **token:** Token that was generated in the LCC Console.<br>
* **host:** IPV4 address of the host where the Action will be executed.<br>
* **hostname:** Hostname of the host where the Action will be executed.<br>

## Request Logs

### Hook Bridge Request

1. Access the Hook Bridge screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3968c8016f628e8c4d5852d59959ee777555774f%2Fhook-bridge-dashboard.png?alt=media)
2. Click on the desired Hook Bridge.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d2d59b06842f9f75cf70a4165e1f1fe6976c088a%2Fbotao_hook_requests.png?alt=media)
3. On this page, you can see the entire execution history for the selected Hook Bridge.

* Host: where the request was executed.<br>
* Status: Result of the request.<br>
* Date and Time of Creation and Last Update.<br>
* Logs: Detailed information about the result of the request.<br>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a2de228eb6b615feb7ba711a59ad6487c01ee4fd%2Fhook-bridge-request-6.png?alt=media)

The **STATUS** field contains an identifier for each step of the process, such as:

* Requested
* Queued
* Executing
* Success
* Error
* No license
* Canceled


# Workflow


# Create Workflow

## Requirements

* Linux Control Center = 2.10.X or higher

## Overview

* The Linux Control Center Workflow allows you to create workflows with decision making and chaining of actions. With an intuitive interface, it allows total control in a simple and fast way.

## Objective

* This document aims to demonstrate the step by step and demonstrate how to use the Linux Control Center Workflow.

## Workflow Steps

* See an example of how a workflow with decision making works.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f1cea985a053feb08c8cf9baa7aece50d45773ef%2Ffluxo_workflow.png?alt=media)

## Create a Workflow

1. Click on **Workflow** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f301dfe8ab8a954bc747fe46be1a9c99c65a5d78%2Fworkflow_dashboard.png?alt=media)
2. Click on **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7dc013a82c79b272a620e40863eb88613c3e143e%2Fbotao_create.png?alt=media)
3. Enter the name for the Workflow in the **Name** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0c85429a0c02587b7b7b0c8b77e38a5a276291d5%2Fcampo_name_workflow.png?alt=media)
4. Click **Start New Workflow**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a76a256c531e3dd82747715ba3f703fd06c73b81%2Fbotao_start_new_workflow.png?alt=media)
5. Choose the desired *Action* in the **Action** field

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-064d0fffd9461a9d71350b81b128e60ca50e241e%2Fcampo_action_workflow.png?alt=media)
6. Choose the **Host** on which you want to execute the action in the **Host** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e256660a7a00ba638cfd41da35810064e76302f2%2Fcampo_host_workflow.png?alt=media)
7. You can also execute the action in a group by selecting it in the **Group** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a6d6db579b7cea18673a6e167af7a95439789a44%2Fcampo_group_workflow.png?alt=media)
8. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fa98f12d3d0ec425e0706f65d51acd40e913bbeb%2Fbotao_create_workflow.png?alt=media)
9. Click **Save** to create the *Workflow*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-239f9b81dbe972555efee3ed8a5aa6e7375c85aa%2Fbotao_save_workflow.png?alt=media)

## Create Sub Action

1. Open the Workflow in which you want to add an *Action* with decision making and click **Add Subaction** for the desired action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a0eaf356ccc04de179d959339175f7c80a1dc17d%2Fadd_subaction.png?alt=media)
2. Click on **Action** and choose the *Sub Action*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8a99557e88975bcbbd12218ed01ea4fa9a00464f%2Fcampo_action_subaction.png?alt=media)
3. Choose which result will be responsible for executing the *Sub Action*.

**Always**: Executes the *Sub Action* regardless of the result of the previous *Action*.\
**Success**: Executes the *Sub Action* only in case of *Success* of the previous *Action*.\
**Error**: Executes the *Sub Action* only in case of *Error* of the previous *Action*.\
**Regex**: Executes the *Sub Action* only if the defined *Regular Expression* is the result of the previous *Action*.<br>

```
![](/pt-br/images/workflow/create_workflow/condicao.png)
```

1. Click **Create** to create the *Sub Action*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5b044b36c97f1a6e852ca4d36576fe9de59760d2%2Fbotao_cretate_subaction.png?alt=media)
2. Click **Save** to save the *Sub Action*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0797c25eaf864541287dc12725b5d05e36e89353%2Fbotao_save_subaction.png?alt=media)

## Executing the Workflow

1. Click **Workflow** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f301dfe8ab8a954bc747fe46be1a9c99c65a5d78%2Fworkflow_dashboard.png?alt=media)
2. Click **Actions** in the *Workflow* line and click **Run**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e58cbd04a55db762c2420fb0ae8a006d6cf0ea2c%2Frun_workflow.png?alt=media)
3. It is also possible to run within the *Workflow* page

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7717f481e2ed4873cac7ec2350b6c2f0251b27bd%2Frun_tela_interna.png?alt=media)
4. Click **Agree** to run the *Workflow*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f32dbf5fb87e7b42fef000798286a7591cfc3847%2Fconfirma_execucao.png?alt=media)
5. See the example of [Workflow Steps](#workflow-steps).

   ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/workflow/create_workflow/lcc_workflow_flow.png)


# Assisted Workflow

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

Assisted Workflow is ideal for delegating specific tasks to specific users. It allows a user to access only one or more workflows previously configured by the administrator, ensuring that they only have permission to perform the designated task.

## Objective

The objective of this document is to demonstrate step by step how to configure Assisted Workflow for a Console user.

## Create a Console Access User

* The first step is to create a user with limited permissions to access the LCC Console.

1. Access the LCC and click **Config** in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Users**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-91f7a03264c2d9e36828172de506071df53da18c%2Fbotao_users.png?alt=media)
3. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-de6634050d293c696689b5caaed6a551d9657ee5%2Fbotao_create.png?alt=media)
4. Fill in the fields as instructed below;

* **Username:** User to log in to the Console.<br>
* **Password:** User password.<br>
* **Confirm Password:** Field to confirm password.<br>
* **Email:** Email to receive notifications.<br>
* **First Name:** First display name.<br>
* **Last Name:** Last display name.<br>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2722777e162eeff3df811e154db2399eac885722%2Fcampos_criar_usuario.png?alt=media)

### User Permissions

1. Click **Configure Permissions**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b442ab4bc31a9cff081c6b38a1e9599843bb5c1a%2Fbotao_configure_permissions.png?alt=media)
2. Enable the following screens with *read-only* or *read and write* permissions.

**Dashboard:** Mandatory in all cases. **Host:** Mandatory in all cases.**Queue:** To track the status of the Action in the queue.**AssistedWorkflow:** Access to the Assisted Workflow screen.**WorkflowRun:** Permission to run the Workflow.

1. Click **Save** to save the permissions.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-19b8ca714c49363b4d51c15c718b6684bd9983ed%2Fbotao_save_permissoes.png?alt=media)
2. Click **Save** to create the user.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7aa5bd2a01154d7f55c69980e5016d3f9717b104%2Fbotao_salvar_conta.png?alt=media)

## Create the Workflow

1. Create the Workflow according to your needs.
2. Click **Workflow** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f301dfe8ab8a954bc747fe46be1a9c99c65a5d78%2Fworkflow_dashboard.png?alt=media)
3. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7dc013a82c79b272a620e40863eb88613c3e143e%2Fbotao_create.png?alt=media)
4. Enter a name for the Workflow in the **Name** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0c85429a0c02587b7b7b0c8b77e38a5a276291d5%2Fcampo_name_workflow.png?alt=media)
5. Click **Start New Workflow**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a76a256c531e3dd82747715ba3f703fd06c73b81%2Fbotao_start_new_workflow.png?alt=media)
6. Choose the desired *Action* in the **Action** field

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-064d0fffd9461a9d71350b81b128e60ca50e241e%2Fcampo_action_workflow.png?alt=media)
7. Choose the **Host** on which you want to execute the action in the **Host** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e256660a7a00ba638cfd41da35810064e76302f2%2Fcampo_host_workflow.png?alt=media)
8. You can also execute the action in a group, selecting it in the **Group** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a6d6db579b7cea18673a6e167af7a95439789a44%2Fcampo_group_workflow.png?alt=media)
9. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fa98f12d3d0ec425e0706f65d51acd40e913bbeb%2Fbotao_create_workflow.png?alt=media)
10. Click **Save** to create the *Workflow*.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-239f9b81dbe972555efee3ed8a5aa6e7375c85aa%2Fbotao_save_workflow.png?alt=media)

## Create Sub Action

1. Open the Workflow in which you want to add an *Action* with decision making and click **Add Subaction** for the desired action.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a0eaf356ccc04de179d959339175f7c80a1dc17d%2Fadd_subaction.png?alt=media)
2. Click **Action** and choose the *Sub Action*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8a99557e88975bcbbd12218ed01ea4fa9a00464f%2Fcampo_action_subaction.png?alt=media)
3. Choose which result will be responsible for executing the *Sub Action*.

* **Always**: Executes the *Sub Action* regardless of the result of the previous *Action*.<br>
* **Success**: Executes the *Sub Action* only in case of *Success* of the previous *Action*.<br>
* **Error**: Executes the *Sub Action* only in case of *Error* of the previous *Action*.<br>
* **Regex**: Executes the *Sub Action* only if the defined *Regular Expression* is the result of the previous *Action*.<br>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b6fb57433a1cf5bdd77a9b483fada9d9b4881126%2Fcondicao.png?alt=media)

1. Click **Create** to create the *Sub Action*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5b044b36c97f1a6e852ca4d36576fe9de59760d2%2Fbotao_cretate_subaction.png?alt=media)
2. Click **Save** to save the *Sub Action*

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0797c25eaf864541287dc12725b5d05e36e89353%2Fbotao_save_subaction.png?alt=media)

## Create the Assisted Workflow

* With the User and the Workflow created, now is the final step to create the Assisted Workflow

1. Access the **Assisted Workflow** screen in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-abc3ce47a5d1f885e2bed548102c5400e77aa855%2Fbotao_assisted_workflow_menu.png?alt=media)
2. Click **Create**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2c9044a638628fc605f069a6215a282e3bd7a4%2Fbotao_create_assisted_workflow.png?alt=media)
3. Enter a name to identify the Assisted Workflow in **Name** and choose which Workflow will be executed in the **Workflow** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-eeb047917578a33991540e88fe1425930edaa599%2Fpreenchendo_assisted_workflow.png?alt=media)
4. Define which l Console user or which Console User Group will have access to this Assisted Workflow.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d63e73ae2683993fd1b15995313d09baea7373cf%2Fmover_usuario.png?alt=media)
5. Click **Save** to create the Assisted Workflow.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-814693f62d97c24092ccea1eba6f4648501a2e4b%2Fbotao_save_assisted_workflow.png?alt=media)

## Running the Assisted Workflow

1. To run the Assisted Workflow, access the LCC with the user it was created as.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2f03e056cc0a980274628d45f415baa57bde0299%2Flogin_support.png?alt=media)
2. Access the **Assisted Workflow** screen in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-abc3ce47a5d1f885e2bed548102c5400e77aa855%2Fbotao_assisted_workflow_menu.png?alt=media)
3. Click on **Actions** of the desired Assisted Workflow and click on **Run**. This will execute the pre-configured workflow.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-902fa35c16b968979f52d531c97bde32620c69e9%2Fexecucao_assisted_workflow.png?alt=media)


# Scheduler

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

* The Schedule feature in the Linux Control Center platform provides a robust time automation capability. This feature allows you to schedule precise operations for individual Hosts, Host Groups or Workflow execution.
* The scheduling options cover all LCC *Actions* for single or recurring events, providing flexibility in the scheduling format.

## Objective

This document aims to demonstrate the step-by-step process for creating a schedule in Linux Control Center.

## Create a Schedule

1. Access the **Schedule** screen in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cd8c4094e9e6334102d4aca4b7b0b48b49a764f8%2Ftela_schedule_dashboard.png?alt=media)

1. Click **Create**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-08996b67fef5fd0cacbe924fd108733288778e16%2Fbotao_create.png?alt=media)

1. Fill in the **Name** field to identify the schedule.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ba437ca07e080151e837a6188fee09aa2aee0f2c%2Fcampo_name.png?alt=media)

## Action Selection

1. The first step is to select which **Action** will be executed in the schedule.

{% hint style="info" %}
Only one action can be executed per schedule, and only one of the three options among *Host/Host Group, Discover, Workflow, Reports* can be selected at a time.

If it is necessary to execute more than one action in a single schedule, you must create a *Workflow* flow and schedule its execution for the desired time.
{% endhint %}

### Hosts / Host Groups

1. Check the first option to run an LCC *Action* on a Host or Host Group.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e4b40223771f8ca5c7f5c0a3921b12a0b73bee10%2Faction_hosts_group.png?alt=media)

1. At least 1 **Host** or a **Host Group** must be selected.
2. It is also possible to run on an individual Host or Host Group simultaneously.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f54fb905d3794b0b23e9e9be707b8035d8f0f419%2Fgrupo_hosts_selecionados.png?alt=media)

1. Choose the **Action** you want to run on the schedule.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d23acf30537d3749100dfdc5d2fc8d24f17cdbc8%2Fcampo_actions_hosts.png?alt=media)

### Discover

1. Check the **Discover** option if you want to schedule the execution of a pre-configured **Discover**. This schedule allows you to run only 1 Discover.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ea9dcf7a1838e4119ffe9698db43ed732c328b10%2Fdiscover_run.png?alt=media)

### Workflow

1. Click **Workflow** to schedule the execution of a pre-configured **Workflow**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8f33c11c1d144d928072a381bc919b8c2645226b%2Fworkflow_run.png?alt=media)

### Reports

1. Click **Reports** to choose which pre-configured Report will be created in the schedule.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/schedule/create_schedule)

## Schedule Type

* This step defines how many times and at what time the schedule will be executed.

### Once

* With this type of schedule, the *Action* will be executed only once and the schedule will remain saved in the LCC Console.

1. Check the **One Time** option to execute only once.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c79428d4ab39694e61f830cf0deb39c1c7e23c0a%2Fcaixa_one_type.png?alt=media)

1. Enter the **Time** you want to execute in the **Hour** field. (24-hour format)
2. Enter the **Minute** you want to execute in the **Minute** field. (0 to 59)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7534cdc7adcd7d2654c44f340f3a0e92828f739d%2Fhora_minuto_one_type.png?alt=media)

1. Enter the day of the **Month** on which you want to execute the action in the **Date** field.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0893b972ef119ce610e9607b0e08928c4852c795%2Fselect_date_one_time.png?alt=media)

### Repeatedly

* The *Repeatedly* scheduling type allows execution according to the 3 options below;

#### Every Minute

1. Check the **Minute** box and enter how many minutes the *Action* will be executed. This way, the action will be executed every X minutes defined. (1 to 59)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a266c1a1a53401ec357ac64aba085f0f3e8f357f%2Fevery_minute.png?alt=media)

#### Daily

* This type of schedule executes the *Action* only once a day, at the configured time.

1. Enter the *Hour* of the day you want to execute the *Action* in the **Hour** field. (24-Hour Format)
2. Enter the *Minute* of the hour you want to execute the *Action* in the **Minutes** field. (0 to 59)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e91523732eb099d4eec82bf8488423c18392d9db%2Frepetidamente_daily.png?alt=media)

#### Advanced

{% hint style="info" %}

* If you want the *Action* to be executed daily, just leave the **Day of Week** field blank(\*)

* If you want the *Action* to be executed monthly, just leave the **Month** field blank(\*)
  {% endhint %}

* This type of scheduling allows the action to be executed every *Day of the Week*, *Day of the Month* or every *Month*.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b4f41bc1da4b47d9f6edd117a54f00487255eb46%2Fbotao_advanced.png?alt=media)

1. Select the day of the week on which the *Action* will always be executed in the **Day of Week** field.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2d1b214e5168fb321ad49cb0bfe979dca65d8dbe%2Fdia_semana.png?alt=media)

1. Select the day of the month on which the *Action* will always be executed in the **Day of Month** field.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-00a4347b22984bbe91b94c1a1ec66f87498264c7%2Fdia_mes.png?alt=media)

1. Select the month on which the *Action* will always be executed in the **Month** field.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1598dfd95cc12a3c4547d9c38ac155794dd5120c%2Fmes_ano.png?alt=media)

## Save and Enable or Disable Schedule

1. Click **Save** to create the schedule.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-00dbff9581cc2f77281f8ebe89465c8b20178770%2Fbotao_save.png?alt=media)

1. The screen of created schedules displays some information;

**Enabled/Disable**: Indicates whether the schedule is enabled or disabled.\
**Repeat**: Indicates that the schedule will occur periodically according to the date entered.\
**Last Run at**: Date of the last execution of the schedule.\
**Created at**: Date of creation of the schedule.\
**Updated at**: Date of the last change to the schedule.<br>

1. Click on the created schedule.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/schedule/create_schedule)

1. The **Enable Schedule** field allows you to Enable and/or Disable the Schedule. When Enabling, the schedule will be executed automatically according to the configuration.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/schedule/create_schedule)

1. It is also possible to *Delete* a schedule permanently by clicking the **Delete** button.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/schedule/create_schedule)


# Unmanaged Hosts


# Microsoft Windows

## Requirements

* Linux Control Center = 2.10.X or higher.<br>
* Access Credentials to the Windows Host with the necessary permissions.<br>
* WinRM Enabled on the Windows Host.<br>

## Overview

The Linux Control Center **Unmanaged Hosts** functionality allows the execution of Scripts on Microsoft Windows Hosts through WinRM (Windows Remote Management) on Hosts that are not being managed by the LCC.

This functionality uses Windows Credentials, Unmanaged Hosts and Unmanaged Host Groups registered in the Console. The LCC offers a history of executions through simplified Logs.

* Configuration flow to execute Scripts on an Unmanaged Microsoft Windows Host.

1. [Unmanaged Host Windows Registration](#unmanaged-host-windows-registration)
2. [Windows Credential Registration](#windows-credential-registration)
3. [PowerShell Script Registration](#powershell-script-registration)
4. [Script Execution with Workflow](#executing-a-powershell-script-on-unmanaged-windows-hosts)

## Objective

This document aims to demonstrate step by step how to register an *Unmanaged Host*, *Unmanaged Windows Credentials* and *PowerShell Script* to execute the *Custom Scripts Quick Windows* Action.

### Unmanaged Host Windows Registration

1. Access the LCC and click on **Unmanaged Hosts**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-52ecdda62a02517f789a5ffe434f65a9cf58af91%2Fbotao_unmanaged_hosts_dashboard.png?alt=media)
2. Click **Unmanaged Inventory**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a2ec79058accde1068d23207cc8511691af7ee42%2Fbotao_unmanaged_inventory.png?alt=media)
3. Click **Create** and fill in the following fields;

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9d756fbcdd60b82cc5385f4e5f98260c9ff23fdd%2Fbotao_create_unmanaged_host.png?alt=media)

**Name**: Name to identify the Host.\
**Host Type**: Select the *Windows* option.\
**Address**: Enter the Windows Host IP address with dots. Ex: 192.168.0.25\
**Port**: Enter the Host's WinRM port<br>

1. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fc05a002af280511b946454d9f704d43e42ca5ad%2Fbotao_save_unmanaged_host.png?alt=media)

### Windows Credential Registration

* This credential will be responsible for accessing the Host and executing the desired *Script*.

1. Access the **Unmanaged Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-52ecdda62a02517f789a5ffe434f65a9cf58af91%2Fbotao_unmanaged_hosts_dashboard.png?alt=media)
2. Click **Host Credentials**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-15029dbf13441d53f31a8800051fccca22842474%2Fbotao_hosts_credentials.png?alt=media)
3. Click **Windows Credentials**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1734297e1e41d34f8586c3925f47c9fb2119dc17%2Fbotao_windows_credentials.png?alt=media)
4. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-72c4daa530f19ffeaec6f4e2a3a8baed2f1c5c62%2Fbotao_create_unmanaged_credentials.png?alt=media)
5. Fill in the requested fields and click **Save**.

**Name**: Name to identify the credential\
**Username**: User to run the Script\
**Password**: User password to run the Script<br>

```
![](/pt-br/images/unmanaged_hosts/windows/create_windows/botao_save_credential.png)
```

### PowerShell Script Registration

1. Access the **Unmanaged Hosts** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-52ecdda62a02517f789a5ffe434f65a9cf58af91%2Fbotao_unmanaged_hosts_dashboard.png?alt=media)
2. Click on **Scripts**.

* This screen is the same as the Hosts screen on the left side menu, where all the scripts registered in LCC are located, both for Windows and Linux.

1. Click on **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f4580c2a230931fa62c0952f325fc144433d7b09%2Fbotao_create_script.png?alt=media)
2. Fill in the following fields;

**Name**: Name to identify the Script.\
**Host Type**: Select the *Windows* option.<br>

```
![](/pt-br/images/unmanaged_hosts/windows/create_windows/campos_script_type_e_name.png)
```

1. Click on **Upload File** and upload the Windows Script.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6fbc129cc8bb7ca93f19b61a583e37709fbc5c26%2Fscript_uploaded.png?alt=media)
2. Click on **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-108f5020ec1928ede52affee1eb528ea48ace29f%2Fbotao_save_script.png?alt=media)

### Executing a PowerShell Script on Unmanaged Windows Hosts

1. Click on **Workflow** on the left sidebar.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f301dfe8ab8a954bc747fe46be1a9c99c65a5d78%2Fworkflow_dashboard.png?alt=media)
2. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7dc013a82c79b272a620e40863eb88613c3e143e%2Fbotao_create.png?alt=media)
3. Enter a name for the Workflow in the **Name** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0c85429a0c02587b7b7b0c8b77e38a5a276291d5%2Fcampo_name_workflow.png?alt=media)
4. Click **Start New Workflow**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a76a256c531e3dd82747715ba3f703fd06c73b81%2Fbotao_start_new_workflow.png?alt=media)
5. Choose the **Custom Script Quick Windows** *Action* in the *Action* field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-35e852755a80cd7eea6104501ff982e66407aab5%2Facao_quick_windows.png?alt=media)
6. Fill in the fields as instructed below;

* **Script**: Choose the PowerShell Script that will be executed.<br>
* **Unmanaged Host**: Choose the Unmanaged Host Windows on which the Script will be executed.<br>
* It is also possible to execute the Script in an *Unmanaged Group*.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fc350d521107b9ca09b052655cf68ce2bcdf8d3d%2Fcampos_workflow_preenchido.png?alt=media)

1. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d4d89d0d9873f85cf87cd643ec233038aff41fa7%2Fbotao_create_workflow.png?alt=media)
2. Click **Save**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8be0968d32518d9a2be287dca56afbe30f68fca2%2Fbotao_save_workflow.png?alt=media)
3. Click **Actions** of the *Workflow* you created and click **Run**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-376c5d0b9fdefa0b574d1e236021bb4c233d48ed%2Frun_workflow.png?alt=media)
4. Click **Agree** to run the *Workflow*.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a1eedeeee24e2b416cd8092367bbe4266c763668%2Fagree_run_workflow.png?alt=media)


# Settings and Integrations


# Settings


# License

## Requirements

Linux Control Center = 2.11.X or higher

## Overview

Linux Control Center offers both Community and Enterprise licenses.

## Objective

The purpose of this document is to show you how to find out the version of the Linux Control Center license and how many hosts can be managed with the current license installed in your environment.

## Current License

Follow the steps below to find out which license is installed in Linux Control Center in your environment.

1. Access the Linux Control Center and click on **Config**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-06f2138d5b4b59568c3fe68d9a8da7add8675bad%2Fconfig_license.png?alt=media)
2. Click on **License**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a3b0d6cbf2c18c99077b8f54a095c80c3b5a56f4%2Fbotao_license.png?alt=media)
3. On this screen you can see the following information:

**Hosts:** Maximum number of Hosts that the current license can manage\
**License Type:** License type\
**End Date:** License expiration date\
**Info**: Field to add notes

1. You can validate the license status by clicking on the **Verify** button

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b82a401a4cb16f6dce11c2cdb857cda8ff99730b%2Ftela_licenca.png?alt=media)
2. The **Hosts** tab shows all hosts that are being managed by the Linux Control Center

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-95d8372a6ea0e23ca2fd7ae22a7b3ebec20a8bf8%2Fhosts_license.png?alt=media)
3. The **Unmanaged Hosts** tab shows all hosts that have been registered in the **Unmanaged Inventory**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5769d11e9bb43303d66314a23885600bbf7c2056%2Funmanaged_hosts_license.png?alt=media)


# Worker

The Worker service plays a fundamental role in the system. He is responsible for carrying out the actions requested by Console users. Here's an overview of how it works:

**Data Reception:** When a user interacts with the Console and generates actions, the Console packages all the data necessary to execute the action. This data is then sent to the Worker.

**Action Processing:** The Worker captures the data sent by the Console and performs the actions as requested. This may involve calculation processes, access to external resources, or any other task necessary to complete the action.

**Sending Results:** After completing the action, the Worker sends the return data to the Console. This feedback data may include results, status information, or any other relevant information.

**Key Features:**

* **Parallel Processing:** The Worker is capable of handling multiple action requests simultaneously, ensuring efficiency and scalability.
* **Integrity Check:** You can regularly check the integrity of the communication to ensure it is operating correctly. This is indicated in the Console through the "Ping At" column.
* **Activity Tracking:** The Console can monitor the number of actions in progress on the Worker, which is reflected in the "Threads" column.
* **Bidirectional Communication:** Communication between the Console and the Worker is bidirectional, allowing the Console to provide input and receive results.

**Multiple Workers Registration:**

Within the **Linux Control Center**, it is possible to register multiple Workers that can run on different networks or regions.

### Requirements

#### Hardware

For each set of 5 threads it is necessary:

* **2 CPUs**
* **4 GB RAM**

#### Firewall

The following connection must be allowed:

* **Host Worker** -> **Host Console Linux Control Center** on **Porta 443** (HTTPS)

### Configuring the Worker

To get the Worker ID, run the following command:

```bash
/opt/lcc-shell/bin/lcc_worker_show_uuid.sh
```

To activate a Worker:

1. Access the **Linux Control Center** through your browser.
2. In the side menu, go to **Config** and select **Worker**.

   ![Menu Worker](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/en/worker/images/config/config-menu.png)
3. Click **Actions** and choose **Trust** to authorize the Worker.

   ![Ativando Worker](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/en/worker/images/worker/workers-actions.png)
4. The *Status* should change from **Pending** to **Accepted**.

   ![Status do Worker](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/en/worker/images/worker/workers-status.png)

> Once authorized, the **Linux Control Center** console will test communication between itself and the **Worker**.

5. To check the communication status, access the side menu again and select the **Logs** option, then click on **Queue**.

   ![Queues](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a5173409bbb20a15b6cf0282d18ab8b66da95d75%2Flogs-01.png?alt=media)
6. When viewing the Queue select **LOGS** to read the response

   ![Log da ação](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/en/worker/images/queue/queue-logs.png)

> This log will indicate that **Linux Control Center** is ready to be used.

{% hint style="warning" %}
If there is a problem with the execution of the queue during the operation of the Worker *Linux Control Center*, it is possible to reinstall the Worker by executing the script *lcc\_worker\_install\_upgrade.sh* located on the machine hosting the *Linux Control Center* by the way */opt/lcc-shell/bin/lcc\_worker\_install\_upgrade.sh*
{% endhint %}


# Nodes

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

The Linux Control Center allows installation in Cluster mode. This screen allows you to find out how many validated nodes are part of the Cluster.

## Objective

The purpose of this document is to identify which nodes are in the LCC Cluster.

## Cluster Nodes

1. Click on **Config** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click on **Nodes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-79cd6cc8b950136a99278aedddae4402c2c8aaa8%2Fconfig_nodes.png?alt=media)
3. This screen will list all the Cluster Nodes currently installed in your environment.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cb858d5037f545295c6f2b07a0ec853c2eea22fa%2Fnodes_listados.png?alt=media)


# Certificate

## Version:

* Linux Control Center = 2.10.X or higher

## Requirement

* SSL/TLS certificate issued by a trusted Certificate Authority (CA).
* Example of a certificate with a valid certificate chain:

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2315bf27f6f95d2d2a17a094c1a8630afe774b88%2Fcertificado_exemplo.png?alt=media)

{% hint style="warning" %}
If the certificate has a password, the encryption must be RSA.
{% endhint %}

## Overview

* This manual contains step-by-step instructions for installing an SSL/TLS certificate in the LCC Console.

## Certificate installation

1. Click **Config** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Certificate**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7b6e5794b0b4f08821c77a40836df6b1186976d4%2Fbotao_certificate.png?alt=media)
3. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-75a793ddcd4d6daa19540e5064be30f88b1e28df%2Fbotao_create.png?alt=media)
4. Fill in the information;

**Name**: Descriptive name for the certificate.\
Certificate password in the **Password** field (not required).\
Certificate in the **Certificate** field.\
Certificate chain in the **Chain** field.\
Certificate key in the **Key** field.<br>

* Click **Save**

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-688a3fad480d64221796884c6b1ae206ed380d77%2Fadd_certificate.png?alt=media)

1. After saving the certificate information, click the **Active** option to enable the certificate.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-08589058faab92020609914d173096ad073595d2%2Factive_certificate.png?alt=media)

## Restart Web Console

* To finish installing the certificate, you need to restart the Web Console.

1. In the side menu on the left, click on **Config > Management.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7957ea15fcd75e52cb3615e4b66f06250758edaa%2Fcertificate.png?alt=media)
2. Click on the arrow in the **Actions** line.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-27cd739aaeaa6cfe3e58796663b232b9cc334794%2Factions_restart_web.png?alt=media)
3. Choose the **Restart Console** option
4. Click on **Save** and confirm the action by clicking on **YES**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8b9bc821f1561db4b9a38041f94adc8a0b8ac2fe%2Frestart_console.png?alt=media)

{% hint style="warning" %}
The console will be unavailable for a few seconds and after restarting, it will return with the certificate active.
{% endhint %}


# LCC Management

## Requirements

* Linux Control Center = 2.10.X or higher

## Overview

* The Management screen allows you to manage the LCC modules to perform maintenance and updates.

## Objective

* This document aims to demonstrate how to use the actions to manage the LCC

  <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Before executing the actions, ensure access to the Host where the LCC is installed. This will allow you to perform corrections in case of unexpected errors.</p></div>

## Management LCC

1. Access the **Config** screen

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f0067e0eeada9fb7160633825211a7dc48fd99d0%2Fbotao_config.png?alt=media)
2. Click on **Management**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e46ad440c880be6cd97050d7cf241624f6ac9cad%2Fbotao_management.png?alt=media)
3. Choose the action you want to perform.

* **Restart Console**\
  Restarts the Container Console
* **Shutdown Console**\
  Shuts down the Container Console
* **Restart Worker**\
  Restarts the Container Worker
* **Shutdown Worker**\
  Shuts down the Container Worker
* **Recreate Worker**\
  Deletes, downloads and reinstalls the Container Worker
* **Restart Alert Report**\
  : Restarts the Container
* **Shutdown Alert Report**\
  Shuts down the Container

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3ae33a1aef1a19a9a1fb45504284426b4b0aab29%2Fbotao_action.png?alt=media)

1. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a040aaf8ef4aa40b5dcb7ecda801541fa034bb18%2Fbotao_save.png?alt=media)
2. Confirm by clicking **Agree** and wait for the action to finish.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5822dcf8165608c02da661d58705f8da7f3e1695%2Fconfirma_acao.png?alt=media)


# Diagnostic

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center needs to maintain a connection with some external components to work properly. Therefore, the *Diagnostics* tool was created to validate the communication status of the Console with these components.

## Objective

This document aims to demonstrate how to test the communication of the Console with the Worker, Vulnerability API and the LCC Customer Portal Server.

## Communication Test

1. Click on **Config** in the left side menu of the LCC

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click on **Diagnostics**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ba87bf77fd859991dcd5dc35044b1426d76685af%2Fbotao_diagnostico.png?alt=media)
3. Click on **Test**.

* This action will test the connection of the LCC Console with the listed components. The Status column will display a red **X** if communication fails.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6feeab6da75fe8a86533c41c4d37a2f81d01b07d%2Fbotao_teste.png?alt=media)


# Linux Credentials

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center uses credentials saved in the Console to perform various tasks. These credentials can be managed on this screen.

This screen only lists credentials for Linux servers.

Microsoft Windows credentials are managed in this manual: <https://docs.linuxcontrolcenter.com.br/unmanaged_hosts/create_windows#cadastro-de-credencial-windows>

## Objective

The objective of this document is to demonstrate how to manage Linux credentials in the LCC console.

## Create Linux Credentials in the Console

### Basic Credential Information

1. Click **Config** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click **Credential**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4516e01ce584e35c45d08049250c48f31beb3fa2%2Fbotao_credential_config.png?alt=media)
3. If a *Discover* was run with a local credential, it will be listed on this page. You can also create a new credential by clicking **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7c05bbdb480a0b5f22542f08a1b29db52616125c%2Fcreate_credential.png?alt=media)

**Name:** Name to identify the credential.\
**Auth Type:** Choose the SSH authentication method, **Password** or **KEY**.\
**Username:** User to authenticate to the SSH of the Hosts.\
**Password:** User password for authentication.\
**Privilege Escalation:** Choose the privilege escalation method according to the credential permission.\
**Privilege Escalation Username**: User to escalate privilege, with rights to create accounts and edit Sudoers files, if necessary.\
**Privilege Escalation Password**: Password for the privileged user, if necessary.

### Privilege Escalation

```
![](/pt-br/images/configurations/credenciais/campos_para_preencher.png)
```

* It is essential to understand the privilege escalation step to enter the credentials correctly, since this step is very important during Discover, it is necessary to configure it correctly. See a summary of how each type of privilege escalation works.

**sudo without password**

* With this privilege escalation method, the user registered in the **Username** field must have permission to escalate directly to the root user, and it is necessary to fill in only the **Username** password in the **Password** field.

**sudo with password**

* With this privilege escalation method, the user registered in the **Username** field must also have permission to escalate privilege, however, in addition to the login user's password, it is also necessary to enter the privileged user's password in the **Privilege Escalation Password** field to escalate the privilege.

**None**

* Option used when the SSH connection credential also has sufficient permissions to create a local account and configure its SSH key (option generally used with the root user).

**su -**

* After logging in with the first user provided (username), switch directly to the privileged credential in **Privilege Escalation Username** with the password in **Privilege Escalation Password**.

### Save and Create Account

1. Click the **Save** button to create the credential in the Console

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-037cf20200638df29ff7505544f89f1be84ed761%2Fbotao_save.png?alt=media)

## Delete Credential from the Console

* Follow the steps below to delete the credential for accessing the Console servers.

1. Click on the desired Credential.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d24c44662a9ac932b66255634a17f07dad548b56%2Fcredencial_salva.png?alt=media)
2. Click the **Delete** button.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b6771a7de99c7e48966b8f85b108aace97745dd3%2Fbotao_delete.png?alt=media)
3. Confirm the deletion by clicking **Agree.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-24ac2e332ed4eb95e923bed1248298833a8ca62c%2Fconfirmacao_delete.png?alt=media)


# Regions

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

Linux Control Center allows installation in Cluster mode. This screen allows the creation of Regions, where Worker modules can be assigned. With this, it is possible to execute Actions in different Regions, ensuring more performance and centralized management through a single Console.

## Objective

This document aims to demonstrate how to create a Region for a Worker.

## Create Region for a Worker

1. Click on **Config** in the left side menu of the LCC

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click on **Regions**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-62b630b8195396e0c92e57b89f10877a1d43c67a%2Fconfig_generico.png?alt=media)
3. Click **Create.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-69dd499cb3eea98a243656cc73ae3b16d80183de%2Fregioes_worker.png?alt=media)
4. Enter a **Name** to identify the region and click **Save.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-db909c4d31a77964f57826f76c6aa559aca89269%2Fnome_save.png?alt=media)


# Syncronized Files

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

The Linux Control Center allows you to upload files to the Console, allowing you to manage files on your servers. To avoid version errors and conflicts, the LCC automatically manages and synchronizes these files in its database. The **Synchronized Files** screen displays the list of these files.

## Objective

This document aims to demonstrate the **Synchronized Files** in the LCC Console.

## Synchronized Files.

1. Click on **Config** in the LCC left side menu

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click on **Synchronized Files**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e69dcfa7da99b2a3741b668608916c6993f62854%2Fbotao_sincronized_files.png?alt=media)
3. The Synchronized Files in the Console will be listed.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dbdf8dc09a909e3280581c5e683e2e5f85e4619b%2Farquivos_sincronizados_listados.png?alt=media)


# Notifications


# SMTP


# Teams

## Requirements

Linux Control Center = 2.13.X or higher

## Overview

Linux Control Center has notification functionality that sends instant updates about actions performed on Linux Hosts directly to your Teams channels.

## Objective

The objective of this document is to demonstrate how to configure notification alerts via Teams.

## Registering Notifications via Teams

1. Access the LCC **Config** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Notifications**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6c6d4acf91f2b182e8417faae93194a471d2d25f%2Fbotao_notificacoes.png?alt=media)
3. Click **Teams.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2afe6678c2e98d124b99d1e1cb7c3a9defcc5628%2Ftela_notificacoes_config.png?alt=media)
4. Click **Create.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d58ac4e6d884d875b1b7fbc91c7d2b8e6e250a99%2Fbotao_create.png?alt=media)
5. Enter the **Name** and **URL.** in the respective fields.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-29b104852e3ca2206aa6a74d6f02f6ff1349aac2%2Fcampos_name_url.png?alt=media)
6. Click **Save.**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9cf54de7c6fa2598e30c981eab31d2e30bbdf7dd%2Fbotao_save.png?alt=media)

1. Click on the integration in which it was created.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4437d65d784c00bb6d90dc035e9bd242c0160fbc%2Fintegracao_criada.png?alt=media)
2. Click on **Actions.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-71b63385338e5dbed8e95e5e6b2effefc39f04e3%2Factions_aba.png?alt=media)
3. Select the *Actions* in which you want to be notified in case of success, failure or both.
4. Click **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fce3280bad11d9ea8739e633c147136048d5ce7b%2Fbotao_save_actions.png?alt=media)

* Notifications will be sent automatically as actions are performed.


# Telegram

## Requirements

Linux Control Center = 2.13.X or higher

## Overview

Linux Control Center has notification functionality that sends instant updates about actions performed on Linux Hosts directly to your Teams channels.

## Objective

The objective of this document is to demonstrate how to configure notification alerts via Teams.

## Registering Notifications via Telegram

1. Access the LCC **Config** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Notifications**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6c6d4acf91f2b182e8417faae93194a471d2d25f%2Fbotao_notificacoes.png?alt=media)
3. Click **Telegram.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f6d28574ec1fe074602bc0556d92fe5dcce05882%2Fbotao_telegram.png?alt=media)
4. Click **Create.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5e83f768c6e220e8028bfc75c4e21f36e7e1afe4%2Fbotao_create_telegram.png?alt=media)
5. Enter the **Name**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bef62fb3d9ef3d42ad23f907f501d0aee9b7fa80%2Fbotao_save_name.png?alt=media)
6. Click on the integration in which it was created.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bd65036447d95f5e587932e5697503c2695b4927%2Fintegracao_criada.png?alt=media)
7. Click on **Actions.**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4f7ba7e3aabe5af70c42ab7a5fea79cf7ba00c59%2Factions_aba.png?alt=media)
8. Enter the *Token* in the respective field and click on **Save**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a5760af6ed8093b712084e4f77c5b40341bfc88b%2Fcampo_token.png?alt=media)
9. Select the *Actions* in which you want to be notified in case of success, failure or both.
10. Click on **Save**.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a62bc6b122be3b5484f51f13d00b012f86d60a28%2Fbotao_save_actions.png?alt=media)

* Notifications will be sent automatically as the actions are executed.


# Parameters

## Requirements

Linux Control Center = 2.11.X or higher

## Overview

Linux Control Center offers several configuration options to adjust the acceptable response time of all Actions. The parameterizations allow you to adapt the LCC to the specific response time of your environment.

## Objective

This document aims to show the default values ​​of all LCC Parameters.

## Heartbeat

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d4b6c2e3e02a952d85488fef8b2f318716ed107b%2Fheartbeat.png?alt=media)

## Ansible

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-87573154b07cc68cf2a8734188c4b9161fb6c43e%2Fansible.png?alt=media)

## Execution

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-599faf4e4dcaaf3edfedf178639e1f9bcbeaf72c%2Fexecution1.png?alt=media)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2f94f63c75fe3df4767767ee40435ed0879abe51%2Fexecution2.png?alt=media)

## SSH

**Host Key Algorithms**<br>

```
ssh-rsa,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519
```

**Ciphers**<br>

```
3des-cbc,aes128-cbc,aes192-cbc,aes256-cbc,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com
```

**Kex Algorithms**<br>

```
diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman- group-exchange-sha1,diffie-hellman-group-exchange-sha256,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,curve25519-sha256,curve25519-sha256@libssh.org
```

**MACS**<br>

```
hmac- sha1,hmac-sha1-96,hmac-sha2-256,hmac-sha2-512,hmac-md5,hmac-md5-96,umac-64@openssh.com,umac-128@openssh.com,hmac-sha1-etm@openssh.com,hmac-sha1-96-etm@openssh.com ,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,umac-64-etm@openssh.com,umac-128-etm@openssh.com
```

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cc661454650bcda97696d26a3feae08b3be183ea%2FSSH.png?alt=media)

## Discover

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dd88028e5427473d990f726423c24a4848b95c67%2Fdiscover.png?alt=media)

## General

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9ee1b44af18d39346f270302d94c0f1f172ab1a2%2Fgeneral.png?alt=media)

## Log

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8f524f9addea26bef933b1a8f7e247e6ca516d9a%2Flog.png?alt=media)


# Discover Timeout

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

The Linux Control Center (LCC) Discover runs in 5 steps, each with a predefined timeout. Since different environments may have different response times, these settings ensure that Discover runs as quickly as needed.

## Purpose

This document aims to explain how to change the LCC Discover Timeout values.

## Discover Timeout

1. Click on **Config** in the left side menu of the LCC

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
2. Click on **Parameters**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-825b81ca437236f43fec5d1d645eaf523e699658%2Fparameters.png?alt=media)
3. Click on **Discover**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-06ce4c357ee55213ed6e00a4d8e18ea571b5302b%2Fdiscover_parameters.png?alt=media)
4. Adjust the times according to your needs;

**Minimal Timeout:** Minimum timeout for all import steps for each host found\
**Ping Timeout:** Maximum response time for Discover's **Ping**.\
**SSH Timeout:** Maximum time to connect to the Host via SSH.\
**SSH Port Timeout:** Maximum response time to obtain the SSH banner on the defined port or with the Search SSH Port option enabled.\
**Credential Timeout**: Maximum time to validate the credential via SSH connection.\
**Impot Timeout:** Maximum time for the import step for each Host found and with validated credentials.\
**PAM timeout:**: Maximum time to import a host via integration with BeyondTrust products.\
**Cache Lock Time:** Time to set the Cache Lock.\
**Linux TTL Min:** Lowest value for the TTL (Time To Live).\
**Linux TTL Max:** Highest value for TTL (Time To Live).<br>

{% hint style="warning" %}
The default values ​​are as shown in the images below.
{% endhint %}

1. Click **Save** after setting new values.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e3f856cd48bd70408a84577ff9b8c3cc9418ee93%2Fcampos_timeout.png?alt=media)


# Backup and Restore

## Version

* Linux Control Center = 2.10.X or higher

## Requirements

* SSH access to the LCC Host with root user

## Overview

* This guide provides information and step-by-step instructions for backing up and restoring the LCC

## Objective

* Demonstrate the complete backup and restore process of the LCC through the CLI interface.

## Default Backup Directory

{% hint style="warning" %}
We strongly recommend that the generated backups be copied to a safe location, ensuring data preservation in case any intervention is necessary in the future.

**Backup destination directory:** `/opt/lcc/bkp/`

The configuration backup files will have a name in the format `backup_config_YYYY-MM-DD_HH-MM-SS.tar.gz`, indicating the year, month, day, hour, minute and seconds in which the backup was created. These files contain the settings required for LCC to work.

The database backup file will be named in the format `lcc_db_YYYY-MM-DD_HH-MM-SS.sql`, following the same pattern. This file stores the entire database, allowing complete recovery of the stored information.
{% endhint %}

## Stopping Containers

1. Before performing the backup, it is necessary to stop the LCC Container processes separately for greater data integrity.
2. **Container lcc\_console**\
   Command: `docker stop lcc_console`
3. **Container lcc\_worker**\
   Command: `docker stop lcc_worker`
4. **Container lcc\_alert\_report**\
   Command: `docker stop lcc_alert_report`
5. See the example in the image below:

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b7be5759f135dddd85765b413756c7ae8fae865d%2Fparando_container.png?alt=media)

### Backup Configuration Files

1. This command backs up all files with the `.yml` extension that were generated during installation. These files are essential for LCC to work.

Command: `lcc-cli backup -a`

1. The backup will be compressed in the tar.gz extension

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-eada7c681807b977fbcb6a998a4caa3c47e23876%2Fbackup.png?alt=media)

{% hint style="warning" %}
The LCC database is encrypted, and within this compressed backup there will be a file called `crypt.yml`, which is the key to decrypt during the restore.

Without this key, it will be impossible to restore the database.
{% endhint %}

### Database Backup

1. To back up the LCC database, run the command below;

Command: `lcc-cli database --backup`

1. The backup will have the .sql extension with the date and time the backup creation command was executed.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-17d7b3732a68f7c3ac1e0707cd1dbdd0a082c7b1%2Fbackup_database.png?alt=media)

### Restoring Backup

1. To restore the LCC, you must extract all [Configuration Files](#backup-of-configuration-files) to the system root directory `/` with the root user

Command: `tar -xzvf file_name.tar.gz -C /`

```
![](/pt-br/images/backup_and_restore/extracting_config.png)
```

1. After extracting the files, run the command to restore the LCC from the `.sql` file created in the [Database Backup](#database-backup) step.

Command: `lcc-cli database --restore file_name.sql`

1. Check if you are using the correct backup and confirm by typing **y** and pressing **enter**

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8958307ff8a0070a7e177c06a004f1af6768c332%2Frestaurando_banco.png?alt=media)

## Starting the Containers

1. After the restoration is complete, run the commands to start the Containers.
2. **Container lcc\_console**\
   Command: `docker start lcc_console`
3. **Container lcc\_worker**\
   Command: `docker start lcc_worker`
4. **Container lcc\_alert\_report**\
   Command: `docker start lcc_alert_report`
5. See the example in the image below:

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fcddc4a6df973590c5fbc5a855d7c8e7e0603755%2Finiciando_containers.png?alt=media)
6. The LCC will be ready for use normally after the Containers are initialized.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c6f30cd5743037573225b162b4fcea817c8c3026%2Ftela_login.png?alt=media)


# Integrations


# BeyondTrust


# Password Safe

This guide provides information and steps for integrating BeyondTrust Password Safe with Linux Control C/enter.

## BeyondTrust

BeyondTrust Password Safe is an /enterprise password manager software which /ensures complete control and accountability over privileged (and non privileged) accounts within an organization.

Through this integration will be possible to perform Discovers using privileged cred/entials managed by Password Safe, Import Assets from Password Safe and create scripts using Managed Accounts and Secrets from Secrets Safe (cred/entials, passwords, tok/ens, files and texts).

### Version Requirem/ents

* BeyondInsight 22.X and later.
* Linux Control C/enter 2.0 and later.

### BeyondTrust Password Safe Configuration

* API registration key;
* API account and group with correct permissions;
* Managed Account used by Linux Control C/enter must be API /enabled;
* Managed System for the Managed Account must exist;
* Asset for the Managed Account must exist.

{% hint style="warning" %}
The Managed Account used in this integration it is preferred that it be a dedicated account for the Linux Control C/enter.
{% endhint %}

{% hint style="danger" %}
It is recomm/ended that the **Assets** that will be imported into Linux Control C/enter should be added to BeyondInsight Password Safe from a Discovery Scan to /ensure the integrity of the data that must be imported correctly. Manually creted Assets and Managed System are also supported, but it is a requirem/ent that the **Asset** be created for each managed Linux Server.
{% endhint %}

{% hint style="danger" %}
Linux Control C/enter does not support this characters in passwords # { } " \ @. This restriction needs to be defined in "Password Policies" for the Managed Account used by Linux Control C/enter:
{% endhint %}

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7a113451174a9c3f104072ff366b14d7d6203140%2Fpwsafe-password-policies-01.png?alt=media)

### API Registration

To register a new API:

1. In BeyondInsight Console, go to **Configuration** > **G/eneral** > **API Registrations,** click on **Create New API Registration** and select **API Key Policy**.
2. Provide a name for the API registration and click **Create API Registration**.
3. You must add an Auth/entication/IP rule for the address of your Linux Control C/enter Worker instance. If there are multiple workers installed on the /environm/ent, all workers addresses must be listed.

   * On the Details page, click Add Auth/entication Rule.
   * From the Type dropdown list, select Single IP Address.
   * Select the IP Rule option.
   * Provide the IP address.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7e5e373e17a548131adbfb6e690aae3ec8218edb%2Fimage%20\(39\).png?alt=media)
4. Disable the /enforce Multi-Factor Auth/entication checkbox option.
5. On the Details page, click Update Registration.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-77778696e465fff07c70d634188cce024fee2410%2Fimage%20\(88\).png?alt=media)

### User Account and Group <a href="#api-user-group" id="api-user-group"></a>

An User account and Group must be configured for Linux Control C/enter. To create a BeyondInsight local user account:

1. In the BeyondInsight Console, go to **Configuration** > **Role Based Access** > **User Managem/ent**. Click the **Users** tab.
2. Click **Create New User** and select **Create a New User**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-63635521fff1427755754ca8d1749700307004f3%2Fimage%20\(42\).png?alt=media)

3. Provide user details, such as id/entification and cred/entials, and click Create User.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e021089a0322c3403bcca482f7048f2935b2d559%2Fimage%20\(94\).png?alt=media)

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0d0b49b14711cacb0cba70ca17393f2d686197d0%2Fimage%20\(95\).png?alt=media)

To create a new BeyondInsight local group, and /enable the required features and Smart Groups for that group:

1. In the BeyondInsight Console, go to **Configuration** > **Role Based Access** > **User Managem/ent**. Click the **Groups** tab.
2. Click Create **New Group** and select **Create a New Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4153d14f1069bf61d8d2a9d1c2b1376d70aa1db2%2Fimage%20\(49\).png?alt=media)
3. Provide group name and description, and th/en click **Create Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d2abedefdcd2b7b8dc3581d05ce4411a8f2e1144%2Fimage%20\(91\).png?alt=media)
4. Check the box next to the newly created group, and th/en click the ellipsis to the right of the group. Select **View Group Details**.
5. Under Group Details, select **Features**.
6. On **Features** page, locate features by selecting **All Features** in the Show dropdown list. Select Feature Name under the Filter By dropdown list, and th/en type the feature in the Feature Name field. The following features must be /enabled:

   * Asset Managem/ent
   * Attribute Managem/ent
   * Password Safe Account Managem/ent
   * Password Safe System Managem/ent

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5ab24c1f6c93eefc84cb1a53800f4737d0193346%2Fimage%20\(43\).png?alt=media)
7. The above features must be assigned a permission of *read only*. Click the corresponding ellipsis to the right of the feature, and th/en select **Assign Permissions Read Only**.
8. Under Group Details, select **Smart Groups**.
9. On the Smart Groups Permissions page, locate Smart Groups by selecting All Smart Groups in the Show dropdown list. Select Smart Group Name under the Filter By dropdown list, and th/en type the Smart Group name in Smart Group Name field. The target Managed Account Smart Group must be /enabled.
10. The Smart Groups must be assigned a permission of full control. Click the corresponding ellipsis to the right of the Smart Group, th/en select **Assign Permissions Full Control**.
11. The target Smart Group must have *Requestor, Approver and Cred/ential Manager* selected as role. Click the corresponding ellipsis to the right of the Smart Group, and th/en select **Edit Password Safe Roles**.
12. Check the Requestor box, and th/en select a policy from the Access Policy for Requestor dropdown list. This policy is applied to the managed account that is used for the integration.

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6ecd768e2eb53a49c9049af51ec61ef13e865e34%2Fimage%20\(103\).png?alt=media)

{% hint style="warning" %}
Linux Control C/enter requires the use of an Access Policy configured with **View Password** permition and **Auto Approve** /enabled. It is also recomm/end to /enable **"Allow multi-day checkout of accounts"** to avoid possible d/enied requests near the /end of day.
{% endhint %}

13. Click Save Roles.
14. To add the user created above to the group:
    * Go to **Configuration** > **Role Based Access** > **User Managem/ent** > **Groups**.
    * Click the ellipsis to the right of the new group, and th/en select View Group Details.
    * Under Group Details, select Users.
    * Select Users Not Assigned from the Show dropdown list.
    * In the Filter by dropdown list, select Username. Type the user name in the Username field.
    * Check the box beside the user name, and th/en click Assign User.
15. Finally, assign the API that was registered for the integration to this group:

    * Go to **Configuration** > **Role Based Access** > **User Managem/ent** > **Groups**.
    * Click the ellipsis to the right of the group, and th/en select **View Group Details**.
    * Under Group Details, select **API Registrations**. A list of API registrations is displayed.
    * Check the box beside the API registration created in [API Registration](#api-registration).

    ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9db1ab64ecd6525533dab0a7a1487e3a6bb32afe%2Fimage%20\(46\).png?alt=media)

### Managed Account Used by Linux Control C/enter

To confirm the account is /enabled for use with API:

1. In the BeyondInsight Console, go to **Managed Accounts**.
2. In the Filter by dropdown list, select Account. /enter the account name in the Account field.
3. Click the ellipsis to the right of each /entry, and th/en select **Edit Account**. Under Account Settings, make sure the **API /enabled** is /enabled.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-37642b866ae614b4b0daa5cfbf874775591a40a9%2Fimage%20\(50\).png?alt=media)

## Linux Control C/enter Configuration

### BeyondTrust Configuration Page

1. In the Linux Control C/enter, go to **Config** > **Integrations** and click on **BeyondTrust** Configuration button.
2. Provide all necessary settings to perform auth/entication on the Password Safe API such as API Url Base, API Auth Key, [API Auth Username](#api-user-group), API Auth Password and the Managed Account that will be used by Linux Control C/enter.
3. Select the Privilege Escalation Type field from dropdown list based on the chos/en account permission.
4. Click Save.
5. After saving, a test connection will be made to validate communication with BeyondInsight. If the connection fails, go to BeyondInsight -> Configuration -> User Audit options and analyze the connection details.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2efc254c19a1fc4e6aed7db99912812bdc03e835%2Fimage%20\(73\).png?alt=media)

## Get Assets Info

1. Get Assets Info option searches for All Assets of the Smart Group linked to the User Group of the API Auth Username used.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f24d5aa417fdbdfa3826c600c393f82fe7e5e1de%2FDiagrama%20sem%20nome.drawio.png?alt=media)
2. To perform a Get Assets Info go to **Config** > **Integrations** > **BeyondTrust** and click **Get Assets Info** th/en **Yes**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-37bfab94e98129d1f07b593eebc5d66bcfd622fe%2Fimage%20\(74\).png?alt=media)
3. A new job will be created in **Logs > Queue** left m/enu with the action "**Get Smart Groups**" of the User Group belonging to the Auth Username API.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-22432bc00cfde76e7caea2463ac8b48f40c66b25%2Fimage%20\(75\).png?alt=media)
4. After the job is completed, all Assets will be available to perform an Import Asset Action.

### Import Assets

1. To list which Assets are available to import to Linux Control C/enter, go to **Config** > **Integrations** > **BeyondTrust** and click **Import Assets**.
2. Select the assets that will be imported by Import Assets process and click **S/end**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cfa3e16386302a3fc5b4329599f47f1d7c1c54a7%2Fimage%20\(77\).png?alt=media)
3. A new action called "Import Assets" will be created, in this action Linux Control Center will try to connect to each selected Asset using the provided Managed Account to confirm that it is able to connect using the Managed Account and password retrieved from Password Safe.
4. After validating, Linux Control Center will start a new job with the "Photography" action for each imported host, fetching host information such as hostname, kernel version, ipv4 address, mac address, ssh port, os version and other informations.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-683303ab247bf3cb7f8ed8da27bfe067e1de0f4a%2Fimage%20\(66\).png?alt=media)
5. Wh/en the **Import Assets Info** successfully reach the "Processed" state in Queue menu, go to left M/enu **Hosts** option, and validate that assets were imported correctly by Linux Control Center with the BeyondTrust Auth/entication Method.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-56f5e2fef2c1a3e42d4afd4b74b1e112c017ea82%2Fimage%20\(67\).png?alt=media)


# Privileged Remote Access

## Requirements

* BeyondInsight = 22.X or higher
* Linux Control Center = 2.10.X or higher
* **OAuth Client ID** and **OAuth Client Secret** from Privileged Remote Access

## Overview

The integration of Linux Control Center with BeyondTrust Privileged Remote Access allows you to transfer Hosts managed by LCC to a *JumpGroup* in PRA.

## Objective

The objective of this document is to demonstrate the step-by-step process for integrating LCC with Privileged Remote Access.

## API Configuration in PRA

1. Access the Privileged Remote Access **/login** screen.
2. Click on **Management** and click on **API Configuration**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-395616557e435cc5917046ae76be76d6cbd937e1%2Fmanagement_pra.png?alt=media)

1. Click on **ADD** in API Accounts.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6b698a4a62822d785ea9d25247315d77a2c4c8ca%2Fadd_api_pra.png?alt=media)

1. Enter the **Permissions** as shown in the image below.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e2133a76038bd36728d618396e7b9f60e269130b%2Fpermissoes_pra.png?alt=media)

1. Create a *name* to identify the access and save the **OAuth Client ID** and **OAuth Client Secret** in a safe place and click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-97abd98ade307246860c0b67ef04739b0c2833bc%2Fids_api.png?alt=media)

## Linux Control Center Integration

1. Access the Linux Control Center and click **Config**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8c0671f317ba546b625aa5609b7b961fc75f67cd%2Fconfig_dashboard_pra.png?alt=media)

1. Click **BeyondTrust**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7975c3cb0503cc3a5b10a85b673ad971103d8ea1%2Fbotao_beyondtrust.png?alt=media)

1. Click **Privileged Remote Access**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-119ef9377771c669bf1c650972976e1a9b36cb5f%2Fbotao_pra.png?alt=media)

1. Click **Create**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0089ebd5f1f67ab834bae316472ca1453f8fcd3e%2Fbotao_create.png?alt=media)

1. Fill in the requested fields

* **Name:** Name to identify the integration
* **URL:** URL of the BeyondTrust PRA of your environment
* **Client ID:** PRA Client ID
* **Secret:** PRA Secret Key

1. Click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c5fbf346c4bccc9f64e015a8a7e74f5ce6cd435a%2Fbotao_save.png?alt=media)

1. Click on the created integration and click **Test Connection** to validate the connection of the LCC with the PRA.

* Wait for the **PRA Test Connection** *Action* to be completed in the *Queue*.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c240d076e0d9815a7954cfaf39a3fa00575311df%2Ftest_connection.png?alt=media)

1. The **Status** field will have a green icon indicating that the authentication was successfully validated.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c91cfb19b1e79f233bc3f7a8a655e061b841de4c%2Fpra_validado.png?alt=media)

1. Click on the **Jump Items** tab and click **Sync**.

* Wait for the **PRA Sync** *Action* to be completed in the *Queue*.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d81794101058178e023d0a22cdb4a1cf5259d8d4%2Fsync_jump_item.png?alt=media)

1. The Hostname of the *Jumpitems* will be listed with their respective *Jump Group* and *Jumpoint*. 1. Click **Create**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8ec0792a8a2d2dff9fe128d6df67f1537174f0b5%2Fbotao_create_jumpoint.png?alt=media)

1. Choose which **Jumpoint** the Host will be imported to.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-74d17a53c7818bf4202dc856a93d5b0af78d7a74%2Fcampo_jumpoint.png?alt=media)

1. Click **Host** to select the desired Host. You can also select an LCC Host group in the **Groups** field.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5ce59ba33ff089e7325bd1c8974d397b92d409f7%2Fcampo_host_jumpoint.png?alt=media)

1. Select the PRA **Jump Group** where the Hosts will be imported.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-def4ece6bdaa7097a35df944f220337ae7db344c%2Fcampo_jump_groups.png?alt=media)

1. Click **Save** to execute the *Action* that will import the selected Hosts to PRA.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-13008ca58d6eaed21b6e87d6213daaa9e9c6a1a8%2Fbotao_save_jumpoint.png?alt=media)


# VMWare

## Version

* Linux Control Center = 2.10.X or Higher
* VMWare ESXi = 7.0 U2 or Higher

## Requirements

* Access credentials with VMware snapshot permission.
* Hosts in the LCC database previously configured

## Overview

The native integration with VMWare Vcenter is classified as a Rollback Item within the scope of Linux Control Center. A Rollback Item generally aims to start a backup task, create a snapshot, recovery point or similar item within the integration scenario, with the aim of ensuring the rollback of a system if a modification generates some unexpected behavior in your technology park.

Whenever one or more actions selected in the integration are called by the LCC, they will trigger the command to create a snapshot, and only after confirmation that the snapshot was successfully created in VMware, the action will be executed.

{% hint style="warning" %}
Please note that all third-party solutions that interact with LCC must be configured correctly. Inconsistent data from these solutions cannot be reliably processed or presented by LCC.
{% endhint %}

## Objective

This guide provides information and step-by-step instructions for integrating Linux Control Center with the VMware vSphere virtualization system.

## VMware Integration with LCC

### Integration Configuration

1. Click **Config** in the left side menu of LCC

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)

1. Click the **VMware** button

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ff2fd2010438f705e38b33ed1240421f9a65d269%2Fvmware_config.png?alt=media)

1. Click the **Create** button

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-92cb6e0fd567e0691fb79de96699f108dd635163%2Fcreate_vmware.png?alt=media)

1. Fill in the fields with your environment information**Name**: Name to identify the integration\
   **URL**: VMware vSphere URL address\
   **Username**: User with the environment domain Ex: @vsphere.local\
   **Password**: Access password\
   **GOVC**: Defines the binary version for integration with VMware, leave it as is **default**\
   **Default Data Center**: Enter the exact name of the VMware Data Center in your environment in this field\
   **Ignore SSL**: Button to ignore communication with SSL<br>

{% hint style="warning" %}
If you need to perform the integration in more than one Data Center, you will need to create an integration for each of them.
{% endhint %}

1. Click **Save** after entering the data correctly

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-07eec344cedcd96bcf3849d4372a905339c92918%2Fadd_vmware.png?alt=media)

### Connection Test

1. After saving, click **Test Connection** to perform the connection with VMware and wait for the action to finish

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b8850a727bcafeff480a3378faac8a2683d18b48%2Fgeneral_semconexao.png?alt=media)

1. You will be able to see the status icon in green, confirming that the connection was successful.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0293acbc2ef795a538255dc570df1eb39b4e1990%2Fgeneral_conectado.png?alt=media)

### Host Synchronization

1. After the connection is validated, click on the **Hosts** tab and click on **Sync** and wait for the synchronization action to finish.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5b50db0fb24b04170e1d37cf2cd25790e2799a6e%2Fhosts_semhost.png?alt=media)

1. After the synchronization is finished, refresh the screen and the hosts will be listed in the **Hosts** tab of the integration.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-60fcfd7e5573f78277ef55ff3e50a2233d928eff%2Fhosts_sincronizado.png?alt=media)

### Host Selection for Rollback

{% hint style="warning" %}
If any VMware host does not appear on the integration hosts screen, make sure that it was inserted in the LCC database.
{% endhint %}

1. To remove one or more hosts from the snapshot task, uncheck it in the **Enable** column and click **Save**. This way, VMware will not create a snapshot of the unchecked hosts when a predefined action is executed in the LCC.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dc2da780f2a36ebce89535532da8ccd50cf0a5a5%2Fescolhendo_hosts.png?alt=media)

### Snapshot Action

1. Click on the **Actions** tab and select as many actions as you want, so that whenever executed by the LCC, it will send the command to create a snapshot of the machines selected on the **Hosts** screen
2. Click on **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-367a1b224dd395564dc1022776b501007ad6bd91%2Factions_vmware.png?alt=media)

### Executing the Snapshot Trigger Action

* The action used for demonstration was the **Host Ping** action

1. Click on **Hosts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)

1. To execute the action on only a single host, select the desired host and click on **Actions** in the host line

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5abb6b308b8cf5bf0aca82686611985f5ab57129%2Fhost_ping_ubuntu.png?alt=media)

1. To run the action on more than one host, select as many as you want in the box on the left column and click **Actions** at the top of the page

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-67df326c1292068698139c3c0e7d3021d8fb47da%2Fhost_ping_grupo.png?alt=media)

1. To run the action on all hosts in the LCC database, select the box next to Hostname and click **Actions** at the top of the page

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-01f719e24bc3a4772566e7f2d39d83c151276634%2Fhost_ping_todos.png?alt=media)

### Scheduling Snapshot Listing

1. On the VmWare integration screen, click the **Schedule** tab

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a470926e81f9ec565895648c644d421659cc9fa3%2Fschedule_general.png?alt=media)

1. Click **Add Schedule**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5a56576856c44de621d4c8f94f7a89380f94072e%2Fadd_schedule.png?alt=media)

**Test Connection:** Performs a connection test connection with VmWare to validate the integration\
**Sync Assets:** Updates the list of VmWare assets according to the LCC host database<br>

4. Then, define a name for the schedule in the **Name** field and choose one of the actions in the **Action** line

By default, the scheduling screen opens with the **One Time** option, to schedule a single execution at a specific hour, minute and date, as shown in the image below;

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-018bfbac97e9ff43ff83b1a9f8a786b905288404%2Factions_schedule.png?alt=media)

1. By checking the **Repeatedly** box together with **Minutes** it is possible to execute the action every X defined minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e8e29ced6adc87c6745aeb40dadec1d27d31cfb6%2Fminutes_schedule.png?alt=media)

1. Checking the **Repeatedly** box together with the **Daily** option allows you to run the action every day, every X hours and X minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e256b38384d88ce7ac263e74a5f167feb42a0aef%2Fdaily_schedule.png?alt=media)

1. Checking the **Repeatedly** box together with the **Advanced** option allows you to choose the custom schedule, where you can choose the hour, minute, day of the week, day of the month and the desired month.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-eefd995b49a52fc6224021477db57af283754e00%2Fschedule_advanced.png?alt=media)

1. After creating and saving a schedule, you can pause it if necessary by clicking **Disable** and monitor the status of whether it is enabled or not in the **Active** column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-651fbb8d4d7fc684a37b70e7f4ed66f0e280eec9%2Fdisable_schedule.png?alt=media)

1. The **Next Run** column displays when the next run will be and the **Last Run** column displays when the last run was. The **Count** column counts how many times the schedule has been run.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5c47cbbfe8059411d1c9eda997f762bac9f1574e%2Flast_next_run.png?alt=media)

1. You can also delete a schedule by clicking the trash can icon next to the Disable/Enable button.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8052dbe3d8042eff63a2900e9d9c7fd5309a3fe9%2Fdelete_schedule.png?alt=media)

## Snapshot Validation

* You can validate if the snapshot was successfully created in Vmware by LCC.

1. Click on **Hosts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf2553b10fbabb1e6772981c894be4d600207cff%2Fhosts_dashboard.png?alt=media)

1. Click on the **Host** where you performed the action.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d7d8c079a754ec74286a5583e99a5573e3323162%2Fubuntu_20.png?alt=media)

1. Click on the **ROLLBACK** tab and click on **SYNC**

* The host's snaphost will appear in **Rollback Items** with the description **Created By LCC**

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7db42a995d5e4bea7f2d9b3e981c7676fb6ca187%2Frollback_list.png?alt=media)


# Nutanix

## Version

* Linux Control Center 2.10.X or higher
* Nutanix Prism Central and/or Element pc.2022.6.0.10 or higher
* AOS Version 6.5.2 LTS or higher

## Requirements

* NGT Agent
* User with permission to list VM information
* User with permission to create Recovery points
* Hosts in the LCC database previously configured

## Overview

This guide provides information and step-by-step instructions for integrating Linux Control Center with Nutanix Prism and/or Element.

Integration with Nutanix Prism is classified as a Rollback Item within the scope of Linux Control Center. A Rollback Item generally aims to initiate a backup task, create a snapshot, recovery point or similar item within the integration scenario, in order to guarantee the rollback of a system if a modification generates some unexpected behavior in your technology park.

{% hint style="warning" %}
Please note that all third-party solutions that interact with the LCC must be configured correctly. Inconsistent data from these solutions cannot be processed or presented reliably by the LCC.
{% endhint %}

## Objective

Create a Recovery Point for a server managed by the Linux Control Center, which has been properly identified in Nutanix Prism.

## Integration flow

1. Configuring Nutanix Prism;
2. Defining which actions will generate a Recovery Point;
3. Searching for information on virtual machines;
4. Identifying the servers managed by the Linux Control Center that are present in Nutanix Prism;
5. Requesting an action;
6. Generating a Recovery Point;
7. Logging in to the server via SSH;
8. Executing commands;

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/nutanix/nutanix_recovery_point.png)

{% hint style="danger" %}
It is important to note that Linux Control Center operates with the minimum permissions required on third-party systems, so Recovery Points are not managed in Nutanix Prism, and the team must be responsible for managing resources, such as available storage space for Recovery Points and other operations in the life cycle of a Recovery Point within your corporation.
{% endhint %}

## Minimum permissions for integration

These are the minimum permissions required for a Nutanix Prism user to integrate with Linux Control Center.

1. To create the profile correctly, you must assign a local Nutanix Prism user or an **Active Directory** to a Nutanix **Role** according to the official documentation in the link below;

* If you choose to use an AD user instead of the local Nutanix Prism user, it is necessary that the user has Domain Admin permission.

<https://portal.nutanix.com/page/documents/details?targetId=Nutanix-Security-Guide-v6_8:mul-security-authentication-pc-t.html>

1. After joining Nutanix Prism to Active Directory, click **Config**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a379cd260b77ea2b85682ec2ca74b137f2e817b3%2Fconfig_nutanix.png?alt=media)

1. Click **Local User Management** and click **New User**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b6af904177810bb64465537bc890cc59e7702b0f%2Fnew_user_nutanix.png?alt=media)

1. Create a user with a **Viewer** profile in Nutanix with the following settings;

* **User Admin:** Disabled
* **Prism Central Admin:** Disabled

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-38d46e189f829958ac792d27b840cd7be93938ea%2Fusuario.png?alt=media)

1. Click on the left side button to open the menu and click on **Administration** and then on **Roles**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c3d87faef3df1d1a7a63e0a38985245c826543a6%2Fnew_role.png?alt=media)

1. Click on **Create Role**

* We suggest the name **Linux Control Center** for better identification.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-38fac7c2e627ea2ef5ed8b4bd23473e5df17a107%2Fcreate_role.png?alt=media)

1. Enable the permissions as below; **App**: Access Console VM, View VM**VM Recovery Point**: Snapshot VM, View VM Recovery Point, Allow VM Recovery Point Creation**VM**: Access Console VM, View VM

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2edc639bd74e69cfd58ffef2430b82f1da321280%2Fsumario_roles.png?alt=media)

1. This will be the result of the **Role Assignment** when it is finished.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e0d8d1efcb9fb2c8fb019431f0b0648fd8d580b7%2Fatribuicao_roles.png?alt=media)

1. Then, go back to settings and click on **Role Mapping** and click on **New Mapping**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a5a6876286d973e06f5c4c975b6fe81730f598d5%2Fnew_role_mapping.png?alt=media)

1. Create the **Role Mapping** with the following settings;

* Specify the user created previously and use it in the next steps to configure the integration with the Linux Control Center.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-990ee75c83b4ed95811bf96f1433343f2361a681%2Frole_mapping.png?alt=media)

## Integrating Nutanix Prism with LCC

### Performing the integration

1. Click **Config** in the left side menu of the LCC

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)

1. Click **Nutanix**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fe0ba011565b93eedb4dd49d85584425e1000400%2Fnutanix_integracao.png?alt=media)

1. On the Nutanix configuration page, click **Add**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76aa798246594a3fb458cec0c418f3f704305026%2Fadd_nutanix.png?alt=media)

1. Provide all the necessary settings to authenticate to Nutanix Prism.

* Enter the Nutanix URL in the **URL** field.<br>
* Enter the Nutanix user in the **Username** field.<br>
* Enter the Nutanix password in the **Password** field.<br>
* Define whether the integration will be with **Nutanix Prism Central** or **Nutanix Prism Element** in the **Integration** button.<br>
* If the Nutanix Prism Central and/or Element solution does not use a valid digital certificate, enable the **Ignore SSL** option.<br>

1. Click **Save**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7da5831a8fa0031fbcc8bb26cfb893b023caf4fa%2Fnutanix01.png?alt=media)

1. After saving, click **Test Connection** to authenticate with Nutanix Prism

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2de1119f1192e2b6a1b67b88c3222be81e590281%2Fnutanix02.png?alt=media)

### Synchronizing Nutanix Prism Hosts

1. After saving the previous configuration and the icon confirming the **Status** of the connection, click on the integration item.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f26ac485ee75f56f6f4eca50bc8520fc90408839%2Fnutanix_sincronizado.png?alt=media)

1. Within the Nutanix Prism integration screen, click on the **Hosts** tab and click on **Sync** to synchronize with the Nutanix Prism hosts.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-963ead7a5339b0691afae8c45b993945668517c4%2Fnutanix03.png?alt=media)

1. The sync action will authenticate to the Nutanix API and attempt to obtain the IP Address and Hostname of the existing Virtual Machines.
2. The list of Virtual Machines returned will match the Hosts already existing in Linux Control Center and, if successful, the Host will be marked with Nutanix integration and Linux Control Center will be able to perform the Rollback feature.
3. At the end of the Synchronization, you will be able to see the Hosts in the same **Hosts** tab in the Nutanix Prism integration configuration.
4. Click on the **Actions** tab and define which actions will trigger the creation of Recovery Point on the previously selected machines and then click **Save**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-073d32461539ed269a94e025aea06a94b032525a%2Fnutanix04.png?alt=media)

## Validating the recovery point

1. Click **Hosts** in the left pane of the Linux Control Center

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a532dd47faff1b1fe76d7a00c2c713eaa58248a6%2Fhosts_dashboard.png?alt=media)

1. Click on the **Host** that was previously configured/enabled in the Nutanix Prism solution integration configuration screen.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-74c7dc9d48a4d9864b234e88f64a1290e79b6ce8%2Fnutanix05.png?alt=media)

1. After selecting the **Host**, perform one of the action(s) that was enabled in the Nutanix Prism solution integration configuration screen.

{% hint style="warning" %}
When executing an action that was previously configured in the integration, the creation of a Recovery Point for that virtual machine will be requested from Nutanix Prism. The requested action will only be executed after the creation of the Recovery Point. In case of an error in the creation of the Recovery Point, the execution of the action will be interrupted and its status will be "error".
{% endhint %}

1. Click on the selected **host** and then click on the **Rollback** tab. You will be able to see the list of Recovery Points in **Rollback Items**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9f6fb877b4869531785f58fa08f9810a4712c5db%2Fnutanix_rollback.png?alt=media)

1. In Nutanix Prism, if the Recovery Point is successful, an event will be created as "Create VM recovery point".

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a4cf3eccf69b501a4b82f7896fb36d10872fbe00%2Fnutanix_event.png?alt=media)


# Tenable


# Security Center

## Version

* Linux Control Center = 2.10.5 or higher
* Tenable Security Center Plus = 6.4.0 or higher

## Requirements

* Tenable Security Center Access Key and Secret Key
* Tenable Security Center Plus with previously configured scans
* Hosts in the LCC database previously configured

## Overview

* This guide provides information and step-by-step instructions for integrating Linux Control Center (LCC) with the Tenable Security Center vulnerability manager.

## Objective

* This integration allows you to run Tenable Security Center scans from the LCC and use the scan results to quickly and easily identify vulnerabilities on hosts managed by the LCC.

{% hint style="warning" %}
Please note that all third-party solutions that interact with the LCC must be configured correctly. Inconsistent data from these solutions cannot be reliably processed or presented by the LCC.

If you have duplicate Assets in Tenable, the LCC will not be able to correctly process the received data.
{% endhint %}

### Integration Configuration

1. To create the LCC connection with Tenable, access the menu on the left of the LCC and click on the **Config** option

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)

1. Click on **Tenable**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2392175ee074a464129fef04ca04976196dade3a%2Ftenable_sc.png?alt=media)

1. Click on **Tenable Security Center**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-50179674d11037dfaa8afc9bbd9b5801a82171f1%2Ftenable_sc_tela.png?alt=media)

1. Click on the **Create** button

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fa0548f4e0047aaf1bcc209a15e6b169515a3f57%2Ftenable_create.png?alt=media)

1. Enter the data in the fields below;

* Enter the name to identify the synchronization in the **Name** field.<br>
* Enter the Tenable Security Center URL in the **URL** field.<br>
* Enter the **Access Key** and **Secret Key** in their respective fields.<br>

1. Click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f4589aecb7cd69ef76f929ecfaf65ca1c7d22bf7%2Ftenable_campos_integracao.png?alt=media)

1. After saving, click on the previously saved item to open the Tenable SC integration window.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6de44f7c2d194bec79274a1f3e8572e3eb52d710%2Ftenable_item.png?alt=media)

1. Click the **Test Connection** button to test the connection with Tenable Security Center.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2832a9ab6af70cc0bb87b6abe17c6e5cb483b34a%2Ftenable_general.png?alt=media)

1. The Status will turn green to confirm that the connection was successful

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f2b6e11afe86c8b34f277c86a5ef4f81600c1edb%2Ftenable_status.png?alt=media)

### Sync Assets

1. Then, click on the **HOSTS** tab

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2b6197cd132ea239e59854181b251ec5a146d699%2Ftenable_guia_hosts.png?alt=media)

1. Click on the **SYNC ASSETS** button and wait for the LCC hosts to synchronize with the Tenable Security Center Hosts.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dcc790f24d9ecb8d8a57c2e70992e6809b33a7f4%2Fsync_assets.png?alt=media)

1. After the Hosts are synchronized, click on the **Repositories** tab to define the repository to search for the scan results.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8c78ccc9b1ee560dea1a4dffd82a3d11da6949f0%2Fguia_repositorio.png?alt=media)

1. Check the box for the desired repository in the **Active** column and click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c80fcf2a963e5d216a0eaf08719fa0469f6ff6c3%2Fativar_repositorio.png?alt=media)

{% hint style="warning" %}
Sync Assets compares the IP addresses of the Hosts in the LCC database with those in the Tenable Security Center database. Only Hosts with the same IP addresses in both databases will be displayed on the LCC Assets screen.
{% endhint %}

### Scan Execution

1. After completing the **Sync Assets** step, the hosts will be listed on the screen.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-cc3453d4c4a2ba6dd7d8f64c1b6cc1c918eeac3f%2Fassets_listados.png?alt=media)

1. Then, click on the **SCANS** tab and click on **Sync Scans**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-81635d385b3d760146ba936ad92365cfac406c0a%2Fsync_scans.png?alt=media)

1. Wait for the synchronization to finish, and you will be able to view the scans from Tenable Security Center.
2. Click on **Run** for the desired scan.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-667e89bf1070a285c631160e94ad75c27390a9a0%2Ftenable_scans.png?alt=media)

### Sync Results

{% hint style="warning" %}
This Action can only be run once every 24 hours. Before running Sync Results, check if any Scans have been performed recently to ensure that vulnerability information is up to date.

The Action will have the status **Aborted** if it is run again within the 24-hour period.
{% endhint %}

1. After the scan in Tenable Security Center is complete, open the integration item again and click on the **Hosts** tab.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2b6197cd132ea239e59854181b251ec5a146d699%2Ftenable_guia_hosts.png?alt=media)

1. Click on **Sync Results** and wait for the scan results to synchronize with the LCC.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0a2b5c29ab93bd5b81a89dca8fe6a947098bac91%2Fassets_listados_botao_sync.png?alt=media)

1. After the Sync Results are complete, you will be able to obtain the risk indexes that Tenable Security Center makes available in the **Risk** column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-f5e23f2c6b7dcfcd500c3c697727a7adb40a0219%2Fsync_results.png?alt=media)

1. To obtain the output of the Scan executed on the Hosts screen, access the menu on the left of the LCC and click on **Hosts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dc18df9bb38647d3817b3020d91224496bf5e0a6%2Fhosts_menu.png?alt=media)

1. Click on the desired **Host** which will open the Host window.
2. Click on **Tenable Plugins**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ae6fac853ddfb67740bca707bc76aba3b2f710fe%2Fhosts_tenable_plugin.png?alt=media)

1. Click on the **Tenable Plugins** tab and you will be able to obtain the separate numbering of the plugins ID relating with AES, ACR, VPR, CVE ID, CVSS indexes, along with the suggested remediation provided by Tenable Security Center.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c4faa308baafe677a5352985763afd4a9edbdd19%2Ftenable_plugins.png?alt=media)

### Schedules

1. On the Tenable Security Center integration screen, click on the **Schedule** tab

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ba96d075435768da2f1ce0df85fb8de78824db80%2Fschedule_general.png?alt=media)

1. Click on **Add Schedule**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-27e676de8cf5178496da7dcba8a259c200116955%2Fadd_schedule.png?alt=media)

**Test Connection:** Performs a connection test with Tenable Security Center to validate the integration\
**Sync Scans:** Updates the list of scans available in Tenable Security Center on the LCC integration Scans screen\
**Sync Assets:** Updates the list of Tenable Security Center assets according to the LCC host database\
**Launch Scan:** Sends the command to run a desired scan in Tenable Security Center\
**Sync Results:** Synchronizes the results of the last scan run in Tenable Security Center with the hosts integrated in LCC.<br>

4. Then, define a name for the schedule in the **Name** field and choose one of the actions in the **Action** line

By default, the scheduling screen opens with the **One Time** option, to schedule a single execution at a specific hour, minute and date, as shown in the image below;

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c9be661dca24f8d5f9fbe51c5363ecc3d887fc45%2Factions_schedule.png?alt=media)

1. By checking the **Repeatedly** box together with **Minutes**, you can run the action every X defined minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a7b10317f5792221fc812b59bbc206af23eb46cf%2Fminutes_schedule.png?alt=media)

1. By checking the **Repeatedly** box together with **Daily**, you can run the action every day every X hours and X minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1817e43f306c84b54033decc0de95fe629d0d70f%2Fdaily_schedule.png?alt=media)

1. Check the **Repeatedly** box along with the **Advanced** box to choose the custom schedule, where you can choose the hour, minute, day of the week, day of the month and the desired month.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ec7de3946fbe5da0941836b03d0be6d4e4b2f76f%2Fschedule_advanced.png?alt=media)

1. After creating and saving a schedule, you can pause it if necessary by clicking **Disable** and monitor the status of whether it is enabled or not in the **Active** column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-686602e8014ade22b58e95ddb6d02f5576c5ec6e%2Fdisable_schedule.png?alt=media)

1. The **Next Run** column displays when the next run will be and the **Last Run** column displays when the last run was. The **Count** column counts how many times the schedule has been run.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-28d47db9a84159a662965c3558b13a7321494ff9%2Flast_next_run.png?alt=media)

1. You can also delete a schedule by clicking the trash can icon next to the Disable/Enable button.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-794ff7fa8ecb56b9bb7ce11325776fe7d5abb48d%2Fdelete_schedule.png?alt=media)

## Vulnerability fix

### Fix Plugin ID 153588 - Weak SSH ciphers

The LCC 7 Library has a script to change SSH encryption ciphers, configuring hosts to use stronger ciphers for SSH authentication.

To download and run this script, follow the steps below.

1. Click **7 Library** in the LCC left menu

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-83d51d88d139beeae61b7f77218c01226232f38c%2F7library_dashboard.png?alt=media)

1. Click **Sync Feed** to update the 7 Library feed

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b4e1e78d085a1bfdba07e4b7df843631d21235e3%2Fsync_feed.png?alt=media)

1. Click on the **Config SSH Ciphers Algorithms** script

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-93fafd8043be44a3b161403453be95879503bfdb%2F7library-page.png?alt=media)

1. Click **Download** and the script will be saved in the LCC and will be available in the **Scripts** screen

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0d2fd45ac85440b63993e038ed6020f3c6dc1e69%2Fdownload_script.png?alt=media)

1. Click on **Scripts** in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7a28660a18ec677122f81c8e4f62942d11ad0c3d%2Fscripts_lateral.png?alt=media)

1. Click on the script that was downloaded.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8d5c8e6b5f8129fe67174e0ebf596744237a7438%2Fscript_baixado.png?alt=media)

1. Click on **User for Execution.**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2e637f7815ba6d7764c2f18a24c7e16521f2608b%2Fcampo_user_for_execution.png?alt=media)

1. Choose which user will run the script (We recommend using the **lcc.local** user to avoid failures due to lack of permission.)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c3086bbec0fc167903431f13568111d84c0f8f9e%2Fconta_lcc_local.png?alt=media)

1. Click on **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2c6d81b5e1a00e9bbe5c9ee218213a9b71622ba5%2Fbotao_save_script.png?alt=media)

1. Then, click on **Workflow** in the left menu of the LCC

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf678eeccdc53dedd861e1460542bf6c2f0ebb2c%2Fbotao_workflow_lateral.png?alt=media)

1. Click **Create**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-aaec5ef3cc146d2b102fefe4943c77e454911665%2Fadd_workflow.png?alt=media)

1. Enter a name for the *Workflow* in the **Name** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-545ce7ea4124400e878e39674c1ea8d8af72ad03%2Fcampo_name_workflow2.png?alt=media)

1. Click **Start New Workflow.**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2f6f312dfa1d82780a72a4ac5ed62af70e5dd9c5%2Fstart_workflow.png?alt=media)

1. Click **Actions** and choose the **Execute Custom Script** option

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-65121154f33ea696ff3dd591a9c6248800d13dbf%2Fcustom_script.png?alt=media)

1. Define one or more Hosts in the **Host** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b27a88376639600f7413102763fa27a3fa4c9cea%2Ftarget_host.png?alt=media)

1. If you have a pre-configured group, choose it in the **Target Group** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-231de58c5451a86bc9d383d51d3013266531fd3c%2Fgrupo_hosts.png?alt=media)

1. Choose the **Config SSH Ciphers Algorithms** script.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e249974d3c69a0fe7400e6b534ec1da094f7fcce%2Fcampo_script.png?alt=media)

1. Click **Create**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-09105987329211611883814d65a554dae016b682%2Fworkflow_completo.png?alt=media)

1. Click **Save** to save the Workflow.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/workflow/fix_153588_tenable/save_button.png)

1. After creating the Workflow, click the **Actions** button, then **Run**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-243783b84ec4866f4b0c4c100967b71e63eb3e74%2Fexecute_workflow.png?alt=media)

1. Click **AGREE** to confirm the execution of the Workflow.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-352cc0bfc0518b7da93d3cf5ac5dbb40278254ec%2Fconfirmacao.png?alt=media)

1. Wait for the Workflow to finish executing.
2. After the Workflow is successfully executed, run the Tenable Security Center scan again, according to step [Scan Execution](#scan-execution)
3. Run **Sync Results**, according to item 2 of the [Sync Results](#sync-results) topic
4. Access the menu on the left of the LCC and click on **Hosts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-dc18df9bb38647d3817b3020d91224496bf5e0a6%2Fhosts_menu.png?alt=media)

1. Click on the desired **Host** that will open the Host window.
2. Click on **Tenable Plugins**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ae6fac853ddfb67740bca707bc76aba3b2f710fe%2Fhosts_tenable_plugin.png?alt=media)

1. Click on the **Tenable Plugins** tab and search for the number 153588 in the **Search** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-118e5414d2aa31bdd94e0612afce72696c7c1e9f%2Ftenable_search.png?alt=media)

1. We can see that the ID 153588 is no longer present in the Plugin ID column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-373898b5ad3ab962752cff91b3f594059aa2f407%2Ftenable_id.png?alt=media)


# Cloud Security

## Version:

* Linux Control Center = 2.10.X or higher

## Requirements:

* Tenable Vulnerability Management Secret Key and Access Key
* Hosts in the LCC database previously configured

## Overview:

* This guide provides information and step-by-step instructions for integrating Linux Control Center (LCC) with Tenable Vulnerability Management vulnerability manager.

## Objective:

* This integration allows you to run Tenable Vulnerability Management scans from LCC and use the scan results to quickly and easily identify vulnerabilities in Hosts managed by LCC.

{% hint style="warning" %}
Please note that all third-party solutions that interact with LCC must be configured correctly. Inconsistent data from these solutions cannot be reliably processed or presented by LCC.

Tenable Vulnerability Management does not have ACR and AES indexes to classify Host risk levels.
{% endhint %}

## Integration Configuration

1. To create the LCC connection with Tenable, access the menu on the left of the LCC and click on the **Config** option

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)

1. Click on **Tenable**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2392175ee074a464129fef04ca04976196dade3a%2Ftenable_sc.png?alt=media)

1. Click on **Vulnerability Manager**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2251d5d48fd04f18102005821767987555b055eb%2Ftenable_integrations.png?alt=media)

1. Click on the **Create** button.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2783802b5a6ddc5e23190980b28c0ba9d8386910%2Fcreate_tenable_vm.png?alt=media)

1. Then, fill in the fields below; 1. Enter the name to identify the synchronization in the **Name** field
2. Enter the URL <https://cloud.tenable.com> in the **URL** field
3. Enter the **Access Key** and **Secret Key** in their respective fields.

* **Chunk Size:** is the number of Assets that will be imported at a time<br>
* **Number of Assets:** is the maximum number of Hosts to import<br>
* **Updated At:** This option allows you to define from which date the LCC will be able to obtain the scan results.<br>

Default: Vulnerabilities from 30 days ago.

1. Click **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ae115944c34e2766a7bb5c8a13c9ff425fe32cdf%2Ftenable_configurado.png?alt=media)

1. After saving, click on the previously saved item to open the Tenable Vulnerability Management integration window.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2759e248b113d11c106b865bc601943be99e40c0%2Ftenable_item.png?alt=media)

1. Click on the **GENERAL** tab, and then click on the **Test Connection** button to test the connection with Tenable Vulnerability Management.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c702707cb6ce425033c64dd8ca75334822a6800b%2Ftenable_general.png?alt=media)

1. The Status will turn green to confirm that the connection was successful

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c3dcb4ede923b3ee7ab130952ac90d4db78b30b5%2Ftenable_status.png?alt=media)

### Sync Assets

{% hint style="warning" %}
Sync Assets compares the IP addresses of the Hosts in the LCC database with those in the Tenable Vulnerability Manager database. Only Hosts with the same IP addresses in both databases will be displayed in the LCC Assets screen.

Be careful not to create duplicate Assets in Tenable Vulnerability Manager. If you do, they cannot be processed or presented reliably by LCC.
{% endhint %}

1. After validating the connection, click on **Hosts**
2. Click on **Sync Assets** to synchronize the LCC Hosts with Tenable Vulnerability Management Assets

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-caef3d6886b9315d36a6e07e6dc9c65bf22594fe%2Ftenable_assets.png?alt=media)

### Running Scans

1. Then, click on **SCANS**, click on the **SYNC SCANS** button to integrate which Scans are present in Tenable Vulnerability Management
2. After **SYNC SCANS** finishes and lists the Tenable scans, click on **RUN** to run the desired scan.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e388e9832f21f48b1d61e949ad0cf9d48a9e9ad1%2Ftenable_scans.png?alt=media)

### Sync Results

{% hint style="warning" %}
This Action can only be run once every 24 hours. Before running Sync Results, check if any scans have been performed recently to ensure that vulnerability information is up to date.

The Action will have the status **Aborted** if it is run again within the 24-hour period.
{% endhint %}

1. Access the Tenable web interface to monitor the scan execution. Once complete, return to **Hosts** and click **Sync Results** to synchronize the scan results with the LCC Console.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-571f2ad8b48b9cfd6bd6018a10ff983901135a23%2Ftenable_hosts.png?alt=media)

### Schedules

1. On the Tenable Vulnerability Management integration screen, click on the **Schedule** tab

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a2b5d85f17f9bb569b5eaa39679dfae54add133d%2Fschedule_general.png?alt=media)

1. Click on **Add Schedule**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4a8e3a114d50c70ad72f487966571f133a517cee%2Fadd_schedule.png?alt=media)

1. These are the actions available to execute in the schedule.

**Test Connection:** Performs a connection test with Tenable Vulnerability Management to validate the integration\
**Sync Scans:** Updates the list of scans available in Tenable Vulnerability Management on the LCC integration Scans screen\
**Sync Assets:** Updates the list of Tenable Vulnerability Management assets according to the database LCC host data\
**Launch Scan:** Sends the command to run a desired scan in Tenable Vulnerability Management\
**Sync Results:** Synchronizes the results of the last scan run in Tenable Vulnerability Management with the hosts integrated in LCC.<br>

4. Then, define a name for the schedule in the **Name** field and choose one of the actions in the **Action** line

By default, the scheduling screen opens with the **One Time** option, to schedule a single execution at a specific hour, minute and date, as shown in the image below;

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-89a0886f820e10aeb1f30756ac259aabe0ff9d72%2Factions_schedule.png?alt=media)

1. By checking the **Repeatedly** box together with **Minutes** it is possible to execute the action every X defined minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-854bf0fe8749cd5e9bc6b1ab2ae9a5572e20bc1f%2Fminutes_schedule.png?alt=media)

1. Checking the **Repeatedly** box together with **Daily** allows you to execute the action every day every X hours and X minutes.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6dcc136fa41e40077f038a6b63d5f870c90e4adb%2Fdaily_schedule.png?alt=media)

1. Checking the **Repeatedly** box together with **Advanced** to choose the custom schedule, where you can choose the hour, minute, day of the week, day of the month and the desired month.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c477531ae861b3fae43a83eab1824e5881e0d788%2Fschedule_advanced.png?alt=media)

1. After creating and saving a schedule, you can pause it if necessary by clicking **Disable** and monitor the status of whether it is enabled or not in the **Active** column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-56cbd191ff8a12aa35e1d3145d5b6bbebcdeb2cd%2Fdisable_schedule.png?alt=media)

1. The **Next Run** column displays when the next run will be and the **Last Run** column displays when the last run was. The **Count** column counts how many times the schedule has been run.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7c3f079fed80d86aa04fe11186ce791aac70c9e3%2Flast_next_run.png?alt=media)

1. You can also delete a schedule by clicking the trash can icon next to the Disable/Enable button.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7257223dae4bc7252acf6866e8627a9ac74e3986%2Fdelete_schedule.png?alt=media)

## Vulnerability Fix

### Fix Plugin ID 153588 - Weak SSH Ciphers

The LCC 7 Library has a script to change SSH encryption ciphers, configuring hosts to use stronger ciphers for SSH authentication.

To download and run this script, follow the steps below.

1. Click **7 Library** in the LCC left menu

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-83d51d88d139beeae61b7f77218c01226232f38c%2F7library_dashboard.png?alt=media)

1. Click **Sync Feed** to update the 7 Library feed

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b4e1e78d085a1bfdba07e4b7df843631d21235e3%2Fsync_feed.png?alt=media)

1. Click on the **config SSH Ciphers Algorithms** script

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-93fafd8043be44a3b161403453be95879503bfdb%2F7library-page.png?alt=media)

1. Click **Download** and the script will be saved in the LCC and will be available in the **Scripts** screen

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0d2fd45ac85440b63993e038ed6020f3c6dc1e69%2Fdownload_script.png?alt=media)

1. Click on **Scripts** in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7a28660a18ec677122f81c8e4f62942d11ad0c3d%2Fscripts_lateral.png?alt=media)

1. Click on the script that was downloaded.

![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/workflow/fix_153588_tenable/downloaded_script.png)

1. Click on **User for Execution.**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2e637f7815ba6d7764c2f18a24c7e16521f2608b%2Fcampo_user_for_execution.png?alt=media)

1. Choose which user will run the script (We recommend using the **lcc.local** user to avoid failures due to lack of permission.)

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c3086bbec0fc167903431f13568111d84c0f8f9e%2Fconta_lcc_local.png?alt=media)

1. Click on **Save**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2c6d81b5e1a00e9bbe5c9ee218213a9b71622ba5%2Fbotao_save_script.png?alt=media)

1. Then, click on **Workflow** in the left menu of the LCC

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-bf678eeccdc53dedd861e1460542bf6c2f0ebb2c%2Fbotao_workflow_lateral.png?alt=media)

1. Click **Create**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-aaec5ef3cc146d2b102fefe4943c77e454911665%2Fadd_workflow.png?alt=media)

1. Enter a name for the *Workflow* in the **Name** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-545ce7ea4124400e878e39674c1ea8d8af72ad03%2Fcampo_name_workflow2.png?alt=media)

1. Click **Start New Workflow.**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2f6f312dfa1d82780a72a4ac5ed62af70e5dd9c5%2Fstart_workflow.png?alt=media)

1. Click **Actions** and choose the **Execute Custom Script** option

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-65121154f33ea696ff3dd591a9c6248800d13dbf%2Fcustom_script.png?alt=media)

1. Define one or more Hosts in the **Host** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b27a88376639600f7413102763fa27a3fa4c9cea%2Ftarget_host.png?alt=media)

1. If you have a pre-configured group, choose it in the **Target Group** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-231de58c5451a86bc9d383d51d3013266531fd3c%2Fgrupo_hosts.png?alt=media)

1. Choose the **Config SSH Ciphers Algorithms** script.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e249974d3c69a0fe7400e6b534ec1da094f7fcce%2Fcampo_script.png?alt=media)

1. Click **Create**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-09105987329211611883814d65a554dae016b682%2Fworkflow_completo.png?alt=media)

1. Click **Save** to save the Workflow.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-400b5469c229a551e4eda188f7603e50f86dbc28%2Fbotao_save.png?alt=media)

1. After creating the Workflow, click the **Actions** button, then **Run**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-243783b84ec4866f4b0c4c100967b71e63eb3e74%2Fexecute_workflow.png?alt=media)

1. Click **AGREE** to confirm the execution of the Workflow.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-352cc0bfc0518b7da93d3cf5ac5dbb40278254ec%2Fconfirmacao.png?alt=media)

1. Wait for the Workflow execution to finish.
2. Run the Tenable Vulnerability Management scan, as per step [Scan Execution](#scan-execution)
3. Run **Sync Results**, as per item 2 from the topic [Sync Results](#sync-results)
4. Access the menu on the left of the LCC and click on **Hosts**

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-571f2ad8b48b9cfd6bd6018a10ff983901135a23%2Ftenable_hosts.png?alt=media)

1. Click on the desired **Host** which will open the Host window.
2. Click on **Tenable Plugins**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c4faa308baafe677a5352985763afd4a9edbdd19%2Ftenable_plugins.png?alt=media)

1. Click on the **Tenable Plugins** tab and search for the number 153588 in the **Search** field

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-118e5414d2aa31bdd94e0612afce72696c7c1e9f%2Ftenable_search.png?alt=media)

1. We can see that the ID 153588 is no longer present in the Plugin ID column.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-373898b5ad3ab962752cff91b3f594059aa2f407%2Ftenable_id.png?alt=media)


# User Management


# Console Users

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

The Linux Control Center allows the creation of user accounts with different levels of access permission to the LCC Management Console.

## Objective

The objective of this document is to demonstrate the step-by-step process for creating user accounts to access the LCC Console.

## Create a Super User Account.

1. Access the LCC and click **Config** in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Users**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-91f7a03264c2d9e36828172de506071df53da18c%2Fbotao_users.png?alt=media)
3. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-de6634050d293c696689b5caaed6a551d9657ee5%2Fbotao_create.png?alt=media)
4. Fill in the fields as instructed below;

**Username:** User to log in to the Console.\
**Password:** User password.\
**Confirm Password:** Field to confirm the password.\
**Email:** Email to receive notifications.\
**First Name:** First display name.\
**Last Name:** Last display name.<br>

```
![](/pt-br/images/user-management/create-user/campos_preenchidos.png)
```

1. Check the **Super User** box and click **Save** to create the account.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-424a615f421fa2e7192bbc29acd478f5b4df461a%2Fcaixa_super_user.png?alt=media)
2. The account will be listed after saving.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-db495999d301c40e632ba9dca57f37514fab444d%2Fconta_criada.png?alt=media)


# Create Super User

## Requirements

Linux Control Center = 2.12.X or higher

## Overview

The Linux Control Center allows the creation of user accounts with different levels of access permission to the LCC Management Console.

## Objective

The objective of this document is to demonstrate the step-by-step process for creating user accounts to access the LCC Console.

## Create a Super User Account.

1. Access the LCC and click **Config** in the left side menu.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)

1. Click **Users**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-91f7a03264c2d9e36828172de506071df53da18c%2Fbotao_users.png?alt=media)

1. Click **Create**.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-de6634050d293c696689b5caaed6a551d9657ee5%2Fbotao_create.png?alt=media)

1. Fill in the fields as instructed below;

**Username:** User to log in to the Console.\
**Password:** User password.\
**Confirm Password:** Field to confirm the password.\
**Email:** Email to receive notifications.\
**First Name:** First display name.\
**Last Name:** Last display name.<br>

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-366fe9f08ae4e1d359053007edf312bc83a001ca%2Fcampos_preenchidos.png?alt=media)

1. Check the **Super User** box and click **Save** to create the account.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-424a615f421fa2e7192bbc29acd478f5b4df461a%2Fcaixa_super_user.png?alt=media)

1. The account will be listed after saving.

![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-db495999d301c40e632ba9dca57f37514fab444d%2Fconta_criada.png?alt=media)


# Create Group Users

## Requirements

Linux Control Center = 2.10.X or higher

## Overview

Linux Control Center allows you to create groups with different permissions to manage user accounts that administer the LCC Console.

## Objective

This document aims to demonstrate step by step how to create user groups to access the LCC Console

## Create User Group

1. Click **Config** in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **User Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e7d8a36df8ddcae1e051febd44ecab644c2e43b9%2Fbotao_users_group.png?alt=media)
3. Click **Create**.

   ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/user-management/user-group/create_button.png)
4. Enter a name for the Group in the **Name** field

   ![](https://gitlab.com/7dev-doc/linux-control-center/-/blob/main/pt-br/images/user-management/user-group/name_field.png)
5. Click **Configure Permissions** and choose the permissions you want to enable for the group's users.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2c2628b8b92991e816d156fb244e54b89e37e6fa%2Fconfigure_permissions.png?alt=media)
6. Select the desired users and click the arrow to move them to the table on the right.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b19d25e94307788532627c0beaa564d6d054f389%2Fusuarios_selecionados.png?alt=media)
7. Click **Save** to create the group.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7cfca61bfa1f9df03c7b66e969a2e0ea551269f8%2Fbotao_save.png?alt=media)
8. The group will be listed on the **User Groups** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-de480df95d0c849cfecb3f9f8ae18bc74763d3ce%2Fgrupo_listado.png?alt=media)


# TOTP

## Requirements

* **Linux Control Center**: version **2.12.X** or higher
* **TOTP Authentication Application** (such as Google Authenticator, Authy, etc.)

***

## Overview

The **Linux Control Center (LCC)** allows you to configure two-factor authentication (2FA) through a TOTP application. This functionality increases security when accessing the Management Console.

## Objective

This document aims to guide the process of enabling 2FA in user accounts with access to the LCC Console.

## How to Enable TOTP in an LCC Access Account

1. Access the **LCC** and click on **Config** in the left side menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click on **User**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-91f7a03264c2d9e36828172de506071df53da18c%2Fbotao_users.png?alt=media)
3. Select the user for whom you want to activate **TOTP**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-070a2239db05f75c7b2b27681031336f4af5d20d%2Fselecionando_user.png?alt=media)
4. Click on the **TOTP** option to open the registration QR code.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-063f6f709aae472f3d8fb7423d69316ab252632c%2Fativando_totp.png?alt=media)
5. Scan the **QR Code** displayed using your preferred authenticator app.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3993fdf7b0dc09f371298ea2aac25d421cace700%2Fqrcode_fake.png?alt=media)

> **hint:** To disable TOTP, simply click on the **TOTP** option again and enter your username and password to confirm the operation.

1. After saving the code, simply log in normally using your enabled authentication method and then the six-digit code.

## Additional Tips

* Keep the recovery code, if provided, in a safe place.
* If you lose your authenticator device, contact your system administrator to reset 2FA authentication or, if you are logged in, reset the TOTP configuration for your user.


# Providers


# SAML


# Cisco Duo

## Requirements

Linux Control Center = 2.12.X or Higher\
Pre-configured Single Sign-On (SSO) Provider (Cisco Duo)

## Overview

The Linux Control Center allows you to configure a single sign-on (SSO) provider for the Console, providing secure and convenient access. LCC offers authentication to the Console via LDAP and SAML.

* See the image representing the authentication flow.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fdea54e7772a5ea0c40ad60e8c46f795c7247f5a%2Ffluxo_provedor.jpg?alt=media)

## Objective

The objective of this document is to present the step-by-step process to configure a Console access provider for LCC using a SAML provider.

## Application Configuration in Cisco Duo

1. Access your environment's Cisco Duo structure and create an Application with the following configurations:

* *Application Type* = Generic SAML Service Provider - Single Sign-On

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5a76e6b88058d16bbf9f966ee747242aebc84ea4%2Fsaml_type.jpg?alt=media)

### Service Provider

1. The *Assertion Consumer Service (ACS) URL* field must be filled with the endpoint from the **URL Assertion Consumer Service** field. This URL is generated after creating the SAML item in the Linux Control Center. This is the URL where Cisco Duo will perform the authentication.

* Example: <https://10.17.76.2/api/v2/authentication/saml2/acs/19>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a44442d62ad19978b0ba0811d245e752f785c651%2Fservice_provider.jpg?alt=media)

### SAML Response

1. Configure the **NameID format** and **NameID attribute** fields.

* Example: NameID attribute <http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress>

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-899a7e1e72362d305bc7957e2dc0aa000bd9b8fd%2Fsaml_response.jpg?alt=media)

### Map attributes

1. The attribute mapping *IdP Attribute*, *SAML Response Attribute*, and *Attribute Name* can be configured according to your environment's needs.

Example;

* *<http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress>* - email
* *<http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname>* - userid
* *<http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name>* - username
* *<http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name>* - name

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e43314a4da2d3cc4967f9760309e313526afe925%2Fmap_attributes.jpg?alt=media)

## User Permissions in LCC

* When using Cisco Duo login to access the Linux Control Center (LCC), the user will be automatically created in the LCC console, but without any assigned permissions. To ensure proper access to resources, it is necessary to create a Group in the LCC Console with the desired access rules and associate this group in the Cisco Duo integration configuration. In this way, authenticated users will receive permissions as defined in the linked group.

1. Click **Config** in the left sidebar menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **User Group**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e7d8a36df8ddcae1e051febd44ecab644c2e43b9%2Fbotao_users_group.png?alt=media)
3. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-904bd7a16232c84b9aae7b79ec949f07f0bacb8b%2Fbotao_create.png?alt=media)
4. Enter a name for the Group in the **Name** field.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4dbb13a4036cc9da2dde5843ddec53336ea5a80b%2Fcampo_name.png?alt=media)
5. Click **Configure Permissions** and choose the permissions you want to enable for the group's users.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-2c2628b8b92991e816d156fb244e54b89e37e6fa%2Fconfigure_permissions.png?alt=media)
6. Click **Save** to create the group.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-7cfca61bfa1f9df03c7b66e969a2e0ea551269f8%2Fbotao_save.png?alt=media)
7. The group will be listed on the **User Groups** screen.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-de480df95d0c849cfecb3f9f8ae18bc74763d3ce%2Fgrupo_listado.png?alt=media)

## Cisco Duo Configuration in LCC

1. Click **Config** in the left sidebar menu of the LCC.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Provider**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1fda6171584c70078f6a582640e204d462ba347c%2Fbotao_provedores.jpg?alt=media)
3. Click **SAML**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d69922c64bf1157c96bd67e9910b384d4b941af7%2Fbotao_saml.jpg?alt=media)
4. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-319970183908a15a4700d1650895c0801c19afea%2Fbotao_create.jpg?alt=media)
5. Access your environment's Cisco Duo and enter the *Application* data in the fields as instructed below:

   * **Name:** This field will be the name of the button on the Login screen with the Cisco Duo logo.
   * **Entity ID:** Enter the Entity ID of the *Application* configured in Cisco Duo.
   * **IDP Metadata URL:** Enter the metadata URL of your Identity Provider.
   * **Certificate:** Enter the certificate of the Application configured in Cisco Duo.
   * **LCC Groups:** Choose the *Permission Group* that will be assigned to users who access the Console through this integration with Cisco Duo.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-13c3435cc5f252b134f47954ffd4eba2c9505c0c%2Fcampos_vazios.jpg?alt=media)
6. Click the **Select an Icon** button and select the *Cisco Duo* icon to define the Login button on the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-8fe5f6f36bc96c4bfc548183429a3051c53499ac%2Fcampo_icone.jpg?alt=media)

### Attribute Map

1. Click **Next** to access the Attribute Map settings.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-b6afcbbb8a8e34cb5b82cf8d04fcb4606b403fea%2Fbotao_next.jpg?alt=media)
2. Fill in the *User Identifier Attribute* field. This field defines the Identity Provider user who will be responsible for validating the authentication. It is possible to define a key to validate the IDP response.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-662c6f417dfd59a40d7040c63c09649d11d7e2ac%2Fattribute_map.jpg?alt=media)
3. Click **Next** again and check the options as needed.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-945d50b02a9912ec4cdea4daa2d6f1a02a05f3d5%2Fnext_2.jpg?alt=media)
4. Click **Save** to create the provider in the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5e25868bbffa80b6092e72496d6aab655a5dfc56%2Fbotao_save.jpg?alt=media)

### Endpoint Registration in IDP

{% hint style="warning" %}
This step is crucial in the configuration of an identity provider; it is necessary to register the LCC Endpoint in your *Identity Provider* so that LCC has permission to perform the queries.
{% endhint %}

1. Click on the created Identity Provider and copy the values from the *URL Assertion Consumer Service* and *URL Single Logout Service* fields and register them in your Identity Provider.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d986c1f61d60410899f9f8e570bc9d5c154b379c%2Fsaml_criado.jpg?alt=media)

### Provider Permission

1. Click **Config** in the left sidebar menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6d80a46d4b182dcc1947e6dde46daf56b842c194%2Fbotao_config_ciscoduo.jpg?alt=media)
2. Click **Authentication**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-124e19e69b92b45599bb757eb183239c778b24d4%2Fbotao_authentication.jpg?alt=media)
3. Click on the **Providers** tab, select the provider, and move it to the table on the right side.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-17a989a7a0c0317cea196d1b5f9e5e406a1a3baa%2Fadicionar-ciscoduo-provedores.jpg?alt=media)
4. Click **Save** to set the Cisco Duo Provider as a valid authentication method.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-46f8663b330582876df50e27defa9f02c58386aa%2Fciscoduo_adicionado.jpg?alt=media)

## Access with Identity Provider

1. Log out with the current user and click on the created Identity Provider button, and LCC will query and read the SAML response to validate access to the Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c540efb491659ef04992bff8b1dc4221231b4808%2Fbotao_login.jpg?alt=media)


# Entra ID

## Requirements

* Linux Control Center = 2.12.X or higher
* Pre-configured Single Sign-On (SSO) Provider

## Overview

Linux Control Center allows you to configure a Single Sign-On (SSO) provider for the Console, offering secure and convenient access. LCC supports authentication via LDAP and SAML.

* See the image representing the authentication flow.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-fdea54e7772a5ea0c40ad60e8c46f795c7247f5a%2Ffluxo_provedor.jpg?alt=media)

## Objective

The objective of this document is to provide a step-by-step guide to configure an access provider to the LCC Console using a SAML provider.

## Microsoft Entra ID Configuration

1. Access the **Entra ID** platform in your environment and go to **Applications**. Select **App Registrations** and click **New Registration**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-3cadd4f6a98c1134260ca58e9647231a9504692c%2Fnovo_registro_entraid.jpg?alt=media)
2. Define a name for the application and choose the type of Microsoft Entra ID account that will have permission to access LCC.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-ca1e82ac26412892c863950e4666c17098fca5b9%2Faplicativo_preenchido.jpg?alt=media)
3. Define the scope of access to the application as desired.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-48c167e4f9a2cafebf38d9b295e1e7696c2d5fd6%2Fapi_entra_id.jpg?alt=media)
4. Click **Register**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-9469a8487137d7dfcb68a79e57dda5cc5561d34d%2Fms_entra_id_registro.jpg?alt=media)

## SAML Provider Configuration

### Registering the Provider in LCC

1. Click **Config** in the left menu of LCC.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-76d7216ee8827d2c1f5960da8bf7f578f536ea98%2Fdashboard_config.png?alt=media)
2. Click **Provider**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-1fda6171584c70078f6a582640e204d462ba347c%2Fbotao_provedores.jpg?alt=media)
3. Click **SAML**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d69922c64bf1157c96bd67e9910b384d4b941af7%2Fbotao_saml.jpg?alt=media)
4. Click **Create**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-319970183908a15a4700d1650895c0801c19afea%2Fbotao_create.jpg?alt=media)
5. Fill in the required fields as follows:

* **Name:** This will be the name of the provider button on the LCC login screen.
* **Entity ID:** Enter the ID of the application created in Microsoft Entra ID.
* **IDP Metadata URL:** Enter the Authority URL from the Entra ID application.
* **IDP Metadata Data:** Enter the metadata URL from your Identity Provider.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-13c3435cc5f252b134f47954ffd4eba2c9505c0c%2Fcampos_vazios.jpg?alt=media)

1. To obtain the IDP URL information from Microsoft Entra ID, go to the **Overview** page of the application and click **Endpoints**.

* Copy the **SAML-P Sign-on Endpoint** and paste it into the **IDP Metadata URL** field.

  ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0225a94b27b704757bc9d4261d52515414fa67c7%2Fcampo_ponto_de_extremidade.png?alt=media)

1. Click **Select an Icon** and choose the login button icon for the provider that will appear on the LCC Console login screen. You can also upload a custom icon using a Base64 string.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-e7d4a041034140c4706523ed4a0cd68e1824dbac%2Ftela_configurada.png?alt=media)
2. Click **Next**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4879bc47ee3f46ab989e154b6c6527d49c36ffa1%2Fbotao_next.png?alt=media)
3. Fill in the **User Identifier Attribute** field. This defines the user from the Identity Provider responsible for validating authentication. You can define a key to validate the IDP response.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-662c6f417dfd59a40d7040c63c09649d11d7e2ac%2Fattribute_map.jpg?alt=media)
4. Click **Next** again and select the options as needed.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-945d50b02a9912ec4cdea4daa2d6f1a02a05f3d5%2Fnext_2.jpg?alt=media)
5. Click **Save** to create the provider in the LCC Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-5e25868bbffa80b6092e72496d6aab655a5dfc56%2Fbotao_save.jpg?alt=media)

### Registering the Endpoint in the IDP

> **Important:**\
> This step is crucial in configuring the identity provider. You must register the LCC endpoint in your **Identity Provider** so that LCC has permission to perform queries.

1. Click on the Identity Provider you created and copy the **Assertion Consumer Service URL**. Paste it into the **Redirect URL** field in the Microsoft Entra ID application.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-d986c1f61d60410899f9f8e570bc9d5c154b379c%2Fsaml_criado.jpg?alt=media)
2. Field configuration in Microsoft Entra ID.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-abb55b0c6c2ec705b5a4645c96012b7881a1b9f9%2Furl_login.jpg?alt=media)

### Granting Permission to the Provider

1. Click **Config** in the left menu.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6d80a46d4b182dcc1947e6dde46daf56b842c194%2Fbotao_config_ciscoduo.jpg?alt=media)
2. Click **Authentication**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-124e19e69b92b45599bb757eb183239c778b24d4%2Fbotao_authentication.jpg?alt=media)
3. Click the **Providers** tab, select the provider, and move it to the table on the right.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-17a989a7a0c0317cea196d1b5f9e5e406a1a3baa%2Fadicionar-ciscoduo-provedores.jpg?alt=media)
4. Click **Save** to set the provider (e.g., Cisco Duo) as a valid authentication method.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-46f8663b330582876df50e27defa9f02c58386aa%2Fciscoduo_adicionado.jpg?alt=media)

## Access with Identity Provider

1. Log out from the current user and click the Identity Provider button you created. LCC will perform the query and read the SAML response to validate access to the Console.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-c540efb491659ef04992bff8b1dc4221231b4808%2Fbotao_login.jpg?alt=media)


# Authentication

## Requirements

* **Linux Control Center**: version **2.12.X** or higher
* **Pre-configured Single Sign-On (SSO)** provider

***

## Overview

The **Linux Control Center (LCC)** allows your users to centrally configure their authentication service through the **"Config Authentication"** menu.

Through this service, you can:

* Control the creation of users through external authentication providers integrated with the LCC
* Define **TOTP** settings
* Manage **active providers**
* Create authentication rules for **groups** and **users**
* Perform other security configurations

***

### Authentication Panel

1. Access the **Authentication** panel through the **Config** option in the side menu.
2. Click on the **Authentication** option.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-a032334bb37592362720e2f2164d64e6750fd8a7%2Facessando.png?alt=media)

***

### Initial Configuration

Configure the initial parameters according to your needs:

```
![](/pt-br/images/authentication/inicial.png)
```

* **Default Provider ID**: Default provider identifier, used if the user does not select a different one at the time of authentication
* **TOTP Time Tolerance**: Tolerance time to validate the TOTP code after starting the login
* **TOTP Time Tmp Token Login Validation**: Tolerance time for using a rotated TOTP token
* **Local Login All Users**: Applies the rules in this panel to all local LCC users
* **Providers Auto Create User**: Allows LCC to create the authenticated user via provider locally, if it does not already exist
* **TOTP Force All Users**: Forces all users to use TOTP to login, regardless of the provider selected

***

### Selecting Users and Groups

1. Click **Next** to select the **users** that will have rules applied during login.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-0591ab3166b504489485d8909bd0beb5d931f5c9%2Fusers.png?alt=media)
2. In the **groups** tab, select the groups that will also have the rules applied.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-04886489687681def2ba051d5ff9068aa19c52da%2Fgroups.png?alt=media)

***

### Selecting Providers

In the **Providers** tab, define which providers will be available for login.

```
![](/pt-br/images/authentication/providers.png)
```

***

### TOTP by User and Group

1. Individually select the users that will be logged in via **TOTP**.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-6610e07054ee368764ec03a7dffd547ccfccd37d%2Fusers_totp.png?alt=media)
2. Click **Next** to define the **groups** that should also use TOTP at login.

   ![](https://1620115297-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtZm19HsLxuDm2GumYKEz%2Fuploads%2Fgit-blob-4734076caa4bdf007c380a358e82c35155ea7040%2Fgroups_totp.png?alt=media)
3. Click **Save** to save the settings and apply them to the LCC Console.

***

> 💡 **Hint**: When defining users individually and **disabling the `TOTP Force All Users`** flag, other users will still be able to manually activate TOTP in their **Profile** panel to use it at login.


# Release Notes

\#Release Notes:

## 2.12.2 - 04/28/2025

* Access to the LCC Console with multiple Single Sign-On (SSO) via SAML standard.
* Access to the LCC Console with multiple LDAP providers via Active Directory or OpenLDAP.
* New Reports interface.

## 2.12.1 - 03/10/2025

* TOTP for Console access user.
* Workflow redesign.
* Possibility of performing multiple Beyondtrust integrations simultaneously.
* Web interface improvements and fixes.

## 2.12.0 - 01/06/2025

* Implementation of the Nodes screen to identify the Node Console.
* **Action Status** and **Host** columns on the Queue screen.
* Operation in a Cluster structure.
* New Installation Script for Cluster configurations.

## 2.11.0 - 11/12/2024

* Availability of the Community version of Linux Control Center
* Timeout parameterization
* Creation of the 7 Library

## 2.10.0 - 08/10/2024

* Interface improvements
* Removal of integration with PAM SenhaSegura
* Improvements in the functionality of using certificates
* Improvement in integration with VmWare allowing integration with a structure with more than 1 DataCenter
* Officialization of Integration with Tenable Security Center and Tenable Vulnerability Manager

## 2.9.0 - 05/10/2024

* HookBridge - Integration focused on Propagation Actions of BeyondTrust Password Safe.
* Officialization of Integration with Tenable Security Center and Tenable Vulnerability Manager
* SenhaSegura - Integration with PAM. - Information screen (About)
* Improvements in the script execution flow.

## 2.8.1 - 04/03/2024

* Fix Nutanix Snapshots
* Fix KB0001 - All versions prior to 2.7.0 are affected.
* Improvements in the script execution flow.

## 2.8.0 - 04/02/2024

* Various fixes in the workflow execution.
* Filter in the queue screen.
* Nutanix - Rollback / Snapshots integration.
* Parameterization of new execution variables.
* Automatic cleaning routines in the database.
* Improvements in the script execution process.
* New action to update only vulnerable packages.
* Parameterization of functional user account for BeyondTrust Password Safe.
* File backup.
* Moving of backup files.
* Creation of users, groups and directories when creating files.

## 2.7.1 - 03/19/2024

* Correction in the update report fields.
* Correction of communication with the vCenter/ESXi API.

## 2.7.0 - 03/14/2024

* Various corrections in the presentation layer.
* Discover 3.0
* Integration with VMWare.
* Reprocessing of reports.


# Introdução - Manual do Usuário

O LCC® - Linux Control Center é uma poderosa solução de gerenciamento centralizado para servidores Linux. Desenvolvido para facilitar a administração e fornecer visibilidade das tarefas executadas no ambiente Linux. O LCC é a ferramenta perfeita para equipes reduzidas que desejam realizar tarefas de administração de forma centralizada, automatizada e eficiente. Com o LCC, você pode reduzir as chances de falhas humanas e ter controle total sobre seu ambiente corporativo.

A criação do LCC tem suas raízes na complexidade do gerenciamento de atualizações de pacotes, implementação de patches, manutenção do histórico de atividades e na exigência da equipe de operações em comunicar de forma eficiente e eficaz a execução dessas tarefas e seus impactos para as esferas gerenciais.

**Principais funcionalidades:**

* Agentless - não é necessário instalar agentes nos servidores remotos
* Discover de rede automatico para inclusão de servidores
* Gerenciamento de pacotes<br>
* Identificação de pacotes vulneráveis<br>
* Gestão de contas de usuários<br>
* Gerenciamento de arquivos<br>
* Administração de serviços<br>
* Execução de scripts e playbooks<br>
* Agendamentos<br>
* Alertas<br>
* Criação de pontos de restauração em virtualizadores<br>
* Integrações diversas<br>
* Alta disponbilidade (modo cluster)<br>
* Relatórios

**Arquitetura:**

![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-0846cdb86038ae0bfa73d09b9cd68255b8720b67%2Ffluxo-lcc-completo.png?alt=media)

***

**Fale conosco**

Website: <https://linuxcontrolcenter.com.br>

Quick Start: <https://docs.linuxcontrolcenter.com.br/quick-start>

Fórum: <https://forum.linuxcontrolcenter.com.br>

Docs: <https://docs.linuxcontrolcenter.com.br>

Instagram: <https://instagram.linuxcontrolcenter.com.br>

Telegram: <https://telegram.linuxcontrolcenter.com.br>

Email Comercial: <comercial@7dev.net.br>

Email Suporte: <suporte@7dev.net.br>

Telefone: [(61) 99883-9004](tel:+5561998839004)

Whatsapp: [(61) 99883-9004](https://wa.me/5561998839004?text=Ol%C3%A1!%20Vi%20seu%20contato%20na%20p%C3%A1gina%20de%20documenta%C3%A7%C3%A3o%20do%20Linux%20Control%20Center!)


# Requisitos Mínimos


# Requisitos do Server

As tabelas abaixo indicam os requisitos mínimos de software e hardware para o Linux Control Center.

{% hint style="warning" %}
**Observação:** Não é necessário instalar previamente nenhum requisito de software. O script de instalação do LCC se encarrega de instalar todas as dependências automaticamente.
{% endhint %}

### Requisitos de Hardware

|    CPU    | Memória RAM | Espaço em Disco |
| :-------: | :---------: | :-------------: |
| 4 Núcleos |     8 GB    |      200 GB     |

### Requisitos de Software

| Sistema Operacional |        Docker       |  Banco de Dados |
| :-----------------: | :-----------------: | :-------------: |
| Debian 12 amd64-bit | Docker Engine 23.x+ | PostgreSQL 15.x |

{% hint style="warning" %}
Para instalações 'all-in-One', onde todos os componentes (Console, Worker e Alert Report) serão instalados no mesmo servidor, considere todas as regras de lançamento, com o mesmo servidor como origem. Nas instalações com servidores dedicados para cada serviço, observe os campos **Origem** e **Destino** das tabelas abaixo como referência para cada componente.
{% endhint %}

### Requisitos de Acesso Externo

|               Origem              |               Destino              |  Porta  | Protocolo |
| :-------------------------------: | :--------------------------------: | :-----: | :-------: |
| Console / Worker / Alert & Report | download.linuxcontrolcenter.com.br | TCP/443 |   HTTPS   |
| Console / Worker / Alert & Report |           deb.debian.org           |  TCP/80 |    HTTP   |
| Console / Worker / Alert & Report |         download.docker.com        | TCP/443 |   HTTPS   |
| Console / Worker / Alert & Report |     customer-portal.lcc7.online    | TCP/443 |   HTTPS   |
|          Console / Worker         |          cloud.tenable.com         | TCP/443 |   HTTPS   |
|              Console              |       7vulndb-api.lcc7.online      | TCP/443 |   HTTPS   |

### Requisitos de Acesso Interno

|     Origem     |               Destino              |               Porta               |    Protocolo   |
| :------------: | :--------------------------------: | :-------------------------------: | :------------: |
|     Worker     |               Console              |              TCP/443              |      HTTPS     |
| Alert & Report |              Database              |              TCP/5432             |       TCP      |
|     Worker     | Hosts a serem gerenciados pelo LCC | Definido de acordo com o ambiente | SSH/WinRM/ICMP |
|     Console    |           vCenter / ESXi           | Definido de acordo com o ambiente |   HTTP/HTTPS   |
|     Worker     |      BeyondTrust Password Safe     | Definido de acordo com o ambiente |   HTTP/HTTPS   |
|     Console    |       Tenable Security Center      | Definido de acordo com o ambiente |   HTTP/HTTPS   |


# Requisitos de Client

A tabela abaixo indica os requisitos mínimos necessários de software que os clientes necessitam para serem gerenciados pelo Linux Control Center.

### Requisitos de Distribuição do Client

|       Distribuição       |                                                                                                                                                                  Release                                                                                                                                                                  |
| :----------------------: | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: |
|        Alma Linux        |                                                                                                                                                    <p>Alma Linux 8<br>Alma Linux 9</p>                                                                                                                                                    |
|          Debian          |                                                                                                                                     <p>Debian 8<br>Debian 9<br>Debian 10<br>Debian 11<br>Debian 12</p>                                                                                                                                    |
|          Fedora          |                                                                                                                                                                 Fedora 37                                                                                                                                                                 |
|          CentOS          |                                                                                                                                  <p>CentOS Linux 7 (Core)<br>CentOS Linux 8 (Core)<br>CentOS Stream 9</p>                                                                                                                                 |
|         openSUSE         |                                                                                                                                              <p>openSUSE 13<br>openSUSE 14<br>openSUSE 15</p>                                                                                                                                             |
|  Oracle Enterprise Linux |                                                                                                                         <p>Oracle Enterprise Linux 7<br>Oracle Enterprise Linux 8<br>Oracle Enterprise Linux 9</p>                                                                                                                        |
| Red Hat Enterprise Linux |                                                                                                                       <p>Red Hat Enterprise Linux 7<br>Red Hat Enterprise Linux 8<br>Red Hat Enterprise Linux 9</p>                                                                                                                       |
|           Rocky          |                                                                                                                                                         <p>Rocky 8<br>Rocky 9</p>                                                                                                                                                         |
|          Ubuntu          |                                                                                                                                                    <p>Ubuntu 20.04<br>Ubuntu 22.04</p>                                                                                                                                                    |
|           Mint           | <p>Linux Mint 19.x (Tara)<br>Linux Mint 19.1 (Tessa)<br>Linux Mint 19.2 (Tina)<br>Linux Mint 19.3 (Tricia)<br>Linux Mint 20.x (Ulyana)<br>Linux Mint 20.1 (Ulyssa)<br>Linux Mint 20.2 (Uma)<br>Linux Mint 20.3 (Una)<br>Linux Mint 21 (Vanessa)<br>Linux Mint 21.1 (Vera)<br>Linux Mint 21.2 (Victoria)<br>Linux Mint 21.3 (Virginia)</p> |

### Requisitos de Software do Client

|                      Software                      |                                                                        Versão                                                                        |
| :------------------------------------------------: | :--------------------------------------------------------------------------------------------------------------------------------------------------: |
|                       Python                       |                                                       <p>2.7 ou superior<br>3.6 ou superior</p>                                                      |
| Cifras habilitadas e suportadas para login via SSH | <p>3des-cbc<br>aes128-cbc<br>aes192-cbc<br>aes256-cbc<br>aes128-ctr<br>aes192-ctr<br>aes256-ctr<br>aes128-gcm<br>aes256-gcm<br>chacha20-poly1305</p> |
|                        Sudo                        |                                                                  1.8.31 ou superior                                                                  |
|                         SSH                        |                                                               Login com Key habilitado                                                               |


# Início Rápido

## Overview

Compreender o funcionamento do LCC® - Linux Control Center é um passo essencial para garantir uma implementação bem-sucedida e um processo de OnBoarding eficiente no ambiente.

Neste Quick Start, abordaremos o funcionamento básico da ferramenta, além de apresentar os primeiros passos que devem ser realizados logo após a instalação do LCC.

## Funcionamento Básico do LCC

O LCC é uma solução de orquestração para sistemas Linux. Ele conta com uma Console Web, por meio da qual comandos podem ser enviados para o módulo Worker, responsável por executar diversas ações solicitadas pelo usuário. Além disso, o LCC dispõe de um módulo de Alert & Report, que gera alertas e registros detalhados de todas as ações realizadas na Console ou pelo Worker, proporcionando uma visão completa e centralizada das operações executadas.

O passo essencial para o processo de Onboarding do LCC é a importação dos Hosts a serem gerenciados para o banco de dados. Essa tarefa pode ser realizada utilizando o recurso Discover ou por meio da importação dos Managed Assets via integração com o BeyondTrust PasswordSafe. Somente após a importação dos Hosts Linux que o LCC consegue executar todas as Actions disponíveis.

* Existe a possilidade de manusear Hosts Microsoft Windows, em que são tratados como **Unmanaged Hosts**, com ação limitada somente a execução de script **PowerShell** por meio do WinRM.

## Como Solicitar a Licença Community

O LCC® - Linux Control Center possui uma versão Community que disponibiliza a utilização do LCC gratuitamente, restringindo apenas a quantidade de Hosts gerenciados, sendo 25 Hosts no total.

1. Acesse o link <https://start.linuxcontrolcenter.com.br>, preencha as informações corretamente, leia e concorde com os Termos e Condições de Uso do LCC

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-3185dff63588a16b6fbc7ec7dcdd5ff2813a4f9e%2Ftela_de_licenca.png?alt=media)

{% hint style="info" %}
Em seguida, você receberá o **UUID** e a **Senha** da licença Community no E-Mail cadastrado.

Caso não receba o E-Mail, verifique a caixa de Spam ou entre em contato pelos canais do Fale Conosco da página <https://docs.linuxcontrolcenter.com.br>
{% endhint %}

## Como Instalar o LCC

### Tutorial de Instalação

1. Após receber a Licença Community, siga o passo a passo para realizar a instalação do LCC no link abaixo;

   <https://docs.linuxcontrolcenter.com.br/setup-install>

### Confiança entre a Console e o Worker

1. Logo após a instalação, é necessário realizar o aceite do Worker para liberar a execução de Actions.
2. Faça login no LCC com o usuário **7dev** e senha **7dev**.

* A Url deve seguir o seguinte padrão: https\:// ip ou Hostname/console/

  ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-974731bf7c9d5334205865cd252e24a19635d8e9%2Flogin_lcc.png?alt=media)

1. Marque a caixa de Termos de uso e clique em Aceito

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-faee517b210776011e63626f47c841281a932773%2Faceite_termos%20de%20uso.png?alt=media)
2. Clique em **Config**

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-c2ecd830666fdc24d2c3a23b4dea0eee70a58c82%2Fconfig_dashboard.png?alt=media)
3. Clique em **Worker**

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-cd65fda9af58f4b015594beb0bc963576b9eda30%2Fbotao_worker.png?alt=media)
4. Clique em **Actions** e depois em **Trust**

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-d291783e31af1fedf9c271cf99572853a9c257f8%2Ftrust_worker.png?alt=media)
5. Veja que o status ficará **Accepted** indicando que o LCC está pronto para o uso !

   ![](https://3122590582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FytotrgCSM7abU2RFWBCP%2Fuploads%2Fgit-blob-f944d6e8626b8f33a6a66b8f50b7d3ba231d85cc%2Fworker_aceito.png?alt=media)

## Primeiras Tarefas Recomendadas Após a Instalação do LCC

### Execução do Discover

* Após realizar o aceite do Worker, a próxima tarefa a ser executada é o Discover.
* Veja mais detalhes técnicos a execução do do Discover do link abaixo;

<https://docs.linuxcontrolcenter.com.br/discover_lcc>

### Checar Pacotes para Encontrar Atualizações Disponíveis

* A Action recomendada para executar é a **Package Check Update**, que irá checar quais pacotes possuem atualizações disponíveis, facilitando a tarefa de atualizar todos os Hosts que estão gerenciados.
* Para executa esta Action, siga os passos do link abaixo;

<https://docs.linuxcontrolcenter.com.br/host-actions/package-check-update>




---

[Next Page](/llms-full.txt/1)

