Red Hat Satellite 5.6
Total Page:16
File Type:pdf, Size:1020Kb
Red Hat Satellite 5.6 Proxy Installation Guide Configuring, registering, and updating your Red Hat Enterprise Linux clients with Red Hat Satellite Proxy Server Edition 1 Last Updated: 2017-09-26 Red Hat Satellite 5.6 Proxy Installation Guide Configuring, registering, and updating your Red Hat Enterprise Linux clients with Red Hat Satellite Proxy Server Edition 1 John Ha Red Hat Engineering Content Services Lana Brindley Red Hat Engineering Content Services Daniel Macpherson Red Hat Engineering Content Services Athene Chan Red Hat Engineering Content Services David O'Brien Red Hat Engineering Content Services Megan Lewis Red Hat Engineering Content Services Legal Notice Copyright © 2013 Red Hat, Inc. This document is licensed by Red Hat under the Creative Commons Attribution-ShareAlike 3.0 Unported License. If you distribute this document, or a modified version of it, you must provide attribution to Red Hat, Inc. and provide a link to the original. If the document is modified, all Red Hat trademarks must be removed. Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law. Red Hat, Red Hat Enterprise Linux, the Shadowman logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries. Linux ® is the registered trademark of Linus Torvalds in the United States and other countries. Java ® is a registered trademark of Oracle and/or its affiliates. XFS ® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries. MySQL ® is a registered trademark of MySQL AB in the United States, the European Union and other countries. Node.js ® is an official trademark of Joyent. Red Hat Software Collections is not formally related to or endorsed by the official Joyent Node.js open source or commercial project. The OpenStack ® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community. All other trademarks are the property of their respective owners. Abstract This document provides guidance on installing, configuring, and updating a Red Hat Satellite Proxy Server. For further information, see the Red Hat Satellite Getting Started Guide and the Red Hat Satellite Installation Guide. Table of Contents Table of Contents .P .R . E. .F . A. .C . E. .2 . .C .H . A. P. T. .E . R. 1. .. I.N . T. .R . O. .D . U. .C . T. .I O. .N . .3 . 1.1. RED HAT SATELLITE PROXY SERVER 3 1.2. ARCHITECTURE AND OPERATIONS 3 1.3. IMPORTANT TERMS 4 .C .H . A. P. T. .E . R. 2. R. .E . Q. .U . .I R. .E . M. .E . N. .T . S. .6 . 2.1. SOFTWARE REQUIREMENTS 6 2.2. HARDWARE REQUIREMENTS 7 2.3. DISK SPACE REQUIREMENTS 7 2.4. ADDITIONAL REQUIREMENTS 7 .C .H . A. P. T. .E . R. 3. I. N. .S . T. A. .L . L. I. N. .G . .R . E. .D . .H . A. .T . .S .A . T. .E . L. L. .I T. .E . .P .R . O. X. .Y . .1 .0 . 3.1. BASE INSTALL 10 3.2. RED HAT SATELLITE PROXY SERVER INSTALLATION PROCESS 10 3.3. AUTOMATING SATELLITE PROXY SERVER INSTALLATION 14 .C .H . A. P. T. .E . R. 4. .C .O . .N . F. I. G. .U . R. .I N. .G . .S . A. .T . E. L. .L .I .T .E . .P . R. .O . X. .Y . .T . O. U. .S . E. C. N. .A . .M . E. R. .E . C. O. R. .D . S. .1 .6 . 4.1. PREREQUISITES 16 4.2. ADDING CNAME RECORDS TO THE SATELLITE PROXY SERVER CONFIGURATION 16 4.3. GENERATING AND USING MULTI-HOST SSL CERTIFICATES 16 .C .H . A. P. T. .E . R. 5. U. P. G. .R . A. D. .I N. .G . .A . .R . E. .D . .H . A. .T . .P . R. .O . X. .Y . .S . E. .R . V. .E .R . .I .N . S. .T .A . L. .L .A . T. .I O. N. .1 .8 . 5.1. PREREQUISITES 18 5.2. UPGRADING YOUR PROXY INSTALLATION 18 .A . P. .P .E . N. .D . I. X. A. .. .S . A. .M . P. .L . E. .S . A. .T . E. .L .L .I .T .E . .P . R. .O . X. .Y . .S . E. .R . V. .E .R . .C . O. .N . .F .I G. .U . .R . A. .T .I .O . N. F. .I L. E. .1 .9 . .A . P. .P .E . N. .D . I. X. B. .. .R . E. .V .I .S . I.O . N. H. .I .S .T . O. .R . Y. 2. .0 . 1 Proxy Installation Guide PREFACE Red Hat Network provides system-level support and management of Red Hat systems and networks. It brings together the tools, services, and information repositories needed to maximize the reliability, security, and performance of Red Hat systems. To use Red Hat Network, system administrators register software and hardware profiles, known as System Profiles, of their client systems with Red Hat Network. When a client system requests package updates, only the applicable packages for the client are returned. Red Hat Satellite (Satellite) allows organizations to use the benefits of Red Hat Network without having to provide public Internet access to their servers or other client systems. System profiles are stored locally on the Satellite server. The Satellite website is served from a local web server and is only accessible to systems that can reach the Satellite. All package management tasks, including errata updates, are performed through the Satellite server. Satellite provides a solution for organizations that require absolute control over and privacy of the maintenance and package deployment of their servers. It allows Red Hat Network customers the greatest flexibility and power in keeping systems secure and updated. Modules can be added to the Satellite server to provide extra functionality. 2 CHAPTER 1. INTRODUCTION CHAPTER 1. INTRODUCTION 1.1. RED HAT SATELLITE PROXY SERVER Red Hat Satellite Proxy Server is a package-caching mechanism that reduces the bandwidth requirements for Red Hat Satellite and enables custom package deployment. Satellite Proxy customers cache RPM packages, such as Errata Updates from Red Hat or custom packages generated by their organization, on an internal, centrally-located server. Client systems then receive these updates from Red Hat Satellite Proxy rather than by accessing the Internet individually. Although the packages are served by Red Hat Satellite Proxy, clients' system profiles and user information are stored on a secure, central Red Hat Satellite Server. The Satellite Proxy acts as a go- between for client systems and the Red Hat Satellite Server. Only the package files are stored on the Satellite Proxy. Every transaction is authenticated, and the Red Hat Update Agent checks the GPG signature of each package retrieved from the local Satellite Proxy. In addition to storing official Red Hat packages, the Satellite Proxy Server can be configured to deliver an organization's own custom packages from private channels. For example, an organization could develop its own software, package it in an RPM, sign it with its own GPG signature, and have the local Satellite Proxy Server update all of the individual systems in the network with the latest versions of the custom software. Advantages of using Satellite Proxy Server include: Scalability: one organization can support multiple local Red Hat Satellite Proxies. Security: a secure connection is maintained from the client systems to the local Satellite Proxy, and from there to the Red Hat Satellite servers. Saves time: packages are delivered significantly faster over a local area network than the Internet. Saves bandwidth: packages are only downloaded once from Red Hat Satellite (using the local Satellite Proxy Server's caching mechanism), instead of downloading each package separately to each client system. Customized updates: create an automated package delivery system for custom software packages, as well as official Red Hat packages required for the client systems. Customized, private Red Hat Satellite channels allow an organization to automate delivery of in-house packages. Customized configuration: restrict or grant updates to specific architectures and operating system versions. 1.2. ARCHITECTURE AND OPERATIONS The Red Hat Update Agent or Package Updater on the client systems does not directly contact a Red Hat Satellite Server. Instead, the client (or clients) connects in turn to a Satellite Proxy Server that connects to a Red Hat Satellite Server. Thus, the client systems do not need direct access to the Internet. They need access only to the Satellite Proxy Server. IMPORTANT Red Hat strongly recommends that clients connected to a Satellite Proxy server be running the latest update of Red Hat Enterprise Linux to ensure proper connectivity. 3 Proxy Installation Guide Clients that access a Red Hat Satellite Proxy are still authenticated by Red Hat Satellite but in this case the Satellite Proxy provides both authentication and route information to Red Hat Satellite. After a successful authentication, the Red Hat Satellite Server informs the Satellite Proxy server that it is permitted to execute a specific action for the client. The Satellite Proxy server downloads all of the updated packages (if they are not already present in its cache) and delivers them to the client system. Requests from the Red Hat Update Agent or Package Updater on the client systems are still authenticated on the server side, but package delivery is significantly faster because the packages are cached in the HTTP Proxy Caching Server or the Satellite Proxy server (for local packages). The Satellite Proxy server and client system are connected over the LAN and transfer speeds are limited only by the speed of the local network.