System Administration
Total Page:16
File Type:pdf, Size:1020Kb
S&C IntelliTeam® DEM Distributed Energy Management Controller System Administration Table of Contents Section Page Section Page Overview Installing S&C Application Updates .............. 34 Administration Phases ......................... 2 DCR Authorization File ........................ 35 Factory Software DEM Controller Time Source ................... 36 Manufacturing the SSD Image ................... 3 DEM Audio Annunciations ..................... 38 Windows Patch Management ................... 39 Installation and Commissioning DEM Event and Diagnostic Logs ................ 40 Planning Connectivity .......................... 5 Oracle Database Troubleshooting ................ 47 System Addressing Conventions. 6 Communication Port Configuration ................ 6 Database Administration Multi-Homed DEM Configuration ................. 7 SQL Developer .............................. 51 Custom Configuration .......................... 7 Rebuilding the Oracle Database ................. 59 DEM Backup ................................. 7 Preparing Schemas and Roles .................. 60 Pre-Commissioning Completion .................. 7 Exporting Dashboard History to Excel ............ 60 Hardware Installation .......................... 8 DEM Alarm Notifications and Reports ............ 64 Configuring DEM Software ...................... 8 Restoring the Oracle Database .................. 70 Windows Configuration ......................... 8 Changing DEM Host Name .................... 75 Device Interface Configuration ................... 11 Customizing the DEM ......................... 79 Final Windows Configuration .................... 15 DEM Reference and Security DEM Storage Organization, Backup, and Windows Server 2008 R2 Features .............. 84 Recovery .................................... 18 Firewall and Ports In Use ...................... 84 Disk Partitioning and Volume Assignment .......... 19 Solidifier Administration. 84 Normal and Emergency Boot Procedures. 19 LGPO Management of DEM Security Controls ..... 86 Automated Disk Backup Procedure .............. 20 RDP Connections to DEM ..................... 88 System Recovery from Internal Backups .......... 20 Network Configuration ........................ 92 Recovery from External USB or Network Backups ... 21 DEM Firewall Operation ....................... 93 Recovery Using a Replacement DEM ............ 21 DEM Software Architecture .................... 97 Oracle Database Recovery ..................... 21 .................. 99 Recreating Boot Menu, Recovery Image, etc.. 21 System Addressing Template SQL Developer for Single-sign-on Accounts 2... 10 DEM System Maintenance .................... 23 System Administration Database Schema Table CES_HUB List of Tables ....................... 103 DEM Backup ................................ 27 ITSG_COMMON List of Tables .................. 104 Adding New Users ........................... 30 Deleting Users .............................. 34 October 6, 2014© S&C Electric Company Instruction Sheet 1047-521 Overview The IntelliTeam DEM computer is an application-specific, Microsoft Windows Server 2008 R2-based controller. It is a prepackaged, rack-mounted PC, ready for installation and commissioning, extensively engineered to integrate into a distribution system oper- ations network with minimum reliance on outside systems and network connections. It has a database management system, its own GIS database and system map, and a complete DNP master-slave communications engine. Because the DEM is a self-contained controller it provides a very secure operating environment with a minimum sacrifice of convenience. There are several aspects of this that will be appreciated by security administrators, without creating significant difficul- ties for the users: 1. No connections to the Internet are required for day-to-day operation of the DEM. The only access point to the outside world is through a secure, encrypted Windows Remote Desktop connection. 2. Security settings for thousands of Windows components have been pre-applied using a Windows-specific feature calledGroup Policy Objects or GPOs. 3. Database security and Windows security are unified—when a user logs in, both the Windows security settings and database security settings are automatically applied. The user need not remember any other passwords. All access is controlled at a very granular level, allowing the system to be shared easily between many users with different roles. Each user may be granted a unique collection of roles, or all users can be granted the same roles. 4. Communication channels can be flexibly configured, allowing traffic to be well controlled, based upon security risk. For example, WAN traffic to the CES Units, typically a less-secure environment, can be both physically and logically isolated from other network resources. The DEM has numerous serial and Ethernet ports, each of which can be configured based on customer requirements. Administration Phases There are distinct administration phases in the DEM installation, from manufacturing to customer operation. • DEM manufacturing—A standard image is loaded onto the DEM SSD drive. This image contains the initial state of the DEM software and database. The generation of this image is described in the DEM Bare Metal Build Manual, an internal S&C document. • DEM pre-ship customer staging—After manufacturing, and before shipment of the DEM to the customer, a few customizations are performed. These include updating windows patches, installing customer/project-specific options such as the map tiles database; and GIS, asset and electrical connectivity data. • DEM initial customer installation—At the time of initial DEM installation, customer specific adjustments will be made: – Configure the two Ethernet ports to customer requirements. – TCP/IP and serial port information will be configured in the Oracle database. – The DEM may be added to the customer domain if desired. Otherwise it will remain as its own unique Windows Workgroup server. – Configure time base to access customer time resource, GPS, NTP server, or domain controller. – Install any customer provided monitoring and logging software clients. – Adjust S&C standard security posture to conform to customer requirements. • DEM ongoing system maintenance—by the customer and S&C. – Add or delete users from Windows and Oracle – Reconstruct Oracle database – Perform Oracle database backups (dumpfile). This document covers initial customer installation, and system maintenance. 2 S&C Instruction Sheet 1047-521 Factory Software Manufacturing The standard image is loaded onto the DEM SSD drive. It is then updated to include the SSD Image improvements or bug fixes to applications and database contents. It is also updated for the latest Windows and other component and security patches, and verified to be opera- tional. These SSD Image features are important to the system administrator: • Built with Windows Server 2008 R2 SP1. • Includes McAfee Anti-Virus software and the McAfee Solidifier. These are recom- mended security components. Although they may be removed or replaced with other security components as a customer option, we recommend that the provided components be used. • The image is updated with all Microsoft updates as of the time of preparation for shipment. The automatic Microsoft update mechanism is disabled by configuration. The customer has the option to re-enable automatic updating via the Internet in lieu of the provided manual update process. However, we recommend that these updates only be applied under manual control to avoid random reboots of the DEM, and the corresponding service interruptions. • The computer name is set to DEM on the workgroup DEM-CONTROLLER. The customer has the option of renaming the computer and/or joining the customer’s domain. • Initial roles installed are: Application Server, File Services, and Web Server (IIS). • Initial features installed are: Desktop Experience, Ink and Handwriting Services (required by the desktop experience feature), Remote Server Administration Tools, Windows Process Activation Service, Windows Server Backup, and .NET Frame- work version 4.51. • Password policy is relaxed through group policy. No password complexity require- ment, passwords as short as 3 characters are accepted. • Through group policy, the initial logon experience suppresses the automatic startup of Server Manager, and Initial Configuration Tasks control panels. • A collection of default users are added to facilitate S&C customer deployment of the DEM. The following users are added/changed: – The windows standard user id “Administrator” is renamed to be “Support.” – Administrative users: S&C configures several user IDs for its internal support personnel. All of these user IDs have the text: “SandC_” prepended to the name. – The user ID “sandc” is configured for use ONLY by applications requiring admin- istrative rights. This ID should not be assigned to a person and should not be included in the Remote Desktop Users group. – Unprivileged users are not configured before shipment, but can be configured during field deployment. • Six Windows user groups are created corresponding to six Oracle roles: CES_ADMIN, CES_COMMTECH, CES_OPERATOR, CES_PLANNER, CES_SCA- DATECH, and CES_SECADMIN. • The default users are defined to Oracle for single-sign-on usage as follows: – admin all roles – SandC_... all roles NOTE: Other IDs for initial customer use are also configured. The names and initial passwords for all customer-accessible accounts are provided directly