Searching the Help
To search for information in the Help, type a word or phrase in the Search box. When you enter a group of words, OR is inferred. You can use Boolean operators to refine your search.
Results returned are case insensitive. However, results ranking takes case into account and assigns higher scores to case matches. Therefore, a search for "cats" followed by a search for "Cats" would return the same number of Help topics, but the order in which the topics are listed would be different.
Search for | Example | Results |
---|---|---|
A single word | cat
|
Topics that contain the word "cat". You will also find its grammatical variations, such as "cats". |
A phrase. You can specify that the search results contain a specific phrase. |
"cat food" (quotation marks) |
Topics that contain the literal phrase "cat food" and all its grammatical variations. Without the quotation marks, the query is equivalent to specifying an OR operator, which finds topics with one of the individual words instead of the phrase. |
Search for | Operator | Example |
---|---|---|
Two or more words in the same topic |
|
|
Either word in a topic |
|
|
Topics that do not contain a specific word or phrase |
|
|
Topics that contain one string and do not contain another | ^ (caret) |
cat ^ mouse
|
A combination of search types | ( ) parentheses |
|
Agent recertification
This section describes how to recertify the agent on one or more managed servers. You can recertify the agent on one or more servers separately from a full core recertification process. The full core recertification process recertifies the core and all agents. For more information, see Agent versus core recertification and SA Core recertification.
To recertify the agents on one or more managed servers:
- In the SA Client, select the Devices tab.
- Under the Servers node, select All Managed Servers or Virtual Servers. This displays all the corresponding servers.
Or under Device Groups, select one or more device groups.
- Select the Actions menu, or right-click and select Run > Agent Recert.
Or if Run Extension > Recertify Agent is not shown, select Run Extension > Select Extension. This displays the Select Extension window and lists the available extensions. Select Recertify Agent on the Managed Servers in the Select Extension window, then select OK.
This displays the Run Program Extension window showing the servers or device groups you selected.
- At any time, you can select Start Job to accept all the remaining default settings and run the job.
- Optionally use Include Devices to add servers or device groups.
- Optionally use Remove to remove servers or device groups.
- Select Next. This displays the Program screen. Do not make any changes on the Program screen.
- Select Next. This displays the Options screen.
- On the Options screen, you can change the program timeout value, request detailed information about the job with the -debug option, or specify the amount of job output to save.
- Program Timeout—Specify the maximum time in minutes you want the agent recertify job to run. If the agent recertify job fails, it will continue running for the specified time period. If after that time period it has not succeeded, it will abort and display an error message.
- Usage options—Enter “-debug” in the text box if you want additional details about the job to be displayed.
- Output Options—Specify what you want done with the program output after the job finishes. If you specify “Discard all program output,” then all the output will be unavailable when you open the completed job.
- Select the Next button. This displays the Scheduling screen. Specify when you want the job to run.
- Select the Next button. This displays the Notifications screen.
- On the Notifications screen, specify the email recipients and whether they should receive email messages if the job fails or succeeds or both.
- Select Next. . This displays the Job Status screen.
- Select Start Job. This starts the job and displays the status.
- Select any server to display details on the status of the job on that server.
- After the agent recertify job finishes, you can optionally run a communication test on your servers to verify the agents on them.
Agent recertification phases
The following three phases are Agent Recertification phases:
- Phase 4: Distributing new Agent CA. The purpose of this phase is to ensure continuous Agent-to-Agent communication (recertified Agents communicating with Agents that have yet to be recertified). In addition, it ensures that the automated communications job that performs a device communications test to the Word will succeed with the re-certified Word, which were introduced during phases 1-3.
- Phase 8: Recertify the Agents. This is a required phase. The purpose of this phase is to issue new crypto material to the Agents.
- Phase 12: Cleanup the old Agent CAs. This phase is optional. If you do not wish to trust both the old and new CA hierarchies, you must use this phase to remove the old CAs. Otherwise, you can skip this phase.
Agent recertification jobs
Each Agent recertification phase is accomplished by a recurring job. This job is dictated by the properties shown in the following table, which you must specify in the Core Recertification configuration file:
Property Name |
Req? |
Description |
Example |
---|---|---|---|
agent_recert.all.
facilities
|
No | The delay in seconds for starting the agent recert jobs after entering the agent recert phases. The value must be between 120 and 7200 seconds. This property is optional. The default delay is 3 minutes. |
The property is available in SA 9.17, 10.03, 10.11,10.22 and later. |
agent_recert.all.
|
No |
The start time for the Agent Recertification phase. You may overwrite this value for a given facility by specifying the Start time must be in the following format,
Only the hour and minute components are needed. If the specified time has already passed, the Agent Recertification job will start at the specified time the next day. |
|
|
No |
If present, the start time of the given facility will be used instead of |
|
|
Yes |
The duration, in hours, for the Agent Recertification job. Duration dictates how long the Agent Recertification job runs before stopping. If the duration has elapsed and the success rate has not been reached, the Agent Recertification job will continue at the next start time. You can overwrite this value for a given facility by specifying the Duration must be an integer value between 1 and 24. |
|
|
No |
If present, the duration of the given facility will be used instead of |
|
|
Yes |
The success rate (in whole percentage) for each facility for the Agent Recertification job. For example, if there are 1000 managed servers in You can overwrite this value for a given facility by specifying the Success rate must be an integer value between 1 and 100. |
|
|
No |
If present, the success rate of the given facility will be used instead of agent_recert.all. |
|
|
No |
The job notification for the Agent Recertification job. You can overwrite this value for a given facility by specifying the |
|
|
No |
If present, the job notification for the given facility will be used instead of |
|
agent_recert.using_cdr
|
Yes |
Indicates whether the new CAs are to be pushed to the agents. Skipping this phase might result in later phases to fail. The default value is 1. |
agent_recert.using _cdr=1 |
Agent Recertification Job Flow
The following figure shows the Agent Recertification job flow:
There can be only one Agent Recertification job, scheduled or active, per facility at any given time. An Agent Recertification job will terminate only if:
- The success rate has been achieved
- You explicitly cancel the job
- A fatal error occurs
We welcome your comments!
To open the configured email client on this computer, open an email window.
Otherwise, copy the information below to a web mail client, and send this email to hpe_sa_docs@hpe.com.
Help Topic ID:
Product:
Topic Title:
Feedback: