Adding privileged execution to commands
BMC Helix Discovery is shipped without any commands that use privileged execution. The following example procedure describes how to add privileged execution to
lsof commands. You must do the same for any command that you want to execute as a privileged user.
The individual discovery scripts for each platform,
getFileSystems, and so on, use a privilege mechanism that is configured in the
initialise script. You do not need to edit the individual scripts to escalate privileges, only the
To configure execution of a command as a privileged user
- From the main menu, click the Administration icon.
The Administration page opens.
- In the Discovery section, click Platforms.
- Click the OS link corresponding to the commands on which you want to add the privileged execution.
- In the Action column of the
initialisemethod row, click Edit.
The Edit window shows the script.
- Click in the edit window to enlarge it.
- In your browser, use the Find function to search for the PRIV section (search for
PRIV_XXXto find the beginning of the PRIV section).
In the PRIV function (in this example
PRIV_RUNCMD), add the command required (for example,
dzdo) to run the commands as a privileged user.
Alternatively, if you need to specify the path:
You can also limit the privilege escalation to a particular command; in this case,
The screen is refreshed, and the
initialisemethod is highlighted to show that it has changed from the default.
Click Show Differences to see the differences between the default script and the current script.
$@ represents the command that BMC Helix Discovery issues. Adding
sudo (or a similar privileged command) tells it how to escalate the privilege for that command. Now when a script needs to call
pmap, it calls the
PRIV_RUNCMD() command with the full command it needs to run, which then runs
pmap with the correct privilege.
If the path is specified, it will affect all discovery commands that use that function. The privileged command might not always be at the same place on all discovery targets.
If the path is not specified, the privileged command will be found with the path of the user profile and the BMC Helix Discovery path environment variable. You can check the path environment variable, see Managing the discovery platform scripts.
You must add a privileged execution method to whichever commands you require so that you gain the fullest possible discovery. The available commands, their impact on discovery, and the platforms they are available on are described on the Privileged commands page.
Password prompt in privileged command execution
sudo (or similar privileged command) configuration on a target host requires the user password to be entered at the command line, discovery resends the credential already used to log on to the target.
In such situations however, if the default sudo "
Password:" prompt has been customized on target systems (for example, by setting the SUDO_PROMPT environment variable, or specifying a passprompt entry in the target's sudoers file), then the
initialize script for the corresponding platform must be edited to specify:
Privileged commands in Solaris
Solaris versions 9 and later no longer use sudo as the preferred method of privilege escalation, rather, they use a more sophisticated Role Based Access Control (RBAC) privilege mechanism. One of the ways of granting a user escalated privileges is to assign them a role, which can be either system, or user defined. The preferred way to provide escalated privileges for BMC Discovery is to grant the
proc_owner role to the discovery user. This enables the discovery user to obtain information on processes that belong to other users.
An alternative method is to use elevated profiles using the
pfexec command. This prompts for a password, but will be handled by the discovery scripts in the same way as