Skip to main content

Desktop Edge Deployment Guide

Caution​

Table of Contents​

  1. Server Installation and Server Configuration
  2. XMPP Installation and Configuration
  3. Admin Page Settings
  4. Appendix

1. Server Installation and Server Configuration​

Open Firewall Information​

  • A firewall distinguishes between information that is opened internally on the server and information that needs to be opened for external access.

  • Open Firewall Ports (Internal)

    • 9090: openfire web console access port
    • 5222: XMPP chat port (connection between server and work PC)
    • 6222: SSH Port (Work PC -> Server Reverse Connection)
    • 8080(80/443): Desktop Service Web server access port
    • 9080: Desktop Service Configuration Page Access Port
  • Open Firewall Ports (External)

    • 8080(80/443): Desktop Service Web server access port
    • 5222(Optional): Open is required when using a public desktop, connection between the public desktop located externally and the server.
  • Check Open Firewall

    $ sudo firewall-cmd --list-all

Check Server Installation Package​

1) Copy (move) the shieldathome.tar.gz file to the /opt folder and extract it.​

  • Unzip command

    $ sudo tar -xvf shieldathome.tar.gz

2) Move to the extracted shieldathome folder​

  • Check package installation status
    unpackImg

Changing SSH Port​

  • default 22the SSH port of the port6222Change to port

1) Install policycoreUtils​

  • *CentOs Series

    $ sudo yum install -y policycoreUtils-python

  • *Ubuntu family

    $ sudo apt-get install -y policycoreutils-python-utils

  • *Closed Network Environment

    • Using the install file included in the package

    $ /opt/shieldathome/policycoreutils_centos.sh

2) Change sshd configuration​

  1. vi /etc/ssh/sshd_config
  2. #Port 22 > Port 6222 (port change history reflected)
  3. semanage port –a –t ssh_port_t –p tcp 6222 (Execute command to change to port 6222)
  4. service sshd restart (restart sshd)
    sshd

Run server installation script​

  • Move to the server package location and execute the installation script

    $ /opt/shieldathome/install.sh

  • *After executing the script

    1. OS Selection
    2. Database Language Selection
    3. Setting Database Password (Must Read)

    installSelect

guacamole log rotate configuration​

  1. Add logrotate configuration

$ vi /etc/logrotate.d/guacd

  • Add the following content
/var/log/guacd.log
{
        daily
        rotate 30
        compress
        missingok
        dateext
        notifempty
        dateyesterday
}
  1. Creating a folder for scripts and moving files

$ sudo mkdir /usr/logrotate
$ sudo mv /etc/cron.daily/logrotate /usr/logrotate
$ ls /usr/logrotate

  • Check that it is displayed as shown in the image below.
    installSelect
  1. Add crontab configuration

$ crontab -e

  • Add the following content

0 0 * * * /usr/logrotate/logrotate

Replace SHIELDGate Desktop Agent file (if necessary)​

  1. Move to the original file location

$ cd /opt/app/tomcat9/webapps/workathome/resources/new/

  1. Rename existing file (backup)

$ sudo mv SHIELDGateSetup.exe SHIELDGateSetup.exe_backup

  1. Move (copy) to the existing file location after uploading a new file
  2. Change New File Name

$ sudo mv 업로드파일명 SHIELDGateSetup.exe

Change Server Configuration File​

  1. Change API Service Settings

$ sudo vi /opt/app/tomcat9/webapps/workathome/WEB-INF/classes/properties/server.properties

  • jdbc.password
    • Check if the entered password is correct.
  • internal.ipaddr=xxx.xxx.xxx.xxx
    • Enter the internal IP of the server
  • SHIELDGate.OAuth.clientId
  • SHIELDGate.OAuth.secretKey
  • SHIELDGate.OAuth.masterExtra
    • Filling in the information for the master tenant SHIELDGate app created in IdGP
  • SHIELDGate.OAuth.apiUrl
    • Enter IdGP server address
  • SHIELDGate.OAuth.extra
    • Enter the company id of the registered company.
  • SHIELDGate.OAuth.appClientId
    • Enter the SHIELDGate app ID within the company
  • SHIELDGate.Oauth.logUrl
    • Enter the integrated log server address
  • root.SHIELDGateUrl
    • Enter SHIELDGate server address
  • *Additional Settings
  • Screen logger usage setting (use true, do not use false)
    • dxl=false
    • *SHIELDGateSetup.exe's upload path is/home/dxl/download/changed to
  • root.useSrt
    • Use of SRT
    • Usage - 1, Not Used (RDP) - 0
  1. Change Web Service Settings

$ vi /opt/app/tomcat9/webapps/workathome/resources/static/config.js

  • VUE_APP_SHIELDGATE_URL
    • Enter SHIELDGate server address
  1. Server Restart

$ sudo systemctl restart tomcat

Check Server Normal Operation & Configuration​

{서버주소}:8080(Web service port) access > Check normal page display​

afterInstall

{서버주소}:9080(Settings Page) Access > Click "Login" Button​

  • 데이터베이스Tab Selection
    • 접속테스트Click the button to confirm normal database access
  • 웹서버Tab Selection
    • Select whether to use SSL
      • Upload certificate file and enter password when using
      • .keystoreUsing the format file
    • Select whether to use port forwarding
      • Forwarding Port When Using443Input
    • 적용하기Button Click
  • 로그아웃Tab Selection