You can install Kaspersky Security Center Linux on Linux devices by using an answer file to run an installation in silent mode, that is, without user participation. The answer file contains a custom set of installation parameters: variables and their respective values.
Before installation:
If you use the operating system RED OS 7.3.4 or later or MSVSPHERE 9.2 or later, install the libxcrypt-compat package for the correct function of Administration Server.
To install Kaspersky Security Center Linux in silent mode:
# adduser ksc
# groupadd kladmins
# gpasswd -a ksc kladmins
# usermod -g kladmins ksc
# adduser ksciam
# gpasswd -a ksciam kladmins
# usermod -g kladmins ksciam
psql -U postgres; CREATE DATABASE <iam_db_name>;
mysql -u root -p; CREATE DATABASE <iam_db_name>;
VARIABLE_NAME=variable_value format to the answer file, each one in a separate line. The answer file should include the variables listed in the table below.KLAUTOANSWERS environment variable in the root or user environment containing the full name of the answer file including the path, for example, with the following command:export KLAUTOANSWERS=/tmp/ksc_install/answers.txt
In the root environment:
# apt install /<path>/ksc64_[version_number]_amd64.deb# yum install /<path>/ksc64-[version_number].x86_64.rpm -yIn the user environment:
$ sudo -E apt install /<path>/ksc64_[version_number]_amd64.deb$ sudo -E yum install /<path>/ksc64-[version_number].x86_64.rpm -y/opt/kaspersky/ksc64/sbin/kladduser -n ksc -p <password>, where the password must contain at least 8 characters.
Variables of the answer file used as parameters of Kaspersky Security Center Linux installation in silent mode
Variable name |
Required |
Description |
Possible values |
|
Yes |
Confirms that you understand and accept the terms of the End User License Agreement. |
|
|
Yes |
Confirms that you understand and accept the terms of the Privacy Policy. |
|
|
Yes |
The Administration Server DNS-name or static IP address. |
DNS name or IP address |
|
No |
The Administration Server port number. Optional, default value is 14000. |
Port number |
|
No |
The Administration Server SSL port number. Optional, default value is 13000. |
Port number |
|
No |
The number of the port for working with OpenAPI. Also this port is used for receiving connections from Kaspersky Security Center Web Console.Optional, default value is 13299. |
Port number |
|
No |
The number of the port for working with the klakaut utility. Optional, default value is 13291. The klakaut utility and a Help system for it are located in the Kaspersky Security Center Linux installation folder. This port is closed by default. If you want to use the klakaut utility to automate the Kaspersky Security Center Linux operation, open the 13291 port by using the klscflag utility. |
Port number |
|
No |
The approximate number of devices that you intend to manage. This setting is used to optimize network load. Optional, default value is 1.
|
|
|
Yes |
The database management system type: MySQL (MariaDB) or Postgres. |
|
|
Yes |
The database server IP address. To use a PostgreSQL, a Postgres Pro Built-in High Availability cluster, or a Platform V Pangolin DBMS cluster, enter DNS names or IP addresses and ports of all nodes in the following format:
Alternatively, if you want to use a Platform V Pangolin DBMS cluster, you can specify only the DNS name or IP address of the master node, or the replica node, when specifying the DBMS address. |
IP address |
|
Yes |
The database server port. Default value for MySQL (MariaDB) is 3306; default value for Postgres is 5432. |
|
|
Yes |
The database name. The name of the database must be different from the IAM database name specified in the |
|
|
Yes |
The username of a user that has access to the database. |
|
|
Yes |
The password of a user that has access to the database. |
|
|
No |
The address to connect to IAM by Node.js. User browsers will be redirected to this address by OpenIDConnect as well. If you do not specify this variable, the DNS name of the computer with Administration Server installed is used. |
FQDN |
|
Yes |
The account name to start the IAM service. The account must be a member of the security group specified in |
ksciam |
|
Yes |
The IAM database management system type: MySQL (MariaDB) or Postgres. |
or
|
|
Yes |
The IAM database server address. To use a PostgreSQL, a Postgres Pro Built-in High Availability cluster, or a Platform V Pangolin DBMS cluster, enter DNS names or IP addresses and ports of all nodes in the following format:
Alternatively, if you want to use a Platform V Pangolin DBMS cluster, you can specify only the DNS name or IP address of the master node, or the replica node, when specifying the DBMS address. |
IP address |
|
Yes |
The IAM database server port. Default value for MySQL (MariaDB) is 3306; default value for Postgres is 5432. |
3306 or 5432 |
|
Yes |
The username of a user that has access to the IAM database. If the IAM database type is MySQL (MariaDB) and has both of the following settings:
ensure that the specified user has either of the following DBMS privileges:
|
|
|
Yes |
The password of a user that has access to the IAM database. |
|
|
Yes |
The IAM database name. The name of the IAM database must be different from the database name specified in the Specify a manually created empty database. |
|
|
Yes |
The security group name for services. |
|
|
Yes |
The account name to start the Administration Server service. The account must be a member of the security group specified in |
|
|
Yes |
The account name to start other services. The account must be a member of the security group specified in |
|
If the Administration Server is to be deployed as a Kaspersky Security Center Linux failover cluster, the answer file must include the following additional variables: |
|||
|
Yes |
The node number (1 or 2). |
|
|
Yes |
The state share mount point. |
|
|
Yes |
The data share mount point. |
|
|
Yes |
The failover cluster connectivity mode. |
or
|
In case the |
|||
|
Yes |
The virtual network adapter name. |
|
|
One of these variables is required |
The virtual network adapter IP address. |
IP address |
|
The virtual network adapter IPv6 address. |
IPv6 address |
|