6.6

Table Of Contents
n
Disable the vRealize Operations Manager user account that you use for agent registration after the
installation is over. You must enable the users access for agent administration activities. For more
information, see the topic called Conguring Users and Groups in vRealize Operations Manager in the
vRealize Operations Manager Help.
n
If a system that runs an agent is compromised, you can revoke the agent certicate using the
vRealize Operations Manager user interface by removing the agent resource. See the section called
Revoking an Agent for more detail.
Minimum Required Permissions for Agent Functionality
You require permissions to install and modify a service. If you want to discover a running process, the user
account you use to run the agent must also have privileges to access the processes and programs. For
Windows operating system installations, you require permissions to install and modify a service. For Linux
installations, you require permission to install the agent as a service, if you install the agent using a RPM
installer.
The minimum credentials that are required for the agent to register with the vRealize Operations Manager
server are those for a user granted the Agent Manager role, without any assignment to objects within the
system.
Linux Based Platform Files and Permissions
After you install the End Point Operations Management agent, the owner is the user that installs the agent.
The installation directory and le permissions such as 600 and 700, are set to the owner when the user who
installs the End Point Operations Management agent extracts the TAR le or installs the RPM.
N When you extract the ZIP le, the permissions might not be correctly applied. Verify and ensure that
the permissions are correct.
All the les that are created and wrien to by the agent are given 700 permissions with the owner being the
user who runs the agent.
Table 31. Linux Files and Permissions
Directory or File
Permissi
ons
Groups or
Users Read Write Execute
agent directory/bin 700 Owner Yes Yes Yes
Group No No No
All No No No
agent directory/conf 700 Owner Yes Yes Yes
Group No No No
All No No No
agent directory/log 700 Owner Yes Yes No
Group No No No
All No No No
agent directory/data 700 Owner Yes Yes Yes
Group No No No
All No No No
agent directory/bin/ep-
agent.bat
600 Owner Yes Yes No
Group No No No
All No No No
Secure Configuration
32 VMware, Inc.