<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Protegrity SDK Upgrade Permissions and Deployment on</title><link>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/</link><description>Recent content in Protegrity SDK Upgrade Permissions and Deployment on</description><generator>Hugo</generator><language>en</language><atom:link href="https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/index.xml" rel="self" type="application/rss+xml"/><item><title>User Roles and Groups</title><link>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/user_role_group/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/user_role_group/</guid><description>&lt;h2 id="groups">Groups&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Group&lt;/th>
 &lt;th>Purpose&lt;/th>
 &lt;th>Example&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>Admin group&lt;/td>
 &lt;td>Users who manage the Upgrade Agent, RPAgent, and Log Forwarder. This group is always required.&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>SDK users group&lt;/td>
 &lt;td>AP Java users who run applications using the SDK.&lt;/td>
 &lt;td>&lt;code>ptyusers&lt;/code>&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;h2 id="user-configuration-examples">User Configuration Examples&lt;/h2>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>User&lt;/th>
 &lt;th>Primary Group&lt;/th>
 &lt;th>Purpose&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>Admin user who can install and run Upgrade Agent, RPAgent, Log Forwarder, and AP Java.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;code>ptyuser1&lt;/code>, &lt;code>ptyuser2&lt;/code>, and so on&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>AP Java user who can run application using the SDK.&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;h2 id="user-and-group-setup-commands">User and Group Setup Commands&lt;/h2>
&lt;p>This section provide commands to create users and groups on Linux.&lt;/p></description></item><item><title>Component Overview</title><link>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/component/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/component/</guid><description>&lt;p>All Protegrity components are owned and primarily run by the &lt;code>ptyadmin&lt;/code> user. The following table lists the components and their ownership.&lt;/p>
&lt;table>
 &lt;thead>
 &lt;tr>
 &lt;th>Component&lt;/th>
 &lt;th>Description&lt;/th>
 &lt;th>Owner or User&lt;sup>*&lt;/sup>&lt;/th>
 &lt;th>Who Runs It&lt;/th>
 &lt;/tr>
 &lt;/thead>
 &lt;tbody>
 &lt;tr>
 &lt;td>&lt;strong>Upgrade Agent&lt;/strong>&lt;/td>
 &lt;td>Upgrades and rolls back Protegrity components.&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code> user&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>AP Java SDK&lt;/strong>&lt;/td>
 &lt;td>Java libraries used by applications to protect and unprotect data.&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>User (&lt;code>ptyuser1&lt;/code>) in the &lt;code>ptyadmin&lt;/code> group.&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>RPAgent&lt;/strong>&lt;/td>
 &lt;td>Downloads and keeps security policy packages in sync.&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code> user&lt;/td>
 &lt;/tr>
 &lt;tr>
 &lt;td>&lt;strong>Log Forwarder&lt;/strong>&lt;/td>
 &lt;td>- Collects logs and forwards them to the ESA. &lt;br> - It is based on Fluent Bit.&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code>&lt;/td>
 &lt;td>&lt;code>ptyadmin&lt;/code> user&lt;/td>
 &lt;/tr>
 &lt;/tbody>
&lt;/table>
&lt;p>&lt;sup>*&lt;/sup> - All components are owned by &lt;code>ptyadmin&lt;/code>.&lt;/p></description></item><item><title>Recommended File and Folder Permissions</title><link>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/file_folder_permissions/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.protegrity.com/protectors/10.1/docs/ap/ap_java/upgrade/set_upg_agent/permissions/file_folder_permissions/</guid><description>&lt;p>This section explains the required users and groups, core components, and recommended file permissions for running Protegrity Upgrade Agent and the AP Java SDK securely on Linux systems.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>Note&lt;/strong>: The user running the Upgrade Agent must own the extracted old SDK build used for the upgrade. If a local path is configured in &lt;code>sdkupgrd.conf&lt;/code>, the user must also own the downloaded new build.&lt;/p>&lt;/blockquote>
&lt;p>The following tables describe which users can access specific directories under the Upgrade Agent installation and explain why these permissions are required.&lt;/p></description></item></channel></rss>