Quick PrivX Setup
Use this guide to set up PrivX for evaluation and become familiar with its features. The procedure uses suggested settings for a simple evaluation environment.
For production use, follow Deployment Overview to plan and configure PrivX for your environment. Before using PrivX in production, complete the Production-Readiness Checklist.
Setting Up PrivX for Evaluation
To set up a PrivX server for evaluation purposes:
-
Add the EPEL and PrivX repositories for downloading PrivX packages and dependencies.
-
On Red Hat/Rocky Linux 9:
yum updateyum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-9.noarch.rpmyum install postgresql-server # or postgresql if using an external DByum install firewallddnf module enable postgresql:16yum install postgresql-server # or postgresql if using external DBrpm --import https://product-repository.ssh.com/info.fi-ssh.com-pubkey.asccurl https://product-repository.ssh.com/rhel9/ssh-products.repo -o /etc/yum.repos.d/ssh-products.repo -
On Red Hat/Rocky Linux 8:
yum updateyum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpmyum install epel-releaseyum install firewallddnf module enable postgresql:16yum install postgresql-server # or postgresql if using external DBrpm --import https://product-repository.ssh.com/info.fi-ssh.com-pubkey.asccurl https://product-repository.ssh.com/rhel8/ssh-products.repo -o /etc/yum.repos.d/ssh-products.repo -
On Amazon Linux 2023:
dnf install postgresql15-server # or postgresql15 if using external DBdnf install libxcrypt-compat firewalldrpm --import https://product-repository.ssh.com/info.fi-ssh.com-pubkey.asccurl https://product-repository.ssh.com/rhel8/ssh-products.repo -o /etc/yum.repos.d/ssh-products.repo -
On Amazon Linux 2:
amazon-linux-extras install -y nginx1 epelamazon-linux-extras enable postgresql14yum install postgresql-server # or postgresql if using an external DByum install firewalldrpm --import https://product-repository.ssh.com/info.fi-ssh.com-pubkey.asccurl https://product-repository.ssh.com/ssh-products.repo -o /etc/yum.repos.d/ssh-products.repo
cautionWhen configuring PrivX with an external PostgreSQL database, make sure the
psqlclient is installed on the same machine. PrivX requires apsqlclient version that matches the server version. -
-
Install the latest PrivX packages with:
yum install PrivX -
Configure PrivX with:
/opt/privx/scripts/postinstall.shThe following lists the required information, along with some recommended values for evaluation setups:
- PKCS #11-keyvault settings:
N - Number of trusted load balancers in front of PrivX node:
0 - NTP server address:
pool.ntp.org - FQDN and IP address(es) of the server. You can obtain these by opening another terminal and running
hostname --fqdnandip addrrespectively. - Local or external database:
L - Database name and credentials. You can go with the defaults.
- Credentials for the initial superuser account.
Once the
postinstall.shscript finishes, the PrivX server is operational.tipThe TLS server certificate generated during installation is valid for 200 days. If you continue using this certificate, renew it before it expires. For more information, see Renewing Certificates.
- PKCS #11-keyvault settings:
-
License your PrivX server to enable its features:
Open a browser and navigate to the FQDN or IP address of your PrivX server. Log in with the superuser credentials provided earlier.
In the PrivX GUI, go to Administration → License and enter your license code.
After following these steps, you have now set up a PrivX server for evaluation purposes.