### Start HTTP Gateway Service (SysVinit) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-installing-http-gateway Starts the IBM Aspera HTTP Gateway service on systems using SysVinit. This command requires root privileges. ```bash service aspera_httpgateway start ``` -------------------------------- ### Start HTTP Gateway Service (systemd) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-installing-http-gateway Starts the IBM Aspera HTTP Gateway service on systems using systemd. This command requires root privileges. ```bash systemctl start aspera_httpgateway ``` -------------------------------- ### Install HTTP Gateway RPM Package Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-installing-http-gateway Installs the IBM Aspera HTTP Gateway using the provided RPM package. This command requires root privileges and assumes the RPM file is present in the current directory. ```bash rpm -Uvh ibm-aspera-httpgateway-version.x86.64.rpm ``` -------------------------------- ### Start HTTP Gateway Service (Linux - SysVinit) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-installing-http-gateway-as-non-root-user This command starts the 'aspera_httpgateway' service using the SysVinit system. This is typically used on older Linux distributions. For systemd-based systems, a different command is required. ```bash # service aspera_httpgateway start ``` -------------------------------- ### Start Aspera HTTP Gateway Service (Shell) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-running-http-gateway-processes-as-non-root-user Commands to start the aspera_httpgateway service. Includes variations for traditional init systems and systemd-based systems. ```shell service aspera_httpgateway start ``` ```shell systemctl start aspera_httpgateway ``` -------------------------------- ### Enable and Start Aspera HTTP Gateway Service Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=appendix-non-root-user-processes Enable the `aspera_httpgateway.service` to start automatically on system reboot and start it immediately. This command uses `systemctl` to manage the systemd service. The `--now` flag ensures the service starts concurrently with enabling. ```shell systemctl enable aspera_httpgateway.service --now ``` -------------------------------- ### Install IBM Aspera HTTP Gateway (Bash) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=appendix-installing-http-gateway-as-non-root-user This command installs the IBM Aspera HTTP Gateway package using RPM. Ensure you replace 'version' with the actual version number of the package. This operation typically requires root privileges. ```bash sudo rpm -Uvh ibm-aspera-httpgateway-version.rpm ``` -------------------------------- ### Install IBM Aspera HTTP Gateway 2.3.0 as Non-Root (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=appendix-non-root-user-processes Instructions for installing the IBM Aspera HTTP Gateway 2.3.0 package as a non-root user ('httpgateway'). It covers copying the RPM, logging in as the non-root user, and executing the installation command using 'sudo'. This process ensures the gateway can be managed without elevated root privileges for daily operations. ```bash cp -iv $PATH_TO_RPM /home/httpgateway ``` ```bash exit ``` ```bash ssh httpgateway@9.x.x.x ``` ```bash sudo rpm -Uvh ibm-aspera-httpgateway-2.3.0.156-b3b9633.x86_64.rpm ``` ```bash exit ``` -------------------------------- ### Example ASCP Process Output Source: https://www.ibm.com/docs/en/aspera-http-gateway/2_topic=appendix-non-root-user-processes This is an example of the expected output from `ps aux | grep ascp` after a transfer. It confirms that the `ascp` command is running under the `httpgat+` user, which is the expected abbreviated username for `httpgateway`. ```text httpgat+ 309645 0.6 0.0 332416 17820 ? Sl 00:02 0:00 /opt/aspera/httpgateway/aspera/ascp -M 9999 --no-mgmt-port-files -u {"transferID":"e7551c96-9454-4ef8-a9dd-170013395900"} --mode send -i /opt/aspera/httpgateway/aspera/aspera_tokenauth_id_rsa -c aes-256-gcm -d -O 33001 -l 1000000 --policy fair --host ats-aws-us-east-1.dev.aspera.io --user xfer -P 33001 --tags64 eyJhc3BlcmEiOnsiZmFzcGV4Ijp7Il9wa2dfaWQiOjgsImY1X3hmZXJfaWQiOiJmZjFmODBhNi03YWE0LTQwMGQtYjY1Yi1jNTAxN2ZkYWUyOTgiLCJtZXRhZGF0YSI6eyJfY3JlYXRlZF91dGMiOiIyMDI0LTA5LTE5VDA1OjAyOjMxLjUzMloiLCJfcGtnX25hbWUiOiJ0ZXN0aW5nIEdXIG5vbiByb290IDIzMCIsIl9wa2dfdXVpZCI6ImNiNzBmMTRhLWMyZWEtNDI1Zi05YzhiLTk2OTZkOGFkZjAxYyJ9LCJudW1fcmVjaXBpZW50cyI6MSwicmVjaXBpZW50cyI6eyJlbWFpbCI6ImFkYXJzaGRlZXAuY2hlZW1hQGlibS5jb20iLCJmaXJzdF9uYW1lIjoiQWRhcnNoZGVlcCIsImxhc3RfbmFtZSI6IkNoZWVtYSIsIm5hbWUiOiJhZGFyc2hkZWVwLmNoZWVtYUBpYm0uY29tIn19LCJodHRwLWdhdGV3YXkiOnsidXVpZCI6ImU3NTUxYzk2LTk0NTQtNGVmOC1hOWRkLTE3MDAxMzM5NTkwMCIsImNsaWVudF9jb25uZWN0aW9uIjp7InBlZXJfaXBfYWRkcmVzcyI6IjkuNjEuMjYuOTIiLCJwZWVyX3RjcF9wb3J0IjoiNTc3ODkiLCJsb2NhbF9pcF9hZGRyZXNzIjoiOS43Mi4xMjkuMTM0IiwibG9jYWxfdGNwX3BvcnQiOiI4NDQzIiwieF9mb3J3YXJkZWRfZm9yIjoiIiwieF9yZWFsX2lwIjoiIiwieF9mb3J3YXJkZWRfaG9zdCI6IiIsInhfZm9yd2FyZGVkX3Byb3RvIjoiIiwiZm9yd2FyZGVkIjoiIiwidXNlcl9hZ2VudCI6Ik1vemlsbGEvNS4wIChNYWNpbnRvc2g7IEludGVsIE1hYyBPUyBYIDEwLjE1OyBydjoxMzAuMCkgR2Vja28vMjAxMDAxMDEgRmlyZWZveC8xMzAuMCJ9LCJ0cmFuc2Zlcl9yZXF1ZXN0Ijp7ImRpcmVjdGlvbiI6InNlbmQiLCJ0YXJnZXRfcmF0ZSI6IjEwMDAwMDAiLCJmaWxlX2NvdW50IjoiNCIsImVuY3J5cHRpb25fYXRfcmVzdCI6Im5vIiwiZmlsZW5hbWVzX29iZnVzY2F0aW9uIjoibm8ifSwiYXJjaGl2ZXIiOnsidHlwZSI6Im5vbmUiLCJjb21wcmVzc2lvbiI6Ik4vQSJ9fSwibm9kZSI6eyJhY2Nlc3Nfa2V5IjoiQ3pCRU5jaE15LURNNlZhTXotTWNheVRydEVycV8ifSwieGZlcl9pZCI6ImU3NTUxYzk2LTk0NTQtNGVmOC1hOWRkLTE3MDAxMzM5NTkwMCJ9fQ== --overwrite=always stdio-tar:// /testing GW non root 230 - cb70f14a-c2ea-425f-9c8b-9696d8adf01c.aspera-package/PKG - testing GW non root 230/ ``` -------------------------------- ### Install IBM Aspera HTTP Gateway Package (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-installing-http-gateway-as-non-root-user This command installs the IBM Aspera HTTP Gateway package using rpm. It assumes the user has already been granted sudo privileges and is logged in as the 'httpgateway' user. Replace 'version' with the actual package version. ```bash # sudo rpm -Uvh ibm-aspera-httpgateway-version.rpm ``` -------------------------------- ### Create gatewayconfig.properties from Template Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=appendix-non-root-user-processes Command to copy the default properties file to create a new configuration file for the http gateway. This serves as a starting point for customization. ```bash cp -iv /opt/aspera/httpgateway/config/default.properties /opt/aspera/httpgateway/config/gatewayconfig.properties ``` -------------------------------- ### Configure gatewayconfig.properties Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=appendix-non-root-user-processes Example configuration properties for the http gateway. Key settings include the host and port for the server, and the user/group under which the ascp process should run. Ensure the port is non-privileged (>1024). ```properties serverconfig.host=0.0.0.0 serverconfig.port=8443 ascpconfig.run_as_user=httpgateway ascpconfig.run_as_group=httpgateway ``` -------------------------------- ### Check HTTP Gateway Service Status Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=upgrade-installing-http-gateway Command to monitor the logs of the `aspera_httpgateway` service in real-time. This is used to verify that the service has started correctly and is operating without errors. ```bash journalctl -fu aspera_httpgateway.service ``` -------------------------------- ### Modify HTTP Gateway Service ExecStart Command Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=appendix-running-http-gateway-processes-as-non-root-user Updates the ExecStart line in the systemd service file to run the aspera-httpgateway start command as the 'httpgateway' user. ```shell ExecStart=/bin/bash -ce "sudo -u httpgateway /opt/aspera/httpgateway/aspera-httpgateway start > /opt/aspera/httpgateway/httpgateway.log 2>&1" ``` -------------------------------- ### Copy Default Gateway Configuration (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-installing-http-gateway-as-non-root-user This command copies the default properties file to create the 'gatewayconfig.properties' file, which will be used to configure the HTTP Gateway. This new file will override settings in the default.properties and should reside in a 'config' folder at the same level as the binary. ```bash # cp /opt/aspera/httpgateway/config/default.properties /opt/aspera/httpgateway/config/gatewayconfig.properties ``` -------------------------------- ### Check HTTP Gateway Status (SysVinit) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-upgrading-http-gateway Command to check the status of the Aspera HTTP Gateway services on systems using SysVinit. ```bash service aspera_httpgateway status ``` -------------------------------- ### Check HTTP Gateway Status (Systemd) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-upgrading-http-gateway Command to check the status of the Aspera HTTP Gateway services on systems using Systemd. ```bash systemctl status aspera_httpgateway ``` -------------------------------- ### HTTP Gateway Transfer Tags Example (JSON) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-http-gateway-transfer-tags This JSON snippet demonstrates the structure of transfer tags provided by IBM Aspera HTTP Gateway. It includes details about the transfer ID, client connection information (like peer and local IPs, ports, and proxy-related headers such as x_real_ip and x_forwarded_for), transfer request parameters (direction, rate, file count, encryption), and archiver method. This data is valuable for external applications needing context about file transfers. ```json { "aspera": { "xfer_id": "9c03f82d-53e1-4c85-b6fe-96c9f88a3dc3", "http-gateway": { "uuid": "9c03f82d-53e1-4c85-b6fe-96c9f88a3dc3", "client_connection": { "peer_ip_address": "127.0.0.1", "peer_tcp_port": "40580", "local_ip_address": "127.0.0.1", "local_tcp_port": "5080", "x_real_ip": "66.211.105.2", "x_forwarded_for": "66.211.105.2", "x_forwarded_host": "http-gateway.example.com:6443", "x_forwarded_proto": "https", "forwarded": "for=66.211.105.2;proto=https", "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" }, "transfer_request": { "direction": "send", "target_rate": "100000", "file_count": "3", "encryption_at_rest": "no", "file_obfuscation": "no" }, "archiver": { "method": "none", "compression_ratio": "N/A" } } } } ``` -------------------------------- ### Restart Aspera HTTP Gateway Service (Systemd) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=upgrade-upgrading-http-gateway This command restarts the `aspera_httpgateway` service using systemd. Restarting the service is necessary for the newly installed version and restored configuration to take effect. This ensures the gateway is running with the correct settings. ```bash systemctl restart aspera_httpgateway ``` -------------------------------- ### Copy Default Gateway Configuration Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-installing-http-gateway Creates the gatewayconfig.properties file by copying the default configuration. This file is used to customize HTTP Gateway settings and should be placed in the 'config' directory. ```bash cp /opt/aspera/httpgateway/config/default.properties /opt/aspera/httpgateway/config/gatewayconfig.properties ``` -------------------------------- ### Modify Aspera HTTP Gateway Service Start Command (Shell) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-running-http-gateway-processes-as-non-root-user Edits the systemd service file for aspera_httpgateway. It shows the original ExecStart line and the modified version to run the start command as the 'httpgateway' user. ```shell ExecStart=/bin/bash -ce "/opt/aspera/httpgateway/aspera-httpgateway start > /opt/aspera/httpgateway/httpgateway.log 2>&1" ``` ```shell ExecStart=/bin/bash -ce "sudo -u httpgateway /opt/aspera/httpgateway/aspera-httpgateway start > /opt/aspera/httpgateway/httpgateway.log 2>&1" ``` -------------------------------- ### Backup IBM Aspera HTTP Gateway Directory (Bash) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=upgrade-upgrading-http-gateway This command creates a backup of the current httpgateway directory before upgrading. It ensures that critical configuration files and data are preserved in case of any issues during the upgrade process. The `-P` flag ensures parent directories are created if they don't exist, and `cp -rivp` performs a recursive, interactive, verbose copy, preserving permissions and timestamps. ```bash mkdir -P /root/httpgateway-2-3-0.bkup cp -rivp /opt/aspera/httpgateway /root/httpgateway-2-3-0.bkup ``` -------------------------------- ### Grant sudo Access to httpgateway User (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.1_topic=appendix-installing-http-gateway-as-non-root-user This command adds the 'httpgateway' user to the 'wheel' group, granting them the ability to execute commands with superuser privileges using sudo. This is a crucial step for installing and managing the HTTP Gateway as a non-root user. ```bash # usermod -aG wheel httpgateway ``` -------------------------------- ### Backup HTTP Gateway Configuration (Shell) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2_topic=appendix-non-root-user-processes This command creates a backup of the current HTTP Gateway configuration directory. It uses `cp -rivp` for recursive, interactive, verbose, and preserving file attributes, ensuring a safe backup before the upgrade. The backup is stored in the specified non-root user accessible path. ```shell cp -rivp /opt/aspera/httpgatway /root/httpgw-2-3-0-non-root.bkup ``` -------------------------------- ### Apply Sysctl Configuration (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=configuration-optimizing-download-performance Reloads the sysctl configuration to apply the changes made to network parameters, including the default queue discipline and congestion control algorithm. This ensures the new settings are active. ```bash sysctl -p ``` -------------------------------- ### Stop HTTP Gateway Services (SysVinit) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-upgrading-http-gateway Command to stop the Aspera HTTP Gateway services on systems using SysVinit. ```bash service aspera_httpgateway stop ``` -------------------------------- ### Create and Configure 'httpgateway' User (Linux) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=appendix-non-root-user-processes This section details the steps to create and configure a dedicated 'httpgateway' user on a Linux system. It includes creating the user, adding them to the 'wheel' group for administrative privileges, and setting a password. These steps are essential for running processes as a non-root user. ```bash useradd -m httpgateway ``` ```bash usermod -aG wheel httpgateway ``` ```bash passwd httpgateway ``` -------------------------------- ### Stop HTTP Gateway Services (Systemd) Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.2_topic=installation-upgrading-http-gateway Command to stop the Aspera HTTP Gateway services on systems using Systemd. ```bash systemctl stop aspera_httpgateway ``` -------------------------------- ### Create and Configure gatewayconfig.properties Source: https://www.ibm.com/docs/en/aspera-http-gateway/2_topic=appendix-non-root-user-processes Steps to copy the default properties file and then modify it to set the host, port, and run-as user/group for the HTTP Gateway. Ensure the port is non-privileged (above 1024). ```shell cp -iv /opt/aspera/httpgateway/config/default.properties /opt/aspera/httpgateway/config/gatewayconfig.properties # Edit gatewayconfig.properties: # serverconfig.host=0.0.0.0 # serverconfig.port=8443 # ascpconfig.run_as_user=httpgateway # ascpconfig.run_as_group=httpgateway ``` -------------------------------- ### Disable SELinux Source: https://www.ibm.com/docs/en/aspera-http-gateway/2.3_topic=upgrade-installing-http-gateway This code snippet shows how to modify the SELinux configuration file to disable SELinux, which is a prerequisite for installing HTTP Gateway 2.3.1. Changes require a system reboot to take effect. ```bash SELINUX=disabled ```