<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding User (Gaia) via script in a cloning group enabled cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159747#M28050</link>
    <description>&lt;P&gt;Oh I see. Is it for all users, or for this specific hash only?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the latter, I would assume the hash is treated as a variable, since it starts with $. Otherwise, looks like a but to me. If it is a global issue, please raise a TAC case for it.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Oct 2022 15:39:55 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-10-17T15:39:55Z</dc:date>
    <item>
      <title>Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159639#M27998</link>
      <description>&lt;P&gt;Good morning!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a script to automate (Gaia) admin users creation in a cluster with 'cloning group feature enabled'. This cluster is composed of two gateways (fwext01 and fwext02). We have R81.10, take 66 on them.&lt;/P&gt;&lt;P&gt;When I run the script on fwext01, for example, these are the commands that are executed:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;clish -s -f comandos.txt&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(The content of 'comandos.txt' file is:)&lt;/P&gt;&lt;P&gt;&lt;EM&gt;set cloning-group-management on&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;add user adm_mickeymouse uid 0 homedir /home/adm_mickeymouse&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse realname "Mickey Mouse"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse password-hash $6$PSTU$EvYhx6iMbZygtZamlZ8MRH0RfeVFGRMpn&lt;/EM&gt;&lt;EM&gt;yfYyeGuXE5O6qq93VB77v.0kVFOEXeRC39gxZBidj4ccOTrGE48x2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse force-password-change yes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;add rba user adm_mickeymouse roles adminRole&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse shell /bin/bash&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;save config&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set cloning-group-management off&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The results of script execution on fwext01 is totally correct:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;add user adm_mickeymouse uid 0 homedir /home/adm_mickeymouse&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;add rba user adm_mickeymouse roles adminRole&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse gid 0 shell /bin/bash&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse realname "Mickey Mouse"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse password-hash $6$PSTU$EvYhx6iMbZygtZamlZ8MRH0RfeVFGRMpnyfYyeGuXE5O6qq93VB77v.0kVFOEXeRC39gxZBidj4ccOTrGE48x2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But... When I look the configuration that was automatically reflected on fwext02 (via cloning group features), I realize that the password is not being replicated at all:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;add user adm_mickeymouse uid 0 homedir /home/adm_mickeymouse&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;add rba user adm_mickeymouse roles adminRole&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse gid 0 shell /bin/bash&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set user adm_mickeymouse realname "Mickey Mouse"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;s&lt;STRONG&gt;et user adm_mickeymouse password-hash *&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone please help us with this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Thanks!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 04:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159639#M27998</guid>
      <dc:creator>msa2003</dc:creator>
      <dc:date>2022-10-16T04:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159706#M28025</link>
      <description>&lt;P&gt;Could you please elaborate on how you ae using cloning to replicate config on the second FW?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 10:10:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159706#M28025</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-17T10:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159723#M28040</link>
      <description>&lt;P&gt;Hello _Val_&lt;/P&gt;&lt;P&gt;Since I am startig the comands execution with '&lt;EM&gt;set cloning-group-management on&lt;/EM&gt;', it was supposed that all the comands would be automatically replicated to the second FW, correct?&lt;/P&gt;&lt;P&gt;This expected replication is ocurring normally for all the commands inside 'comandos.txt' file. The only exception refers to the &lt;EM&gt;"set user adm_mickeymouse password-hash $6$PSTU$EvYh..."&lt;/EM&gt; command. I mean, the hash config is not being replicated.&lt;/P&gt;&lt;P&gt;I realized that this is also happening even when I execute these commands (via clish) interactively.&lt;/P&gt;&lt;P&gt;But... When I create this user via Gaia GUI in FW1, the password is automatically and correctly replicated on FW2.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 13:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159723#M28040</guid>
      <dc:creator>msa2003</dc:creator>
      <dc:date>2022-10-17T13:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159747#M28050</link>
      <description>&lt;P&gt;Oh I see. Is it for all users, or for this specific hash only?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the latter, I would assume the hash is treated as a variable, since it starts with $. Otherwise, looks like a but to me. If it is a global issue, please raise a TAC case for it.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 15:39:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159747#M28050</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-17T15:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159750#M28052</link>
      <description>&lt;P&gt;This is happening for any user I try to create. And it seems that is happening for any hash.&lt;/P&gt;&lt;P&gt;I tried to use MD5 ($1$) hash and the behavior was the same.&lt;/P&gt;&lt;P&gt;I also tried to use single and double quotes around the hash (to try to avoid the 'hash being treated as variable'). But the behavior is the same.&lt;/P&gt;&lt;P&gt;I´ll contact TAC staff.&lt;/P&gt;&lt;P&gt;Thanks anyway!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 17:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159750#M28052</guid>
      <dc:creator>msa2003</dc:creator>
      <dc:date>2022-10-17T17:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159779#M28067</link>
      <description>&lt;P&gt;Understood. Please let us know what TAC finds out, when it is resolved. Meanwhile, you can use the same scripts on both members to define users, without cloning groups feature&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 07:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159779#M28067</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-18T07:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159836#M28108</link>
      <description>&lt;P&gt;Yes, it would be possible to run the scripts separately. But in order to do that I would have to remove "Users and Roles" from the Cloning Group Shared Features list.&amp;nbsp;Otherwise, the system will not allow me to add the user. It warns me with the following message: "&lt;EM&gt;CLINFR0699 This command belongs to a cloning group synchronized feature and therefore cannot be executed in normal mode&lt;/EM&gt;."&lt;/P&gt;&lt;P&gt;Yes, I will let you know what TAC finds out!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your attention and help!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 12:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/159836#M28108</guid>
      <dc:creator>msa2003</dc:creator>
      <dc:date>2022-10-18T12:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Adding User (Gaia) via script in a cloning group enabled cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/166477#M29960</link>
      <description>&lt;P&gt;It was a bug and people from R&amp;amp;D developed a fix. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 13:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-User-Gaia-via-script-in-a-cloning-group-enabled-cluster/m-p/166477#M29960</guid>
      <dc:creator>msa2003</dc:creator>
      <dc:date>2023-01-02T13:48:10Z</dc:date>
    </item>
  </channel>
</rss>

