Server Installation Linux
Server Installation Linux
SERVER INSTALLATION
GUIDE - LINUX
OCTOBER 2025
This document applies to ARIS Version 10 and to all subsequent releases.
Specifications contained herein are subject to change and these changes will be reported in
subsequent release notes or new editions.
Copyright © 2010-2025 SAG ARIS GmbH, Saarbrücken, Germany and/or its subsidiaries and/or
its affiliates and/or their licensors.
The name Software AG and all SAG ARIS GmbH product names are either trademarks or
registered trademarks of Software GmbH and/or SAG ARIS GmbH and/or its subsidiaries
and/or its affiliates and/or their licensors. Other company and product names mentioned
herein may be trademarks of their respective owners.
This software may include portions of third-party products. For third-party copyright notices,
license terms, additional rights or restrictions, please refer to "License Texts, Copyright
Notices and Disclaimers of Third Party Products". For certain specific third-party license
restrictions, please refer to section E of the Legal Notices available under "License Terms and
Conditions for Use of Software GmbH Products / Copyright and Trademark Notices of
Software GmbH Products". These documents are part of the product documentation, located
at [Link] and/or in the root installation directory of the licensed
product(s).
Use, reproduction, transfer, publication or disclosure is prohibited except as specifically
provided for in your License Agreement with SAG ARIS GmbH.
SERVER INSTALLATION GUIDE - LINUX
Contents
Contents ........................................................................................................................................................... I
1 Installation................................................................................................................................................ 1
I
SERVER INSTALLATION GUIDE - LINUX
1 Installation
This chapter describes the single node installation of an ARIS server using the Windows setup
program. For further information, read the relevant documents on the ARIS Documentation
website ([Link] or download them from ARIS Download Center
([Link]
To install ARIS server on Linux systems, the ARIS agent must be provided (page 5) first. The
required files are available in the installation folder
<ARIS_Installation_and_Documentation-<version>>\Linux setup that you can download
from the ARIS Download Center (login required). After you have copied and installed the files,
you must start the remote installation from a Windows system. If you do not want to run the
setup remotely from a Windows machine, you must execute all required steps manually using
ARIS Cloud Controller. For more information on manual setup, refer to the ARIS Distributed
Installation Cookbook. The necessary knowledge can only be acquired by attending the
ARIS Server Installation training course, which is available at ARIS Academy.
If you run an ARIS server Windows setup remotely, the following components are installed:
ARIS Cloud Controller (ACC)
ARIS agent
ARIS server*
Viewer*
Designer*: The functionalities workflows‚ Share model, Change request and Approve
model are available using an ARIS server license. For full ARIS Process Governance
functionality, you need to purchase and import an ARIS Process Governance license.
ARIS download client: Authorized users can start ARIS download clients within their
browsers. All necessary files are downloaded from the ARIS server to a local directory.
Users do not need a local ARIS client installation.
The default tenant for all user data.
The master infrastructure tenant.
ARIS Risk and Compliance (optionally): The installation procedure is described in the
ARIS Risk and Compliance Installation Guide (see ARIS installation package).
Dashboards (optionally)*
*The functional range depends on the server license that you have purchased (see ARIS
Product Feature Matrix). Read the documents on the ARIS Documentation website
([Link] or download them from the ARIS Download Center
([Link]
You can install ARIS server along with ARIS Risk and Compliance on one machine. The ARIS
Risk and Compliance installation procedure is described in the ARIS Risk and Compliance
Installation Guide. For advanced installations, it is strongly recommended that you request
an installation service from ARIS Professional Services. This is of particular importance when
1
SERVER INSTALLATION GUIDE - LINUX
you intend to install ARIS across several computers/VMs (distributed installation). A scenario
this specific requires in-depth knowledge of the technical infrastructure and environment.
This information cannot be included in the product documentation. The necessary knowledge
can only be acquired by attending the ARIS Server Installation training course, which is
available at ARIS Academy.
Setup activities are logged in the files %temp%\ARIS_install_log and
%temp%\aris_install_full.log.
REMOTE INSTALLATION
To install ARIS server on Linux systems, the ARIS agent must be provided (page 5) first. The
required files are available in the installation folder
<ARIS_Installation_and_Documentation-<version>>\Linux setup that you can download
from the ARIS Download Center (login required). After you have copied and installed the files,
you must start the remote installation from a Windows system. If you do not want to run the
setup remotely from a Windows machine, you must execute all required steps manually using
ARIS Cloud Controller. For more information on manual setup, refer to the ARIS Distributed
Installation Cookbook. The necessary knowledge can only be acquired by attending the
ARIS Server Installation training course, which is available at ARIS Academy.
2
SERVER INSTALLATION GUIDE - LINUX
General prerequisites
For each setup procedure described in this document, the following general prerequisites
must be met. Additional prerequisites are listed in related procedure descriptions.
Prerequisites
You have downloaded the ARIS installation package to access the *.rpm files (see: Linux
setups\Linux_<system>\ARIS_Agent, as well as Linux setups\Linux\ARIS_Admin
and ARIS_Scriptrunner) included in
<ARIS_Installation_and_Documentation-<version>>.
To download the package, you need access to the ARIS Download Center
([Link] where a login is
required.
Make sure that the hard and software requirements are met. For information about
hardware and software requirements, please refer to the ARIS system requirements
(../../yay-system-requirements-guide/en/[Link]). Read the
documents on the ARIS Documentation website ([Link] or download
them from the ARIS Download Center
([Link]
In the Linux operating system port 14000 must be open.
In the Windows operating system ports 13131-13140 must be open to give access to the
setup repository server.
Ensure that the virtual memory available on your Linux operating system is set to 262144
(page 41).
Make sure that the FONTCONFIG Linux package is installed on the Linux operating
system together with all required fonts. Otherwise, fonts are not visible in ARIS and
unreadable text is displayed.
It is a good idea to read the ARIS Release [Link] for last-minute information which
could not be included in this document anymore.
3
SERVER INSTALLATION GUIDE - LINUX
If virus scanners are active on application servers used by ARIS, the performance of
Java-based ARIS software is seriously reduced by on-access scanning. By automatically
removing suspicious files mandatory for ARIS operations, quarantining can lead to
malfunctions or a complete failure of ARIS. We therefore strongly recommend that you
exclude the ARIS installation directory from on-access scanning to prevent performance
impact. Scan the directory on a regular basis using a schedule. The scan should run
outside of typical working hours. As some virus scanners detect false-positives, we
recommend that you limit the scan to executable files only, for example, *.exe and *.jar.
Known cases of false-positives are, for example, Windows Defender Antivirus blocking
*.pos files (elastic runnable) or McAfeeTM slowing down report execution and failing ARIS
setups. Make sure that the overnight scan does not quarantine suspicious files
immediately so that further inspection can be performed by ARIS Global Support. If you
scan network traffic, this can also result in performance problems with ARIS. To prevent
this, exclude the IP addresses of the ARIS server nodes or the ARIS processes from these
network scans.
If you want to import the ARIS license file during the setup procedure, make sure to have
the zip file saved on this computer. Otherwise, you must import licenses after the
installation (see Manage licenses).
If you use SELinux, make sure that the defined security settings are met. If the setup fails,
modify the SELinux settings or turn it off. Please follow the instructions in the SELinux
User's and Administrator's Guide
([Link]
linux_users_and_administrators_guide/index), as well as the documentation provided
by the manufacturer.
4
SERVER INSTALLATION GUIDE - LINUX
2 Setup scenarios
This chapter describes the installation processes of ARIS products using different database
management systems on Linux operating systems (page 5). By default, these installations will
create an unprivileged and locked user aris10 which uses /home/ARIS10 to install ARIS
itself. If you want to use different settings, make sure to change them before installing the
first rpm file (page 8).
From ARIS [Link], ARIS Risk and Compliance and ARIS server use the same external
database management system if configured. When you update your ARIS server, ARIS Risk
and Compliance still uses the database connection as configured for ARIS Risk and
Compliance. If you want ARIS server and ARIS Risk and Compliance to use the same
connection, you must first update ARIS server. Then configure the database connection
manually, as described in the ARIS Risk and Compliance Installation Guide.
If you currently run ARIS in version 10.0.18 or lower, you must update to version 10.0.21 first
and then update to ARIS in the current version. The direct update to the current version is
blocked in server setup, the agent setup, and via ACC update command. The ARIS Risk and
Compliance installation procedure is described in the ARIS Risk and Compliance Installation
and Upgrade Help. Documents are available in the Documents folder. Read the documents
on the ARIS Documentation website ([Link] or download them from the ARIS
Download Center ([Link]
Before installing an ARIS server on a Linux operating system, you must provide the ARIS
agent to your Linux Red Hat or SUSE system. To allow customizing activities additionally
provide the command-line tools ARIS Server Administrator and ARIS Scriptrunner. Use the
*.rpm files for Red Hat or SUSE systems.
After you have copied and installed the files, you must start the remote installation from a
Windows system. If you do not want to run the setup remotely from a Windows machine, you
must execute all required steps manually using ARIS Cloud Controller. For more information
on manual setup, refer to the ARIS Distributed Installation Cookbook. The necessary
knowledge can only be acquired by attending the ARIS Server Installation training course,
which is available at ARIS Academy.
All required rpm files are available in the downloaded
<ARIS_Installation_and_Documentation-<version>>\Linux setup folder. You find all setup
programs within the Windows setups\ARIS_Server folder. Copy the whole content to a
directory of your choice. This will make available all documents needed to setup ARIS as well
as the database scripts. These scripts are needed to setup your external database
management system for the use of ARIS. If you only copy a single ARIS setup, make sure to
copy the content of the folder containing the [Link] file as well as the Setup_Data
folder.
5
SERVER INSTALLATION GUIDE - LINUX
<ARIS_INSTALLATION_AND_DOCUMENTATION-<VERSION>>
Get an overview of the content of the downloaded installation directory:
Folder Content
Add-ons Required files needed to connect third-party tools, for
example, Microsoft SQL server, Oracle databases or SAP tools.
Linux <system> Required files to install the ARIS agent and several tools for
administration on SUSE and RedHat Linux systems.
ARIS_Agent Provides the ARIS agent. After the ARIS agent is provided,
you can install an ARIS server remotely (page 5) from a
Windows machine.
6
SERVER INSTALLATION GUIDE - LINUX
Folder Content
ARIS_Agent Installs the ARIS agent. The ARIS agent will be installed on all
Windows machines that will have an ARIS server. It provides
basic components, for example, ARIS Cloud Controller (ACC)
and handles internal communication processes.
If you are about to install an ARIS server remotely, please
make sure to first install the ARIS agent locally on that
machine.
7
SERVER INSTALLATION GUIDE - LINUX
CODE EXAMPLE
sudo -s
export TARGETDIR=/mnt/largedisk
export user=TheOtherUser
rpm install aris10-cloud-agent-<number>-1.x86_64.rpm
8
SERVER INSTALLATION GUIDE - LINUX
on manual setup, refer to the ARIS Distributed Installation Cookbook. The necessary
knowledge can only be acquired by attending the ARIS Server Installation training course,
which is available at ARIS Academy.
In RedHat and SUSE systems *.rpm files will perform these actions automatically:
/etc/[Link]
[Link]:
if "[Link] < 629145600" then "[Link] = 629145600"
max_file_max:
if "max_file_max < 200000” then "[Link]-max = 200000"
/etc/security/limits.d/[Link]
$max_file_max = "ulimit –n"
If "$max_file_max > 2^20" then max_file_max = 2^20
aris10 soft nofile $max_file_max
aris10 hard nofile $max_file_max
aris10 soft nproc 12204
aris10 hard nproc 12204
/etc/pam.d/su
session required pam_limits.so
Prerequisites
Make sure that the general prerequisites are met (page 3).
Procedure
1. Copy the file aris10-cloud-agent-<number>-1.x86_64.rpm or
aris10-cloud-agent-SLES-<number>-1.x86_64.rpm from the ARIS installation
package to the hard drive of your Linux system.
This file provides the ARIS agent. The ARIS agent is needed to perform a remote server
installation.
2. Optionally copy the files for installing ARIS Server Administrator and ARIS Scriptrunner.
These files are not mandatory for ARIS server to be installed.
3. Depending on the files you have copied and the type of the Linux system enter the
relevant command to install the files. By default, these installations will create an
unprivileged and locked user aris10 which uses /home/ARIS10 to install ARIS itself. If
you want to use different settings, make sure to change them before installing the first
rpm file (page 8).
rpm –i aris10-cloud-agent-<number>-1.x86_64.rpm
This command installs the ARIS agent to your Red Hat system.
rpm –i aris10-cloud-agent-SLES-<number>-1.x86_64.rpm
This command installs the ARIS agent to your SUSE system.
rpm –i aris10adm-<number>-1.x86_64 and rpm –i
aris10-scriptrunner-<number>-1.x86_64
9
SERVER INSTALLATION GUIDE - LINUX
These commands optionally install the administrator tools ARIS Server Administrator
and ARIS Scriptrunner.
4. Perform the ARIS server installation from a machine running a Microsoft Windows
operating system (see ARIS installation package\Windows setups\ARIS_Server).
5. Start the [Link] file as an administrator.
6. Select the Perform installation on a remote server option and enter the name of your
Linux system.
7. Select ARIS server to be installed.
8. Select Use dashboards to make dashboards available. This will activate the
dashboarding runnable. If you do not select this option, the runnable will be installed but
not activated.
9. Select ARIS Risk and Compliance if you want to install this program as well. The ARIS Risk
and Compliance installation procedure is described in the ARIS Risk and Compliance
Installation and Upgrade Help. Documents are available in the Documents folder. Read
the documents on the ARIS Documentation website ([Link] or download
them from the ARIS Download Center
([Link]
10. Select the installation directory if required.
11. Only if you need to specify an external proxy server IP address for incoming requests
enter the proxy server computer name or IP.
12. Change the ARIS agent user credentials to prevent unauthorized access to your ARIS
system. Make sure to store the credentials in a save place. If you forget the credentials,
you can no longer update the system or modify the configuration.
13. If you change the credentials, you will be further on prompted to enter that password
you've chosen whenever you start/stop the ARIS server or access your ARIS installation
using ARIS Cloud Controller.
14. If the ports 1080 or 1443 are already in use, specify the port numbers to be used. If you
change the default port numbers users must add :<this port number> to the URL (see
below).
15. To force secure connections (HTTPS), uncheck HTTP port. If you do so, make sure to
make a valid TLS server certificate (page 31) available.
16. Select the suitable system settings option. You need to take the RAM required and the
number of users who will be accessing the ARIS server into account. For a productive
system it is recommended to select the Medium or Large option.
The Demo scenario option is recommended for demonstration purposes (laptop) only.
Warning
If the hardware does not fit the system requirements, a warning is prompted. In this case
do not proceed the setup. Otherwise, ARIS might not work reliably.
10
SERVER INSTALLATION GUIDE - LINUX
17. To import the ARIS license file, enable Import now, click Select file..., and navigate to the
license archive file. Otherwise, licenses must be imported after the installation.
Make sure this file contains the required ARIS server license. The functional range
depends on the server license that you have purchased (see ARIS Product Feature
Matrix). Read the documents on the ARIS Documentation website
([Link] or download them from the ARIS Download Center
([Link]
18. Select the Standard database system.
19. Enter the SMTP mail processing parameters of an existing account.
Warning
If you don't, ARIS will not send any notifications, due to the missing mailing functionality.
But you can configure SMTP mail processing (page 44) at any later point of time. Some
parameters can also be managed using the ARIS Administration of this server. Please
refer to the online help of ARIS Administration.
20. Activate Use TLS/SSL encryption to prevent password sniffing.
21. Only if your mail server requires SMTP authentication, select the option SMTP
authentication and enter the user credentials.
Warning
If you enter these parameters but your mail server does not require SMTP authentication,
the connection will be rejected.
22. If you are about to use a proxy server, enter all proxy processing parameters. You can also
enter them later, using the ARIS Administration of this server. Please refer to the online
help of ARIS Administration.
You can specify a URL to be used for validating the proxy server settings.
23. Select the start option:
Select Start automatically if you want to have the server started up with every restart
of your operating system.
Select Start manually if you want to start/stop the server on the active computer
manually.
24. Start the installation process. If you have changed the ARIS agent's default user
credentials during this procedure, you will be prompted for that password you have
chosen.
The installation process takes some time. You can change settings entered during the setup
process. Use the reconfigure ACC command to change settings, such as ports. After the
ARIS server installation has completed, you must check the installation and configure the
system (page 28).
11
SERVER INSTALLATION GUIDE - LINUX
To ensure optimum performance when you are using ARIS with the standard database
system, we recommend that you regularly shrink the database. This prevents that the used
disk space constantly increases. To do so, execute the [Link] file (<ARIS installation
directory>\server\bin\agentLocalRepo\.unpacked\<build
number>_PostgreSQL-run-prod-<ARIS version>-[Link]\postgresql\bin).
For detailed information, read the instructions provided by the manufacturer
([Link]
To uninstall ARIS from a Red Hat or a SUSE system enter, for example, rpm –e
aris10-cloud-agent.
12
SERVER INSTALLATION GUIDE - LINUX
/etc/security/limits.d/[Link]
$max_file_max = "ulimit –n"
If "$max_file_max > 2^20" then max_file_max = 2^20
aris10 soft nofile $max_file_max
aris10 hard nofile $max_file_max
aris10 soft nproc 12204
aris10 hard nproc 12204
/etc/pam.d/su
session required pam_limits.so
Prerequisites
Make sure that the general prerequisites are met (page 3).
An operating Microsoft SQL Server database. If you have not yet installed the Microsoft
SQL Server, follow the instructions in the Microsoft installation program, as well as the
documentation provided by the manufacturer. The external database management
system is not included in this package. If you need help in setting up ARIS using your
external database system, please contact ARIS ([Link] Note that this service
is not subject to the standard software maintenance agreement and that these changes
can only be performed if you requested and agreed on them.
Ensure that Latin1_General_CI_AI sorting is selected for the COLLATE statement.
The SQL Server and Windows authentication mode (mixed mode) option is selected
(Microsoft SQL Console > Security tab).
13
SERVER INSTALLATION GUIDE - LINUX
You must know the port number, the database name of the new database instance if it
was not configured as a default instance, and also the user name and the password of the
application user.
You have downloaded the latest supported version (see ARIS System Requirements) of
the Microsoft SQL Server JDBC driver from the Microsoft Download Center to a directory
of your choice.
SQL scripts and all additional files. All scripts and files are located on the installation
medium (Add-ons\DatabaseScripts\Design&ConnectServer\mssql) or they can be
downloaded from the ARIS Download Center
([Link]
Procedure
1. Copy the file aris10-cloud-agent-<number>-1.x86_64.rpm or
aris10-cloud-agent-SLES-<number>-1.x86_64.rpm from the ARIS installation
package to the hard drive of your Linux system.
This file provides the ARIS agent. The ARIS agent is needed to perform a remote server
installation.
2. Optionally copy the files for installing ARIS Server Administrator and ARIS Scriptrunner.
These files are not mandatory for ARIS server to be installed.
3. Depending on the files you have copied and the type of the Linux system enter the
relevant command to install the files. By default, these installations will create an
unprivileged and locked user aris10 which uses /home/ARIS10 to install ARIS itself. If
you want to use different settings, make sure to change them before installing the first
rpm file (page 8).
rpm –i aris10-cloud-agent-<number>-1.x86_64.rpm
This command installs the ARIS agent to your Red Hat system.
rpm –i aris10-cloud-agent-SLES-<number>-1.x86_64.rpm
This command installs the ARIS agent to your SUSE system.
rpm –i aris10adm-<number>-1.x86_64 and rpm –i
aris10-scriptrunner-<number>-1.x86_64
These commands optionally install the administrator tools ARIS Server Administrator
and ARIS Scriptrunner.
4. Your database administrator must adjust the settings that are used by all database
scripts. These scripts must be executed by the database administrator to set up the
database as required.
Edit the [Link] file to specify the connection data of the Microsoft SQL server
instance. It's a good idea to write down the credentials. They must be entered later during
the ARIS setup process.
14
SERVER INSTALLATION GUIDE - LINUX
To specify the connection data of the Microsoft SQL instance, modify the highlighted
parameters and refer to the comments:
REM
REM You may edit this section for customizing purposes.
REM
REM This script is intended to be executed on the Microsoft SQL server
machine, therefore the default value is 'localhost'
REM If the MSSQL_SAG_FILEGROUP_FILE_DIR directory exists on the Microsoft
SQL server machine, you can run the script remotely. When executed locally,
the script creates this mandatory directory.
REM If you use a default instance, an instance name is not required.
REM If you use named instances, enter a backslash ‘\’ followed by the instance
name.
SET MSSQL_SAG_MSSQL_SERVER_NAME=localhost
REM This script is configured for the use of Windows authentication by
default.
REM Windows authentication uses the user account running this script and
does not require user credentials to be specified in this script.
REM If you want to use user/password authentication instead, uncomment
the following lines and modify the settings for use by the SQL Server command
line tool (sqlcmd).
REM SET SQLCMDUSER=sa
REM SET SQLCMDPASSWORD=manager
REM name of database that will be created by the script.
SET MSSQL_SAG_DATABASE_NAME=ARIS10DB
REM folder in which the database files should be stored.
SET MSSQL_SAG_FILEGROUP_FILE_DIR=F:\msqldata\ARIS10DB
REM credentials of the login that is used by the application.
SET MSSQL_SAG_APP_USER=ARIS10
REM If using % character in your password: Write %% to yield a single %
character.
SET MSSQL_SAG_APP_PWD=*ARIS!1dm9n#
REM schema names for the default and master tenants
SET MSSQL_SAG_TENANT_DEFAULT=ARIS_DEFAULT
SET MSSQL_SAG_TENANT_MASTER=ARIS_MASTER
REM
REM The rest of the script must not be modified.
....
5. Execute the [Link] file. This will create the database including the two mandatory
tenants and the application user. The application user (APP_USER) is the Microsoft SQL
user connecting ARIS and the Microsoft SQL database. The default user name is ARIS10.
But you may have changed that name in the [Link] earlier. Two schemes are
mandatory. One for the master tenant and one for the default tenant. Write down the
tenant names. These names must be entered later during the ARIS server setup process.
6. If you need additional tenants, you must create additional schemes for each new tenant.
If you are going to create additional tenants for ARIS10 to migrate data from ARIS 9.8.7 or
later, make sure to use identical names in both ARIS versions.
Run the script create_schema_for_tenant.bat and pass the schema name as
parameter, for example:
create_schema_for_tenant.bat <schema name for additional tenant>
15
SERVER INSTALLATION GUIDE - LINUX
If the schema already exists it will be dropped and recreated automatically. If you do not
use the scripts, you can also set up the database and create an empty schema for each
tenant manually.
If you use an external database management system and you have created empty
schemes for additional tenants, you must assign additional tenants (page 35) to these
schemes after the ARIS server setup is completed. The default tenant and the master
tenant were assigned automatically.
7. Perform the ARIS server installation from a machine running a Microsoft Windows
operating system (see ARIS installation package\Windows setups\ARIS_Server).
8. Start the [Link] file as an administrator.
9. Select the Perform installation on a remote server option and enter the name of your
Linux system.
10. Select ARIS server to be installed.
11. Select Use dashboards to make dashboards available. This will activate the
dashboarding runnable. If you do not select this option, the runnable will be installed but
not activated.
12. Select ARIS Risk and Compliance if you want to install this program as well. The ARIS Risk
and Compliance installation procedure is described in the ARIS Risk and Compliance
Installation and Upgrade Help. Documents are available in the Documents folder. Read
the documents on the ARIS Documentation website ([Link] or download
them from the ARIS Download Center
([Link]
13. Select the installation directory if required.
14. Only if you need to specify an external proxy server IP address for incoming requests
enter the proxy server computer name or IP.
15. Change the ARIS agent user credentials to prevent unauthorized access to your ARIS
system. Make sure to store the credentials in a save place. If you forget the credentials,
you can no longer update the system or modify the configuration.
If you change the credentials, you will be further on prompted to enter that password
you've chosen whenever you start/stop the ARIS server or access your ARIS installation
using ARIS Cloud Controller.
16. If the ports 1080 or 1443 are already in use, specify the port numbers to be used. If you
change the default port numbers users must add :<this port number> to the URL (see
below).
17. To force secure connections (HTTPS), uncheck HTTP port. If you do so, make sure to
make a valid TLS server certificate (page 31) available.
18. Select the suitable system settings option. You need to take the RAM required and the
number of users who will be accessing the ARIS server into account. For a productive
system it is recommended to select the Medium or Large option.
16
SERVER INSTALLATION GUIDE - LINUX
The Demo scenario option is recommended for demonstration purposes (laptop) only.
Warning
If the hardware does not fit the system requirements, a warning is prompted. In this case
do not proceed the setup. Otherwise, ARIS might not work reliably.
19. To import the ARIS license file, enable Import now, click Select file..., and navigate to the
license archive file. Otherwise, licenses must be imported after the installation.
Make sure this file contains the required ARIS server license. The functional range
depends on the server license that you have purchased (see ARIS Product Feature
Matrix). Read the documents on the ARIS Documentation website
([Link] or download them from the ARIS Download Center
([Link]
20. Select MSSQL.
21. Select the required JDBC driver for the Microsoft SQL database management system.
22. Enter the connection parameters used in the [Link] file and exactly the values used
by the Microsoft SQL server.
The values shown are the default values used in the [Link] file and the default
parameters used when setting up the Microsoft SQL server.
Server: Fully qualified name or IP address of the Microsoft SQL server. The default
parameter used in the [Link] file is localhost. The default name works only if
you run that script from the machine were the Microsoft SQL server is installed.
Port: Port addressing the SQL server instance running over TCP. The default port
number used in the [Link] file is 1433.
Database name: Name of the database that was created by the [Link] script.
The default value is ARIS10DB.
Application user: Login user name that is used by the application. The default value
used in the from [Link] file is ARIS10.
Password: The application user's password. The default value used in the from
[Link] file is *ARIS!1dm9n#.
Default schema: Schema name for the default tenant and user name for that
schema's owner. The default value used in the from [Link] file is
ARIS_DEFAULT.
Master scheme: Schema name for the master tenant and user name for that
schema's owner. The default value used in the from [Link] file is
ARIS_MASTER.
23. Enter the SMTP mail processing parameters of an existing account.
Warning
If you don't, ARIS will not send any notifications, due to the missing mailing functionality.
17
SERVER INSTALLATION GUIDE - LINUX
But you can configure SMTP mail processing (page 44) at any later point of time. Some
parameters can also be managed using the ARIS Administration of this server. Please
refer to the online help of ARIS Administration.
24. Activate Use TLS/SSL encryption to prevent password sniffing.
25. Only if your mail server requires SMTP authentication, select the option SMTP
authentication and enter the user credentials.
Warning
If you enter these parameters but your mail server does not require SMTP authentication,
the connection will be rejected.
26. If you are about to use a proxy server, enter all proxy processing parameters. You can also
enter them later, using the ARIS Administration of this server. Please refer to the online
help of ARIS Administration.
You can specify a URL to be used for validating the proxy server settings.
27. Select the start option:
Select Start automatically if you want to have the server started up with every restart
of your operating system.
Select Start manually if you want to start/stop the server on the active computer
manually.
28. Start the installation process. If you have changed the ARIS agent's default user
credentials during this procedure, you will be prompted for that password you have
chosen.
The installation process takes some time. You can change settings entered during the setup
process. Use the reconfigure ACC command to change settings, such as ports. After the
ARIS server installation has completed, you must check the installation and configure the
system (page 28).
To uninstall ARIS from a Red Hat or a SUSE system enter, for example, rpm –e
aris10-cloud-agent.
18
SERVER INSTALLATION GUIDE - LINUX
/etc/security/limits.d/[Link]
$max_file_max = "ulimit –n"
If "$max_file_max > 2^20" then max_file_max = 2^20
aris10 soft nofile $max_file_max
aris10 hard nofile $max_file_max
aris10 soft nproc 12204
aris10 hard nproc 12204
/etc/pam.d/su
session required pam_limits.so
Prerequisites
Make sure that the general prerequisites are met (page 3).
An operating Oracle database management system. If you have not yet installed the
Oracle database management system, please follow the instructions in the Oracle
installation program, as well as the documentation provided by the manufacturer. The
external database management system is not included in this package. If you need help in
setting up ARIS using your external database system, please contact ARIS
([Link] Note that this service is not subject to the standard software
maintenance agreement and that these changes can only be performed if you requested
and agreed on them.
Ensure that SQL*PLUS is available. Therefore, an ORACLE client or an ORACL server must
be installed on the machine where the scripts are run.
Use of the database character set AL32UTF8 is mandatory.
19
SERVER INSTALLATION GUIDE - LINUX
You must know the port number, the database/service name of the new database
instance and also the credentials, for example, the user name and the password of the
application user.
You have downloaded the latest supported version (see ARIS System Requirements) of
the Oracle JDBC driver from the Oracle website to a directory of your choice.
SQL scripts and all additional files. All scripts and files are located on the installation
medium (Add-ons\DatabaseScripts\Design&ConnectServer\oracle) or they can be
downloaded from the ARIS Download Center
([Link]
Procedure
1. Copy the file aris10-cloud-agent-<number>-1.x86_64.rpm or
aris10-cloud-agent-SLES-<number>-1.x86_64.rpm from the ARIS installation
package to the hard drive of your Linux system.
This file provides the ARIS agent. The ARIS agent is needed to perform a remote server
installation.
2. Optionally copy the files for installing ARIS Server Administrator and ARIS Scriptrunner.
These files are not mandatory for ARIS server to be installed.
3. Depending on the files you have copied and the type of the Linux system enter the
relevant command to install the files. By default, these installations will create an
unprivileged and locked user aris10 which uses /home/ARIS10 to install ARIS itself. If
you want to use different settings, make sure to change them before installing the first
rpm file (page 8).
rpm –i aris10-cloud-agent-<number>-1.x86_64.rpm
This command installs the ARIS agent to your Red Hat system.
rpm –i aris10-cloud-agent-SLES-<number>-1.x86_64.rpm
This command installs the ARIS agent to your SUSE system.
rpm –i aris10adm-<number>-1.x86_64 and rpm –i
aris10-scriptrunner-<number>-1.x86_64
These commands optionally install the administrator tools ARIS Server Administrator
and ARIS Scriptrunner.
4. Your database administrator must adjust the settings that are used by all database
scripts. These scripts must be executed by the database administrator to set up the
database as required.
Edit the file [Link] to specify the connection data of the Oracle instance. It's a good
idea to write down values and credentials. They must be entered later during the ARIS
server setup process.
5. Edit the [Link] file and adjust the following lines replacing the highlighted
parameters with the settings appropriate for your environment:
20
SERVER INSTALLATION GUIDE - LINUX
21
SERVER INSTALLATION GUIDE - LINUX
To create the schema objects, run these commands for each schema name aris_master,
aris_default and additional tenants.
Run the script cip_create_schema_for_tenant.bat and pass the schema name as
parameter, for example:
cip_create_schema_for_tenant.bat aris_master (mandatory)
cip_create_schema_for_tenant.bat aris_default (mandatory)
cip_create_schema_for_tenant.bat <oracle schema name for additional tenant>
(optional)
If you are going to create additional tenants for ARIS10 to migrate data from ARIS 9.8.7 or
later, make sure to use identical names in both ARIS versions. If the schema already exists
it will be dropped and recreated.
If you use an external database management system and you have created empty
schemes for additional tenants, you must assign additional tenants (page 35) to these
schemes after the ARIS server setup is completed. The default tenant and the master
tenant were assigned automatically.
12. Perform the ARIS server installation from a machine running a Microsoft Windows
operating system (see ARIS installation package\Windows setups\ARIS_Server).
13. Start the [Link] file as an administrator.
14. Select the Perform installation on a remote server option and enter the name of your
Linux system.
15. Select ARIS server to be installed.
16. Select Use dashboards to make dashboards available. This will activate the
dashboarding runnable. If you do not select this option, the runnable will be installed but
not activated.
17. Select ARIS Risk and Compliance if you want to install this program as well. The ARIS Risk
and Compliance installation procedure is described in the ARIS Risk and Compliance
Installation and Upgrade Help. Documents are available in the Documents folder. Read
the documents on the ARIS Documentation website ([Link] or download
them from the ARIS Download Center
([Link]
18. Select the installation directory if required.
19. Only if you need to specify an external proxy server IP address for incoming requests
enter the proxy server computer name or IP.
20. Change the ARIS agent user credentials to prevent unauthorized access to your ARIS
system. Make sure to store the credentials in a save place. If you forget the credentials,
you can no longer update the system or modify the configuration.
22
SERVER INSTALLATION GUIDE - LINUX
If you change the credentials, you will be further on prompted to enter that password
you've chosen whenever you start/stop the ARIS server or access your ARIS installation
using ARIS Cloud Controller.
21. If the ports 1080 or 1443 are already in use, specify the port numbers to be used. If you
change the default port numbers users must add :<this port number> to the URL (see
below).
22. To force secure connections (HTTPS), uncheck HTTP port. If you do so, make sure to
make a valid TLS server certificate (page 31) available.
23. Select the suitable system settings option. You need to take the RAM required and the
number of users who will be accessing the ARIS server into account. For a productive
system it is recommended to select the Medium or Large option.
The Demo scenario option is recommended for demonstration purposes (laptop) only.
Warning
If the hardware does not fit the system requirements, a warning is prompted. In this case
do not proceed the setup. Otherwise, ARIS might not work reliably.
24. To import the ARIS license file, enable Import now, click Select file..., and navigate to the
license archive file. Otherwise, licenses must be imported after the installation.
Make sure this file contains the required ARIS server license. The functional range
depends on the server license that you have purchased (see ARIS Product Feature
Matrix). Read the documents on the ARIS Documentation website
([Link] or download them from the ARIS Download Center
([Link]
25. Select Oracle.
26. Select the required JDBC driver for the Oracle database management system.
27. Enter the connection parameters used in the [Link] file and exactly the values used
by the Oracle server.
The values shown are the default values used in the [Link] file and the default
parameters used when setting up the Oracle server.
Enter exactly the values used by the Oracle server, for example, database name. Use the
default schema's name and the master schema's name that have been created earlier.
Server: Fully qualified name or IP address of the Oracle server.
Port: Specify the port number addressing the Oracle server instance running over
TCP. The corresponding line in the [Link] file is SET TARGET_PORT=1521.
Database/Service name: Specify the Oracle SID or Oracle service name. The
corresponding line in the [Link] file is SET TARGET_SERVICE_NAME=ARIS.
Application user: Login user name that is used by the application. The
corresponding line in the [Link] file is SET CIP_APP_USER=ARIS10.
23
SERVER INSTALLATION GUIDE - LINUX
24
SERVER INSTALLATION GUIDE - LINUX
The installation process takes some time. You can change settings entered during the setup
process. Use the reconfigure ACC command to change settings, such as ports. After the
ARIS server installation has completed, you must check the installation and configure the
system (page 28).
To ensure optimum performance when you are using ARIS with an Oracle database, we
recommend that you recalculate the database statistics regularly
([Link]
To uninstall ARIS from a Red Hat or a SUSE system enter, for example, rpm –e
aris10-cloud-agent.
Update installations are available. Components will be stopped. After the system has been
updated all components will be started automatically.
25
SERVER INSTALLATION GUIDE - LINUX
Warning
ACC commands will majorly impact your system. They require profound knowledge of the
technical ARIS infrastructure and environment. This knowledge can be acquired only by
attending related training courses. These are provided by ARIS Academy. According to the
standard software maintenance agreement, we cannot guarantee proper functioning if you
use ACC commands without this knowledge or without our services.
ARIS Cloud Controller (ACC) can be used in three modes:
BATCH MODE
Batch mode is activated by specifying a command file with the -f command line parameter
(see ACC command line parameters below). ACC will execute the commands in the file in the
given sequence and exit after execution or if one of the commands fails.
A command file line starting with # will be interpreted as a comment line and ignored by ACC.
COMMAND MODE
You can directly pass a single command to ACC as a command line parameter. The command
will be executed and ACC will exit.
When passing commands directly as a command line parameter, you must be careful when
escaping strings in your command, for example, double-quote-delimited parameters. The
operating system command shell will eliminate the double quotes, leaving your string
parameter un-escaped. Therefore, make sure to escape the quote characters and special
characters.
Examples
If you issue the command in command mode, for example:
set [Link]="[Link]
you must enter:
[Link] -h localhost -u <user name> -pwd <remoteAccessPassword> set
[Link]=\"[Link]
If you enter:
26
SERVER INSTALLATION GUIDE - LINUX
To obtain information about the usage of ACC commands, enter help or help <command>.
27
SERVER INSTALLATION GUIDE - LINUX
Procedure
1. Due to the current Tomcat (Ghostcat) vulnerability, block (page 32) all ports except the
load balancer HTTPS port.
2. If you use an external database management system and you have created empty
schemes for additional tenants, you must assign additional tenants (page 35) to these
schemes after the ARIS server setup is completed. The default tenant and the master
tenant were assigned automatically.
3. If you use an external load balancer (LB), you must reconfigure ARIS LB (page 53) to
prevent system failure caused by ARIS brute-force protection.
4. Make sure that all fonts are available (page 46).
5. To check the installation, start ARIS server.
To do so, start ARIS Cloud Controller (su -c [Link] aris10). If you have changed the
ARIS agent's default user credentials during this procedure, you will be prompted for that
password you have chosen.
As the internal ARIS user running all runnables has no root privileges all privileged ports
(<1024) cannot be used. To run ARIS under a privileged port you need to redirect the ports
(page 50).
6. Enter startall. This process will take a while.
7. Enter list to monitor the status of all runnables.
28
SERVER INSTALLATION GUIDE - LINUX
The state of all runnables represented by their instance IDs is listed. Possible states are:
UNKNOWN
The runnable state is not yet known. This state is shown directly after the ARIS agent
was started.
STARTING
The runnable is starting, but this process is not complete yet.
STARTED
The runnable is running.
DEACTIVATED
The runnable is not in use. It has been deactivated manually and can be activated if
necessary.
This runnable is deactivated if ARIS server was installed without ARIS Aware.
DOWN
This runnable started and crashed. The ARIS agent will attempt to automatically
restart the runnable momentarily.
FAILED
This runnable has crashed. The ARIS agent has given up trying to restart the
runnable.
If you want more detailed information on health checks, please refer to the ARIS System
Monitoring guide. If a runnable does not start properly, read the Basic Troubleshooting.
8. After all runnables have started, open your browser and enter localhost or [Link]
address or fully-qualified host name>:<load balancer port>/#<tenant
name>/adminSettings. You must enter the port number only if you have changed or
redirected the standard port. The login dialog opens.
9. Enter the user name superuser and the password superuser. This user only has access
to the ARIS Administration of the tenant.
10. Click OK. ARIS Administration opens.
11. Click Licenses and check whether the licenses were properly imported during setup.
If you have not imported licenses during setup, do so now. For detailed information on
license and user management and security settings refer to the Manage ARIS online help
chapter.
12. Click User management. The list of users is displayed. It contains all default users.
13. Make sure to assign all required license privileges to the system user, such as ARIS
Architect. Otherwise, the system user cannot perform administrative actions, such as
running scheduled reports. For detailed information on license and user management and
security settings refer to the Manage ARIS online help chapter.
29
SERVER INSTALLATION GUIDE - LINUX
14. Change all default passwords and customize the password policy (see Configure user
management).
Warning
To prevent unauthorized access to the ARIS system, after installation or data migration,
always change the default passwords of all users that are automatically created
(arisservice user, guest user, system user, superuser user) on all operational tenants,
as well as on the infrastructure tenant (master). It is mandatory to provide administrator
permissions to different users and/or make sure to not lose the superuser's password.
Otherwise, the system will not allow administrator access. If you did not change the ARIS
agent user's credentials during the setup process, please at least change the ARIS agent
user's password manually.
By default, the elastic_<s, m, or l> runnable (Elasticsearch) uses generic user credentials
required for communication with other ARIS runnables. You can check (page 39) and
change (page 40) the user name and the password if required.
15. Create users or import LDAP users and assign privileges and licenses for the default
tenant. For detailed information on user management and security settings refer to the
Manage ARIS online help chapter.
If you have created additional tenants, users and licenses must be managed for each
additional tenant.
16. Create additional system users and superusers for each tenant holding all required
administrator permissions. This will allow access to the ARIS system in case of password
loss.
17. Optionally customize the password policy. You can define passwords to expire after a
period of time, define length or strength of a password or you can force users to change
their passwords before first login.
18. If you use functionalities and extension packs as listed, you must customize ARIS
accordingly.
If you are going to use ARIS for SAP® Solutions, additional requirements must be
met. For details, see Technical Help: Connect SAP® systems and Required SAP
systems.
To make dashboards available, refer to the online help.
19. Click Logout.
20. Send the URL [Link] address or fully-qualified host name>:<load balancer
port>/#<tenant name>/home to all users.
ARIS server is installed and running.
You can stop ARIS server using the Stop ARIS server link in the Windows start menu or enter
stopall in the ARIS Cloud Controller (see ARIS Cloud Controller (ACC) Command-line
Tool).
30
SERVER INSTALLATION GUIDE - LINUX
31
SERVER INSTALLATION GUIDE - LINUX
If an ARIS client cannot perform connections to servers using TLS certification, you need to
provide an additional certificate (see: Basic Troubleshooting Guide).
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. To check ports used by runnables, enter: show node
The list is displayed. Navigate to the Known used ports section.
Port Runnable Port Parameter
443 loadbalancer_m [Link] Set
explicitly
32
SERVER INSTALLATION GUIDE - LINUX
33
SERVER INSTALLATION GUIDE - LINUX
34
SERVER INSTALLATION GUIDE - LINUX
ADDITIONAL SETTINGS
To enable validationQuery for external database connections (Oracle & Microsoft SQL) use
the correct validation query for the DBMS.
For Oracle use:
validationQuery="select 1 from dual" and testOnBorrow=true
For Microsoft SQL use:
validationQuery="select 1" and testOnBorrow=true
For better readability, the parameters of the command are shown with line-wraps. For
execution you must enter a single-line command.
35
SERVER INSTALLATION GUIDE - LINUX
During registration of external service add parameters, for example, for Oracle:
register external service db
url="jdbc:oracle:thin:@<target_host>:<target_port>:<oracle_sid>"
driverClassName="[Link]"
username="<cip_app_user>
password="<cip_app_pwd>"
maxIdle=15
maxActive=100
maxWait=10000
removeAbandoned=false
removeAbandonedTimeout=600
defaultAutoCommit=false
rollbackOnReturn=true
host=<target_host>
port=<target_port>
jmxEnabled=true
validationQuery="select 1 from dual"
testOnBorrow="true"
After the external service was already registered, for example, for Oracle:
update external service <dbserviceID>
url="jdbc:oracle:thin:@<target_host>:<target_port>:<oracle_sid>"
driverClassName="[Link]"
username="<cip_app_user>"
password="<cip_app_pwd>"
maxIdle=15
maxActive=100
maxWait=10000
removeAbandoned=false
removeAbandonedTimeout=600
defaultAutoCommit=false
rollbackOnReturn=true
host=<target_host>
jmxEnabled=true
validationQuery="select 1 from dual"
testOnBorrow="true"
36
SERVER INSTALLATION GUIDE - LINUX
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. To connect to an Oracle cluster using a JDBC URL you may use this example:
update external service <dbserviceID>
url="jdbc:oracle:thin:@(DESCRIPTION=ADDRESS_LIST=(ADDRESS=(PROTOCOL=TCP
) (HOST=<virtual-ip-oracle-cluster>)(PORT = <target
port>)))(CONNECT_DATA=(SERVICE_NAME=cluster-database-name)))"
driverClassName="[Link]" username="<cip_app_user>"
password="<new_cip_app_pwd>" maxIdle=15 maxActive=100 maxWait=10000
removeAbandoned=false removeAbandonedTimeout=600 logAbandoned=true
defaultAutoCommit=false rollbackOnReturn=true host=<target_host>
jmxEnabled=true validationQuery="select 1 from dual" testOnBorrow=true
ARIS server can be started using the Oracle cluster.
37
SERVER INSTALLATION GUIDE - LINUX
Procedure
1. Start ARIS Server Administrator. This command line tool is available, if you have
installed ARIS server, or the ARIS Administrator Tools (see Technical Help: ARIS client
Installation Guide. Read the documents on the ARIS Documentation website
([Link] or download them from the ARIS Download Center
([Link]
If you have installed ARIS server, navigate to <ARIS installation
path>\server\bin\work\work_abs_<s, m, or l>\tools\arisadm and run the batch file.
Under a Linux operating system, execute the [Link] shell script instead. The
command prompt opens and ARIS Server Administrator is launched in interactive mode.
If you accepted the program group suggested by the installation program, click Start >
Programs > ARIS > Administration > ARIS Server Administrator 10.
2. Establish a connection to the server using the server command:
syntax: server <server name>:<port number> <tenant> <user name> <password>
example: server localhost:80 default system manager
3. Enter command: encrypt <pwd_to_be_encrypted>
Example:
encrypt databaseuser
encrypted password:{crypted}123456789abcdefg
4. Copy the encrypted password, such as {crypted}123456789abcdefg to a text editor
file.
You can paste the encrypted password to related fields.
38
SERVER INSTALLATION GUIDE - LINUX
3.3 Elasticsearch
The Document index (Elasticsearch) is a basic component that contains the full-text search
index for documents and collaboration data. It also stores users, user groups, licenses, and
privileges. By default, the elastic_<s, m, or l> runnable (Elasticsearch) uses generic user
credentials required for communication with other ARIS runnables.
Procedure
1. Navigate to <ARIS installation path>\server\bin\work\work_elastic_m, for example,
C:\ARIS10.0\server\bin\work\work_elastic_m.
2. Open the [Link] file with a text editor.
3. Copy the instance ID, for example:
elasticsearch0000000000
4. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
5. Once ACC is initialized, enter show service elastisearch<ID>, for example:
show service elasticsearch0000000000
User name and password are displayed.
You can change (page 40) the user name and the password if required.
39
SERVER INSTALLATION GUIDE - LINUX
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. Once ACC is initialized, enter:
reconfigure elastic_<s, m, or l> +[Link]="<new user
name" +[Link]="<new password>"
for example:
reconfigure elastic_m +[Link]="administrator"
+[Link]="Thssmynwpsswrd"
3. Stop the Collaboration runnable ecp_<s, m, or l>. Enter, for example:
stop ecp_m
4. Restart the Collaboration runnable. Enter, for example:
5. start ecp_m
You have changed the user credentials required for the Elasticsearch.
40
SERVER INSTALLATION GUIDE - LINUX
Warning
Disabling authentication is not recommended and must be considered carefully. It bears a
potentially risk to data security.
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. Once ACC is initialized, enter: reconfigure elastic_<s, m, or l>
+[Link]="true"
for example: reconfigure elastic_m
+[Link]="true"
You have disabled the authentication for the Elasticsearch.
41
SERVER INSTALLATION GUIDE - LINUX
3.5 Mailing
This chapter provides information on configuring automatic mailing.
Parameter Description
[Link] true enables automatic mailing.
d
(default: false)
[Link] User name on the mail server. If this parameter is set, the
applications will implicitly enable SMTP authentication. There
is NO dedicated parameter to explicitly enable SMTP
authentication.
42
SERVER INSTALLATION GUIDE - LINUX
Parameter Description
[Link] Sender's e-mail address.
43
SERVER INSTALLATION GUIDE - LINUX
Default
Parameter Type Description
value
Host String Qualified hostname or IP of the SMTP server.
host
44
SERVER INSTALLATION GUIDE - LINUX
Default
Parameter Type Description
value
TLS mode String STARTTL Specifies the method used to secure the
[Link] S connection. Accepted values are STARTTLS
and SSL. STARTTLS upgrades an initially
non-secure connection to an encrypted one
without requiring a dedicated port for secure
communication, whereas SSL immediately
establishes a secured connection on a
dedicated port.
45
SERVER INSTALLATION GUIDE - LINUX
46
SERVER INSTALLATION GUIDE - LINUX
When ARIS server is installed on a Windows® operating system, all fonts saved in the Fonts
folder of the operating system are available for report and model graphic generation. Linux
operating systems usually provide a smaller set of fonts.
If you use additional fonts in report scripts or in models, you must add the missing fonts to
the system database of this tenant. If a used font is missing, unreadable content appears in
report output files or incorrect line breaks show up in model graphics. This can occur, for
example, in Japanese, if the default attribute font MS UI Gothic is missing. In this case, add at
least the [Link] font file.
Warning
If ARIS server is installed on a Linux operating system, usually no Windows® standard fonts
are available. To prevent unreadable content or incorrect line breaks, make sure to add all
used fonts from your Windows® operating system to the system database of the tenant.
Prerequisite
You are the script administrator for this tenant.
You have access to the required font file (*.ttf or *.ttc).
Procedure
1. In ARIS Architect, click ARIS > Administration.
2. Click Navigation in the bar panel if the Navigation bar is not activated yet.
3. In the navigation tree, click the folder Evaluations > Fonts. All additional fonts
available in the system database of this tenant are listed. If no fonts are displayed, only
the fonts of the Windows® operating system are in use. These fonts are not displayed
here.
4. Click Add font. The dialog for file selection opens.
5. Navigate to the required ttf or ttc file.
If you want to add fonts, such as the [Link] font file from your Windows/Fonts
folder, you must first copy them to a different folder. The Windows/Fonts folder cannot
be used as source folder because the Windows® operating system does not allow direct
access.
6. Select the font files and click Open.
The fonts are added to the system database of this tenant. They are available for reports and
model graphic generation.
If you want to delete a font, move the mouse pointer to the required font, right-click, and click
Delete.
Adding fonts to the system database has the advantages that font sets are update-prove
and there is no need restarting ARIS server to make changes available.
47
SERVER INSTALLATION GUIDE - LINUX
Warning
If ARIS server is installed on a Linux operating system, usually no Windows® standard fonts
are available. To prevent unreadable content or incorrect line breaks, make sure to add all
used fonts from your Windows® operating system to the system database of the tenant.
48
SERVER INSTALLATION GUIDE - LINUX
Prerequisite
You are the script administrator for this tenant.
You have access to the required font file (*.ttf or *.ttc).
Procedure
1. In ARIS Architect, click ARIS > Administration.
2. Click Navigation in the bar panel if the Navigation bar is not activated yet.
3. In the navigation tree, click the folder Evaluations > Fonts. All additional fonts
available in the system database of this tenant are listed. If no fonts are displayed, only
the fonts of the Windows® operating system are in use. These fonts are not displayed
here.
4. Click Add font. The dialog for file selection opens.
5. Navigate to the required ttf or ttc file.
If you want to add fonts, such as the [Link] font file from your Windows/Fonts
folder, you must first copy them to a different folder. The Windows/Fonts folder cannot
be used as source folder because the Windows® operating system does not allow direct
access.
6. Select the font files and click Open.
The fonts are added to the system database of this tenant. They are available for reports and
model graphic generation.
If you want to delete a font, move the mouse pointer to the required font, right-click, and click
Delete.
Prerequisites
You have access to a Web server with SSL configuration.
You have downloaded the zipped help file from the ARIS Download Center
([Link] for example
ARIS_Installation_and_Documentation_<version>.zip, and unzipped it to the Root
directory of your Web server.
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
49
SERVER INSTALLATION GUIDE - LINUX
2. Enter the path to your internal Web server on which the documents and the online help
are provided:
[Link]="<URL to your Web server>"
Syntax: "[Link] number>"
The default path is: [Link]="[Link]
3. To reconfigure the abs, copernicus, and arcm runnables using the [Link] of your Web
server, enter the following on all nodes:
reconfigure abs_<s, m, or l> [Link]="<URL to your Web server>"
reconfigure copernicus_<s, m, or l> [Link]="<URL to your Web server>"
reconfigure arcm_<s, m, or l> [Link]="<URL to your Web server>"
4. To specify the version of the content to be used, enter the following for each runnable on
all nodes:
reconfigure <runnable> [Link]="10.2025.10.0"
Example
reconfigure abs [Link]="10.2025.10"
The help is redirected to your internal Web server.
After an update setup, the help on your internal Web server will keep the current version until
you have downloaded the corresponding zipped help file from the ARIS Download Center and
updated your Web server.
Procedure
1. To redirect ports, use the basic syntax of the iptables command:
iptables -t nat -A PREROUTING -i <network interface> -p tcp --dport <port number
to redirect> -j REDIRECT --to-ports <port number>
50
SERVER INSTALLATION GUIDE - LINUX
Replace <network interface> with the name of the network interface through which
each ARIS client accesses the ARIS server. You can use the ip addr command to get an
overview of all network interfaces and their associated IP addresses.
Replace <port number to redirect> with the port on which ARIS should be made
accessible to clients. Usually this is the default port of the respective protocol: port 80 for
HTTP and port 443 for HTTPS.
Replace <port number> with the physical port used by the loadbalancer runnable, that
is: port 1080 for HTTP and port 1443 for HTTPS, unless the load balancer port
configuration was changed.
This example redirects port 80 to port 1080 to allow HTTP access over the standard port
for the network interface enp0s8:
iptables -t nat -A PREROUTING -i enp0s8 -p tcp --dport 80 -j REDIRECT --to-ports
1080
This example redirects port 443 to port 1443 to allow HTTPS access over the standard
port, here for a network interface named eth0:
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-ports
1443
Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. Run a reconfigure command on the loadbalancer runnable.
To make the loadbalancer runnable know through which ports users are now accessing
it, you need to run an ACC reconfigure command with the following syntax:
reconfigure loadbalancer_<SIZING>
[Link]=<externalHttpPort>
[Link]=<externalHttpsPort>
Replace <SIZING> with the sizing you used to install ARIS server, such as s, m, or l.
Replace <externalHttpPort> with the port from which you redirect to the physical HTTP
port of the loadbalancer runnable (usually port 80).
Replace <externalHttpsPort> with the port from which you redirect to the physical
HTTPS port of the loadbalancer runnable (usually port 443).
This example tells the loadbalancer runnable in an m size installation that users are now
accessing through the redirected ports 80 and 443:
reconfigure loadbalancer_m [Link]=80
[Link]=443
ARIS users access ARIS using the redirected ports.
If runnables do not start up properly, resolve possible port conflicts.
51
SERVER INSTALLATION GUIDE - LINUX
Procedure
1. Start ARIS Cloud Controller (ACC) (page 26) and establish a connection.
2. Enter:
reconfigure loadbalancer_m [Link]=":443"
You must enter a colon followed by the port number.
Users are forwarded correctly.
52
SERVER INSTALLATION GUIDE - LINUX
53
SERVER INSTALLATION GUIDE - LINUX
X-Forwarded-Proto contains the protocol (HTTPS or HTTP) that the client originally
used.
X-Forwarded-Host contains the original host name that the client used.
There is also a more recent header specified (Forwarded header), which puts all this
information into a single header, but the concept is the same.
To make all the functionality above work properly, an external LB has to add the
X-Forwarded-* headers or the Forwarded header to the request, putting in the true client
information.
However, if ARIS would simply accept these headers from anywhere, an attacker could create
requests that already contain these headers. For example, using the X-Forwarded-For
header, he could circumvent the login attempt limitation. He could use a physical IP address,
but change the IP in the X-Forwarded-For header for each attempt. For this and similar
reasons, ARIS LB will by default not accept any of the X-Forwared-* headers from anyone.
They will simply be removed from the request before passing it on to the actual application
micro services.
Using the [Link] parameter, you can specify a
regular expression. Any client IP that matches this regex will be considered trustworthy, and
only from those the ARIS LB will accept the X-Forwarded-* headers.
Note that while this parameter name suggests that it is only relevant for the X-Forwarded-For
it is now used for all of these headers - we merely decided to keep the parameter name for
compatibility.
Therefore, in any scenario where clients do not directly access ARIS LB, but go through
external LBs, you must declare the IPs of your external LBs as trustworthy to ARIS LBs.
Therefore, reconfigure each ARIS LB. And if your external LB is using more than one IP
address to access ARIS, you must change the regex so that all of these IP addresses match.
The regex syntax used is that of the perl-compatible regular expressions library (PCRE)
[Link] The only caveat is that if you need to use a backslash in your regex
(like to escape the "." in the above proposal), it has to be replaced by four backslashes.
Example
If the IP of your external LB is [Link] and you are using two ARIS LBs, enter the
following ARIS Cloud Controller (ACC) commands:
on n1 reconfigure loadbalancer_l
[Link]="198\\\\.20\\\\.212\\\\.156"
on n2 reconfigure loadbalancer_l
[Link]="198\\\\.20\\\\.212\\\\.156"
54
SERVER INSTALLATION GUIDE - LINUX
4.2 Support
PRODUCT SUPPORT
We provide support for ARIS products to all customers with a valid support contract.
Contact our Global Support services at ARIS Community to raise and update support incidents
([Link] or post ideas and feature requests
([Link]
55
SERVER INSTALLATION GUIDE - LINUX
COMMUNITY
Register with ARIS Community to download products, updates and fixes, find expert
information, and interact with other users.
DOCUMENTATION
For information on how to use and activate products and for other technical support
questions, visit the ARIS Documentation website ([Link]
If you want to give feedback on any documentation topic, write to documentation@[Link].
56