The TAC Shell Access function allows a Cisco engineer to log in directly to the Ubuntu shell using multifactor authentication through the dg-tac user.
By default, the dg-tac account is locked and the password is expired to prevent unauthorized access. Once enabled, the dg-tac user is active for less than 24 hours (until midnight UTC [00:00 UTC] the next day).
Before you begin
Confirm that the Cisco engineer you are working with has access to the Secure Web Identity Management Service (SWIMS) Aberto tool. Active communication with the Cisco engineer is required to enable dg-tac access.
Procedure
|
1. |
Log in to the Crosswork Data Gateway VM as the dg-admin user. |
|
2. |
From the Main Menu, select Troubleshooting. |
|
3. |
From the Troubleshooting menu, select Enable TAC Shell Access.
A dialog appears, warning you that the dg-tac user login requires a password you set, along with a challenge token from TAC. Choose Yes to continue or No to cancel.
|
|
4. |
If you proceed, the system prompts you to set a password for the dg-tac user. |
|
5. |
Enter a password, and the system displays the expiration date when the account will be disabled. |
|
6. |
Log out of Crosswork Data Gateway. |
|
7. |
If the Cisco engineer has direct access to the Crosswork Data Gateway VM, share the password you set in Step 3.
-
Share the password that you had set in Step 5 for the dg-tac user with the Cisco engineer who is working with you.
-
The engineer logs in via SSH as the dg-tac user with the password you provided.
The system will then prompt for a challenge token. The engineer signs it using SWIMS Aberto, pastes the signed response into the VM, and logs in successfully.
-
The Cisco engineer logs in successfully as the dg-tac user and completes the troubleshooting.
There is a fifteen-minute idle timeout period for the dg-tac user. If the Cisco engineer logs out, they must sign a new challenge to log in again.
-
After troubleshooting is complete, the Cisco engineer logs out of the TAC shell.
|
|
8. |
If the Cisco engineer does not have direct access:
-
Start a meeting with desktop sharing enabled.
-
Log in as dg-tac using SSH:
ssh dg-tac@<DG hostname or IP>
-
Enter the password that you set and obtain the challenge token.
-
Share the token with the Cisco engineer, who will sign it using SWIMS Aberto and provide the signed response.
-
Paste the signed response back into the VM to get the shell prompt.
-
Share your desktop, or follow the engineer’s instructions to troubleshoot.
There is a fifteen-minute idle timeout period for the dg-tac user. If logged out, the Cisco engineer must sign a new challenge to log in again.
-
Once troubleshooting is complete, the engineer logs out of the TAC shell.
|