Installing Delinea Credentials Cache on Linux
This topic describes how to install Delinea Credentials Cache on Linux. The steps cover downloading the package, installing the .NET runtime, creating a systemd service, and setting up Apache HTTP Server as a reverse proxy.
These instructions apply to Ubuntu Linux and Red Hat Enterprise Linux (RHEL). Where steps differ between distributions, both variants are shown.
Before you begin, make sure that the requirements in Prerequisites are met.
Step 1: Download and Extract the Package
To download and extract the Delinea Credentials Cache package for Linux:
-
Download the Linux package (a zip archive).
-
Create a directory for Delinea Credentials Cache and extract the archive into it:
mkdir ~/credcacheunzip DelineaCredentialCache_Linux.zip -d ~/credcache
Step 2: Install the .NET Runtime
Delinea Credentials Cache requires the ASP.NET Core 10.0 runtime. Follow the steps for your Linux distribution.
Ubuntu Linux
Open a terminal with root privileges and run the following commands in order:
-
Get the Ubuntu version:
declare repo_version=$(if command -v lsb_release &> /dev/null; then lsb_release -r -s; else grep -oP '(?<=^VERSION_ID=).+' /etc/os-release | tr -d '"'; fi) -
Download the Microsoft signing key and repository:
wget https://packages.microsoft.com/config/ubuntu/$repo_version/packages-microsoft-prod.deb -O packages-microsoft-prod.deb -
Install the Microsoft signing key and repository:
sudo dpkg -i packages-microsoft-prod.deb -
Clean up the downloaded file:
rm packages-microsoft-prod.deb -
Update the package index and install the ASP.NET Core runtime:
sudo apt updatesudo apt install aspnetcore-runtime-10.0
Red Hat Enterprise Linux (RHEL)
Open a terminal with root privileges and run the following commands in order:
-
Import the Microsoft signing key:
sudo rpm --import https://packages.microsoft.com/keys/microsoft.asc -
Add the Microsoft .NET repository:
sudo tee /etc/yum.repos.d/dotnet-sdk.repo << EOF [microsoft-dotnet] name=Microsoft dotnet baseurl=https://packages.microsoft.com/rhel/8/prod/ enabled=1 gpgcheck=1 gpgkey=https://packages.microsoft.com/keys/microsoft.asc EOFIf you are using RHEL 7, replace
rhel/8withrhel/7in thebaseurlline. -
Install the ASP.NET Core runtime:
sudo yum install aspnetcore-runtime-10.0
Step 3: Create a systemd Service
Create a systemd service so that Delinea Credentials Cache runs in the background and restarts automatically if it stops.
-
Create the service configuration file:
sudo nano /etc/systemd/system/credcache.service -
Insert the following content. Replace the
WorkingDirectoryandExecStartpaths with the actual location of your extracted package (runrealpath ~/credcacheto find it, andwhich dotnetto confirm the runtime path), and replaceyourusernamewith the user account that will run the service.[Unit] Description=Delinea Credentials Cache After=network.target [Service] WorkingDirectory=/home/ubuntu/credcache ExecStart=/usr/bin/dotnet /home/ubuntu/credcache/DelineaCredentialCache.dll Restart=always RestartSec=10 SyslogIdentifier=delineacredcache User=yourusername Environment=ASPNETCORE_ENVIRONMENT=Production [Install] WantedBy=multi-user.target -
Press Ctrl + O to save the file, press Enter, then press Ctrl + X to exit.
-
Reload the systemd daemon to register the new service:
sudo systemctl daemon-reload -
Start the service:
sudo systemctl start credcache.service -
Enable the service to start automatically on boot:
sudo systemctl enable credcache.service -
Verify that the service is running:
sudo systemctl status credcache.service
To stop the service when required, run sudo systemctl stop credcache.service. To restart it after changing appsettings.json, run sudo systemctl restart credcache.service.
Step 4: Set Up Apache HTTP Server as a Reverse Proxy
When started by the systemd service, Delinea Credentials Cache listens on http://localhost:5000 (the ASP.NET Core default; the package does not override it). Apache HTTP Server acts as a reverse proxy to expose the service over HTTP or HTTPS. Follow the steps for your Linux distribution and protocol.
Ubuntu Linux — HTTP
-
Install Apache HTTP Server:
sudo apt install apache2 -
Create the configuration file:
sudo nano /etc/apache2/sites-available/credcache.conf -
Insert the following content. Replace
your-domain.comwith your server name.<VirtualHost *:80> ServerName your-domain.com ProxyPass / http://localhost:5000/ ProxyPassReverse / http://localhost:5000/ </VirtualHost> -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Enable the proxy modules:
sudo a2enmod proxysudo a2enmod proxy_http -
Enable the site:
sudo a2ensite credcache -
Restart Apache HTTP Server:
sudo systemctl restart apache2
Ubuntu Linux — HTTPS
-
Install Apache HTTP Server and OpenSSL:
sudo apt install apache2sudo apt-get update && sudo apt-get install openssl -
Create an OpenSSL configuration file:
sudo nano /etc/ssl/openssl2.cnf -
Insert the following content. Replace the
commonName,DNS.1, andIP.1values with the fully qualified domain name and IP address of your Linux computer.[req] default_bits = 2048 default_keyfile = localhost.key distinguished_name = req_distinguished_name req_extensions = req_ext x509_extensions = v3_ca [req_distinguished_name] commonName = your-host.your-domain.com commonName_default = your-host.your-domain.com commonName_max = 64 [req_ext] subjectAltName = @alt_names [v3_ca] subjectAltName = @alt_names [alt_names] DNS.1 = your-host.your-domain.com DNS.2 = localhost IP.1 = 0.0.0.0 -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Generate a self-signed certificate:
sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/selfsigned.key -out /etc/ssl/certs/selfsigned.crt -config /etc/ssl/openssl2.cnf -
Generate the certificate in PFX format (needed if a client application must trust the same certificate):
sudo openssl pkcs12 -export -out /etc/ssl/certs/selfsigned.pfx -inkey /etc/ssl/private/selfsigned.key -in /etc/ssl/certs/selfsigned.crt -
Create the Apache HTTP Server configuration file:
sudo nano /etc/apache2/sites-available/credcache.conf -
Insert the following content. Replace the server name and file paths if required.
<VirtualHost *:443> ServerName your-host.your-domain.com SSLEngine on SSLCertificateFile /etc/ssl/certs/selfsigned.crt SSLCertificateKeyFile /etc/ssl/private/selfsigned.key SSLProxyEngine on ProxyPass / http://localhost:5000/ ProxyPassReverse / http://localhost:5000/ </VirtualHost> -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Enable the required modules and the site:
sudo a2enmod proxy proxy_http sslsudo a2ensite credcache -
Restart Apache HTTP Server:
sudo systemctl restart apache2
Red Hat Enterprise Linux — HTTP
-
Install the required packages:
sudo yum install httpd mod_proxy mod_proxy_http -
Create the configuration file:
sudo nano /etc/httpd/conf.d/credcache.conf -
Insert the following content. Replace
your-domain.comwith your server name.<VirtualHost *:80> ServerName your-domain.com ProxyPass / http://localhost:5000/ ProxyPassReverse / http://localhost:5000/ </VirtualHost> -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Enable httpd to start on boot, then start (or restart) it:
sudo systemctl enable httpdsudo systemctl restart httpd
Red Hat Enterprise Linux — HTTPS
-
Install OpenSSL and the proxy and SSL modules:
sudo yum install openssl mod_proxy mod_proxy_http mod_ssl -
Create an OpenSSL configuration file:
sudo nano /etc/ssl/openssl2.cnf -
Insert the configuration content shown in the Ubuntu Linux — HTTPS section, replacing
commonName,DNS.1, andIP.1with your server's values. -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Generate a self-signed certificate:
sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/selfsigned.key -out /etc/ssl/certs/selfsigned.crt -config /etc/ssl/openssl2.cnf -
Generate the certificate in PFX format:
sudo openssl pkcs12 -export -out /etc/ssl/certs/selfsigned.pfx -inkey /etc/ssl/private/selfsigned.key -in /etc/ssl/certs/selfsigned.crt -
Create the HTTPS configuration file:
sudo nano /etc/httpd/conf.d/ssl.conf -
Insert the following content. Replace the server name and file paths if required.
<VirtualHost *:443> ServerName your-host.your-domain.com SSLEngine on SSLCertificateFile /etc/ssl/certs/selfsigned.crt SSLCertificateKeyFile /etc/ssl/private/selfsigned.key SSLProxyEngine on ProxyPass / http://localhost:5000/ ProxyPassReverse / http://localhost:5000/ </VirtualHost> -
Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.
-
Enable httpd to start on boot, then restart it:
sudo systemctl enable httpdsudo systemctl restart httpd
On RHEL with SELinux enforcing, Apache HTTP Server may be blocked from opening outbound connections to the local Kestrel port. If the proxy returns 503 Service Unavailable, run sudo setsebool -P httpd_can_network_connect 1.
Next Steps
-
Confirm that the service is running and the Swagger UI loads through the proxy: Verifying the Deployment.
-
Adjust the cache expiration and logging settings in
appsettings.json: Configuring Delinea Credentials Cache.