Installing Delinea Credentials Cache on Linux

This topic describes how to install Delinea Credentials Cache on Linux. The steps cover downloading the package, installing the .NET runtime, creating a systemd service, and setting up Apache HTTP Server as a reverse proxy.

These instructions apply to Ubuntu Linux and Red Hat Enterprise Linux (RHEL). Where steps differ between distributions, both variants are shown.

Before you begin, make sure that the requirements in Prerequisites are met.

Step 1: Download and Extract the Package

To download and extract the Delinea Credentials Cache package for Linux:

  1. Download the Linux package (a zip archive).

  2. Create a directory for Delinea Credentials Cache and extract the archive into it:

    mkdir ~/credcache

    unzip DelineaCredentialCache_Linux.zip -d ~/credcache

Step 2: Install the .NET Runtime

Delinea Credentials Cache requires the ASP.NET Core 10.0 runtime. Follow the steps for your Linux distribution.

Ubuntu Linux

Open a terminal with root privileges and run the following commands in order:

  1. Get the Ubuntu version:

    declare repo_version=$(if command -v lsb_release &> /dev/null; then lsb_release -r -s; else grep -oP '(?<=^VERSION_ID=).+' /etc/os-release | tr -d '"'; fi)

  2. Download the Microsoft signing key and repository:

    wget https://packages.microsoft.com/config/ubuntu/$repo_version/packages-microsoft-prod.deb -O packages-microsoft-prod.deb

  3. Install the Microsoft signing key and repository:

    sudo dpkg -i packages-microsoft-prod.deb

  4. Clean up the downloaded file:

    rm packages-microsoft-prod.deb

  5. Update the package index and install the ASP.NET Core runtime:

    sudo apt update

    sudo apt install aspnetcore-runtime-10.0

Red Hat Enterprise Linux (RHEL)

Open a terminal with root privileges and run the following commands in order:

  1. Import the Microsoft signing key:

    sudo rpm --import https://packages.microsoft.com/keys/microsoft.asc

  2. Add the Microsoft .NET repository:

    sudo tee /etc/yum.repos.d/dotnet-sdk.repo << EOF
    [microsoft-dotnet]
    name=Microsoft dotnet
    baseurl=https://packages.microsoft.com/rhel/8/prod/
    enabled=1
    gpgcheck=1
    gpgkey=https://packages.microsoft.com/keys/microsoft.asc
    EOF

    If you are using RHEL 7, replace rhel/8 with rhel/7 in the baseurl line.

  3. Install the ASP.NET Core runtime:

    sudo yum install aspnetcore-runtime-10.0

Step 3: Create a systemd Service

Create a systemd service so that Delinea Credentials Cache runs in the background and restarts automatically if it stops.

  1. Create the service configuration file:

    sudo nano /etc/systemd/system/credcache.service

  2. Insert the following content. Replace the WorkingDirectory and ExecStart paths with the actual location of your extracted package (run realpath ~/credcache to find it, and which dotnet to confirm the runtime path), and replace yourusername with the user account that will run the service.

    [Unit]
    Description=Delinea Credentials Cache
    After=network.target
    
    [Service]
    WorkingDirectory=/home/ubuntu/credcache
    ExecStart=/usr/bin/dotnet /home/ubuntu/credcache/DelineaCredentialCache.dll
    Restart=always
    RestartSec=10
    SyslogIdentifier=delineacredcache
    User=yourusername
    Environment=ASPNETCORE_ENVIRONMENT=Production
    
    [Install]
    WantedBy=multi-user.target
  3. Press Ctrl + O to save the file, press Enter, then press Ctrl + X to exit.

  4. Reload the systemd daemon to register the new service:

    sudo systemctl daemon-reload

  5. Start the service:

    sudo systemctl start credcache.service

  6. Enable the service to start automatically on boot:

    sudo systemctl enable credcache.service

  7. Verify that the service is running:

    sudo systemctl status credcache.service

To stop the service when required, run sudo systemctl stop credcache.service. To restart it after changing appsettings.json, run sudo systemctl restart credcache.service.

Step 4: Set Up Apache HTTP Server as a Reverse Proxy

When started by the systemd service, Delinea Credentials Cache listens on http://localhost:5000 (the ASP.NET Core default; the package does not override it). Apache HTTP Server acts as a reverse proxy to expose the service over HTTP or HTTPS. Follow the steps for your Linux distribution and protocol.

Ubuntu Linux — HTTP

  1. Install Apache HTTP Server:

    sudo apt install apache2

  2. Create the configuration file:

    sudo nano /etc/apache2/sites-available/credcache.conf

  3. Insert the following content. Replace your-domain.com with your server name.

    <VirtualHost *:80>
        ServerName your-domain.com
        ProxyPass / http://localhost:5000/
        ProxyPassReverse / http://localhost:5000/
    </VirtualHost>
  4. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  5. Enable the proxy modules:

    sudo a2enmod proxy

    sudo a2enmod proxy_http

  6. Enable the site:

    sudo a2ensite credcache

  7. Restart Apache HTTP Server:

    sudo systemctl restart apache2

Ubuntu Linux — HTTPS

  1. Install Apache HTTP Server and OpenSSL:

    sudo apt install apache2

    sudo apt-get update && sudo apt-get install openssl

  2. Create an OpenSSL configuration file:

    sudo nano /etc/ssl/openssl2.cnf

  3. Insert the following content. Replace the commonName, DNS.1, and IP.1 values with the fully qualified domain name and IP address of your Linux computer.

    [req]
    default_bits       = 2048
    default_keyfile    = localhost.key
    distinguished_name = req_distinguished_name
    req_extensions     = req_ext
    x509_extensions    = v3_ca
    [req_distinguished_name]
    commonName         = your-host.your-domain.com
    commonName_default = your-host.your-domain.com
    commonName_max     = 64
    [req_ext]
    subjectAltName = @alt_names
    [v3_ca]
    subjectAltName = @alt_names
    [alt_names]
    DNS.1 = your-host.your-domain.com
    DNS.2 = localhost
    IP.1  = 0.0.0.0
  4. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  5. Generate a self-signed certificate:

    sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/selfsigned.key -out /etc/ssl/certs/selfsigned.crt -config /etc/ssl/openssl2.cnf

  6. Generate the certificate in PFX format (needed if a client application must trust the same certificate):

    sudo openssl pkcs12 -export -out /etc/ssl/certs/selfsigned.pfx -inkey /etc/ssl/private/selfsigned.key -in /etc/ssl/certs/selfsigned.crt

  7. Create the Apache HTTP Server configuration file:

    sudo nano /etc/apache2/sites-available/credcache.conf

  8. Insert the following content. Replace the server name and file paths if required.

    <VirtualHost *:443>
        ServerName your-host.your-domain.com
        SSLEngine on
        SSLCertificateFile /etc/ssl/certs/selfsigned.crt
        SSLCertificateKeyFile /etc/ssl/private/selfsigned.key
        SSLProxyEngine on
        ProxyPass / http://localhost:5000/
        ProxyPassReverse / http://localhost:5000/
    </VirtualHost>
  9. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  10. Enable the required modules and the site:

    sudo a2enmod proxy proxy_http ssl

    sudo a2ensite credcache

  11. Restart Apache HTTP Server:

    sudo systemctl restart apache2

Red Hat Enterprise Linux — HTTP

  1. Install the required packages:

    sudo yum install httpd mod_proxy mod_proxy_http

  2. Create the configuration file:

    sudo nano /etc/httpd/conf.d/credcache.conf

  3. Insert the following content. Replace your-domain.com with your server name.

    <VirtualHost *:80>
        ServerName your-domain.com
        ProxyPass / http://localhost:5000/
        ProxyPassReverse / http://localhost:5000/
    </VirtualHost>
  4. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  5. Enable httpd to start on boot, then start (or restart) it:

    sudo systemctl enable httpd

    sudo systemctl restart httpd

Red Hat Enterprise Linux — HTTPS

  1. Install OpenSSL and the proxy and SSL modules:

    sudo yum install openssl mod_proxy mod_proxy_http mod_ssl

  2. Create an OpenSSL configuration file:

    sudo nano /etc/ssl/openssl2.cnf

  3. Insert the configuration content shown in the Ubuntu Linux — HTTPS section, replacing commonName, DNS.1, and IP.1 with your server's values.

  4. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  5. Generate a self-signed certificate:

    sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/selfsigned.key -out /etc/ssl/certs/selfsigned.crt -config /etc/ssl/openssl2.cnf

  6. Generate the certificate in PFX format:

    sudo openssl pkcs12 -export -out /etc/ssl/certs/selfsigned.pfx -inkey /etc/ssl/private/selfsigned.key -in /etc/ssl/certs/selfsigned.crt

  7. Create the HTTPS configuration file:

    sudo nano /etc/httpd/conf.d/ssl.conf

  8. Insert the following content. Replace the server name and file paths if required.

    <VirtualHost *:443>
        ServerName your-host.your-domain.com
        SSLEngine on
        SSLCertificateFile /etc/ssl/certs/selfsigned.crt
        SSLCertificateKeyFile /etc/ssl/private/selfsigned.key
        SSLProxyEngine on
        ProxyPass / http://localhost:5000/
        ProxyPassReverse / http://localhost:5000/
    </VirtualHost>
  9. Press Ctrl + O to save, press Enter, then press Ctrl + X to exit.

  10. Enable httpd to start on boot, then restart it:

    sudo systemctl enable httpd

    sudo systemctl restart httpd

On RHEL with SELinux enforcing, Apache HTTP Server may be blocked from opening outbound connections to the local Kestrel port. If the proxy returns 503 Service Unavailable, run sudo setsebool -P httpd_can_network_connect 1.

Next Steps