wazuh-manager-authd
The wazuh-manager-authd executable runs the Wazuh manager agent enrollment service.
The agent enrollment service registers Wazuh agents with the Wazuh manager and generates unique client keys for encrypted, authenticated communication between agents and the Wazuh manager.
By default, the service listens for agent enrollment requests on TCP port 1515. It supports additional security measures, including password authentication, Wazuh manager identity verification, and Wazuh agent identity verification.
For more information about agent enrollment and the available authentication methods, see the Agent enrollment service section of the User Manual.
Option |
Description |
|---|---|
-c <ciphers> |
Specifies the list of TLS 1.3 cipher suites. The default is TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256. The daemon exits if the value is not a valid list of TLS 1.3 cipher suites. |
-d |
Runs the daemon in debug mode. Repeat the option to increase the debug level. |
-D <directory> |
Specifies the Wazuh manager installation directory used to build the default server certificate and key paths. The default is /var/wazuh-manager. This option does not change the working directory of the daemon. |
-f |
Runs the daemon in the foreground. |
-g <group> |
Specifies the group under which the daemon runs. The default is wazuh-manager. |
-h |
Displays the help message and exits. |
-k <path> |
Specifies the full path to the server private key. The default is etc/certs/remoted-key.pem. |
-p <port> |
Specifies the port used by the enrollment service. The default is 1515. |
-P |
Forces shared-password enrollment on. The daemon itself has this method disabled by default, but the configuration shipped by the installer enables it. The password is read from etc/authd.pass or generated automatically. |
-s |
Enables source host verification. Use this option with -v. |
-t |
Tests the configuration and exits. |
-u <user> |
Specifies the user under which the daemon runs. The default is wazuh-manager. |
-v <path> |
Specifies the full path to the certificate authority certificate used to verify agents. |
-V |
Displays version and license information. |
-x <path> |
Specifies the full path to the server certificate. The default is etc/certs/remoted.pem. |
Enrollment token commands
The wazuh-manager-authd executable also manages enrollment tokens. Except for --show-token, which decodes a token locally, these commands connect to the running daemon, so the agent enrollment service must be running. Create and revoke tokens only on the master node. Each invocation accepts only one of --create-enrollment-token, --list-enrollment-tokens, --revoke-enrollment-token, --purge-enrollment-tokens, or --show-token.
Option |
Description |
|---|---|
--create-enrollment-token |
Creates an enrollment token for the host set in |
--address <host> |
Used with |
--port <N> |
Used with |
--prefix <P> |
Used with |
--ttl <duration> |
Used with |
--max-uses <N> |
Used with |
--description <text> |
Used with |
--embed-ca |
Used with |
--no-credential |
Used with |
--list-enrollment-tokens |
Lists the enrollment tokens. The output never includes their credentials. |
--revoke-enrollment-token <id> |
Revokes the enrollment token with the given ID. |
--purge-enrollment-tokens |
Removes the tokens that can no longer authorize an enrollment because they are revoked, expired, or out of uses. |
--all |
Used with |
--force |
Used with |
--show-token[=<token>] |
Decodes a token and prints its content without its credential. The token is read from the
argument, from the file set in |