Novell Privileged User Manager 2.3 User guide

  • Hello! I am an AI chatbot trained to assist you with the Novell Privileged User Manager 2.3 User guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
Installation Guide
Privileged User Manager 2.3.2
January, 2013
Legal Notice
NetIQCorporation(“NetIQ”)makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthis
documentation,andspecificallydisclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticular
purpose.Further,NetIQreservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,without
obligationtonotifyanypersonorentityofsuchrevisionsorchanges.
NetIQmakesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsanyexpressorimplied
warrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,NetIQreservestherighttomakechangesto
any
andallpartsofthesoftware,atanytime,withoutanyobligationtonotifyanypersonorentityofsuchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreetocomplywithall
exportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexport,orimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.exportlaws.You
agreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.NetIQassumesnoresponsibilityfor
yourfailuretoobtainanynecessaryexportapprovals.
Copyright©2013NetIQCorporation.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,stored
onaretrievalsystem,or
transmittedwithouttheexpresswrittenconsentofthepublisher.
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Formoreinformation,pleasecontactNetIQat:
1233 West Loop South, Houston, Texas 77027
U.S.A.
www.netiq.com
Contents 3
Contents
About This Guide 5
1 NetIQ Privileged User Manager Overview 7
1.1 Product Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.2 Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.3 What’s New in 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
2 Installation Requirements 9
2.1 Software Prerequisites. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
2.2 System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
2.3 Supported Platforms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
2.4 Supported Browsers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
2.5 Procedural Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
3 Installing the Framework Manager 13
3.1 Installing a Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
3.1.1 AIX Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13
3.1.2 HP-UX Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14
3.1.3 Linux Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.1.4 SLES Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.1.5 Solaris Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.1.6 Windows Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.2 Accessing the Framework Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
3.3 Installing a NetIQ Privileged User Manager License . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18
3.4 Setting Up a Package Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3.5 Stopping and Restarting the Framework . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3.5.1 AIX. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
3.5.2 HP-UX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.3 Linux . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.4 Solaris . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.5 Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .21
3.6 Removing the Framework Manager. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
3.6.1 AIX Manager Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
3.6.2 HP-UX Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .22
3.6.3 Linux Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
3.6.4 SLES Framework Manager Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
3.6.5 Solaris Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
3.6.6 Windows Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .23
4 Installing the Agents 25
4.1 Agent Installation Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
4.2 Creating a Host Name for Each Agent. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
4.3 Opening Firewall Ports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4 Installing and Registering a Framework Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4.1 AIX Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4.2 HP-UX Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
4 Contents
4.4.3 Linux Agent Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
4.4.4 SLES Agent Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
4.4.5 Windows Agent Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
4.4.6 Solaris Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
4.4.7 Tru64 Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
4.5 Removing the Agent Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
4.5.1 AIX Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
4.5.2 HP-UX Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
4.5.3 Linux Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
4.5.4 SLES Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
4.5.5 Solaris Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
4.5.6 Tru64 Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
4.5.7 Windows Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .34
5 Upgrading NetIQ Privileged User Manager 35
5.1 Upgrading from 2.2.x to 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
5.2 Migrating from Generic Linux 2.2.x to 2.3 on SLES. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
5.2.1 Migrating Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
5.2.2 Migrating Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
5.3 Upgrading from SLES 2.2.x to 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
5.3.1 Upgrading Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
5.3.2 Upgrading Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
About This Guide 5
About This Guide
ThisGettingStartedGuideexplainsthehardwarerequirementsforthePrivilegedUserManager
components,thenexplainshowtoinstallthecomponents.
Chapter 1,“NetIQPrivilegedUserManagerOverview,onpage 7
Chapter 2,“InstallationRequirements,”onpage 9
Chapter 3,“InstallingtheFrameworkManager,”onpage 13
Chapter 4,“InstallingtheAgents,”onpage 25
Chapter 5,“UpgradingNetIQ
PrivilegedUserManager,”onpage 35
Audience
ThisguideisintendedforuserswhoinstallandmanagethePrivilegedUserManagerproduct.
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualandtheotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgotowww.novell.com/documentation/feedback.htmlandenteryour
commentsthere.
Documentation Updates
ForthemostrecentversionoftheGettingStartedGuide,visitthePrivilegedUserManagerWebSite
(http://www.novell.com/documentation/privilegedusermanager23).
Additional Documentation
PrivilegedUserManagerAdministrationGuide(http://www.novell.com/documentation/
privilegedusermanager23/npum_admin/data/bkyzr9y.html)
6 NetIQ Privileged User Manager 2.3.2 Installation Guide
1
NetIQ Privileged User Manager Overview 7
1
NetIQ Privileged User Manager Overview
NetIQPrivilegedUserManagerdeliversarobustandscalablearchitecture,intuitivemanagement
consoleandreusablescriptandcommandlibrariesthatenableadministratorstoreducemanagement
overheadandinfrastructurecostsinyourenvironment.
Section 1.1,“ProductOverview,”onpage 7
Section 1.2,“Components,”onpage 7
Section 1.3,“What’sNewin2.3,”onpage 8
1.1 Product Overview
Certainsituationsopenpotentialbackdoorsintosystemsandincreasethelikelihoodofasecurity
breachinanenterprisenetwork.Forexample,whenrunningsomecommandsthatrequireelevated
privileges,userssometimesgetexposedtothesuperuserorrootaccountcredentials.Similarly,
passwordsareoftennotchangedwhenauseris
nomoreperformingtheadministrativerole.
NetIQPrivilegedUserManagerhelpsITadministratorsmanagetheidentityandaccessfor
superuserandrootaccountsbyprovidingcontrolledsuperuseraccesstoadministrators,allowing
themtoperformjobswithoutneedlesslyexposingrootaccountcredentials.Italsoprovidesa
centralizedactivitylogacrossmultiple
platforms.TheintroductionofNetIQPrivilegedUser
ManagerenrichestheNovellIdentityandAccessManagementandComplianceManagement
solutionsbyaddingauditingandtrackingcapabilitiesforprivilegeduseractivityacrossthe
organization.
NetIQPrivilegedUserManagerlimitscorporatesusceptibilitytounauthorizedtransactionsand
informationaccessbyhelpingorganizationsrapidlydeploysuperuser
managementandtracking
acrossallUNIXandLinuxenvironments.Itreducesmanagementoverheadandinfrastructurecosts,
controlsandrecordswhichprivilegedusershaveaccesstowhat,andreducescostsanderrors
throughdemonstrablecomplianceaudits.
NetIQPrivilegedUserManagerworksbydelegatingprivilegedaccess,whichisauthorizedviaa
centralizeddatabase.
Theendresultisthatauserisauthorizedtorunthepriv ilegedcommandand
allactivityislogged.Thecentralizeddatabaseprovidesforeasieradministration.Comparedto
competitivesolutionsinthemarketplace,NetIQPrivilegedUserManagerisdeployedmorequickly,
providesfasterresponsetime,betterloggingandauditingandimproved
administration,andleads
toamoresecuresystemandafastreturnoninvestment.
1.2 Components
PrivilegedUserManagerconsistsofaFrameworkManager,whereyoumanageandconfigurethe
system,andanagent,whichisinstalledoneachmachinewhereyouwanttomonitorandcontrol
superuseraccess.
8 NetIQ Privileged User Manager 2.3.2 Installation Guide
Figure 1-1 FrameworkManager
FromtheHomepage,youhaveaccesstosixadministrativeconsoles:
ComplianceAuditor:Proactiveauditingtoolthatpullseventsfromtheeventlogsforanalysis,
accordingtopredefinedrules.Itpullsfilteredauditeventsathourly,daily,weeklyormonthly
intervals.Thisenablesauditorstoviewprefilteredsecuritytransactions,playback
recordingsof
useractivity,andrecordnotesforcompliancepurposes.Inaneraofincreasingregulatory
compliancerequirements,theabilitytosupplydemonstrableauditcomplianceatanytime
providesamoresecuresystemandreducesauditrisk.
FrameworkUserManager:ManagesuserswhologintotheFrameworkManagerthrough
role
basedgrouping.
Hosts:CentrallymanagesPrivilegedUserManagerinstallationandupdates,loadbalancing,
redundancyofresources,andhostalerts.
Reporting:Provideseasyaccessandsearchcapabilityforeventlogsandallowsyoureviewand
colorcodeuserkeystrokeactivitythroughtheCommandRiskAnalysisEngine.
CommandControl:Usesanintuitive
graphicalinterfacetomanagesecuritypoliciesfor
privilegemanagement.
PackageManager:LetsyoueasilyupdateanyPrivilegedUserManagerapplication.
1.3 What’s New in 2.3
ForinformationaboutthenewfeaturesaddedinNetIQPrivilegedUserManager2.3seePrivileged
UserManager2.3Readme(http://www.novell.com/documentation/privilegedusermanager23/).
2
Installation Requirements 9
2
Installation Requirements
Section 2.1,“SoftwarePrerequisites,onpage 9
Section 2.2,“SystemRequirements,”onpage 9
Section 2.3,“SupportedPlatforms,”onpage 10
Section 2.4,“SupportedBrowsers,”onpage 11
Section 2.5,“ProceduralOverview,”onpage 11
2.1 Software Prerequisites
NetIQPrivilegedUserManagerinstallationsoftware.LogintotheNovellCustomerCenter
(http://www.novell.com/center)andfollowthelinkthatallowsyoutodownloadthesoftware.
AdobeFlashPlayer.
NetIQPrivilegedUserManagerlicense.LogintotheNovellCustomerCenter(http://
www.novell.com/center)anddownloadthelicense.
NOTE:Bydefault,newinstallationsareprovidedwitha90daylicenseforfiveagents,oneof
whichisthemanager.
2.2 System Requirements
APUMagentshouldhavethefollowingsystemrequirements:
CPU‐300MHz(RISC),1GHz(CISC)
Memory‐50MBadditionalmemory
HardDisk‐100MBadditionalmemory
APUMmanagershouldhavethefollowingsystemrequirements:
CPU‐1GHz ormore(RISC),2GHzormore(CISC)
Memory‐250MBadditional
memory
HardDisk‐150MBadditionalmemoryandadditionalmemoryforAuditStorage
TIP:ApproximateadditionalmemorycalculationforAuditStorage=(250KB)X(numberofPUM
users)X(numberofsessionsperday(usually8sessions)).
10 NetIQ Privileged User Manager 2.3.2 Installation Guide
2.3 Supported Platforms
TheFrameworkManagersoftwarehasbeentestedonthefoll owingplatforms:
Windows2008R232bitand64bit
Windows200332bitand64bit
Windows200832bitand64bit
RedHat532bitand64bit
RedHat632bitand64bit
AIX5.3
32bitand64bit
AIX6.132bitand64bit
SUSELinuxEnterpriseServer10(SLES)32bitand64bit
OpenEnterpriseServer2(32bitand64bit)
SUSELinuxEnterpriseServer11(SLES)32bitand64bit
OpenEnterpriseServer11(32bitand
64bit)
Ubuntu10.04LTS64bit
HPUX(PARISC)11.1132bitand64bit
HPUX(PARISC)11.2332bitand64bit
HPUX(Itanium)11.2364bit
SunSolaris(SPARC)32bitand64bitonversions9and10
SunSolaris(Intel)32bit
and64bitonversions10
TheFrameworkAgentsoftwarehasbeentestedonthefollowingplatforms:
HPTru64UNIX64biton5.1aand5.1b
Windows2008R232bitand64bit
Windows200332bitand64bit
Windows200832bitand64bit
RedHat5
32bitand64bit
RedHat632bitand64bit
AIX5.332bitand64bit
AIX6.132bitand64bit
SUSELinuxEnterpriseServer10(SLES)32bitand64bit
OpenEnterpriseServer2(32bitand64bit)
SUSELinuxEnterprise
Server11(SLES)32bitand64bit
OpenEnterpriseServer11(32bitand64bit)
Ubuntu10.04LTS64bit
HPUX(PARISC)11.1132bitand64bit
HPUX(PARISC)11.2332bitand64bit
HPUX(Itanium)11.2364bit
SunSolaris(SPARC)
32bitand64bitonversions9and10
SunSolaris(Intel)32bitand64bitonversions10
Installation Requirements 11
IMPORTANT
Ensurethatyouroperatingsystemisrunningthevendorʹslatestmaintenancepatches.
Usethe64bitinstallerofPrivilegedUserManagerforthe64bitWindowsplatforms.
Third Party Tested Platforms
TheagentcanbeinstalledonthefollowingLinuxplatform:
UniventionCorporateServer(UCS)2.3
2.4 Supported Browsers
ToaccessNetIQPrivilegedUserManager,youneedtoinstallAdobeFlashPlayer11oraboveona
supportedbrowser.
Thefollowingarethesupportedbrowsers:
MicrosoftInternetExplorer7.0
MicrosoftInternetExplorer8.0
MozillaFirefox17.0
Chrome23.0
NOTE:Somefeatures,suchasRDPRelay,aresupportedonlyonInternetExplorer8.0.
2.5 Procedural Overview
ThefollowingstepsarerequiredtoinstallPrivilegedUserManager:
1 InstallaFrameworkManager.SeeChapter 3,“InstallingtheFrameworkManager,onpage 13.
2 Whentheinstallationhascompleted, accessandlogintotheconsole.SeeSection 3.2,Accessing
theFrameworkConsole,”onpage 18.
3 InstallthePrivilegedUserManagerlicense.SeeSection 3.3,“InstallingaNetIQPrivilegedUser
ManagerLicense,”onpage 18.
Bydefault,newinstallationsareprovidedwitha90daylicenseforfiveagents,oneofwhichis
themanager.Youneedtoinsta llyourlicensebeforethedefaultlicenseexpires.
4 SetupaPackageManagersoyoucaninstalladditionalpackagesontheagentsandpush
packageupdatestoyourframeworkcomponents.SeeSection 3.4,“SettingUpaPackage
Manager,”onpage 19.
5 InstallandregisteraFrameworkAgentonthecomputersthatyouwanttomanage.See
Chapter 4,“InstallingtheAgents,”onpage 25.
WhenyouhaveinstalledandregisteredtheFrameworkagents,youhavecompletedthe
installationoftheFramework.
6 Forconfigurationinform ation,seetheNetIQPrivilegedUserManager2.3.2AdministrationGuide.
12 NetIQ Privileged User Manager 2.3.2 Installation Guide
3
Installing the Framework Manager 13
3
Installing the Framework Manager
Section 3.1,“InstallingaFrameworkManager,”onpage 13
Section 3.2,AccessingtheFrameworkConsole,”onpage 18
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18
Section 3.4,“SettingUpaPackageManager,”onpage 19
Section 3.5,“StoppingandRestartingtheFramework,”onpage 19
Section 3.6,“RemovingtheFrameworkManager,”onpage 21
3.1 Installing a Framework Manager
Currently,theFrameworkManagerisavailableforinstallationontheplatformslistedbelow.Referto
Chapter 2,“InstallationRequirements,”onpage 9formoreinformationregardingsupported
versions.
NOTE:AftertheFrameworkManagerisinstalled,themanagerconsolerunsonthedefaultport443
andcanbeaccessedwith
https://<ip>
.Thedefaultportcan bechangedbychangingtheport
numberinthe
connector.xml
filelocatedat
<install_path>/service/local/admin/
connector.xml
.ForSUSE,theconnector.xmlfileislocatedat
/etc/opt/novell/npum/service/
local/admin/connector.xml
.
Fordetailedinstallationinstructionsforyourplatform,selectfromthelistbelow:
Section 3.1.1,“A I XFrameworkManagerInstallation,”onpage 13
Section 3.1.2,“HPUXFrameworkManagerInstallation,”onpage 14
Section 3.1.3,“LinuxFrameworkManagerInstallation,”onpage 15
Section 3.1.4,“SLESFrameworkManagerInstallation,”onpage 15
Section 3.1.5,“SolarisFrameworkManagerInstallati on,”onpage 17
Section 3.1.6,“Windows
FrameworkManagerInstallation,onpage 17
3.1.1 AIX Framework Manager Installation
TheAIXinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,youmust
unzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
14 NetIQ Privileged User Manager 2.3.2 Installation Guide
ToinstalltheAIXmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheAIXinstallationpackageisuncompressed,useoneofthefollowingmethodsto
performtheinstallation.
TheAIXsmittyprogram.
Thefollowingcommand:
installp -acgNQqwX -d <directory of .bff file> netiqnpum
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.2 HP-UX Framework Manager Installation
TheHPUXinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,you
mustunzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheHPUXmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheHPUXinstallationpackageisuncompressed,usethefollowingcommandtoinstall
themanager:
swinstall -s /<directory of .depot file>/<filename>.depot \*
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log,
ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
Installing the Framework Manager 15
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.3 Linux Framework Manager Installation
LinuxhostsusetheRPMpackagingsystemforinstallation,upgrade,andremoval.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheLinuxmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoinstall
thefile:
rpm -i <filename>.rpm
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
3 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.4 SLES Framework Manager Installation
Toinstallanewmanagerhost,youmustinstallbasepackages,managerpackagesandotherrequired
dependencies.
NOTE:
ForSLESspecificRPMs,theopensourcedependenciesmustbefulfilledbeforetheRPMis
installedusingtheRPMcommand.
IftheSLESoperatingsystemisproperlyregisteredandtheSLESupdatechannelsare
configured,youcanusethezyppercommandwiththeSLESspecificRPMswhichwill
automatically
pulltherequiredopensourcedependenciesfromtheconfiguredSLESupdate
channels.
BeforeinstallingthemanagerRPM,insta lltheagentRPM.
ToinstalltheSLESmanager:
1 Copytheinstallationpackagetoatemporarylocation.
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
16 NetIQ Privileged User Manager 2.3.2 Installation Guide
2 AftertheSLESinstallationpackageisuncompressed,installtheSLESmanager.Toinstallthe
SLESmanager,youmust installtheagentpackagebeforeinstallingthemanagerpackage.
UsethefollowingcommandtoinstalltheSLESmanager:
ForSLES11usezypper:
zypper install <Agent name>.rpm
<Manager name>.rpm
ForSLES10userug:
rug install <Agent name>.rpm
<Managername>.rpm
rpm:
rpm -i <Agent name>.rpm
rpm -i <Manager name>.rpm
NOTE:Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/
documentation/privilegedusermanager23/readme/data/
privilegedusermanager_readme.html)fortheactualAgentnameandManagername.
Aspartoftheinstallationprocessthezypperorrugcommandlineinterfacesautomatically
resolvetherequireddependencies.However,iftheinstallationisthroughtheRPMcommand,
theinstallationwillfailifthefollowingdependenciesarenotinstalled.
libapr1
libapr-util1
openssl
perl
apr
zlib
pcre
openldap
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/var/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwas
accepted.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and
0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
NOTE:ForupgradingtoNPUM2.2.2onSLESfromapreviousrelease,seeSection 5.2,“Migrating
fromGenericLinux2.2.xto2.3onSLES,”onpage 36.
Installing the Framework Manager 17
3.1.5 Solaris Framework Manager Installation
TheSolarisinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,youmust
unzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheSolarismanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheSolarisinstallationpackageisuncompressed,usethefollowing commandtoinstallthe
manager:
pkgadd -d /<directory of .pkg file>/<filename>.pkg
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwas
accepted.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and
0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.6 Windows Framework Manager Installation
1 Runthefollowinginstallexecutabletostarttheinstallation:
<filename>.exe
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 Followthestepsintheinstallwizard.
TheFrameworkManagerservicecanbeinstalledonanypartofthenormalfilesystem.It
defaultstothe
C:\Program Files\Novell\npum
folder.
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
C:\Program Files\Novell\npum\logs\unifid.log
,ifthedefaultinstall
locationwasused.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0 :29120
and0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
18 NetIQ Privileged User Manager 2.3.2 Installation Guide
3.2 Accessing the Framework Console
1 OpenaWebbrowseronyourchosenplatform.
2 Intheaddressbar,entertheURLfortheFrameworkConsoleasfollows:
https://<hostname>
Replace<hostname>withoneofthefollowing:
TheDNSnameoftheserverwheretheFrameworkManagerisinstalled.
TheDNSnameofaserverthathasthe AdministrationAgentpackageinstalled.
3 Ifyouarepresentedwithasecurityalert,verifythedetailsandselectYestocontinue.
4 IfyourbrowserisnotalreadyequippedwithAdobeFlashPlayer,thebrowserattemptstoinstall
it.VerifythedetailsandselectInstalltocontinue.
Arebootorbrowserrestartmightberequired.
5 LogintotheFrameworkConsole.
AfteryouentertheURLfortheFrameworkConsole,theinitiallogonscreenisdisplayedinthe
browserwindow.Youmustauthenticatetothesystembyusingausernameandpassword
definedonthesystem.
6 (Conditional)Ifthisisthefirsttimetologintothe console,specifytheusername
admin
and
password
novell
,thenclickLogon.
7 (Conditional)Ifthisisthefirsttimetologintothe FrameworkConsole,youarepromptedto
changethedefaultpassword.
Yournewpasswordshouldbeaminimumofeightcharacters.Ifthenewpasswordisacceptable
tothesystem,youareloggedintotheconsole.
IMPORTANT:TonavigateintheFrameworkConsole,donotuseyourbrowsersForwardor
Backbuttons;usethetrailatthetopofeachpage,suchas:
Home/ComplianceAuditor
ClickHometoreturntomainconsolemenu.
8 ContinuewithSection 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.3 Installing a NetIQ Privileged User Manager License
LogintotheNovellCustomerCenter(http://www.novell.com/center)anddownloadyourlicense
file.Usethefollowingstepstoinstallit:
1 LogintotheFrameworkConsole.
2 FromtheTaskPane,clickAboutFramework.
3 ClickRegisterFramework.
4 Copythesuppliedlicenseandpasteitintothetextarea.
5 ClickFinish>Close.
YourlicensedetailscanbeviewedbyselectingtheAboutFrameworkoptionfromtheTaskPane.
6 Continuewithoneofthefollowing:
Section 3.4,“SettingUpaPackageManager,”onpage 19
Chapter 4,“InstallingtheAgents,”onpage 25
Installing the Framework Manager 19
3.4 Setting Up a Package Manager
ThePackageManagerallowsyoutopushupdatestohostsandtoinstalladditionalpackagesonthe
hostsforloadbalancingandfailover.TousetheNovellUpdateServerasthePackageManager,see
ConfiguringthePa ckage ManagerintheNetIQPrivilegedUserManager2.3.2AdministrationGuide.
Touse
alocalhostasaPackageManager:
1 Createadirectorysuchas
framework
ontheFrameworkManagerinthe
/tmp
directory.
Thisdirectoryiscalled
framework
intherestoftheseinstructions.
2 Copythe
netiq-npum-packages-2.3.2.tar.gz
fromthePackageManagerdirectoryonthe
CDtothemachine.
3 Extractthefiletothe
framework
directory.
ForUNIXandLinuxplatforms,usethefollowingcommands:
gunzip netiq-npum-packages-2.3.2.tar.gz
tar -xvf netiq-npum-packages-2.3.2.tar
ForWindowsplatforms,useWinZiptoextractthe file.
4 UsethefollowingcommandtopublishthepackagestothePackageManager.
Replace<admin>withthenameofyouradminuser.
ForLinuxandUNIXplatforms:
/opt/novell/npum/sbin/unifi -u <admin> distrib publish -d /tmp/framework
ForWindowsplatforms:
c:\Program Files\novell\npum\bin\unifi -u <admin> distrib publish -d
c:\tmp\framework
5 Whenprompted,enterthepasswordfortheadminuser.
6 (Optional)Toviewavailablepackages,logintotheFrameworkManager,thenclickPackage
Manager.
7 Deletethe
framework
directory.
3.5 Stopping and Restarting the Framework
TheFrameworkservicesandprocessesstartautoma ticallyafterinstallationandsystemreboot,so
thereisnormallynoneedtostopandrestartthem.Ifyouneedtostopandrestarttheservicesand
processesmanually,followtheinstructionsbelowforyourplatform:
Section 3.5.1,“A I X, onpage 20
Section 3.5.2,“HPUX,”onpage 20
Section 3.5.3,“Linux,”onpage 20
Section 3.5.4,“Solaris,”onpage 20
Section 3.5.5,“Windows,”onpage 21
20 NetIQ Privileged User Manager 2.3.2 Installation Guide
3.5.1 AIX
TostoptheFram eworkprocess:
stopsrc -s npum
TostarttheFrameworkprocess:
startsrc -s npum
3.5.2 HP-UX
TostoptheFram eworkprocess:
/sbin/init.d/npum stop
TostarttheFrameworkprocess:
/sbin/init.d/npum start
Tocheckthestatus:
/sbin/init.d/npum status
3.5.3 Linux
Thefollowinginstructionsapplytoalldistributions.
TostoptheFram eworkprocess:
/etc/init.d/npum stop
TostarttheFrameworkprocess:
/etc/init.d/npum start
Tocheckthestatus:
/etc/init.d/npum status
3.5.4 Solaris
Thefollowinginstructionsapplytoallsupporteddistributions.
TostoptheFram eworkprocess:
/etc/init.d/npum stop
TostarttheFrameworkprocess:
/etc/init.d/npum start
Tocheckthestatus:
/etc/init.d/npum status
Solaris10alsousestheSMF(ServiceManagementfacility).Examplecommandsare:
svcs | grep npum
/