Novell Privileged User Manager 2.3 User guide

Type
User guide
Installation Guide
Privileged User Manager 2.3.2
January, 2013
Legal Notice
NetIQCorporation(“NetIQ”)makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthis
documentation,andspecificallydisclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticular
purpose.Further,NetIQreservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,without
obligationtonotifyanypersonorentityofsuchrevisionsorchanges.
NetIQmakesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsanyexpressorimplied
warrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,NetIQreservestherighttomakechangesto
any
andallpartsofthesoftware,atanytime,withoutanyobligationtonotifyanypersonorentityofsuchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreetocomplywithall
exportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexport,orimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.exportlaws.You
agreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.NetIQassumesnoresponsibilityfor
yourfailuretoobtainanynecessaryexportapprovals.
Copyright©2013NetIQCorporation.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,stored
onaretrievalsystem,or
transmittedwithouttheexpresswrittenconsentofthepublisher.
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Formoreinformation,pleasecontactNetIQat:
1233 West Loop South, Houston, Texas 77027
U.S.A.
www.netiq.com
Contents 3
Contents
About This Guide 5
1 NetIQ Privileged User Manager Overview 7
1.1 Product Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.2 Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.3 What’s New in 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
2 Installation Requirements 9
2.1 Software Prerequisites. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
2.2 System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
2.3 Supported Platforms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
2.4 Supported Browsers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
2.5 Procedural Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
3 Installing the Framework Manager 13
3.1 Installing a Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
3.1.1 AIX Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13
3.1.2 HP-UX Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14
3.1.3 Linux Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.1.4 SLES Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.1.5 Solaris Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.1.6 Windows Framework Manager Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.2 Accessing the Framework Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
3.3 Installing a NetIQ Privileged User Manager License . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18
3.4 Setting Up a Package Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3.5 Stopping and Restarting the Framework . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3.5.1 AIX. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
3.5.2 HP-UX . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.3 Linux . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.4 Solaris . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
3.5.5 Windows . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .21
3.6 Removing the Framework Manager. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
3.6.1 AIX Manager Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
3.6.2 HP-UX Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .22
3.6.3 Linux Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
3.6.4 SLES Framework Manager Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
3.6.5 Solaris Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
3.6.6 Windows Manager Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .23
4 Installing the Agents 25
4.1 Agent Installation Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
4.2 Creating a Host Name for Each Agent. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
4.3 Opening Firewall Ports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4 Installing and Registering a Framework Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4.1 AIX Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .26
4.4.2 HP-UX Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
4 Contents
4.4.3 Linux Agent Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
4.4.4 SLES Agent Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
4.4.5 Windows Agent Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
4.4.6 Solaris Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
4.4.7 Tru64 Agent Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
4.5 Removing the Agent Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
4.5.1 AIX Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
4.5.2 HP-UX Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
4.5.3 Linux Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
4.5.4 SLES Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
4.5.5 Solaris Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
4.5.6 Tru64 Agent Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
4.5.7 Windows Agent Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .34
5 Upgrading NetIQ Privileged User Manager 35
5.1 Upgrading from 2.2.x to 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
5.2 Migrating from Generic Linux 2.2.x to 2.3 on SLES. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
5.2.1 Migrating Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
5.2.2 Migrating Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
5.3 Upgrading from SLES 2.2.x to 2.3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
5.3.1 Upgrading Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
5.3.2 Upgrading Framework Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
About This Guide 5
About This Guide
ThisGettingStartedGuideexplainsthehardwarerequirementsforthePrivilegedUserManager
components,thenexplainshowtoinstallthecomponents.
Chapter 1,“NetIQPrivilegedUserManagerOverview,onpage 7
Chapter 2,“InstallationRequirements,”onpage 9
Chapter 3,“InstallingtheFrameworkManager,”onpage 13
Chapter 4,“InstallingtheAgents,”onpage 25
Chapter 5,“UpgradingNetIQ
PrivilegedUserManager,”onpage 35
Audience
ThisguideisintendedforuserswhoinstallandmanagethePrivilegedUserManagerproduct.
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualandtheotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgotowww.novell.com/documentation/feedback.htmlandenteryour
commentsthere.
Documentation Updates
ForthemostrecentversionoftheGettingStartedGuide,visitthePrivilegedUserManagerWebSite
(http://www.novell.com/documentation/privilegedusermanager23).
Additional Documentation
PrivilegedUserManagerAdministrationGuide(http://www.novell.com/documentation/
privilegedusermanager23/npum_admin/data/bkyzr9y.html)
6 NetIQ Privileged User Manager 2.3.2 Installation Guide
1
NetIQ Privileged User Manager Overview 7
1
NetIQ Privileged User Manager Overview
NetIQPrivilegedUserManagerdeliversarobustandscalablearchitecture,intuitivemanagement
consoleandreusablescriptandcommandlibrariesthatenableadministratorstoreducemanagement
overheadandinfrastructurecostsinyourenvironment.
Section 1.1,“ProductOverview,”onpage 7
Section 1.2,“Components,”onpage 7
Section 1.3,“What’sNewin2.3,”onpage 8
1.1 Product Overview
Certainsituationsopenpotentialbackdoorsintosystemsandincreasethelikelihoodofasecurity
breachinanenterprisenetwork.Forexample,whenrunningsomecommandsthatrequireelevated
privileges,userssometimesgetexposedtothesuperuserorrootaccountcredentials.Similarly,
passwordsareoftennotchangedwhenauseris
nomoreperformingtheadministrativerole.
NetIQPrivilegedUserManagerhelpsITadministratorsmanagetheidentityandaccessfor
superuserandrootaccountsbyprovidingcontrolledsuperuseraccesstoadministrators,allowing
themtoperformjobswithoutneedlesslyexposingrootaccountcredentials.Italsoprovidesa
centralizedactivitylogacrossmultiple
platforms.TheintroductionofNetIQPrivilegedUser
ManagerenrichestheNovellIdentityandAccessManagementandComplianceManagement
solutionsbyaddingauditingandtrackingcapabilitiesforprivilegeduseractivityacrossthe
organization.
NetIQPrivilegedUserManagerlimitscorporatesusceptibilitytounauthorizedtransactionsand
informationaccessbyhelpingorganizationsrapidlydeploysuperuser
managementandtracking
acrossallUNIXandLinuxenvironments.Itreducesmanagementoverheadandinfrastructurecosts,
controlsandrecordswhichprivilegedusershaveaccesstowhat,andreducescostsanderrors
throughdemonstrablecomplianceaudits.
NetIQPrivilegedUserManagerworksbydelegatingprivilegedaccess,whichisauthorizedviaa
centralizeddatabase.
Theendresultisthatauserisauthorizedtorunthepriv ilegedcommandand
allactivityislogged.Thecentralizeddatabaseprovidesforeasieradministration.Comparedto
competitivesolutionsinthemarketplace,NetIQPrivilegedUserManagerisdeployedmorequickly,
providesfasterresponsetime,betterloggingandauditingandimproved
administration,andleads
toamoresecuresystemandafastreturnoninvestment.
1.2 Components
PrivilegedUserManagerconsistsofaFrameworkManager,whereyoumanageandconfigurethe
system,andanagent,whichisinstalledoneachmachinewhereyouwanttomonitorandcontrol
superuseraccess.
8 NetIQ Privileged User Manager 2.3.2 Installation Guide
Figure 1-1 FrameworkManager
FromtheHomepage,youhaveaccesstosixadministrativeconsoles:
ComplianceAuditor:Proactiveauditingtoolthatpullseventsfromtheeventlogsforanalysis,
accordingtopredefinedrules.Itpullsfilteredauditeventsathourly,daily,weeklyormonthly
intervals.Thisenablesauditorstoviewprefilteredsecuritytransactions,playback
recordingsof
useractivity,andrecordnotesforcompliancepurposes.Inaneraofincreasingregulatory
compliancerequirements,theabilitytosupplydemonstrableauditcomplianceatanytime
providesamoresecuresystemandreducesauditrisk.
FrameworkUserManager:ManagesuserswhologintotheFrameworkManagerthrough
role
basedgrouping.
Hosts:CentrallymanagesPrivilegedUserManagerinstallationandupdates,loadbalancing,
redundancyofresources,andhostalerts.
Reporting:Provideseasyaccessandsearchcapabilityforeventlogsandallowsyoureviewand
colorcodeuserkeystrokeactivitythroughtheCommandRiskAnalysisEngine.
CommandControl:Usesanintuitive
graphicalinterfacetomanagesecuritypoliciesfor
privilegemanagement.
PackageManager:LetsyoueasilyupdateanyPrivilegedUserManagerapplication.
1.3 What’s New in 2.3
ForinformationaboutthenewfeaturesaddedinNetIQPrivilegedUserManager2.3seePrivileged
UserManager2.3Readme(http://www.novell.com/documentation/privilegedusermanager23/).
2
Installation Requirements 9
2
Installation Requirements
Section 2.1,“SoftwarePrerequisites,onpage 9
Section 2.2,“SystemRequirements,”onpage 9
Section 2.3,“SupportedPlatforms,”onpage 10
Section 2.4,“SupportedBrowsers,”onpage 11
Section 2.5,“ProceduralOverview,”onpage 11
2.1 Software Prerequisites
NetIQPrivilegedUserManagerinstallationsoftware.LogintotheNovellCustomerCenter
(http://www.novell.com/center)andfollowthelinkthatallowsyoutodownloadthesoftware.
AdobeFlashPlayer.
NetIQPrivilegedUserManagerlicense.LogintotheNovellCustomerCenter(http://
www.novell.com/center)anddownloadthelicense.
NOTE:Bydefault,newinstallationsareprovidedwitha90daylicenseforfiveagents,oneof
whichisthemanager.
2.2 System Requirements
APUMagentshouldhavethefollowingsystemrequirements:
CPU‐300MHz(RISC),1GHz(CISC)
Memory‐50MBadditionalmemory
HardDisk‐100MBadditionalmemory
APUMmanagershouldhavethefollowingsystemrequirements:
CPU‐1GHz ormore(RISC),2GHzormore(CISC)
Memory‐250MBadditional
memory
HardDisk‐150MBadditionalmemoryandadditionalmemoryforAuditStorage
TIP:ApproximateadditionalmemorycalculationforAuditStorage=(250KB)X(numberofPUM
users)X(numberofsessionsperday(usually8sessions)).
10 NetIQ Privileged User Manager 2.3.2 Installation Guide
2.3 Supported Platforms
TheFrameworkManagersoftwarehasbeentestedonthefoll owingplatforms:
Windows2008R232bitand64bit
Windows200332bitand64bit
Windows200832bitand64bit
RedHat532bitand64bit
RedHat632bitand64bit
AIX5.3
32bitand64bit
AIX6.132bitand64bit
SUSELinuxEnterpriseServer10(SLES)32bitand64bit
OpenEnterpriseServer2(32bitand64bit)
SUSELinuxEnterpriseServer11(SLES)32bitand64bit
OpenEnterpriseServer11(32bitand
64bit)
Ubuntu10.04LTS64bit
HPUX(PARISC)11.1132bitand64bit
HPUX(PARISC)11.2332bitand64bit
HPUX(Itanium)11.2364bit
SunSolaris(SPARC)32bitand64bitonversions9and10
SunSolaris(Intel)32bit
and64bitonversions10
TheFrameworkAgentsoftwarehasbeentestedonthefollowingplatforms:
HPTru64UNIX64biton5.1aand5.1b
Windows2008R232bitand64bit
Windows200332bitand64bit
Windows200832bitand64bit
RedHat5
32bitand64bit
RedHat632bitand64bit
AIX5.332bitand64bit
AIX6.132bitand64bit
SUSELinuxEnterpriseServer10(SLES)32bitand64bit
OpenEnterpriseServer2(32bitand64bit)
SUSELinuxEnterprise
Server11(SLES)32bitand64bit
OpenEnterpriseServer11(32bitand64bit)
Ubuntu10.04LTS64bit
HPUX(PARISC)11.1132bitand64bit
HPUX(PARISC)11.2332bitand64bit
HPUX(Itanium)11.2364bit
SunSolaris(SPARC)
32bitand64bitonversions9and10
SunSolaris(Intel)32bitand64bitonversions10
Installation Requirements 11
IMPORTANT
Ensurethatyouroperatingsystemisrunningthevendorʹslatestmaintenancepatches.
Usethe64bitinstallerofPrivilegedUserManagerforthe64bitWindowsplatforms.
Third Party Tested Platforms
TheagentcanbeinstalledonthefollowingLinuxplatform:
UniventionCorporateServer(UCS)2.3
2.4 Supported Browsers
ToaccessNetIQPrivilegedUserManager,youneedtoinstallAdobeFlashPlayer11oraboveona
supportedbrowser.
Thefollowingarethesupportedbrowsers:
MicrosoftInternetExplorer7.0
MicrosoftInternetExplorer8.0
MozillaFirefox17.0
Chrome23.0
NOTE:Somefeatures,suchasRDPRelay,aresupportedonlyonInternetExplorer8.0.
2.5 Procedural Overview
ThefollowingstepsarerequiredtoinstallPrivilegedUserManager:
1 InstallaFrameworkManager.SeeChapter 3,“InstallingtheFrameworkManager,onpage 13.
2 Whentheinstallationhascompleted, accessandlogintotheconsole.SeeSection 3.2,Accessing
theFrameworkConsole,”onpage 18.
3 InstallthePrivilegedUserManagerlicense.SeeSection 3.3,“InstallingaNetIQPrivilegedUser
ManagerLicense,”onpage 18.
Bydefault,newinstallationsareprovidedwitha90daylicenseforfiveagents,oneofwhichis
themanager.Youneedtoinsta llyourlicensebeforethedefaultlicenseexpires.
4 SetupaPackageManagersoyoucaninstalladditionalpackagesontheagentsandpush
packageupdatestoyourframeworkcomponents.SeeSection 3.4,“SettingUpaPackage
Manager,”onpage 19.
5 InstallandregisteraFrameworkAgentonthecomputersthatyouwanttomanage.See
Chapter 4,“InstallingtheAgents,”onpage 25.
WhenyouhaveinstalledandregisteredtheFrameworkagents,youhavecompletedthe
installationoftheFramework.
6 Forconfigurationinform ation,seetheNetIQPrivilegedUserManager2.3.2AdministrationGuide.
12 NetIQ Privileged User Manager 2.3.2 Installation Guide
3
Installing the Framework Manager 13
3
Installing the Framework Manager
Section 3.1,“InstallingaFrameworkManager,”onpage 13
Section 3.2,AccessingtheFrameworkConsole,”onpage 18
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18
Section 3.4,“SettingUpaPackageManager,”onpage 19
Section 3.5,“StoppingandRestartingtheFramework,”onpage 19
Section 3.6,“RemovingtheFrameworkManager,”onpage 21
3.1 Installing a Framework Manager
Currently,theFrameworkManagerisavailableforinstallationontheplatformslistedbelow.Referto
Chapter 2,“InstallationRequirements,”onpage 9formoreinformationregardingsupported
versions.
NOTE:AftertheFrameworkManagerisinstalled,themanagerconsolerunsonthedefaultport443
andcanbeaccessedwith
https://<ip>
.Thedefaultportcan bechangedbychangingtheport
numberinthe
connector.xml
filelocatedat
<install_path>/service/local/admin/
connector.xml
.ForSUSE,theconnector.xmlfileislocatedat
/etc/opt/novell/npum/service/
local/admin/connector.xml
.
Fordetailedinstallationinstructionsforyourplatform,selectfromthelistbelow:
Section 3.1.1,“A I XFrameworkManagerInstallation,”onpage 13
Section 3.1.2,“HPUXFrameworkManagerInstallation,”onpage 14
Section 3.1.3,“LinuxFrameworkManagerInstallation,”onpage 15
Section 3.1.4,“SLESFrameworkManagerInstallation,”onpage 15
Section 3.1.5,“SolarisFrameworkManagerInstallati on,”onpage 17
Section 3.1.6,“Windows
FrameworkManagerInstallation,onpage 17
3.1.1 AIX Framework Manager Installation
TheAIXinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,youmust
unzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
14 NetIQ Privileged User Manager 2.3.2 Installation Guide
ToinstalltheAIXmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheAIXinstallationpackageisuncompressed,useoneofthefollowingmethodsto
performtheinstallation.
TheAIXsmittyprogram.
Thefollowingcommand:
installp -acgNQqwX -d <directory of .bff file> netiqnpum
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.2 HP-UX Framework Manager Installation
TheHPUXinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,you
mustunzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheHPUXmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheHPUXinstallationpackageisuncompressed,usethefollowingcommandtoinstall
themanager:
swinstall -s /<directory of .depot file>/<filename>.depot \*
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log,
ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
Installing the Framework Manager 15
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.3 Linux Framework Manager Installation
LinuxhostsusetheRPMpackagingsystemforinstallation,upgrade,andremoval.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheLinuxmanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoinstall
thefile:
rpm -i <filename>.rpm
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwasused.
Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and0.0.0.0:443.
3 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.4 SLES Framework Manager Installation
Toinstallanewmanagerhost,youmustinstallbasepackages,managerpackagesandotherrequired
dependencies.
NOTE:
ForSLESspecificRPMs,theopensourcedependenciesmustbefulfilledbeforetheRPMis
installedusingtheRPMcommand.
IftheSLESoperatingsystemisproperlyregisteredandtheSLESupdatechannelsare
configured,youcanusethezyppercommandwiththeSLESspecificRPMswhichwill
automatically
pulltherequiredopensourcedependenciesfromtheconfiguredSLESupdate
channels.
BeforeinstallingthemanagerRPM,insta lltheagentRPM.
ToinstalltheSLESmanager:
1 Copytheinstallationpackagetoatemporarylocation.
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
16 NetIQ Privileged User Manager 2.3.2 Installation Guide
2 AftertheSLESinstallationpackageisuncompressed,installtheSLESmanager.Toinstallthe
SLESmanager,youmust installtheagentpackagebeforeinstallingthemanagerpackage.
UsethefollowingcommandtoinstalltheSLESmanager:
ForSLES11usezypper:
zypper install <Agent name>.rpm
<Manager name>.rpm
ForSLES10userug:
rug install <Agent name>.rpm
<Managername>.rpm
rpm:
rpm -i <Agent name>.rpm
rpm -i <Manager name>.rpm
NOTE:Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/
documentation/privilegedusermanager23/readme/data/
privilegedusermanager_readme.html)fortheactualAgentnameandManagername.
Aspartoftheinstallationprocessthezypperorrugcommandlineinterfacesautomatically
resolvetherequireddependencies.However,iftheinstallationisthroughtheRPMcommand,
theinstallationwillfailifthefollowingdependenciesarenotinstalled.
libapr1
libapr-util1
openssl
perl
apr
zlib
pcre
openldap
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/var/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwas
accepted.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and
0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
NOTE:ForupgradingtoNPUM2.2.2onSLESfromapreviousrelease,seeSection 5.2,“Migrating
fromGenericLinux2.2.xto2.3onSLES,”onpage 36.
Installing the Framework Manager 17
3.1.5 Solaris Framework Manager Installation
TheSolarisinstallationpackageiscompressedthroughgzip.Inordertoinstallthepackage,youmust
unzipthepackagethroughgunzip.
Bydefault,theinstallationprograminstallsthesoftwareinto
/opt/novell/npum
.Tochangethis,
createadirectoryintherequiredpartofthefilesystemandcreateasymboliclinkto
/opt/novell/
npum
.
ToinstalltheSolarismanager:
1 Copytheinstallationpackagetoatemporarylocationandusethefollowingcommandtoextract
theinstallationfiles:
gunzip <filename>
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 AftertheSolarisinstallationpackageisuncompressed,usethefollowing commandtoinstallthe
manager:
pkgadd -d /<directory of .pkg file>/<filename>.pkg
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
/opt/novell/npum/logs/unifid.log
,ifthedefaultinstalllocationwas
accepted.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0:29120and
0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.1.6 Windows Framework Manager Installation
1 Runthefollowinginstallexecutabletostarttheinstallation:
<filename>.exe
Seethe“NetIQPrivilegedUserManagerReadme”(http://www.novell.com/documentation/
privilegedusermanager23/readme/data/privilegedusermanager_readme.html)fortheactual
filename.
2 Followthestepsintheinstallwizard.
TheFrameworkManagerservicecanbeinstalledonanypartofthenormalfilesystem.It
defaultstothe
C:\Program Files\Novell\npum
folder.
3 Afterinstallationiscomplete,checkthattheserviceisrunningbyviewingthelogfile.Thelog
fileislocatedin
C:\Program Files\Novell\npum\logs\unifid.log
,ifthedefaultinstall
locationwasused.Ifthemanagerinstalledcorrectly,servicesshouldbelisteningon0.0.0.0 :29120
and0.0.0.0:443.
4 Ifyouhavebeensuppliedwithalicense,logintotheFrameworkConsoleandinstallthelicense.
Forinformation,refertoSection 3.2,AccessingtheFrameworkConsole,”onpage 18,andthen
Section 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
18 NetIQ Privileged User Manager 2.3.2 Installation Guide
3.2 Accessing the Framework Console
1 OpenaWebbrowseronyourchosenplatform.
2 Intheaddressbar,entertheURLfortheFrameworkConsoleasfollows:
https://<hostname>
Replace<hostname>withoneofthefollowing:
TheDNSnameoftheserverwheretheFrameworkManagerisinstalled.
TheDNSnameofaserverthathasthe AdministrationAgentpackageinstalled.
3 Ifyouarepresentedwithasecurityalert,verifythedetailsandselectYestocontinue.
4 IfyourbrowserisnotalreadyequippedwithAdobeFlashPlayer,thebrowserattemptstoinstall
it.VerifythedetailsandselectInstalltocontinue.
Arebootorbrowserrestartmightberequired.
5 LogintotheFrameworkConsole.
AfteryouentertheURLfortheFrameworkConsole,theinitiallogonscreenisdisplayedinthe
browserwindow.Youmustauthenticatetothesystembyusingausernameandpassword
definedonthesystem.
6 (Conditional)Ifthisisthefirsttimetologintothe console,specifytheusername
admin
and
password
novell
,thenclickLogon.
7 (Conditional)Ifthisisthefirsttimetologintothe FrameworkConsole,youarepromptedto
changethedefaultpassword.
Yournewpasswordshouldbeaminimumofeightcharacters.Ifthenewpasswordisacceptable
tothesystem,youareloggedintotheconsole.
IMPORTANT:TonavigateintheFrameworkConsole,donotuseyourbrowsersForwardor
Backbuttons;usethetrailatthetopofeachpage,suchas:
Home/ComplianceAuditor
ClickHometoreturntomainconsolemenu.
8 ContinuewithSection 3.3,“InstallingaNetIQPrivilegedUserManagerLicense,”onpage 18.
3.3 Installing a NetIQ Privileged User Manager License
LogintotheNovellCustomerCenter(http://www.novell.com/center)anddownloadyourlicense
file.Usethefollowingstepstoinstallit:
1 LogintotheFrameworkConsole.
2 FromtheTaskPane,clickAboutFramework.
3 ClickRegisterFramework.
4 Copythesuppliedlicenseandpasteitintothetextarea.
5 ClickFinish>Close.
YourlicensedetailscanbeviewedbyselectingtheAboutFrameworkoptionfromtheTaskPane.
6 Continuewithoneofthefollowing:
Section 3.4,“SettingUpaPackageManager,”onpage 19
Chapter 4,“InstallingtheAgents,”onpage 25
Installing the Framework Manager 19
3.4 Setting Up a Package Manager
ThePackageManagerallowsyoutopushupdatestohostsandtoinstalladditionalpackagesonthe
hostsforloadbalancingandfailover.TousetheNovellUpdateServerasthePackageManager,see
ConfiguringthePa ckage ManagerintheNetIQPrivilegedUserManager2.3.2AdministrationGuide.
Touse
alocalhostasaPackageManager:
1 Createadirectorysuchas
framework
ontheFrameworkManagerinthe
/tmp
directory.
Thisdirectoryiscalled
framework
intherestoftheseinstructions.
2 Copythe
netiq-npum-packages-2.3.2.tar.gz
fromthePackageManagerdirectoryonthe
CDtothemachine.
3 Extractthefiletothe
framework
directory.
ForUNIXandLinuxplatforms,usethefollowingcommands:
gunzip netiq-npum-packages-2.3.2.tar.gz
tar -xvf netiq-npum-packages-2.3.2.tar
ForWindowsplatforms,useWinZiptoextractthe file.
4 UsethefollowingcommandtopublishthepackagestothePackageManager.
Replace<admin>withthenameofyouradminuser.
ForLinuxandUNIXplatforms:
/opt/novell/npum/sbin/unifi -u <admin> distrib publish -d /tmp/framework
ForWindowsplatforms:
c:\Program Files\novell\npum\bin\unifi -u <admin> distrib publish -d
c:\tmp\framework
5 Whenprompted,enterthepasswordfortheadminuser.
6 (Optional)Toviewavailablepackages,logintotheFrameworkManager,thenclickPackage
Manager.
7 Deletethe
framework
directory.
3.5 Stopping and Restarting the Framework
TheFrameworkservicesandprocessesstartautoma ticallyafterinstallationandsystemreboot,so
thereisnormallynoneedtostopandrestartthem.Ifyouneedtostopandrestarttheservicesand
processesmanually,followtheinstructionsbelowforyourplatform:
Section 3.5.1,“A I X, onpage 20
Section 3.5.2,“HPUX,”onpage 20
Section 3.5.3,“Linux,”onpage 20
Section 3.5.4,“Solaris,”onpage 20
Section 3.5.5,“Windows,”onpage 21
20 NetIQ Privileged User Manager 2.3.2 Installation Guide
3.5.1 AIX
TostoptheFram eworkprocess:
stopsrc -s npum
TostarttheFrameworkprocess:
startsrc -s npum
3.5.2 HP-UX
TostoptheFram eworkprocess:
/sbin/init.d/npum stop
TostarttheFrameworkprocess:
/sbin/init.d/npum start
Tocheckthestatus:
/sbin/init.d/npum status
3.5.3 Linux
Thefollowinginstructionsapplytoalldistributions.
TostoptheFram eworkprocess:
/etc/init.d/npum stop
TostarttheFrameworkprocess:
/etc/init.d/npum start
Tocheckthestatus:
/etc/init.d/npum status
3.5.4 Solaris
Thefollowinginstructionsapplytoallsupporteddistributions.
TostoptheFram eworkprocess:
/etc/init.d/npum stop
TostarttheFrameworkprocess:
/etc/init.d/npum start
Tocheckthestatus:
/etc/init.d/npum status
Solaris10alsousestheSMF(ServiceManagementfacility).Examplecommandsare:
svcs | grep npum
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40

Novell Privileged User Manager 2.3 User guide

Type
User guide

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI