Change Guardian

Version 4.1 Service Pack 1

Release Notes

Date Published: September 2014

 
 

 

NetIQ Change Guardian 4.1 Service Pack 1 improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the Change Guardian forum in the NetIQ Forums, our online community that also includes product information, blogs, and links to helpful resources.

The documentation for this product is available on the NetIQ Web site in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click comment on this topic at the bottom of any page in the HTML version of the documentation posted at the Change Guardian Documentation page. To download this product, see the NetIQ Downloads Web site. To download patches for this product, see the Patch Finder Web site.

What's New?

The following outline the key features and functions provided by this version, as well as issues resolved in this release:

Enhancements

Syslog Forwarding

Change Guardian 4.1 SP1 allows you to use Syslog to forward events with the Common Event Format (CEF) specification.

Software Fixes

Change Guardian 4.1 SP1 includes software fixes that resolve several previous issues.

If you use the upgrade installer, the set of new features and fixed defects depend upon the version from which you upgrade. For example, if the system is running Change Guardian 4.0 SP1, defect fixes from Change Guardian 4.1 are also applied as part of this upgrade.

Special Characters in Policy Names and Descriptions Cause an Error when Upgrading to Version 4.1

Issue:

If you used a backslash (\) in the name or description of a policy, and then upgraded to version 4.1, the backslash prevented Change Guardian from correctly assigning the policies during the upgrade process. (ENG334238)

Fix:

Policies with a backslash in the name or description now work properly after upgrading to the current version.

Change Guardian for Active Directory Might Not Send User and Group Events After Rebooting a Monitored Domain Controller

Change Guardian for Active Directory now correctly re-establishes user and group monitoring after rebooting a monitored Domain Controller. (ENG329595)

Additional and Delayed Events Arrive when Configuring Windows Firewall

Issue:

When you create a new rule for inbound or outbound categories in the Windows Firewall with Advanced Security settings on a Group Policy Object on a Domain Controller computer running Microsoft Windows 2008, the provider does not generate the events related to your changes immediately. Instead, the events are delayed and arrive with duplicate events when you configure another setting. (ENG329244)

Fix:

Events related to changes in the Advanced Security settings on a Group Policy Object arrive when they are supposed to, with no delay or duplicate events.

Resource Expansion Cannot Use Credentials from Different Domains

Resource expansion is now able to use credentials from different domains. (ENG330278, ENG332023)

Email Alert Displays Arabic Characters Incorrectly

Email alerts in Change Guardian now display Arabic characters correctly. (ENG331437)

LDAP Authentication Fails when User Account Names Include a Period

Users can now authenticate in the Policy Editor through LDAP with an Active Directory user account that contains a period (.) in the name. (ENG334581)

NT Authority\System Account Not Allowed in Local User Restrictions

Policy Editor now allows you to use the NT Authority\System account in Local User Restrictions. (ENG335177)

Return to Top

System Requirements

For detailed information on hardware requirements and supported operating systems and browsers, see the User Guide for NetIQ Change Guardian.

Return to Top

Installing This Version

This service pack includes a full version of Change Guardian. For detailed information about installing Change Guardian components and modules, see the User Guide for NetIQ Change Guardian.

Installing Change Guardian

You can install this version in a clean environment or upgrade an existing installation.

Installing the Change Guardian Server

For information about installing the Change Guardian server, see the User Guide for NetIQ Change Guardian.

Installing the Change Guardian Console and Windows Agent

(Conditional) To locally install the Change Guardian console or Windows agent, see the instructions in the User Guide for NetIQ Change Guardian.

(Conditional) To distribute the Windows agent to multiple computers, complete the steps for creating a silent installer package in Upgrading the Console and Windows Agent.

Upgrading Change Guardian

You can also apply this service pack to the following Change Guardian components:

  • Change Guardian Server
  • Change Guardian Policy Editor
  • Change Guardian for Windows agent

Note
You must upgrade the Change Guardian Server prior to upgrading the Windows agent. If you upgrade the Windows agent before you upgrade the Change Guardian Server, the agent does not receive policies after the server upgrade.

Upgrading the Change Guardian Server Appliance

You must use the zypper patch to upgrade the Change Guardian server appliance. You cannot use WebYaST to upgrade.

Notes

  • Ensure you reboot the Change Guardian Server computer when the upgrade process is complete. If you do not reboot the Change Guardian Server after upgrading, Change Guardian cannot perform resource expansion.
  • If you are monitoring Linux or UNIX servers, ensure you restart all UNIX agents when the upgrade process is complete. If you do not restart the UNIX agents after upgrading, the UNIX agents will stop monitoring.

To upgrade the appliance by using the zypper patch:

  1. Back up your configuration.
  2. Log in to the Change Guardian appliance console as the root user.
  3. Run the following command:

    /usr/bin/zypper patch

  4. Enter yes to continue.
  5. Select Solution 1 to update the Change Guardian server dependencies as part of the upgrade.
  6. When the installation completes, restart the appliance.

Upgrading the Change Guardian Server on a Standard Computer

To upgrade the Change Guardian Server on a standard computer, perform the installation steps in the User Guide for NetIQ Change Guardian.

Notes

  • Ensure you reboot the Change Guardian Server computer when the upgrade process is complete. If you do not reboot the Change Guardian Server after upgrading, Change Guardian cannot perform resource expansion.
  • If you are monitoring Linux or UNIX servers, ensure you restart all UNIX agents when the upgrade process is complete. If you do not restart the UNIX agents after upgrading, the UNIX agents will stop monitoring.

Upgrading the Console and Windows Agent

You can use the IqcgInstaller.exe program in the installation kit to locally update a console or Windows agent or create a silent installer package for upgrading multiple agents.

(Conditional) To locally install the console or Windows agent, run the IqcgInstaller.exe program and follow the steps in the wizard.

(Conditional) To silently install or upgrade the Windows agent, you must create a silent installer package. Complete the following steps:

To create a silent installer package:

  1. Run the IqcgInstaller.exe program and follow the steps until you get to the Change Guardian Agent window.
  2. In the Change Guardian Agent window, clear Install the selected components locally.
  3. Select Create a silent installer.
  4. Specify the location for the silent installer package.
  5. Complete the steps in the wizard.
  6. The setup program creates a silent installer package called Upgrade NetIQ Change Guardian.exe. Run this program to upgrade your remote agents.

Note
When you specify Create a silent installer, the setup program also creates NetIQ Change Guardian.msi file in the specified path. To use this program to upgrade your agents, you must use the following command to run the file: msiexec.exe /i "NetIQ Change Guardian.msi" REINSTALL=ALL REINSTALLMODE=vomus.

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Upgrade Fails if You Renamed the .msi Package for the Original Installation

If you renamed the .msi file when packaging the program to silently install a previous version of Change Guardian, the upgrade to the current release fails. During an upgrade, Microsoft Windows looks for an original installation with the same identification as the .msi package for the upgrade. For more information about this issue, see the Windows Installer Team Blog. (ENG328889)

Upgrading the Windows Agent Out of Order Prevents Agent from Receiving Policies

You should upgrade the Change Guardian Server prior to upgrading the Windows agent. If you upgrade the Windows agent before you upgrade the Change Guardian Server, the agent will not receive policy updates after the server upgrade. To enable the agent to receive policy updates again, restart the Change Guardian service on the agent machine. (ENG335193)

Upgrading the Appliance from 4.0.x Removes Change Guardian User Accounts

Upgrading the Change Guardian appliance from 4.0 to 4.1 SP1 removes any previously created Change Guardian user accounts. The cgadmin account is recreated with its password set to a random value. After the update, you will need to log on to the Change Guardian web console using the "admin" account to reset the password for the "cgadmin" account. You must recreate all other user accounts.

Unsupported Event Routing Rules are Visible After Upgrading from 4.0

The following Event Routing Rules rules are visible after upgrading from Change Guardian 4.0:

  • Log to File
  • Log to Syslog
  • Send Events via Sentinel Link
  • Send SNMP Trap

For assistance removing these Event Routing Rules, contact Support. (DOC333152)

Default Database Service Port Must Be Used for Change Guardian Server

To successfully install Change Guardian 4.1 SP1, you cannot modify the default Database Service port. (ENG333165)

Event Severity is Always Calculated Automatically for Unix Agent Events

Event Severity is always calculated automatically for Unix Agent events, including events generated by policies configured with a custom severity.(DOC333969)

VMware vSphere 5.5 Web Client Cannot Import OVF Templates

Issue:

An issue with VMware vSphere 5.5 Web Client prevents you from using it to import .ovf templates. (DOC332977)

Workaround:

To import an .ovf template, you must use the VMware vSphere 5.5 Client.

Modifications to System-Only Object Might Not Generate Security Events

Change Guardian for Active Directory requires a security event to generate a Change Guardian event. System-only object attributes in Active Directory cannot be modified manually. They can only be modified internally by Active Directory. Modifications to system-only attributes do not generate security events, so Change Guardian is unaware of these changes and cannot track them or create Change Guardian events. (ENG332134)

Missing Sections in 'Process was Terminated' Events

If you create a process policy in Change Guardian for Windows that monitors an application for Process was Terminated events, and the monitored application is open before you assign the policy to the agent, when the monitored application shuts down, the generated event does not contain the Event Message and Who sections. To ensure the generated event contains all sections, turn off the application you want to monitor before assigning the policy to the agent. After you assign the policy to the agent, start the application again. (ENG332876)

Resource Expansion Cannot Expand Group Members from Trusted Domains

If you configure resource expansion for a group that contains members from a trusted domain other than the domain to which the group belongs, Change Guardian cannot expand the group members. (ENG331982)

Resource Expansion Does Not Support Parentheses

Resource expansion does not work on Active Directory users or users of groups if the name attribute contains open or close parentheses:

( )

(ENG331896)

'Demoted from DC' Events Not Generated on Windows Server 2003

If you configure Change Guardian for Active Directory to monitor for Computer Demoted from DC events, and the demoted computer is running Microsoft Windows Server 2003, a Computer Demoted from DC event is not generated. (ENG332176)

Change Guardian for Active Directory Does Not Generate Some Events on Microsoft Windows Server 2012 R2

If you run Change Guardian for Active Directory on a computer with the Microsoft Windows Server 2012 R2 operating system, Change Guardian for Active Directory does not generate some events. If you install Windows Update KB2911106, Change Guardian for Active Directory is able to generate all events except Active Directory Object was Renamed events. (ENG332396)

Microsoft Windows Server 2012 R2 + KB2887595 Can Cause Instability on Domain Controller

If your domain controller runs Windows Server 2012 R2, ensure you have installed the most recent Windows updates. If the most recent Windows Update you have installed is KB2887595, the computer can become unstable when the following are true:

  • Audit Directory Service Changes is enabled in Active Directory
  • An Active Directory object is renamed

(ENG332396)

Change Guardian for Windows Does Not Capture Some File Share Settings

Change Guardian for Windows does not capture modifications to the following types of share settings:

  • Management Properties
  • Quota

(ENG326828)

Migrating Locally Saved Policies Not Supported

Before you upgrade the Policy Editor to the current version, ensure you back up or submit locally saved policies to the Change Guardian Policy Repository. If you upgrade without backing up locally saved policies from version 4.0 or version 4.0.1, the policies will be lost. (DOC331358)

Active Directory Schema Events Might Display 'N/A' in Before and After Fields

The Schema Attribute Modified and Schema Class Modified events from Active Directory do not support Before and After fields, and display N/A. (ENG330960)

Reports Might Not Display Surrogate Characters Correctly

An issue with DevExpress prevents reports from displaying some surrogate characters correctly. (ENG332580)

A Nessus Scan Results in Loss of Communication with Change Guardian Server

An issue with proxy client connections causes Change Guardian to lose the connection with the Change Guardian server when you run a Nessus scan.

To work around this issue, comment out the following section in the server.xml file:

	<obj-component id="ProxyService">
		<class>esecurity.ccs.comp.clientproxy.ClientProxyService</class>
		<property name="clientports">ssl:${clientproxyservice.port.client}</property>
		<property name="certclientports">ssl:${clientproxyservice.port.certclient}</property>
		<property name="keystore">${esecurity.config.home}/config/.proxyServerKeystore</property>
		<property name="certificateAlias">SentinelProxyServer</property>
	</obj-component>
	

(ENG334480, ENG334500)

Forwarded Events Might Contain Extra Characters

When you use the Syslog Dispatcher to forward events in Change Guardian, event attributes might contain additional backslash (\) characters to escape the following characters: \, =, and |. These extra characters are necessary to allow the event to conform to the Common Event Format (CEF) specification. To remove them, parse the events with a CEF parser. (ENG334907)

File Integrity Diff Data Might Be Truncated in Events Forwarded to Syslog Severs

If you configure the Change Guardian Server to forward File Integrity events to a Syslog Server, and then you modify a monitored file, the diff data in the forwarded event might be truncated if the diff data size is greater than 1 KB. The forwarded event provides a URL that allows you to view the full event and the complete file diff data in the Change Guardian web console. (ENG335411)

UNIX Agent Might Generate File Integrity Events without Diff Data

If a UNIX agent monitors for File Integrity changes, and a user modifies a monitored file, if the amount of modified data is larger than 1 KB, the generated event does not contain diff data. (ENG335309)

Return to Top

Additions to Documentation

Supported Versions of Red Hat Enterprise Linux for Servers

The User Guide for NetIQ Change Guardian incorrectly specifies support for Red Hat Enterprise Linux for Servers 6.x. It should specify Red Hat Enterprise Linux for Servers 6.3 and 6.4. For the most current list of supported products, see the Technical Information for Change Guardian and Change Guardian Modules page.

Return to Top

Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For general corporate and product information, see the NetIQ Corporate Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of our community. The NetIQ online community provides product information, useful links to helpful resources, blogs, and social media channels.

Return to Top

Legal Notice

Return to Top