NetIQ Change Guardian 4.1 SP 1 Hotfix 1 Release Notes

February 2015

This hotfix resolves specific previous issues. This document outlines why you should install this hotfix.

Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the Change Guardian forum on NetIQ Communities, our online community that also includes product information, blogs, and links to helpful resources.

1.0 What’s New?

This hotfix resolves an issue where a vulnerability in SSL version 3.0 leaves Change Guardian open to a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack. (Bug 902891, Bug 905149)

This hotfix disables SSL version 3.0 on the following Change Guardian ports:

  • 8443

  • 8094

  • 10013

  • 10014

  • 61616

2.0 Installing This Hotfix

To install Change Guardian 4.1 SP 1 Hotfix 1, see “Upgrading Change Guardian” in the User Guide for NetIQ Change Guardian.

3.0 Verifying the Installation

Complete the following steps to verify that the installation was successful.

To check the installed version:

  1. Open a command prompt on the Change Guardian server.

  2. Run the following command: rpm –qa | grep ncg

  3. Ensure the result is 4.1.1-1096.

4.0 Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information website.

For general corporate and product information, see the NetIQ Corporate website.

For interactive conversations with your peers and NetIQ experts, become an active member of our community. The NetIQ online community provides product information, useful links to helpful resources, blogs, and social media channels.