NetIQ Privileged Account Manager 3.2 Patch Update 5 Release Notes

July 2018

NetIQ Privileged Account Manager 3.2 P5 resolves some of the previous issues.

Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure that our products meet all your needs. You can post feedback in the Privileged Account Manager Community Support Forum on NetIQ Communities, our online community that also includes product information, blogs, and links to helpful resources.

The documentation for this product is available on the NetIQ website in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click the comment icon on any page in the HTML version of the documentation posted at the Privileged Account Manager Documentation website. To download this product, see the NetIQ Downloads website.

1.0 What’s New?

The following sections outline the enhancements and issues resolved in this release:

1.1 Support for REST Call to get SSH host key of the Target Server

The REST call for SSH agent module has been implemented to get the SSH host key of the target server.

1.2 Software Fixes

Audits Missing in Direct RDP Session as Privileged Account Manager does not Monitor Certain Operations

Issue: Privileged Account Manager does not monitor the following on Windows server:

  • Windows Explorer intermittently.

  • Folder and File operations from Windows Explorer at the command level.

  • In a reconnected session, applications that were running prior to the disconnection. (Bug 1100730)

Fix:

  • During a fresh login in Windows session or a reconnected Windows session, PAM agent monitors the operations done using Windows Explorer.

  • PAM agent monitors the activities done in applications that were already running in a reconnected session.

  • File or folder operations such as creation of a file are monitored at command level, like CreateFile <filename>. For delete operations on a file or folder in the Windows GUI, the operation is monitored using GUI audits such as Delete menu clicks.

Using the Run as Privileged User Option Displays an Error

You can use the Run as Privileged formatting option to get elevated access to a target application, based on user’s policy defined in Privileged Account Manager. (Bug 1099605)

Session Recordings are Trimmed when Screen Scaling is Set to 125% or Higher

Issue: When screen scaling is set to 125% or higher on the computer from where RDP session is initiated to the target system, the videos captured for the monitored session are trimmed and the entire screen is not captured. (Bug 1100822)

Fix: Even when screen scaling is set to 125% or higher, Privileged Account Manager records the entire screen in video captures. Ensure that the latest Microsoft Windows patches are installed on the computer for this feature to work as expected.

Secure Shell Relay Connection Fails with an Error

Issue: Secure Shell Relay (SSH Relay) connection fails with the following error: no matching mac found (Bug 1099646)

Fix: SSH relay connections work as expected and does not display an error.

Intermittent Connectivity Issues and Client Timeout from WinSCP SFTP through SSH Relay

SFTP connections using WinSCP now works as expected even when the target system is slow.(Bug 1099649)

SSH connection Fails to a Target Server when Banner is Enabled on the Target System

SSH connection to a target server is now successful even when a SSH banner is enabled on the target system. (Bug 1099648)

Command Control Authorization fails when the Command included in Rule is not Enclosed in Asterisks

Command control authorization can now be done by either entering the full path of the executable or including the executable name inside asterisks as per your requirement. You need to enclose the path of executable in double quotes if the file path includes space. (Bug 1099651)

Enhanced Access Control Capability to Control Kill Command does not Work

The Enhanced Access Control (EAC) feature now controls the Kill command using the capability argument. (Bug 1101034)

All Registered Agents become Unregistered after License is Added to Privileged Account Manager

Install PAM License immediately after deploy PAM manager. If License is added later, re-register the agents after you add a new license. (Bug 1100050)

Rewind and Forward Buttons do not work when an Auditor plays an SSH Tunnel Session Recording

The Rewind and Forward buttons now work as expected. (Bug 1099650)

X11 Enable Check Box is Displayed Only when Account Domain is SSH Type

You can enable or disable X11 for a policy with Credentials as Run User@Run Host and without specifying an account domain. (Bug 1102406).

2.0 System Requirements

For information about hardware requirements, supported operating systems and browsers, and software requirements, see Installation Requirements in the NetIQ Privileged Account Manager 3.2 Installation Guide.

3.0 Installing the Patch Update

3.1 Prerequisites

Before installing this patch update, ensure the following:

3.2 Module Updates in 3.2.0.5

The modules (packages) updated in this patch are:

  • Framework Patch

  • Command Control Agent

  • Command Control Console

  • SSH Agent

  • SSH Relay Agent

  • Administration Manager

  • Command Reporting Console

  • My Access Console

3.3 Installing 3.2.0.5

Installing the patch update includes publishing the packages on the Package Manager and installing the published packages to the Hosts.

Publishing the Packages on the Package Manager

You can publish the packages on the package manager in the following ways:

Using Package Manager with NCC
  1. Configure the Package Manager by using the Novell Update Server:

    1. Log in to the Administration console.

    2. Click Package Manager > Settings.

    3. From the drop-down, select Novell Update Server.

    4. To view the update server information, select Advanced Settings.

      • Select the Packages check box.

      • Ensure that https is selected in the drop-down list.

      • Specify the entire URL for download as follows:

        nu.novell.com/PUM/packages

      • Ensure that the port number is 443.

      • Leave the last text field blank since /PUM/Packages is already added in the previous text field.

      NOTE:Ensure that you retain the default settings for other fields in this screen.

    5. Click Finish.

      For more details and alternate options to download packages to Package Manager, see Downloading Packages to Package Manager.

  2. To push the packages to your host machines, continue with Installing the Packages on Host Machines.

Using Package Manager with a Local Server
  1. Download the patch update manually:

    1. On the NetIQ Downloads site, select the Basic Search tab.

    2. On the right pane, select Search Patches.

    3. On the Patch Finder page, select Privileged User Manager from the list of products.

    4. Click Search, then click Privileged Account Manager 3.2.

      This displays the current patch update.

    5. Download all the Superseded Patches and Current Patches for Privileged Account Manager.

  2. Repeat the following steps for all the patches that is 3.2.0.2, 3.2.0.3, 3.2.0.4, and 3.2.0.5 in a sequential order:

    1. Copy the netiq-npam-packages-3.2.0.x.tar.gz file to any of the Privileged Account Manager machines.

    2. Extract netiq-npam-packages-3.2.0.x.tar.gz into a temporary location, for example, /tmp/framework/ directory.

      tar -xvf netiq-npam-packages-3.2.0.x.tar.gz 
    3. Use the following command to publish the packages to the Package Manager:

      Replace <admin> with the name of your admin user.

      For Linux and UNIX platforms:

      /opt/netiq/npum/sbin/unifi -u <admin> distrib publish -d /tmp/framework

      For Windows platforms:

      c:\Program Files\netiq\npum\bin\unifi -u <admin> distrib publish -d c:\tmp\framework
    4. When prompted, enter the name and password for the administrator.

  3. To push the packages to your host machines, continue with Installing the Packages on Host Machines.

Installing the Packages on Host Machines

Before installing the patch update, disconnect all the Privileged Account Manager sessions to the host on which you are installing this patch.

You can install the updated packages on all the hosts or selected hosts in the following ways:

Installing the Packages Through Command Line

You can install the packages on a Windows, LINUX, or UNIX through command line. For more information about the commands for installing the updated packages, see Upgrade and Rollback Packages section in the NetIQ Privileged Account Manager 3.2 Administration Guide.

Installing the Packages Through Administration Console

When you are installing the packages through the Administration Console, you can create a backup of the existing packages that you are replacing. To create the backup, you need to leave the Create backup option enabled when installing the patch update. Then, if you want to remove the update, you can use the Rollback Packages option.

When you are installing the packages through the Administration Console, you must first install the Framework Patch (spf) and then install other updated packages. Thus, these updated packages are listed in the Host Console only after installing the Framework patch.

To install the packages, perform the following:

  1. Log in to the Framework Manager console.

  2. (Conditional) If you want to install the patch update on all the hosts, perform the following:

    1. On the Home page of the console, click Hosts.

    2. Select the root domain.

    3. In the left pane, click Update Domain Packages.

    4. Select the latest Framework Patch (spf), then click Next.

    5. In the left pane, click Update Domain Packages.

    6. Select all the listed packages, then click Next.

    7. Click Finish.

    8. Repeat Step e, f, and g till no more packages are listed.

  3. (Conditional) If you want to install the patch update on selected hosts, perform the following:

    1. On the Home page of the console, click Hosts.

    2. Select the host on which you want to install this patch.

    3. In the left pane, click Update Packages.

    4. Select the latest Framework Patch (spf), then click Next.

    5. In the left pane, click Update Packages.

    6. Select all the listed packages, then click Next.

    7. Click Finish.

    8. Repeat Step e, f, and g till no more packages are listed.

4.0 Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

4.1 Moving Multiple Objects Does Not Work

Issue: Selecting and moving multiple objects by using the Shift/ Ctrl key does not work.

Workaround: To move multiple objects, you can use shift + select the required objects, or use Select All. (Bug 915307)

4.2 The Run as privileged user Option Is Not Displayed on a Windows 2012 Server

Issue: When you right-click Start on a Windows 2012 server, the Run as privileged user option does not get displayed. (Bug 901032)

Workaround: To workaround this issue, right-click an application in the folder where the application is installed to execute Run as privileged user.

4.3 The Command Control Objects Are Not Displayed When Large Number of Objects Are Added Simultaneously

Issue: When Command Control Objects are added simultaneously in large numbers, the objects do not appear in the console. This is an intermittent behavior. (Bug 908307)

Workaround: No Workaround.

4.4 The Unregistered Hosts List Is Not Displayed

Issue: In the Administration console, when you search for unregistered hosts by clicking Hosts > List Unregistered Hosts > IP Range, the Failed to list unregistered agents error is displayed. (Bug 832747)

Workaround: Ensure that when you install Agents, you register it with the Manager for Privileged Account Manager.

4.5 The Changes to the Syslog Settings Do Not Get Applied

Issue: In the Reporting console, when you save the changes to Syslog settings, such as select > SSL, or Allow Persistent Connections, the changes are not applied. (Bug 895993)

Workaround: To workaround this issue, restart Privileged Account Manager.

4.6 Package Update Fails with an Error in Windows Client Operating System

Issue: Package update in Windows 7, 8.1, or 10 fails with the message Failed to copy PUMCredProv.dll. Ensure LogonUI.exe process is not running on the target host and try again. (Bug 1072645)

Workaround: Perform the following on all the hosts in which you are updating the packages:

  1. Disconnect all the RDP sessions to the host.

  2. Log in to the console of the host.

  3. Continue with the steps in the Installing the Packages on Host Machines.

4.7 Performance Drop in Privileged Account Manager Monitored Windows System

Issue: System performance of Privileged Account Manager monitored Windows machine is slow when the video fps value is set to 10. This is apparent on Windows machine having a single CPU. (Bug 1074472)

Workaround: Click Command Control > Video Settings and set the value of Video fps to 5 or lower.

5.0 Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information website.

For general corporate and product information, see the NetIQ Corporate website.

For interactive conversations with your peers and NetIQ experts, become an active member of our community. The NetIQ online community provides product information, useful links to helpful resources, blogs, and social media channels.

6.0 Legal Notice

For information about legal notices, trademarks, disclaimers, warranties, export and other use restrictions, U.S. Government rights, patent policy, and FIPS compliance, see https://www.netiq.com/company/legal/.

Copyright © 2018 NetIQ Corporation. All Rights Reserved.