NetIQ Privileged User Manager 2.4.1 Release Notes

August 2014

NetIQ Privileged User Manager 2.4.1 includes new features and resolves several previous issues.

Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable inputs. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Privileged User Manager Community Support Forum, our community Web site that also includes product notifications, blogs, and product user groups.

To download this product, see the NetIQ Downloads Web site. For more information about this release and for the latest release notes, see the Privileged User Manager Documentation Web site.

1.0 What’s New?

The following sections outline the enhancements and issues resolved in this release:

1.1 Support for XenApp Citrix Server By Using RDP Relay

This release supports establishing an RDP session to the XenApp Citrix server. By using this enhancement you can establish connections and manage configurations for applications hosted on a Citrix server.

1.2 Support for OpenSSL version 1.0.1h

This release includes OpenSSL version 1.0.1 h.

1.3 Software Fixes

Privileged User Manager 2.4.1 provides software fixes for the following issues:

When Establishing Remote Session Licensing Error is Displayed

Issue: When establishing a remote session through RDP Relay, the following error is displayed:

The remote computer disconnected the session because of an error in the licensing protocol

Fix: This release resolves this issue.

PUM Crashes When Establishing an RDP Relay to Windows Server

Issue: By using RDP Relay, when you attempt to connect (through RDP Relay) to any Windows machine that has Terminal Server and Terminal Services License roles installed, PUM crashes. (BUG 877628)

Fix: This release contains RDP protocol change fix, which resolves this issue.

Stopping SYSLOG Server Results in Missing the Audit Events

Issue: If the SYSLOG server stops, some of the initial audit events are not included in the log file. (BUG 886201)

Fix: In this release, this issue is fixed and all the generated audit events are displayed in the log file when the SYSLOG server is restarted. (maximum of 120 seconds delay).

Error When Installing PUM on Linux Server

Issue: When you install PUM on a Linux machine, the following error is displayed and installation fails:

error: unpacking of archive failed on file /etc/software/init.d/npum;52a5e1ef:
cpio: link failed - Invalid cross-device link

This error occurs because the /opt and the /etc folders are present in different volumes.(BUG 866654)

Fix: In PUM 2.4.1, the installation does not fail even if the /opt and the /etc folders are in different volumes.

2.0 System Requirements

For information about hardware requirements, supported operating systems and browsers, and software requirements, see Installation Requirements in the NetIQ Privileged User Manager 2.4.1 Installation Guide.

3.0 Installing Privileged User Manager 2.4.1

To install Privileged User Manager 2.4.1, see the NetIQ Privileged User Manager 2.4.1 Installation Guide.

To obtain the purchased license, log in to the NetIQ Customer Center and download the software and the license key. The ISO image contains the following directories and files for Framework Managers, Agents, and the Package Manager:

3.1 AIX

Package

Description

netiq-npum-agent-2.4.1-aix-5.1-powerpc.bff.gz

Agent package for AIX 5.1

netiq-npum-manager-2.4.1-aix-5.1-powerpc.bff.gz

Framework Manager package for AIX 5.1

3.2 HP-UX

Package

Description

netiq-npum-agent-2.4.1-hpux-11.00-hppa.depot.gz

Agent package for HP-UX 11 and 11i HPPA

netiq-npum-agent-2.4.1-hpux-11.23-ia64.depot.gz

Agent package for HP-UX 11i v2 and v3 Itanium

netiq-npum-manager-2.4.1-hpux-11.00-hppa.depot.gz

Framework Manager package for HP-UX 11 & 11i HPPA

netiq-npum-manager-2.4.1-hpux-11.23-ia64.depot.gz

Framework Manager package for HP-UX 11i v2 and v3 Itanium

3.3 Linux

Package

Description

netiq-npum-agent-2.4.1-linux-2.6-x86_64.rpm

Agent package for Linux on Intel 64-bit machines with a 2.6 kernel

netiq-npum-agent-2.4.1-linux-2.6-intel.rpm

Agent package for Linux on Intel 32-bit machines with a 2.6 kernel

netiq-npum-manager-2.4.1-linux-2.6-x86_64.rpm

Framework Manager package for Linux on Intel 64-bit machines with a 2.6 kernel

netiq-npum-manager-2.4.1-linux-2.6-intel.rpm

Framework Manager package for Linux on Intel 32-bit machines with a 2.6 kernel

3.4 Solaris

Package

Description

netiq-npum-agent-2.4.1-solaris-2.8-intel.pkg.gz

Agent package for Solaris 2.8 Intel

netiq-npum-agent-2.4.1-solaris-2.8-sparc.pkg.gz

Agent package for Solaris 2.8 SPARC

netiq-npum-manager-2.4.1-solaris-2.8-intel.pkg.gz

Framework Manager package for Solaris 2.8 Intel

netiq-npum-manager-2.4.1-solaris-2.8-sparc.pkg.gz

Framework Manager package for Solaris 2.8 SPARC

3.5 Tru64

Package

Description

netiq-npum-agent-2.4-tru64-5.0-alpha.tar.gz

Agent package for Tru64 v5.x OSF1

NOTE:This package is for PUM 2.4 and this does not include the software fixes that are made in this release.

3.6 Windows

Package

Description

netiq_pum_agent_2.4.1_x86.msi

Agent package for Windows 32-bit computer

netiq_pum_agent_2.4.1_x64.msi

Agent package for Windows 64-bit computer

netiq_pum_manager_2.4.1_x86.msi

Framework Manager package for Windows 32-bit computer

netiq_pum_manager_2.4.1_x64.msi

Framework Manager package for Windows 64-bit computer

3.7 Package Manager

Package

Description

netiq-npum-packages-2.4.1.tar.gz

Zipped file for setting up a local package manager

4.0 Upgrading to Privileged User Manager 2.4.1

You can upgrade to Privileged User Manager 2.4.1 from the previous versions of Privileged User Manager. For more information on upgrading, see Upgrading NetIQ Privileged User Manager in the NetIQ Privileged User Manager 2.4.1 Installation Guide.

5.0 Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

For the list of known issues in previous versions of Privileged User Manager, see the Privileged User Manager Documentation Web site.

5.1 Initiating an RDP Session On a Citrix Terminal Results in an Application Crash

Issue: When you connect (through RDP Relay) to a Windows 2008 or later machine and if that machine is installed and configured with the XenApp Citrix client then, you cannot launch any application that are listed in the Citrix client.

Fix: No workaround.

5.2 RDP Relay Sessions Remain Connected After Uninstalling or Stopping PUM

Issue: RDP Relay sessions remain connected even after uninstalling or stopping PUM service.

Fix: Disconnect all the RDP Relay sessions before uninstalling or stopping PUM service.

5.3 “Register PUM Agent” Appears in the Start Menu Even After Registering PUM Agent

Issue: When you install PUM on a Windows computer, Start>All Programs>NetIQ Privileged User Manager>Register PUM Agent option is displayed. After you register the PUM Agent, this option continues to display on the Start menu as a recently run application.

Non-admin users can view this and might try to register the PUM Agent again. This might cause a duplicate entry or break the current agent registration.

5.4 Insufficient Memory Error While Adding Packages in AIX

Issue: You might get insufficient memory error while adding packages in AIX. This happens because the AIX OS restricts the “per process memory” (RAM) to 128MB or 256MB, hence the unifid process fails to expand up to the required space for decompressing the package file.

Fix: Perform the following before adding packages:

  1. Stop the NPUM Service:

    stopsrc -s npum

  2. Ensure that the service is stopped:

    ps ax | grep unifid

  3. Start the NPUM Service:

    (Conditional) If you want to expand to 2GB RAM:

    startsrc -s npum -e "LDR_CNTRL=MAXDATA=0x70000000"

    (Conditional) If you want to expand to 1GB RAM:

    startsrc -s npum -e "LDR_CNTRL=MAXDATA=0x30000000"

5.5 Authorization Error in the UI

Issue: PUM UI displays the following error infrequently:

You are not authorized to perform this operation.

Fix: Perform the operation again or reload the page.

5.6 Insufficient Memory Error When You Add Packages in Solaris

Issue: You might get insufficient memory error while adding packages in Solaris. This happens because Solaris restricts the “per process memory” (RAM) to 128 MB or 256 MB, so the unifid process fails to expand up to the required space for decompressing the package file.

Fix: Run the following command before adding packages:

ulimit -a

5.7 RDP Relay Fails on Windows Server 2012 when the RDP Version is 8.0 or Higher

Issue: RDP Relay fails on a Windows Server 2012 computer when the RDP version is 8.0 or higher. To know the RDP version, see the mstsc version. If the mstsc version is 6.2.9200, it means that the RDP version is 8.0. By default, in Windows 8 and Windows Server 2012, RDP version is 8.0 or higher. When you perform RDP Relay from a client machine where RDP 8.0 is installed, RDP Relay to Windows Server 2012 does not work.

Fix: You can use Windows 7 or earlier version with mstsc 6.1.7601 or earlier version. If Windows 7 is updated to use latest version of RDP, you can downgrade to lower version by uninstalling update KB2592687. This is an optional update for Windows 7 and Windows Server 2008 R2 to update RDP protocol version.