NetIQ Privileged User Manager 2.3.3 Release Notes

June, 2013

1.0 Documentation

The following sources provide information about Privileged User Manager:

2.0 Installing Privileged User Manager 2.3

Privileged User Manager can be downloaded from the Novell Downloads site.

To obtain the purchased license, log in to the Novell Customer Center and follow the link that allows you to download the software and the license key.

The ISO image contains the following directories and files for Framework Managers, Agents, and the Package Manager.

2.1 AIX

Package

netiq-npum-agent-2.3.3-aix-5.1-powerpc.bff.gz

 

Agent package for AIX* 5.1

netiq-npum-manager-2.3.3-aix-5.1-powerpc.bff.gz

 

Framework Manager package for AIX 5.1

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.2 HP-UX

Package

netiq-npum-agent-2.3.3-hpux-11.00-hppa.depot.gz

 

Agent package for HP-UX 11 and 11i HPPA

netiq-npum-agent-2.3.3-hpux-11.23-ia64.depot.gz

 

Agent package for HP-UX 11i v2 and v3 Itanium*

netiq-npum-manager-2.3.3-hpux-11.00-hppa.depot.gz

 

Framework Manager package for HP-UX 11 & 11i HPPA

netiq-npum-manager-2.3.3-hpux-11.23-ia64.depot.gz

 

Framework Manager package for HP-UX 11i v2 and v3 Itanium

For installation instructions, see the follow

ing sections in the NetIQ Privileged User Manager Installation Guide:

2.3 Linux

Package

netiq-npum-agent-2.3.3-linux-2.6-s390x.rpm

 

Agent package for Linux on zSeries mainframes with a 2.6 kernel.

netiq-npum-agent-2.3.3-linux-2.6-x86_64.rpm

 

Agent package for Linux on Intel 64-bit machines with a 2.6 kernel

netiq-npum-agent-2.3.3-linux-2.6-intel.rpm

 

Agent package for Linux on Intel 32-bit machines with a 2.6 kernel

netiq-npum-manager-2.3.3-linux-2.6-s390x.rpm

 

Framework Manager package for Linux on zSeries mainframes with a 2.6 kernel

netiq-npum-manager-2.3.3-linux-2.6-x86_64.rpm

 

Framework Manager package for Linux on Intel 64-bit machines with a 2.6 kernel

netiq-npum-manager-2.3.3-linux-2.6-intel.rpm

 

Framework Manager package for Linux on Intel 32-bit machines with a 2.6 kernel

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.4 SLES10

Package

novell-pum-2.3.3-22885.i586.rpm

 

Agent package on SLES10 32-bit machine

novell-pum-2.3.3-22885.x86_64.rpm

 

Agent package on SLES10 64-bit machine

novell-pum-manager-2.3.3-22885.i586.rpm

 

Framework Manager package on SLES10 32-bit machine

novell-pum-manager-2.3.3-22885.x86_64.rpm

 

Framework Manager package on SLES10 64-bit machine

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.5 SLES11

Package

novell-pum-2.3.3-22885.i586.rpm

 

Agent package on SLES11 32-bit machine

novell-pum-2.3.3-22885.x86_64.rpm

 

Agent package on SLES11 64-bit machine

novell-pum-manager-2.3.3-22885.i586.rpm

 

Framework Manager package on SLES11 32-bit machine

novell-pum-manager-2.3.3-22885.x86_64.rpm

 

Framework Manager package on SLES11 64-bit machine

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.6 Solaris

Package

netiq-npum-agent-2.3.3-solaris-2.8-intel.pkg.gz

 

Agent package for Solaris* 2.8 Intel

netiq-npum-agent-2.3.3-solaris-2.8-sparc.pkg.gz

 

Agent package for Solaris 2.8 SPARC*

netiq-npum-manager-2.3.3-solaris-2.8-intel.pkg.gz

 

Framework Manager package for Solaris 2.8 Intel

netiq-npum-manager-2.3.3-solaris-2.8-sparc.pkg.gz

 

Framework Manager package for Solaris 2.8 SPARC

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.7 Tru64

Package

netiq-npum-agent-2.3.3-tru64-5.0-alpha.tar.gz

 

Agent package for Tru64 v5.x OSF1

For installation instructions, see the following sections in the NetIQ Privileged User Manager Installation Guide:

2.8 Windows

Package

netiq_pum_agent_2.3.3_x86.msi

 

Agent package for Windows 32-bit machine

netiq_pum_agent_2.3.3_x64.msi

 

Agent package for Windows 64-bit machine

netiq_pum_manager_2.3.3_x86.msi

 

Framework Manager package for Windows 32-bit machine

netiq_pum_manager_2.3.3_x64.msi

 

Framework Manager package for Windows 64-bit machine

For installation instructions, see “Installing a Framework Manager” in the NetIQ Privileged User Manager Installation Guide.

2.9 Package Manager

Package

netiq-npum-packages-2.3.3.tar.gz

 

Zipped file for setting up a local package manager.

For instructions on how to set up either the Framework Manager or an agent to be the local package manager, see “Setting Up a Package Manager” in the NetIQ Privileged User Manager Installation Guide.

3.0 Upgrading from Novell Privileged User Manager 2.2 to 2.3

To upgrade from Novell Privileged User Manager 2.2 to 2.3, you can download the packages from the Novell Customer Center or from Novell Downloads. Then you must add the packages to your Framework Manager and update your system with the Framework patch.You can then update the other packages.

To install new 2.3 agents, you need to download the ISO image from Novell Downloads or from the Novell Customer Center.

4.0 New Features

4.1 Privileged User Manager as a Service

Privileged User Manager is also offered as a service, through NetIQ Cloud Security Services. For more information, see Privileged User Manager as a Service in the NetIQ Privileged User Manager 2.3.3 Administration Guide.

4.2 New Platforms Support

Privileged User manager 2.3.3 is now supported on the following platforms:

  • AIX 7.1 64-bit

  • HP-UX (Itanium) 11.31 64-bit

For detailed information, see Supported Platforms in the NetIQ Privileged User Manager 2.3.3 Installation Guide.

4.3 RDP Relay Support

RDP Relay is supported with the following installers:

  • Generic Linux Installer

  • SLES Installer

For detailed information, see Remote Desktop Protocol Relay in the NetIQ Privileged User Manager 2.3.3 Administration Guide.

5.0 Known Issues

5.1 Uninstaller does not Remove all PUM Files and Registry Entries

When you uninstall Privileged User Manager, the uninstaller does not remove all the PUM files and registry entries.

To remove the complete Privileged User Manager folder, manually delete the existing files and restart the system.

5.2 RDP Relay Related Error Message

An error message, “This computer cannot connect to the remote computer” is displayed when host name cannot be resolved either from DNS or Hosts file on a machine from where a user is trying to connect to an RDP relay session using RDP relay feature.

To resolve this issue, on the Windows machine from where you are trying to run the RDP relay session, add the host name resolved to IP address on hosts file.

5.3 Account Domains are not Imported or Exported in Command Control

Account Domains are not imported or exported with the rest of the configuration for Command Control.

5.4 RPM Upgrade Issues on SLES Platform

While upgrading RPM on SLES platforms from version 2.2.2.x to 2.3, new packages such as LDAP agent, SSH relay agent, SSH agent and Privileged Credential manager are unregistered.

To resolve this issue, do one of the following:

  • Use the unifi regclnt register to re-register the packages to manager.

  • Use the console to register the packages in hosts console.

5.5 RDP Session Cannot be Connected when a Screensaver or Lock Screen Prompts Appears

During an RDP session, if a screensaver appears or if the user locks the system, the RDP session cannot be connected.

To resolve this issue, close the active RDP session and reconnect to a new RDP session.

5.6 Package Manager Update Issue

While upgrading from version 2.2.2 to 2.3 using Package Manager, new packages such as Privileged Credential Manager, SSH Relay Agent, SSH Agent are not installed.

To resolve this issue, install the new packages through the host's Install packages option.

5.7 Cannot Start/Stop Services After Applying EAC for the Privilege Users

After applying EAC for the privileged users, users will not be able to stop/start the services of the Splunk application.

5.8 RDP on W8K Does Not Audit Until New Application is Opened if Administrator is Already Logged in from the Desktop

RDP on W8K does not audit until a new application is opened if Administrator is already logged in from Desktop. In such case, session capture starts only after a new application is opened.

5.9 When User Account Control is Enabled, None of the Administrative Applications Open

When UAC (User Account Control) is enabled on a target host, if a RDP session is started, the following error message is displayed:

“The Requested resource is in use”

5.10 Error Executing PostInstall

When installing the Administration Manager (admin) package on a new agent install through the Package Manager, the following cosmetic error is displayed at install time.

In the GUI:

Administration Manger version 2.3.3 (Rev:23981, Bld:65) (can't open /opt/novell/npum/service/local/admin/../.keystore/https_ssl.xml: No such file or directory at (eval 15) line 10.

In the unifid.logfile:

Error executing PostInstall: can't open /opt/novell/npum/service/local/admin/../.keystore/https_ssl.xml: No such file or directory at (eval 16) line 10.

In the GUI, select Finish to complete the Administration Manager Package installation. The Administration Manager package will be installed but will show red in the GUI when you select Packages under the host. To resolve this problem, select the red 'admin' package from the installed packages, and then select Register Package in the left navigation pane.