NetIQ Privileged User Manager 2.4 SP1 Hotfix 1 Release Notes

December 2014

NetIQ Privileged User Manager 2.4 SP1 Hotfix 1 resolves specific previous issues. This document outlines why you should install this hotfix.

Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable inputs. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Privileged User Manager Community Support Forum, our community Web site that also includes product notifications, blogs, and product user groups.

To download this product, see the NetIQ Downloads Web site. For more information about the new features, enhancements, and software fixes in the previous release, see the Privileged User Manager Documentation Web site.

1.0 What’s New?

The following sections outline the issues resolved in this release:

1.1 OpenSSL version is Updated to 1.0.1j

Issue: The OpenSSL version 1.0.1h is vulnerable to the Poodle vulnerability. (Bug 905691)

Fix: This hotfix updates the OpenSSL version from 1.0.1h to 1.0.1j to address the vulnerability. For information about the list of fixes for OpenSSL 1.0.1, see OpenSSL 1.0.1 Branch Release Notes.

1.2 The RDP Relay Session Crashes and the Report Data is not Generated

Issue: When a user runs an RDP Relay session for an extended period, the session becomes unresponsive. Due to this, the session does not generate the report data and the unifid.log file includes an access violation message. (Bug 786206)

Fix: With this hotfix, the session runs seamlessly and hence, generates the report data.

1.3 The SSH Relay Session Prompts to Enter the Passphrase to Start the Session

Issue: When a user attempts to establish an SSH relay session, the session displays a prompt to enter the PUM credentials. After entering the PUM credentials, the session displays a prompt to enter the passphrase of the private key. (Bug 906251)

Fix: This hotfix updates the passphrase for the privileged account. To ensure the prompt for passphrase does not display, after creating a privileged account, modify the credentials by using the Modify Credentials option.

2.0 System Requirements

For information about hardware and software requirements, see Installation Requirements in the NetIQ Privileged User Manager 2.4.1 Installation Guide.

3.0 Installing the Hotfix

Privileged User Manager supports two ways to install the hotfix. You can use any of the following ways:

3.1 Using the Package Manager with NCC

  1. Configure the Package Manager by using Novell Update Server:

    1. Log in to the Framework Manager console.

    2. Click Package Manager > Settings.

    3. From the drop-down menu, select Novell Update Server.

    4. Configure the following fields:

      User name: Specify the user name that allows you to log in to the NetIQ Customer Center.

      Password: Specify the password that is associated with this account.

    5. To view the update server information, select Advanced Settings.

      • Select the Packages checkbox, the following URL is configured:

        https://nu.novell.com:443/PUM/packages

    6. Click Finish.

  2. (Conditional) Configure the Package Manager by using Local Package Manager:

    1. Select Local Package Manager.

    2. Fill in the following fields:

      Host name: Specify the DNS name of the host.

      Port: Specify the communication port. The default is 29120.

      The Local Package Manager is a Framework host that has been configured to store the packages.

  3. (Conditional) If you do not have the Framework patch loaded in your Package Manager:

    1. Click Package Manager on the home page of the console, then click Add Packages.

    2. Configure the Package Filter to display the packages you need.

      Platform: Select your platforms. Make sure you select Cross Platform, which displays the console packages that run on all platforms.

      Types: Select at least Console, Module, and Patch.

      Components: Select all of them: Command Control, Framework, and Miscellaneous.

    3. Select all the packages that are listed. Make sure you select the Framework Patch.

    4. Click Next, then click Finish when the packages have been successfully downloaded.

    5. To ensure that all packages are up-to-date, click Check for Updates.

    6. Select any packages that are listed.

    7. Click Next, then click Finish when the packages have been successfully downloaded.

  4. Load the updates:

    1. In the Package Manager page, click Check for Updates.

    2. If updates are listed, select the packages, then click Next.

    3. After the hotfix are loaded, click Finish.

  5. To push the hotfix to your host machines, continue with Section 3.3, Installing the Hotfix on Host Machines.

3.2 Using the Package Manager with a Local Server

  1. Download the hotfix manually:

    1. On the NetIQ Downloads site, select the Basic Search tab.

    2. On the right pane, select Search Patches.

    3. On the Patch Finder page, select Privileged User Manager from the list of products.

    4. Click Search > Privileged User manager 2.4.1 and select to download Privileged User Manager 2.4.1 HF1.

  2. Extract and publish packages into the Framework:

    1. Copy the netiq-npum-packages-2.4.1-1.tar.gz file to any of the Privileged User Manager machines.

    2. Extract netiq-npum-packages-2.4.1-1.tar.gz into a temporary location, such as a /tmp/framework/ directory.

      tar -xvf netiq-npum-packages-2.4.1-1.tar.gz 
      
    3. Use the following command to publish the packages to the Package Manager.

      Replace <admin> with the name of your admin user.

      For Linux and UNIX platforms:

      /opt/netiq/npum/sbin/unifi -u <admin> distrib publish -d /tmp/framework
      

      NOTE:If you are using PUM 2.3.3 or earlier version, run the following command:

      /opt/novell/npum/sbin/unifi -u <admin> distrib publish -d /tmp/framework

      For Windows platforms:

      c:\Program Files\netiq\npum\bin\unifi -u <admin> distrib publish -d c:\tmp\framework
      

      NOTE:If you are using PUM 2.3.3 or earlier version, run the following command:

      c:\Program Files\novell\npum\bin\unifi -u <admin> distrib publish -d c:\tmp\framework

    4. When prompted, enter the name and password for the administrator.

  3. To push the hotfix to your host machines, continue with Section 3.3, Installing the Hotfix on Host Machines.

3.3 Installing the Hotfix on Host Machines

During the process of installing the packages through the Framework, you can create a backup of the existing packages that are being replaced. To create the backup, you need to leave the Create backup option enabled when installing the hotfix. Then if you want to remove the update, you can use the Rollback Packages option.

You can select to install the hotfix on all hosts or on selected hosts.

  1. Log in to the Framework Manager console.

  2. To install the hotfix on all hosts (if you want to install the hotfix on only selected hosts, skip to Step 3):

    1. On the Home page, click Hosts.

    2. Select the root domain.

    3. In the left frame, select Update Domain Packages.

    4. Select the desired hosts.

      Use Shift+click or Ctrl+click to select multiple hosts.

    5. Click Next.

    6. Click Finish.

  3. To install the hotfix on selected hosts:

    1. Click Hosts > Update Packages on the home page of the console.

    2. Select the desired Hosts.

      Use Shift+click or Ctrl+click to select multiple hosts.

    3. Click Next.

    4. Click Finish.