HP UX Security Products and Features Software Installing, removing, and upgrading, Installing WLI

Page 21

4 Installing, removing, and upgrading

To install, remove, or upgrade WLI, HP recommends the following procedures.

4.1 Installation requirements

Hardware requirement

HP Integrity servers

Operating system requirements

The operating system must be HP-UX 11iv3 at level B.11.31.0909 or later.

To determine the level of HP-UX 11iv3 installed on your system:

%swlist grep HPUX11i

For example:

%swlist grep HPUX11i

HPUX11i-DC-OE B.11.31.0909 HP-UX Data Center Operating Environment

If your HP-UX 11iv3 system level is earlier than B.11.31.0909, download this release from:

https://h20392.www2.hp.com/portal/swdepot/try.do?productNumber=SD

Patch requirements

The following corequisite patches are required for WLI installation:

HP-UX patch PHKL_38951—VFS cumulative patch

HP-UX patch PHKL_39401—VM cumulative patch

HP-UX patch PHKL_40450—DLKM cumulative patch

These patches are bundled with the WLI product and are installed if necessary.

Disk space requirements

At least 28 MB of disk space must be available on file system “/”.

At least 24 MB of disk space available on file system “/stand”.

System reboot

The system automatically reboots following installation.

4.2 Installing WLI

Only a root user (user ID 0) can successfully install WLI. To install WLI, use the following procedure:

1.Review Section 4.1 (page 21)

2.Log in to the target system as the root user.

3.Go to the HP Software Depot: http://www.hp.com/go/softwaredepot

4.Search for HP-UX Whitelisting. Read the product information webpage for the latest updates and release information.

5.Click Receive for Free >>.

6.Enter your registration information. Read and accept the Terms and Conditions and the Software License Agreement. Click Next.

4.1 Installation requirements

21

Image 21
Contents HP-UX Whitelisting A.01.00 Administrator Guide Copyright 2010 Hewlett-Packard Development Company, L.P Table of Contents HP Serviceguard considerations Glossary Index List of Figures List of Examples Page Security features File access policiesFile lock access controls Capabilities Identity-based access controls4 api Page WLI architecture Product overviewApplication API CommandsApplications WLI metadata files WLI database3 .$WLISIGNATURE$ Page Generating keys Key usageUser keys Administrator keysInstalling, removing, and upgrading Installation requirementsInstalling WLI Removing WLI Upgrading WLI Page Configuring Authorizing the recovery keyAuthorizing administrator keys Backing up the WLI database Signing DLKMsRebooting to restricted mode Page Enhancing security with WLI Signing an executable binaryCreating a Flac policy Removing a file access policy Enabling DLKMs to load during bootCreating an Ibac policy Wlisign -a -k adminpriv /usr/sbin/kcmodule # wlisign -a -k /home/admin1/adminpriv /usr/conf/mod/cissLoading unsigned DLKMs # kcmodule ciss=unusedPage Backup and restore considerations OverviewWLI database files Write protected Policy protected and metadata filesRead/write protected files RecommendationsFlac policies Ibac policiesMetadata files Page HP Serviceguard considerations AdministrationWLI database Policy protected files Software distributor issues Troubleshooting and known issuesWLI reinstallation Lost WLI administrator key or passphraseSu root # rm -r /etc/wli Wlisyspolicy -s mode=maintenance -k adminkey# tar -xf /tmp/wlikeydb.tar # kcmodule wli=unused # shutdown -rSupport and other resources Contacting HPRelated information Typographic conventions WebsitesUser input Times Page Instructions # make clean# make all # su wliusr1Ibac add and delete program Flac add and delete programIbac add and delete program Page Administration examples Su root # wlisign -a -k adm1.pvt /usr/bin/tar Wlicert -s -c wli.admin1 -o wmd -k adm1.pvtBdf mydir Tar -vtf tartest.tarCat /tmp/.$WLIFSPARMS$ Wlisys -k adm1.pvt -s wmdstoretype=pseudoBprestore -f backuplist Bpbackup -f backuplistConfiguring WLI Quick setup examplesAuthorizing an administrator key Authorizing a user keyFlac policies Testing a Flac policyCreating a Flac policy Enabling a Flac policyIbac policies Removing an Ibac policy Disabling an Ibac policyASM GlossaryPage Index SymbolsIndex
Related manuals
Manual 130 pages 58.55 Kb