In Example 8-2and Example 8-3we present the final content required for the files that must be changed or added.

Example 8-2 nac.win.any.services.PostureServices_SERVICE_RUNNING_WF.Defa ultConfig.properties file content

#SPUtil default config file for nac.win.any.services.PostureServices_SERVICE_RUNNING_WF

#PostureCollectorName=nac.win.any.services.PostureServices #PostureCollectorParameterName=SERVICE_RUNNING_WF

PackageName.input=NULLABLE

PackageName.format=${WorkflowName}

#EnableLogging=true

TmfWebUIPublicName.input=NULL

TmfWebUIPublicName.format=/${WorkflowName}/${PostureCollectorName}/${Postur eCollectorParameterName}/latest

Example 8-3 nac.win.any.services.PostureServices_SERVICE_DISABLED_WF.Def aultConfig.properties file content

#SPUtil default config file for nac.win.any.services.PostureServices_SERVICE_DISABLED_WF

#PostureCollectorName=nac.win.any.services.PostureServices #PostureCollectorParameterName=SERVICE_DISABLED_WF

PackageName.input=NULLABLE

PackageName.format=${WorkflowName}

#EnableLogging=true

TmfWebUIPublicName.input=NULL

TmfWebUIPublicName.format=/${WorkflowName}/${PostureCollectorName}/${Postur eCollectorParameterName}/latest

8.3 Creating remediation instructions for the users

With the Network Admission Control solution in place, a security administrator deploying a new policy must be aware of the possible side effects (for example, that a large number of noncompliant workstations may experience restricted

Chapter 8. Remediation subsystem implementation

397

Page 415
Image 415
IBM Tivoli and Cisco manual Creating remediation instructions for the users, 397