26
Symantec Enterprise Security ManagerModules for IBM DB2 Databases Release Notes Release 3.0 for Symantec ESM 6.5.x and 9.0 for Windows, AIX, Solaris, Red Hat Linux

Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Symantec Enterprise SecurityManager™ Modules for IBMDB2 Databases ReleaseNotes

Release 3.0 for Symantec ESM 6.5.x and9.0 for Windows, AIX, Solaris, Red HatLinux

Page 2: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Symantec ESM Modules for IBM DB2 Databases ReleaseNotes 3.0

The software described in this book is furnished under a license agreement andmay be usedonly in accordance with the terms of the agreement.

Documentation version 3.0

Legal NoticeCopyright © 2009 Symantec Corporation. All rights reserved.

Symantec, the Symantec Logo, LiveUpdate, Symantec Enterprise Security Architecture,Enterprise Security Manager, and NetRecon are trademarks or registered trademarks ofSymantec Corporation or its affiliates in the U.S. and other countries. Other names may betrademarks of their respective owners.

The product described in this document is distributed under licenses restricting its use,copying, distribution, and decompilation/reverse engineering. No part of this documentmay be reproduced in any form by any means without prior written authorization ofSymantec Corporation and its licensors, if any.

THEDOCUMENTATIONISPROVIDED"ASIS"ANDALLEXPRESSORIMPLIEDCONDITIONS,REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OFMERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT,ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TOBELEGALLYINVALID.SYMANTECCORPORATIONSHALLNOTBELIABLEFORINCIDENTALOR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING,PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINEDIN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

The Licensed Software andDocumentation are deemed to be commercial computer softwareas defined in FAR12.212 and subject to restricted rights as defined in FARSection 52.227-19"Commercial Computer Software - Restricted Rights" and DFARS 227.7202, "Rights inCommercial Computer Software or Commercial Computer Software Documentation", asapplicable, and any successor regulations. Any use, modification, reproduction release,performance, display or disclosure of the Licensed Software andDocumentation by theU.S.Government shall be solely in accordance with the terms of this Agreement.

Page 3: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Symantec Corporation20330 Stevens Creek Blvd.Cupertino, CA 95014

http://www.symantec.com

Page 4: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Technical SupportSymantec Technical Support maintains support centers globally. TechnicalSupport’s primary role is to respond to specific queries about product featuresand functionality. TheTechnical Support group also creates content for our onlineKnowledge Base. The Technical Support group works collaboratively with theother functional areas within Symantec to answer your questions in a timelyfashion. For example, theTechnical Support groupworkswithProductEngineeringand Symantec Security Response to provide alerting services and virus definitionupdates.

Symantec’s maintenance offerings include the following:

■ A range of support options that give you the flexibility to select the rightamount of service for any size organization

■ Telephone and Web-based support that provides rapid response andup-to-the-minute information

■ Upgrade assurance that delivers automatic software upgrade protection

■ Global support that is available 24 hours a day, 7 days a week

■ Advanced features, including Account Management Services

For information about Symantec’sMaintenance Programs, you can visit ourWebsite at the following URL:

www.symantec.com/techsupp/

Contacting Technical SupportCustomerswith a currentmaintenance agreementmay access Technical Supportinformation at the following URL:

www.symantec.com/techsupp/

Before contacting Technical Support, make sure you have satisfied the systemrequirements that are listed in your product documentation. Also, you should beat the computer onwhich theproblemoccurred, in case it is necessary to replicatethe problem.

When you contact Technical Support, please have the following informationavailable:

■ Product release level

■ Hardware information

■ Available memory, disk space, and NIC information

■ Operating system

Page 5: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

■ Version and patch level

■ Network topology

■ Router, gateway, and IP address information

■ Problem description:

■ Error messages and log files

■ Troubleshooting that was performed before contacting Symantec

■ Recent software configuration changes and network changes

Licensing and registrationIf yourSymantecproduct requires registrationor a licensekey, access our technicalsupport Web page at the following URL:

www.symantec.com/techsupp/

Customer serviceCustomer service information is available at the following URL:

www.symantec.com/techsupp/

Customer Service is available to assist with the following types of issues:

■ Questions regarding product licensing or serialization

■ Product registration updates, such as address or name changes

■ General product information (features, language availability, local dealers)

■ Latest information about product updates and upgrades

■ Information about upgrade assurance and maintenance contracts

■ Information about the Symantec Buying Programs

■ Advice about Symantec's technical support options

■ Nontechnical presales questions

■ Issues that are related to CD-ROMs or manuals

Page 6: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Maintenance agreement resourcesIf you want to contact Symantec regarding an existing maintenance agreement,please contact the maintenance agreement administration team for your regionas follows:

[email protected] and Japan

[email protected], Middle-East, and Africa

[email protected] America and Latin America

Additional enterprise servicesSymantec offers a comprehensive set of services that allow you tomaximize yourinvestment in Symantec products and to develop your knowledge, expertise, andglobal insight, which enable you to manage your business risks proactively.

Enterprise services that are available include the following:

These solutions provide early warning of cyber attacks, comprehensive threatanalysis, and countermeasures to prevent attacks before they occur.

SymantecEarlyWarningSolutions

These services remove the burdenofmanaging andmonitoring security devicesand events, ensuring rapid response to real threats.

Managed Security Services

Symantec Consulting Services provide on-site technical expertise fromSymantec and its trustedpartners. SymantecConsultingServices offer a varietyof prepackaged and customizable options that include assessment, design,implementation,monitoring, andmanagement capabilities. Each is focused onestablishing andmaintaining the integrity and availability of your IT resources.

Consulting Services

Educational Services provide a full array of technical training, securityeducation, security certification, and awareness communication programs.

Educational Services

To access more information about Enterprise services, please visit our Web siteat the following URL:

www.symantec.com

Select your country or language from the site index.

Page 7: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Technical Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

Chapter 1 What's new in this release . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9

What's new in this release ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9New support ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10New module ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10New checks .... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10

ESM DB2 Audit Configuration (Windows) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11ESM DB2 Audit Configuration (UNIX) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11ESM DB2 Discovery (Windows) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12ESM DB2 Discovery (UNIX) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13ESM DB2 Fix Packs (Windows) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15ESM DB2 Fix Packs (UNIX) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16

New message .... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16All checks (ESM DB2 Audit Configuration - Windows) ... . . . . . . . . . . . . . . . . 16

Chapter 2 Modified messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17

Modified messages ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17

Chapter 3 Enhancements and Resolved issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19

Enhancements ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19Resolved issues ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21

ESM DB2 Remote module (Windows) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22ESM DB2 Remote module (Windows) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23ESM DB2 Remote module (UNIX) ... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23

Chapter 4 Known issue . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25

Known issue .... . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25

Contents

Page 8: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Contents8

Page 9: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

What's new in this release

This chapter includes the following topics:

■ What's new in this release

■ New support

■ New module

■ New checks

■ New message

What's new in this releaseThe following are new in this release of Symantec ESM DB2 modules:

■ New Platform support

■ New Database version support

■ LiveUpdate support

■ ESM DB2 Discovery module (Windows and UNIX)

■ Three new checks in the ESM DB2 Audit Configuration module (Windows)

■ Three new checks in the ESM DB2 Audit Configuration module (UNIX)

■ One new check in the ESM DB2 Fix Packs module (Windows)

■ One new check in the ESM DB2 Fix Packs module (UNIX)

■ Four new checks in the ESM DB2 Discovery module (Windows)

■ Eight new checks in the ESM DB2 Discovery module (UNIX)

■ Three new messages in the ESM DB2 Audit Configuration module (Windows)

1Chapter

Page 10: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

New supportThis release of Symantec ESM Modules for Database supports the following:

New Platform support

■ Windows Server 2008

■ IBM AIX 6.1

■ RHEL AS 4

New Database version support

■ IBM DB2 version 9.5 database

LiveUpdate support

■ LiveUpdate is available for the ESM DB2 modules. Before you use theLiveUpdate functionality ensure that you have the ESM DB2 version 2.0 orlater installed on the ESM agent computers.

For more information on the System requirements, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

New moduleThe following new module has been added:

■ ESM DB2 Discovery module (Windows and UNIX)

The checks in the ESM DB2 Discovery module lets you automate the detectionand configuration of new databases and instances that are not yet configured onthe local ESM agent computers. The checks also detect the deleted databases andinstances and let you remove the deleted databases and instances from theconfiguration file.

See “ESM DB2 Discovery (Windows)” on page 12.

See “ESM DB2 Discovery (UNIX)” on page 13.

New checksNew checks have been added in the following modules:

■ ESM DB2 Audit Configuration (Windows)

■ ESM DB2 Audit Configuration (UNIX)

■ ESM DB2 Discovery (Windows)

■ ESM DB2 Discovery (UNIX)

What's new in this releaseNew support

10

Page 11: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

■ ESM DB2 Fix Packs (Windows)

■ ESM DB2 Fix Packs (UNIX)

ESM DB2 Audit Configuration (Windows)The following new checks have been added to the ESM DB2 Audit Configuration(Windows) module:

■ DB2 Copies

■ Audit Data Path

■ Audit Archive Path

DB2 CopiesThis check lets you include or exclude the DB2 copies that themodule reports on.

For more information on the DB2 Copies check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

Audit Data PathThis check reports the path that you set for the audit data. This check has beenintroduced under a new check group ‘Other Audit Settings’ and is only supportedon the IBM DB2 version 9.5 database.

For more information on the Audit Data Path check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

Audit Archive PathThis check reports the path that you set for the audit archive. This check has beenintroduced under a new check group ‘Other Audit Settings’ and is only supportedon the IBM DB2 version 9.5 database.

Formore informationon theAuditArchivePath check, see theSymantecEnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

ESM DB2 Audit Configuration (UNIX)The following new checks have been added to the ESM DB2 Audit Configuration(UNIX) module:

■ DB2 Instances

■ Audit Data Path

11What's new in this releaseNew checks

Page 12: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

■ Audit Archive Path

DB2 InstancesThis check lets you include or exclude the DB2 instances that the module reportson.

For more information on the DB2 Instances check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

Audit Data PathThis check reports the path that you set for the audit data. This check has beenintroduced under a new check group ‘Other Audit Settings’ and is only supportedon the IBM DB2 version 9.5 database.

For more information on the Audit Data Path check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

Audit Archive PathThis check reports the path that you set for the audit archive. This check has beenintroduced under a new check group ‘Other Audit Settings’ and is only supportedon the IBM DB2 version 9.5 database.

Formore informationon theAuditArchivePath check, see theSymantecEnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

ESM DB2 Discovery (Windows)The following new checks have been added to the ESM DB2 Discovery:

■ Detect New Database

■ Detect Deleted Database

■ Automatically Add New Database

■ Automatically Remove Deleted Database

Detect New DatabaseThis check reports the database that are newly detected on the ESM agentcomputers and that were not configured earlier in the \\ProgramFiles\Symantec\ESM\config\DB2Module.dat configuration file.

What's new in this releaseNew checks

12

Page 13: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

For more information on the Detect New Database check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Detect Deleted DatabaseThis check reports all the databases that are deleted but are still configured inthe configuration file \\Program Files\Symantec\ESM\config\DB2Module.dat

on the ESM agent computers.

For more information on the Detect Deleted Database check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Automatically Add New DatabaseThis check works in collaboration with the ‘Detect New Database' check. Thischeck uses the generic credentials to automatically configure the newly detecteddatabases.

For more information on the Automatically Add New Database check, see theSymantecEnterpriseSecurityManager™Modules for IBMDB2UniversalDatabasesUser’s Guide.

Automatically Remove Deleted DatabaseThis check works in collaboration with the ‘Detect Deleted Database’ check. Thischeck automatically deletes the removed database records from the \\ProgramFiles\Symantec\ESM\config\DB2Module.dat configuration file.

For more information on the Automatically Remove Deleted Database check, seethe Symantec Enterprise Security Manager™Modules for IBM DB2 UniversalDatabases User’s Guide.

ESM DB2 Discovery (UNIX)The following new checks have been added to the ESM DB2 Discovery:

■ Detect New Database

■ Detect Deleted Database

■ Automatically Add New Database

■ Automatically Remove Deleted Database

■ Detect New Instance

■ Detect Deleted Instance

13What's new in this releaseNew checks

Page 14: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

■ Automatically Add New Instance

■ Automatically Remove Deleted Instance

Detect New DatabaseThis check reports the database that are newly detected on the ESM agentcomputers and thatwerenot configuredearlier in the/esm/config/DB2Module.datconfiguration file.

For more information on the Detect New Database check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Detect Deleted DatabaseThis check reports all thedatabases that aredeleted fromtheESMagent computersbut are still configured earlier in the /esm/config/DB2Module.dat configurationfile.

For more information on the Detect Deleted Database check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Automatically Add New DatabaseThis check works in collaboration with the ‘Detect New Database’ check. Thischeck uses the user name that is specified in the User Name text box toautomatically configure the newly detected databases.

For more information on the Automatically Add New Database check, see theSymantecEnterpriseSecurityManager™Modules for IBMDB2UniversalDatabasesUser’s Guide.

Automatically Remove Deleted DatabaseThis check works in collaboration with the 'Detect Deleted Database' check. Thischeck automatically removes the deleted database records fromthe/esm/config/DB2Module.dat configuration file.

For more information on the Automatically Remove Deleted Database check, seethe Symantec Enterprise Security Manager™Modules for IBM DB2 UniversalDatabases User’s Guide.

What's new in this releaseNew checks

14

Page 15: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Detect New InstanceThis check reports the IBM DB2 instances that are newly detected on the ESMagent computers and which were not configured earlier in the/esm/config/DB2ModulePath.dat configuration file.

For more information on the Detect New Instance check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Detect Deleted InstanceThis check reports the instances that were deleted but are still configured in the/esm/config/DB2ModulePath.dat configuration file on the ESMagent computer.

For more information on the Detect Deleted Instance check, see the SymantecEnterprise Security Manager™Modules for IBM DB2 Universal Databases User’sGuide.

Automatically Add New InstanceThis check works in collaboration with the ‘Detect New Instance’ check. Thischeck uses the user name as specified in the User Name text box to automaticallyconfigure the newly detected instance.

For more information on the Automatically Add New Instance check, see theSymantecEnterpriseSecurityManager™Modules for IBMDB2UniversalDatabasesUser’s Guide.

Automatically Remove Deleted InstanceThis check works in collaboration with the 'Detect Deleted Instance' check. Thischeck automatically removes the deleted instance records from the/esm/config/DB2ModulePath.dat configuration file.

For more information on the Automatically Remove Deleted Instance check, seethe Symantec Enterprise Security Manager™Modules for IBM DB2 UniversalDatabases User’s Guide.

ESM DB2 Fix Packs (Windows)The following new check has been added to the ESM DB2 Fix Packs:

■ DB2 Copies

15What's new in this releaseNew checks

Page 16: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

DB2 CopiesThis check lets you include or exclude the DB2 copies that themodule reports on.

For more information on the DB2 Copies check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

ESM DB2 Fix Packs (UNIX)The following new check has been added to the ESM DB2 Fix Packs:

■ DB2 Instances

DB2 InstancesThis check lets you include or exclude the DB2 instances that the module reportson.

For more information on the DB2 Instances check, see the Symantec EnterpriseSecurity Manager™Modules for IBM DB2 Universal Databases User’s Guide.

New messageNew message has been added in the following check:

■ All checks (ESM DB2 Audit Configuration - Windows)

All checks (ESM DB2 Audit Configuration - Windows)The following three new messages have been added to the check. The checksreport the messages only on the IBM DB2 version 9.5 database.

Table 1-1 lists the new messages

Table 1-1 New messages for all checks

Message SeverityMessage TitleMessage ID

green-0Audit EnabledESM_SETTING_ENABLED

red-4Auditing DisabledESM_SETTING_DISABLED

yellow-1Auditing DisabledESM_SETTING_DISABLED_WARNING

Note: The checks 'Audit Failure Events', 'Audit Success Events', and 'AuditingEnabled' do not report the above messages.

What's new in this releaseNew message

16

Page 17: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Modified messages

This chapter includes the following topics:

■ Modified messages

Modified messagesMessages of the following checks have been modified:

Themessagenameof theESM_LOG_ERRORmessage has been changed to'ESM_LOG_DB2ERROR.'

Audit Failure Events (ESM DB2 AuditConfiguration - Windows)

Themessage name of the ESM_LOG_AUDITmessage has been changed to'ESM_LOG_DB2AUDIT.'

Auditing Related Events (ESM DB2 AuditConfiguration - Windows)

2Chapter

Page 18: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Modified messagesModified messages

18

Page 19: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Enhancements andResolved issues

This chapter includes the following topics:

■ Enhancements

■ Resolved issues

EnhancementsThe following enhancements are made in this release:

The IBM DB2 Remote module has beenenhanced to configure the DB2 databasewithout a password. The module no longerrequires the –P option. Now the moduleprompts for the database name, the instancename, and the user name.

ESM DB2 Remote module (UNIX)

3Chapter

Page 20: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

The ESM DB2 database configuration hasbeen enhanced to validate the connection tothe database before it adds the configurationrecord.

To validate the silent configurationconnection to the DB2 database, choose the-V option. The -V is optional.

If you specify the -V option, the optionvalidates the connection of theDB2databasewith specified parameters. On successfulvalidation, the option adds the configurationrecords in the configuration file.

If the validation fails then no records areadded in the configuration file.

If you do not specify the -V option then themodule does not validate the configurationrecords. The option automatically adds theconfiguration records in the configurationfile.

During the interactive configuration, themodule prompts you to validate theconfiguration records.

Silent and interactive configuration(Windows and UNIX)

The template files have been updated withthe latest fix packs released by IBM.

ESM DB2 Fix Packs module (Windows andUNIX)

A Logging feature has been enabled on allthe ESM DB2 modules.

The logging feature enables ESM to loginformation such as the information, suchas errors and exceptions that a modulegenerates at the runtime.

To know more about configuring a file andlog levels of the messages, refer to theSymantec Enterprise Security Manager™Modules for IBM DB2 Universal DatabasesUser’s Guide.

ESM DB2 Modules (Windows and UNIX)

Enhancements and Resolved issuesEnhancements

20

Page 21: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Earlier, during the silent installation orconfiguration, the users entered theirpassword in the installation or theconfiguration command.

The configuration and installation has beenenhanced and now you have an option to setthe passwords as environment variables.Moreover, you do not have to enter yourpasswords in the installation or theconfiguration command.

On UNIX

For example:

#export ESMPASS =<esm-password>

#export ESMDB2PASS=<DB2-account-password>

If you use the environment variables duringthe installation and configuration then youdo not have to enter your password options.

On Windows

For example:

db2setup -q -D <database\alias name> -I<instance\node name> -U <username> -X<InstallPath> -V

esmdb2tpi.exe -it –-m<esmManager> -U<esmUser> -p <port> -g <esmAgent> -e

If you do not use the environment variablesduring installation and configuration thenyou have to enter your password options.

For example:

db2setup -q -D <database\alias name> -I<instance\node name> -U <username> -P<password> -X <InstallPath> -Vesmdb2tpi.exe -it –m<esmManager> -U<esmUser> -p <port> -P <esmPassword> -g<esmAgent> -e

Configurationand installation (WindowsandUNIX)

Resolved issuesThe following issues are resolved in this release:

21Enhancements and Resolved issuesResolved issues

Page 22: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

ESM DB2 Remote module (Windows)The following checks in the ESMDB2Remotemodule has beenmodified to reportthe Instance/Node name in the Information field apart from the user name andgrantee type:

■ New Group / User in Database Administrator Authority

■ Deleted Group / User in Database Administrator Authority

■ Modified Group / User in Database Administrator Authority

■ New Group / User in CONNECT Database Privilege

■ Deleted Group / User in CONNECT Database Privilege

■ Modified Group / User in CONNECT Database Privilege

■ New Group / User in BINDADD Database Privilege

■ Deleted Group / User in BINDADD Database Privilege

■ Modified Group / User in BINDADD Database Privilege

■ New Group / User in CREATETAB Database Privilege

■ Deleted Group / User in CREATETAB Database Privilege

■ Modified Group / User in CREATETAB Database Privilege

■ New Group / User in IMPLICIT_SCHEMA Database Privilege

■ Deleted Group / User in IMPLICIT_SCHEMA Database Privilege

■ Modified Group / User in IMPLICIT_SCHEMA Database Privilege

■ New Group / User in LOAD Authority

■ Deleted Group / User in LOAD Authority

■ Modified Group / User in LOAD Authority

■ New Group / User in CREATE_NOT_FENCED Database Privilege

■ Deleted Group / User in CREATE_NOT_FENCED Database Privilege

■ Modified Group / User in CREATE_NOT_FENCED Database Privilege

Note: The suppressed messages reappear if you have suppressed the messagesfor a new, modified, or deleted user on the information field.

Enhancements and Resolved issuesResolved issues

22

Page 23: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

ESM DB2 Remote module (Windows)The ESM DB2 Remote module has been modified to report on the instances andthe databases that are not attached to the default control center.

ESM DB2 Remote module (UNIX)TheDatabaseDiscoverymode check in theDB2Remotemodule has beenmodifiedto report on all the DB2 versions.

23Enhancements and Resolved issuesResolved issues

Page 24: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Enhancements and Resolved issuesResolved issues

24

Page 25: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Known issue

This chapter includes the following topics:

■ Known issue

Known issueThe following issue is known in this release:

When thenode is unregistered from theDB2server then the databases with theunregistered node name are reported asdeleted databases.

ESM DB2 Discovery (Windows)

4Chapter

Page 26: Symantec Enterprise Security Manager Modules for IBM DB2 ...Mar 20, 2009  · See “ESM DB2 Discovery (Windows)” on page 12. See “ESM DB2 Discovery (UNIX)” on page 13. New checks

Known issueKnown issue

26