IBM Support

IBM Security Privileged Identity Manager fix pack 2.0.2-ISS-ISPIM-VA-FP0006

Download


Abstract

This fix pack for IBM Security Privileged Identity Manager, Version 2.0.2 contains new enhancements and fixes.

Download Description

IBM Security Privileged Identity Manager version 2.0.2 fix pack 6 introduces the following new features:

  • Support for the integration of IBM Security Guardium with IBM Security Privileged Identity Manager
    This integration allows IBM Security Guardium to report the real users who perform privileged actions on databases using shared IDs. To support it, IBM Security Privileged Identity Manager introduces a new database resource type, allows resources to be bulk loaded separately from credentials, and provides new database views. For more information, see the following links:
    - #Resources type identifier column headers
    -
    Creating a user to access database views
    -
    Database views
  • Bulk uploading for resources and accesses
    Access can now be created using bulk upload, and resources can now be uploaded separately from credentials. For more information about the bulk upload CSV file format, see the following links:
    -
    #Resources type identifier column headers
    -
    #Access type identifier column headers
  • Support for Basic Authentication in REST APIs
    Published REST APIs of IBM Security Privileged Identity Manager now supports pre-emptive Basic Authentication. When the correct credentials are specified in the Basic Authentication header, CSRF token is not required. The APIs continue to accept the existing authentication method of form-based login and CSRF token. For more information, see REST APIs for IBM Security Privileged Identity Manager.
  • Self-Service User Interface update
    The Self-Service User Interface is updated with a new look and feel. The features of this console are not changed.
  • Password Policy Rules
    The password policy rules are updated with three new rules. For more information, see Password strength rules.

This fix pack corrects security vulnerabilities and the following issues that are found in IBM Security Privileged Identity Manager 2.0.2 release:
  • APAR IV86030
    The privileged administrator is unable to connect an AIX credential to identity provider.
  • APAR IV84509
    The ISIM server is unable to check the status account request on the ISPIM server.
  • APAR IV82807
    The virtual appliance allows weak Message Authentication Code (MAC) algorithms for incoming SSH connections.
  • APAR IV81706
    The administrator is unable to add a member node to a cluster.
  • APAR IV79399
    The ISIM server is unable to provision an ISPIM user with a user ID that contains mixed or upper case characters.
  • APAR IV81732
    Spaces are trimmed when the administrator modifies the property value by using the CLI.
  • APAR IV82853
    The administrator is unable to reconnect member nodes to the existing cluster when the primary node password is changed.
  • APAR IV68186
    The virtual appliance reports exceptions in trace.log file from bad erservicepwd1 attribute.
  • APAR IV78726
    The administrator is unable to create users in ISPIM by using REST APIs because of the difficulty in obtaining the CSRF token.
  • APAR IV83689
    The administrator is unable to configure the external user registry in ISPIM to match the Active Directory environment because of restrictions on placement of the system user account.
  • APAR IV85646
    The administrator is unable to update service properties using the CLI.
  • Defect
    Incorrect audit_event data for check-in/check-out credentials.
  • Defect
    The administrator is unable to synchronize cipher suites configuration from primary to node.
  • Defect
    The privileged administrator does not receive email notifications for the reconfiguration result of managed services.
  • Defect
    In a clustered environment, the administrator is unable to change the virtual appliance administrator password using the LMI.
  • Defect
    After changing password of the Directory Server bind user , the administrator is unable to configure the Directory Server with the new password.

Installation Instructions

Note:

  • You must be on IBM Security Privileged Identity Manager version 2.0.2, Fix Pack 3, or later to upgrade to Fix Pack 6.
  • This fix pack can take up to 10 minutes to install. Do not shut down or reboot the virtual appliance while installation is in progress.
  • This fix pack is certified for use with virtual appliances operating in FIPS-compliant mode.


Installation from the LMI User Interface (recommended)
Access the LMI of the virtual appliance using a web browser at https://<pimva>:9443/login.

Procedure
  1. Download the Fixpack to your local workstation.
  2. From the IBM Security Privileged Identity Manager dashboard, select Manage.
  3. Under the Manage dropdown, select Fix Packs.
  4. In the Fix Pack page, select New.
  5. In the Add Fix Pack, select Browse for Fix Pack.
  6. Select the required fix pack.
  7. Select Save Configuration in the Add Fix Pack panel.


Installation from the command line interface (CLI)
Access the command line interface of the virtual appliance by using either an SSH session or the console.

Procedure
  1. Copy the fix pack to a USB device.
    Note: The fix pack must not be in a folder on the USB device.
  2. Attach the USB device to your virtual appliance.
  3. In the virtual appliance CLI, run the command, fixpacks.
  4. Run the command, install.
    Note: It lists all the fix packs that are available in the USB device.
  5. Select the index of the 2.0.2-ISS-ISPIM-VA-FP0006.fixpack and press Enter.
  6. Run the command, list to view the list of installed fix packs.

On
[{"DNLabel":"2.0.2-ISS-ISPIM-VA-FP0006","DNDate":"30 Jun 2016","DNLang":"English","DNSize":"155929307","DNPlat":{"label":"Platform Independent","code":"PF025"},"DNURL":"https://www-945.ibm.com/support/fixcentral/swg/downloadFixes?parent=Security%2BSystems&product=ibm/Tivoli/IBM+Security+Privileged+Identity+Manager&release=2.0.2&platform=Linux&function=fixId&fixids=2.0.2-ISS-ISPIM-VA-FP0006&includeRequisites=1&includeSup","DNURL_FTP":" ","DDURL":null}]
[{"Product":{"code":"SSRQBP","label":"IBM Security Privileged Identity Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"2.0.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
15 June 2018

UID

swg24042342