Hp Insight Vulnerability and Patch Manager Software Manuel d'utilisateur Page 1

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Logiciel Hp Insight Vulnerability and Patch Manager Software. HP Insight Vulnerability and Patch Manager Software User Manual [es] Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 110
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
HP ProLiant Essentials Vulnerability and Patch
Management Pack
User Guide
Part number 367562-004
Fourth edition July 2007
Vue de la page 0
1 2 3 4 5 6 ... 109 110

Résumé du contenu

Page 1 - Management Pack

HP ProLiant Essentials Vulnerability and Patch Management Pack User Guide Part number 367562-004 Fourth edition July 2007

Page 2

Introduction 10 The following figure depicts a shared server configuration, in which the VPM Acquisition Utility is used to obtain patch and vuln

Page 3 - Contents

Vulnerability and Patch Management Pack events 100 Patch and fix events Table 7 lists the events created by the Vulnerability and Patch Manageme

Page 4 - Contents 4

Vulnerability and Patch Management Pack events 101 Table 7 VPM patch and fix events Event Description Occurs Failed VPM Patch and Fix for a Sys

Page 5 - Contents 5

Vulnerability and Patch Management Pack events 102 Acquisition events Table 8 lists the events created by the Vulnerability and Patch Management

Page 6 - About this guide

Vulnerability and Patch Management Pack events 103 Miscellaneous events Table 9 lists the miscellaneous events created by Vulnerability and Patc

Page 7 - Introduction

Vulnerability and Patch Management Pack events 104 Table 9 Miscellaneous VPM events Event Description Occurs Failed VPM Patch Agent Install A f

Page 8 - Introduction 8

HP services and technical support 105 HP services and technical support Vulnerability and Patch Management Pack is offered exclusively as a part

Page 9 - Infrastructure

HP services and technical support 106 • Obtain the latest SmartStart (http://www.hp.com/servers/smartstart)—The SmartStart, Management, and Fir

Page 10 - Introduction 10

Index 107 Index A acquisition patch, 37 settings, 37 adding licenses, 46 additional help resources, 6 applying licenses with License Manager, 47

Page 11 - Introduction 11

Index 108 IIS. See Internet Information Services installation default location, 18 logs, 79 reinstalling, 87 uninstalling, 85 viewing status, 68

Page 12 - Introduction 12

Index 109 scheduled task canceling, 51 modifying, 51 viewing, 51 security, 35 settings acquisition, 37 changing password, 96 default menu, 27 fir

Page 13

Introduction 11 Distributed server configuration In a distributed server configuration, Vulnerability and Patch Management Pack and HP SIM are ea

Page 14

Index 110 default settings, 18 events, 99 hardware requirements, 15 help resources, 6 infrastructure, 9 installation logs, 79 installing, 19 inte

Page 15 - Requirements

Introduction 12 The following figure depicts a distributed server configuration, in which the VPM Acquisition Utility is used to obtain patch and

Page 16 - HP Systems Insight Manager

Introduction 13 The Vulnerability and Patch Management Pack interface Vulnerability and Patch Management Pack vulnerability information appears i

Page 17 - Target systems

Introduction 14 Table 1 Vulnerability and Patch Management Pack icons Icon Status Risk assessment This system is available for licensing, but

Page 18 - Installation location

Requirements 15 Requirements This section lists the hardware and software required for each component in the Vulnerability and Patch Management P

Page 19

Requirements 16 Table 3 Software requirements Component Specification Microsoft Windows 2000 Server SP4 Windows 2000 Advanced Server SP4 Micros

Page 20

Requirements 17 VPM Acquisition Utility (optional) The VPM Acquisition Utility can be installed on a system with Internet access to acquire patch

Page 21

Installation and configuration 18 Installation and configuration This section provides detailed instructions to perform a first-time installatio

Page 22

Installation and configuration 19 Installing from the Insight Control Management DVD 1. Insert the Insight Control Management DVD into the DVD-

Page 23

Legal notices © Copyright 2004, 2007 Hewlett-Packard Development Company, L.P. Confidential computer software. Valid license from HP required for

Page 24

Installation and configuration 20 4. At the welcome screen, click Install. 5. At the Software Selection screen, select Vulnerability and Patch

Page 25

Installation and configuration 21 6. Review the requirements, and click Next.

Page 26

Installation and configuration 22 7. If this is an upgrade installation, be sure that all Vulnerability and Patch Management Pack functions ar

Page 27

Installation and configuration 23 9. If Vulnerability and Patch Management Pack is installed on a separate server from HP SIM, enter the user

Page 28

Installation and configuration 24 10. Specify the database type to use for storing your patch database, and click Next. An existing SQL Server

Page 29

Installation and configuration 25 11. Specify the installation directory or accept the default directory. NOTE: If this is an upgrade instal

Page 30 - Click Next

Installation and configuration 26 14. Click Finished. The HP SIM service is restarted and Vulnerability and Patch Management Pack is available

Page 31

Installation and configuration 27 Installing from the VPM download website 1. After downloading the Vulnerability and Patch Management Pack fro

Page 32

Installation and configuration 28 − View by System − View Patches Installed by VPM ○ View Patch Reboot Status ○ View Patch Repository • De

Page 33 - Finish

Installation and configuration 29 Vulnerability and Patch Management Pack upgrades New versions of Vulnerability and Patch Management Pack are

Page 34

Contents 3 Contents About this guide...

Page 35 - Establishing security

Installation and configuration 30 6. Click Next. 7. Specify the installation directory or accept the default directory, and click Next.

Page 36

Installation and configuration 31 8. Specify the Start Menu folder or accept the default folder, and click Next. 9. Select whether to create a

Page 37

Installation and configuration 32 10. Review the installation details. Click Back to change any settings, or click Install to begin the instal

Page 38

Installation and configuration 33 11. When the installation is complete, select whether to launch the VPM Acquisition Utility, and click Finis

Page 39

Installation and configuration 34 Post-installation configuration 1. Log in to HP SIM from an account with administrator privileges. NOTE: A

Page 40

Installation and configuration 35 5. Perform an automatic discovery to locate and identify target systems in the network that can be used with

Page 41

Installation and configuration 36 ○ If the VPM server does not have Internet access, select Acquire updates from local repository to use the V

Page 42

Installation and configuration 37 Configuring Vulnerability and Patch Management Pack acquisition for Red Hat Enterprise Linux If Red Hat patch

Page 43

Installation and configuration 38 Acquisitions from the VPM server IMPORTANT: If a proxy is used to connect to the Internet, proxy settings

Page 44

Installation and configuration 39 4. Select the appropriate languages for the required patches, and click Schedule. 5. Schedule a suitable

Page 45 - Licensing

Contents 4 Deleting scan results by system ...

Page 46 - Adding licenses

Installation and configuration 40 Progress of the acquisition can be monitored at C:\Program Files\HP\VPM\Radia\IntegrationServer\ logs\patch-a

Page 47

Installation and configuration 41 3. Select the appropriate operating system platforms and platform-related applications, and click Next. 4.

Page 48 - Click Run Now

Installation and configuration 42 6. If you use a proxy, select the I use a proxy checkbox, and enter the appropriate configuration informatio

Page 49 - Vulnerability scanning

Installation and configuration 43 The vulnerability and patch acquisition begins. Progress of the acquisition can be monitored at C:\Program F

Page 50

Installation and configuration 44 11. On the VPM server, create a directory named “data” at C:\Program Files\HP\VPM\Radia\Integration Server.

Page 51

Licensing 45 Licensing This section provides information about licensing systems for use with Vulnerability and Patch Management Pack. NOTE: Th

Page 52

Licensing 46 3. Click Next to continue the task. NOTE: Selected target systems not yet licensed or licensed using a time-limited license appe

Page 53

Licensing 47 NOTE: Vulnerability and Patch Management Pack does not support the HP SIM License Manager Add Key from File feature. NOTE: If t

Page 54

Licensing 48 5. Select the appropriate Vulnerability and Patch Management Pack license key to apply to the selected systems. 6. Click Run Now.

Page 55

Vulnerability scanning 49 Vulnerability scanning This section provides an overview of setting up and using the Vulnerability and Patch Managemen

Page 56

Contents 5 Other tools report that a Windows system is patched, but Vulnerability and Patch Management Pack reports patches needed...

Page 57

Vulnerability scanning 50 4. Verify that the correct target systems appear in the lists, click Add Targets or Remove Targets if it is necessary

Page 58

Vulnerability scanning 51 NOTE: Scans are run one system at a time in a serial process from the VPM server. 9. If scheduling the vulnerabili

Page 59

Vulnerability scanning 52 3. Modify the event details. a. If necessary, change target systems on which the task is scheduled to run by click

Page 60 - Deploying patches and fixes

Vulnerability scanning 53 Viewing vulnerability scan results The Vulnerability and Patch Management Pack scan results can be viewed either for

Page 61

Vulnerability scanning 54 Viewing scan results by system 1. Select Diagnose>Vulnerability and Patch Management>Scan>View Results by S

Page 62

Vulnerability scanning 55 4. Results for all scans performed on the selected system appear. Select the scan results to view, and click View.

Page 63

Vulnerability scanning 56 3. Select one or more vulnerabilities to include in the custom scan definition. 4. Enter a name and description for

Page 64

Vulnerability scanning 57 Deleting a customized vulnerability scan NOTE: Only custom vulnerability scans can be deleted. Default system scans

Page 65

Vulnerability scanning 58 2. Select the appropriate scan or scans, and click Delete. All results associated with the selected scan are deleted.

Page 66 - Viewing the patch repository

Vulnerability scanning 59 4. Select the scan results to delete, and click Delete.

Page 67

About this guide 6 About this guide This user guide provides step-by-step instructions for installing and using HP ProLiant Essentials Vulnerabi

Page 68

Deploying patches and fixes 60 Deploying patches and fixes This section provides an overview of using Vulnerability and Patch Management Pack to

Page 69

Deploying patches and fixes 61 To deploy patches, configuration fixes, or both to systems based on a specific vulnerability scan: 1. Select Dep

Page 70

Deploying patches and fixes 62 4. Select the systems on which to apply patches or fixes, and click Next. 5. Designate when the patched systems

Page 71

Deploying patches and fixes 63 8. View task results in the VPM Events list after the task completes. To view the list of target systems that r

Page 72 - Validating installed patches

Deploying patches and fixes 64 5. If any selected systems are unlicensed or licensed with a time-limited license, permanent licenses can be ap

Page 73

Deploying patches and fixes 65 8. Designate when the patched systems should be rebooted. Reboots can be performed immediately after the patche

Page 74

Deploying patches and fixes 66 a. Enter an appropriate name for the deployment task or accept the default name, and select Once. b. Designate

Page 75

Deploying patches and fixes 67 4. Verify that the correct target systems appear in the lists, click Add Targets or Remove Targets, if necessa

Page 76 - Removing patches

Deploying patches and fixes 68 7. If scheduling the reboot task: a. Enter an appropriate name for the reboot task or accept the default name,

Page 77 - Schedule

Deploying patches and fixes 69 Viewing patch installation status by search filter 1. Select Diagnose>Vulnerability and Patch Management>

Page 78

Introduction 7 Introduction Malicious software security threats are becoming more frequent, more sophisticated, and more costly to businesses, dr

Page 79 - Troubleshooting

Deploying patches and fixes 70 Viewing patch installation status by system 1. Select Diagnose>Vulnerability and Patch Management>View Pa

Page 80

Deploying patches and fixes 71 3. Verify that the correct target systems appear in the lists, click Add Targets or Remove Targets, if necessar

Page 81 - Required open ports

Deploying patches and fixes 72 Validating installed patches Patch validation identifies any missing patches on target systems and immediately r

Page 82 - Configuring a DNS server

Deploying patches and fixes 73 5. Enter an appropriate name for the validation task, or accept the default name. 6. To schedule the validatio

Page 83 - Multiple VPM servers

Deploying patches and fixes 74 NOTE: If the VPM Patch Agent deployment failed, be sure that the system is accessible by selecting Options>Pr

Page 84 - HTTP connection

Deploying patches and fixes 75 IMPORTANT: Any unlicensed systems not licensed at this time will not be included in the VPM Patch Agent deploym

Page 85

Deploying patches and fixes 76 9. View task results in the VPM Events list after the task completes. Removing patches Only patches that can be

Page 86

Deploying patches and fixes 77 3. Select the systems on which to remove the designated patches. 4. To remove the patches immediately, click R

Page 87 - Vulnerability scans

Deploying patches and fixes 78 5. If scheduling the patch removal task: a. Enter an appropriate name for the removal task or accept the default

Page 88 - Windows VPM server

Troubleshooting 79 Troubleshooting This section identifies and provides solutions for commonly encountered issues, as well as answers to frequent

Page 89 - Linux target systems

Introduction 8 the need to recreate these tasks in multiple tools for vulnerability assessment and patch management. • Comprehensive vulnerabili

Page 90 - Troubleshooting 90

Troubleshooting 80 Vulnerability and Patch Management Pack installation updates MDAC and MSDE If MSDE or files used by MSDE are not up-to-date, f

Page 91 - Troubleshooting 91

Troubleshooting 81 4. Click the Log On tab, and update with the new password. 5. Click the General tab, and click Stop>Start to restart the H

Page 92 - Check for missing patches

Troubleshooting 82 • UDP 1433, 1434—MSDE Shared Instance Support • TCP (variable)—MSDE TCP/IP communications. This port, assigned at random by

Page 93 - Troubleshooting 93

Troubleshooting 83 Be sure that the DNS suffix for this connection field has the correct DNS suffix and that both the Register this connection’s

Page 94 - HP SIM integration

Troubleshooting 84 For information about backing up and restoring the ISS Metabase, see http://www.microsoft.com/technet/prodtechnol/WindowsServe

Page 95

Troubleshooting 85 f. Clear the Require secure channel (SSL) option, and click OK>OK. Uninstalling Vulnerability and Patch Mana

Page 96

Troubleshooting 86 IMPORTANT: Vulnerability and Patch Management Pack licenses are not removed from target systems when Vulnerability and Patch

Page 97

Troubleshooting 87 Hiding the VPM column in the HP SIM console Vulnerability and Patch Management Pack uses the VPM column in the HP SIM console

Page 98 - Patch Management Pack

Troubleshooting 88 Windows • The account used to scan the target system is a member of the Administrator group or Domain Administrator group for

Page 99 - Scan events

Troubleshooting 89 Configure file permissions on all necessary DLLs. Configure Windows NT Registry permissions on the following: • HKEY_LOCAL_M

Page 100 - Patch and fix events

Introduction 9 Infrastructure A server environment using Vulnerability and Patch Management Pack consists of the following components: • Vulnera

Page 101 - Event Description Occurs

Troubleshooting 90 A scan was submitted but never started All target systems scanned by Vulnerability and Patch Management Pack must have an IP a

Page 102 - Acquisition events

Troubleshooting 91 To deploy the VPM Patch Agent to target systems, see the “Deploying the VPM Patch Agent” section. Be sure that the Red Hat li

Page 103 - Miscellaneous events

Troubleshooting 92 This message occurs because the Microsoft information pertaining to the patch location is incorrect and the patch cannot be do

Page 104

Troubleshooting 93 Other tools report that a Windows system is patched, but Vulnerability and Patch Management Pack reports patches needed Many o

Page 105

Troubleshooting 94 HP SIM integration Vulnerability and Patch Management Pack menus do not appear in the HP SIM console after installation The to

Page 106

Vulnerability and Patch Management Pack provided scan definitions 95 Vulnerability and Patch Management Pack provided scan definitions The follo

Page 107

Using the Change VPM Credentials Utility 96 Using the Change VPM Credentials Utility The Change VPM Credentials Utility can be used to update Vu

Page 108

Using the Change VPM Credentials Utility 97 4. If changing database credentials, enter your current database credentials, and click Change.

Page 109

Backing up and restoring Vulnerability and Patch Management Pack 98 Backing up and restoring Vulnerability and Patch Management Pack Introductio

Page 110

Vulnerability and Patch Management Pack events 99 Vulnerability and Patch Management Pack events Vulnerability and Patch Management Pack creates

Commentaires sur ces manuels

Pas de commentaire