ibm tivoli java collector: user's guidepublib.boulder.ibm.com/tividd/td/itjcol/sc32-1487... ·...

228
IBM Tivoli Java Collector User’s Guide Version 1.0 November 2003 SC32-1487-00

Upload: doantuyen

Post on 10-Jun-2018

222 views

Category:

Documents


0 download

TRANSCRIPT

  • IBM

    Tivoli

    Java

    Collector

    Users

    Guide

    Version

    1.0

    November

    2003

    SC32-1487-00

  • IBM

    Tivoli

    Java

    Collector

    Users

    Guide

    Version

    1.0

    November

    2003

    SC32-1487-00

  • Note

    Before

    using

    this

    information

    and

    the

    product

    it

    supports,

    read

    the

    information

    in

    Appendix

    C,

    Notices,

    on

    page

    203.

    Limited

    Edition

    (November

    2003)

    Copyright

    International

    Business

    Machines

    Corporation

    2003.

    All

    rights

    reserved.

    US

    Government

    Users

    Restricted

    Rights

    Use,

    duplication

    or

    disclosure

    restricted

    by

    GSA

    ADP

    Schedule

    Contract

    with

    IBM

    Corp.

  • Contents

    Preface

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . ix

    Who

    should

    read

    this

    book

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . ix

    What

    this

    book

    contains

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . ix

    Publications

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . x

    IBM

    Tivoli

    Java

    Collector

    library

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . x

    Related

    publications

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . x

    Accessing

    publications

    online

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xi

    Accessibility

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xi

    Contacting

    software

    support

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xi

    Conventions

    used

    in

    this

    book

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xi

    Typeface

    conventions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xi

    Operating

    system

    differences

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . xii

    Chapter

    1.

    IBM

    Tivoli

    Java

    Collector

    Overview

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 1

    Using

    Tivoli

    Java

    Collector

    to

    monitor

    security

    compliance

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 1

    Tivoli

    Java

    Collector

    architecture

    and

    specifications

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 2

    The

    JAC

    Server

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 3

    The

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 4

    Collectors

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 6

    The

    JAC

    Administration

    GUI

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 7

    Securing

    the

    Tivoli

    Java

    Collector

    environment

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 8

    Background

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 8

    Security

    enhancements

    overview

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 9

    Certificate

    descriptions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 10

    Authorizing

    a

    collector

    with

    certificates

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 12

    Chapter

    2.

    Using

    the

    JAC

    Administration

    GUI

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 15

    Reviewing

    the

    JAC

    Administration

    GUI

    panels

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 15

    Managing

    JAC

    Administration

    GUI

    sessions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 17

    Creating

    a

    new

    session

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 17

    Reconnecting

    the

    current

    session

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 17

    Closing

    a

    session

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 18

    Refreshing

    the

    JAC

    Administration

    GUI

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 18

    Performing

    basic

    user

    tasks

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 18

    Changing

    your

    password

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 18

    Viewing

    the

    message

    of

    the

    day

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 19

    Chapter

    3.

    Managing

    users

    and

    access

    permissions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 21

    Using

    the

    Users

    panel

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 21

    Managing

    user

    accounts

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 22

    Creating

    a

    new

    user

    account

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 22

    Removing

    a

    user

    account

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 24

    Changing

    the

    account

    password

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 24

    Managing

    general

    and

    group

    permissions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 25

    Best

    practices

    for

    managing

    permissions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 28

    Chapter

    4.

    Managing

    client

    machines

    and

    client

    groups

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 31

    Using

    the

    Clients

    panel

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 31

    Managing

    client

    machine

    registration

    and

    status

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 33

    Registering

    a

    client

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 33

    Displaying

    inactive

    client

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 34

    Changing

    the

    IP

    address

    of

    an

    existing

    client

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 35

    Unregistering

    a

    client

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 35

    Displaying

    unregistered

    client

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 36

    Copyright

    IBM

    Corp.

    2003

    iii

  • Managing

    client

    groups

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 37

    Managing

    collectors

    using

    groups

    and

    access

    permissions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 37

    Adding

    a

    client

    group

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 38

    Removing

    a

    client

    group

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 39

    Adding

    a

    client

    machine

    to

    a

    client

    group

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 39

    Removing

    a

    client

    machine

    from

    a

    client

    group

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 40

    Adding

    a

    group

    to

    a

    group

    (nested

    groups)

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 40

    Chapter

    5.

    Managing

    collectors

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 43

    Using

    the

    Collectors

    panel

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 43

    Default

    collector

    schedules

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 44

    Managing

    collectors

    on

    the

    JAC

    Server

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 44

    Best

    practices

    for

    managing

    collectors

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 45

    Authorizing

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 45

    Registering

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 47

    Unregistering

    (disabling)

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 48

    Updating

    Collectors

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 49

    Managing

    collectors

    on

    client

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 49

    Adding

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 49

    Managing

    collectors

    with

    client

    groups

    and

    inheritance

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 50

    Specifying

    custom

    collector

    parameters

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 51

    Removing

    (disabling)

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 52

    Configuring

    a

    collector

    schedule

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 53

    Manually

    run

    a

    collector

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 55

    Using

    Run

    Collector

    Now

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 55

    Using

    Immediate

    Collector

    Execute

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 56

    Collector

    naming

    conventions

    and

    reference

    information

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 56

    Chapter

    6.

    Extracting

    and

    displaying

    collected

    data

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 59

    Viewing

    collector

    data

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 59

    Editing

    collector

    data

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 60

    Viewing

    collector

    table

    attributes

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 61

    Viewing

    column

    names

    and

    attributes

    for

    a

    selected

    table

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 62

    Setting

    the

    Maximum

    Data

    Age

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 62

    Enabling

    delta

    monitoring

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 63

    Writing

    and

    testing

    SQL

    queries

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 63

    Using

    database

    schemas

    to

    define

    table

    types

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 65

    Query

    statement

    syntax

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 65

    Example

    query

    statements

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 65

    Using

    reports

    to

    extract

    and

    display

    data

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 66

    Adding

    a

    report

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 66

    Removing

    a

    report

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 67

    Configuring

    a

    report

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 67

    Managing

    reports

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 68

    Importing

    and

    exporting

    reports

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 68

    Chapter

    7.

    Managing

    policies

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 69

    Adding

    a

    new

    policy

    container

    object

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 70

    Adding

    compliance

    queries

    to

    a

    policy

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 70

    Example

    compliance

    queries

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 71

    Creating

    a

    policy

    snapshot

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 72

    Example

    policy

    hierarchical

    view

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 73

    Exporting

    a

    snapshot

    to

    an

    HTML

    file

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 73

    Removing

    a

    policy

    snapshot

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 74

    Responding

    to

    violations

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 75

    Identifying

    non-compliant

    client

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 75

    Recording

    intended

    actions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 75

    Using

    policy

    bundles

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 76

    Policy

    bundle

    overview

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 76

    Generating

    and

    saving

    the

    collector

    list

    for

    a

    policy

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 77

    iv

    IBM

    Tivoli

    Java

    Collector:

    Users

    Guide

  • Exporting

    a

    policy

    bundle

    file

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 79

    Authorizing

    the

    collectors

    in

    a

    policy

    bundle

    file

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 79

    Importing

    a

    policy

    bundle

    file

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 80

    Adding

    a

    policy

    bundle

    to

    a

    client

    or

    client

    group

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 81

    Removing

    a

    policy

    bundle

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 81

    Chapter

    8.

    Managing

    the

    JAC

    Server

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 83

    Starting

    and

    stopping

    the

    JAC

    Server

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 83

    Syntax

    for

    the

    jacserver

    utility

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 84

    Using

    the

    jacserver

    utility

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 84

    Server

    tasks

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 85

    Using

    Server

    Console

    to

    view

    server

    activity

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 85

    Editing

    the

    Message

    of

    the

    Day

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 85

    Server

    information

    views

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 86

    Viewing

    server

    status

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 86

    Viewing

    message

    threads

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 86

    Viewing

    message

    exceptions

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 87

    Viewing

    client

    code

    information

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 87

    Monitoring

    memory

    activity

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 88

    Chapter

    9.

    Managing

    the

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 89

    Starting

    and

    stopping

    the

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 89

    Syntax

    for

    the

    jacclient

    utility

    (UNIX

    only)

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 89

    Using

    the

    jacclient

    utility

    (UNIX

    only)

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 90

    Controlling

    the

    JAC

    Client

    on

    Windows

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 90

    Updating

    the

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 91

    Viewing

    client

    code

    information

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 91

    Updating

    the

    client

    software

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 91

    Managing

    the

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 92

    Pinging

    a

    client

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 92

    Using

    a

    hard

    reset

    to

    restart

    the

    JAC

    Client

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 92

    Using

    soft

    reset

    to

    initiate

    a

    manual

    heartbeat

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 93

    Searching

    for

    client

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 94

    Pushing

    a

    file

    to

    a

    client

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 94

    Chapter

    10.

    Setting

    up

    a

    server-to-client

    proxy

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 95

    Proxy

    functionality

    overview

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 95

    Securing

    the

    JAC

    proxy

    machine

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 96

    Access

    Control

    List

    definition

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 96

    Access

    Control

    List

    format

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 96

    Example

    deployment

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 97

    Applying

    ACLs

    to

    JAC

    proxy

    machines

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 98

    Creating

    a

    proxy

    router

    definition

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 98

    Background

    and

    example

    scenario

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 98

    Router

    configuration

    procedure

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 99

    Example

    proxy

    scenario

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 100

    1.

    Configuration

    for

    Network

    B

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 101

    2.

    Configuration

    on

    Network

    C

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 102

    3.

    Configuration

    on

    Network

    D

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 103

    Proxy

    collector

    information

    output

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 104

    Appendix

    A.

    Security

    collectors

    reference

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 105

    aix.any.i4ls.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 108

    aix.any.network_opts.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 109

    aix.any.rhosts_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 110

    aix.any.sec_passwd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 111

    aix.any.sec_user.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 112

    aix.any.tftp_control.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 114

    aix.any.xdm-config.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 115

    aix.any.xserver_acl.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 116

    Contents

    v

  • any.any.jre_info.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 117

    any.any.nntp_auth.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 118

    hpux.any.umask.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 119

    linux.any.faillog.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 120

    linux.any.login_defs.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 121

    linux.any.pam.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 122

    linux.any.securetty.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 123

    linux.any.sysctl.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 124

    linux.any.sysctl_conf.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 125

    linux.any.syslog_conf.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 126

    linux.any.xinetd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 127

    linux.any.xinetd_conf.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 128

    solaris.any.default_login.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 130

    solaris.any.eeprom.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 131

    solaris.any.etc_default.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 132

    solaris.any.etc_system.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 133

    solaris.any.ndd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 134

    unix.any.anon_ftp_passwd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 136

    unix.any.anon_ftp_sys_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 137

    unix.any.anon_ftp_user_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 138

    unix.any.bsh_queue.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 139

    unix.any.crontab.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 140

    unix.any.crontab_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 141

    unix.any.exports.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 142

    unix.any.file_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 143

    unix.any.file_search.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 144

    unix.any.ftpusers.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 146

    unix.any.group_members.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 147

    unix.any.groups.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 148

    unix.any.home_fs.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 149

    unix.any.home_fs_profiles.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 150

    unix.any.hosts_allow.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 151

    unix.any.hosts_deny.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 152

    unix.any.hosts_equiv.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 153

    unix.any.inittab.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 154

    unix.any.login_prompt.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 155

    unix.any.logs_exist.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 156

    unix.any.motd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 157

    unix.any.netstat.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 158

    unix.any.nis_maps.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 159

    unix.any.passwd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 160

    unix.any.processes.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 161

    unix.any.rc_files.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 162

    unix.any.resolv_conf.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 163

    unix.any.services.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 164

    unix.any.shells.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 165

    unix.any.snmpd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 166

    unix.any.syslog_conf.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 167

    unix.multi.inetd.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 168

    unix.multi.login_defs.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 169

    unix.multi.shadow.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 170

    win.any.AnonFtpIIS.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 171

    win.any.audit_policy.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 172

    win.any.BusUseNotice.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 174

    win.any.File_Perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 175

    win.any.generic_registry_key.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 176

    win.any.global_group.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 178

    win.any.HKCR_permission.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 179

    win.any.hotfix.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 180

    win.any.local_group.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 181

    win.any.log_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 182

    vi

    IBM

    Tivoli

    Java

    Collector:

    Users

    Guide

  • win.any.log_size.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 183

    win.any.nav.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 184

    win.any.net_accounts.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 185

    win.any.os_info.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 186

    win.any.partition.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 187

    win.any.reg_perms.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 188

    win.any.services.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 190

    win.any.SnmpActive.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 191

    win.any.user.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 192

    win.any.user_rights.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 193

    win.nt.pw_complexity.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 195

    win.win2k.protocols.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 196

    Appendix

    B.

    General

    collectors

    reference

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 197

    any.any.cleanup_collectors.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 198

    any.any.client_files.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 199

    any.any.client_pref.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 200

    com.ibm.jac.server.JACProxy.jar

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 201

    Appendix

    C.

    Notices

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 203

    Trademarks

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 204

    Index

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    .

    . 207

    Contents

    vii

  • viii

    IBM

    Tivoli

    Java

    Collector:

    Users

    Guide

  • Preface

    The

    IBM

    Tivoli

    Java

    Collector

    Users

    Guide

    explains

    how

    to

    administer

    the

    Tivoli

    Java

    Collector

    service

    using

    the

    JAC

    Administration

    GUI.

    IBM

    Tivoli

    Java

    Collector

    (JAC)

    is

    a

    data

    collection

    service

    that

    gathers

    and

    stores

    a

    wide

    variety

    of

    information

    from

    multiple

    participating

    systems.

    Information

    types

    can

    include

    any

    data

    residing

    on

    a

    system,

    such

    as

    operating

    system

    versions,

    software

    patch

    levels,

    and

    security-related

    data.

    System

    and

    security

    administrators

    can

    use

    the

    Tivoli

    Java

    Collector

    service

    to

    monitor

    specific

    data

    checkpoints

    on

    any

    given

    machine

    (or

    group

    of

    machines).

    Who

    should

    read

    this

    book

    The

    target

    audience

    for

    this

    users

    guide

    includes:

    v

    System

    administrators

    v

    Application

    specialists

    v

    Security

    analysts

    v

    IT

    planners

    v

    Auditors

    What

    this

    book

    contains

    This

    document

    contains

    the

    following

    chapters:

    v

    Chapter

    1,

    IBM

    Tivoli

    Java

    Collector

    Overview,

    on

    page

    1

    This

    chapter

    provides

    a

    conceptual

    and

    functional

    overview

    of

    the

    Tivoli

    Java

    Collector

    product.

    v

    Chapter

    2,

    Using

    the

    JAC

    Administration

    GUI,

    on

    page

    15

    This

    chapter

    provides

    an

    overview

    of

    the

    components

    and

    functionality

    of

    the

    JAC

    Administration

    GUI.

    v

    Chapter

    3,

    Managing

    users

    and

    access

    permissions,

    on

    page

    21

    This

    chapter

    provides

    information

    and

    procedures

    for

    managing

    user

    accounts

    and

    applying

    permissions

    that

    permit

    or

    deny

    access

    to

    administration

    operations.

    v

    Chapter

    4,

    Managing

    client

    machines

    and

    client

    groups,

    on

    page

    31

    This

    chapter

    provides

    information

    and

    procedures

    for

    managing

    client

    machines

    participating

    in

    a

    Tivoli

    Java

    Collector

    environment.

    v

    Chapter

    5,

    Managing

    collectors,

    on

    page

    43

    This

    chapter

    provides

    information

    and

    procedures

    for

    managing

    information-gathering

    collectors.

    v

    Chapter

    6,

    Extracting

    and

    displaying

    collected

    data,

    on

    page

    59

    This

    chapter

    provides

    information

    and

    procedures

    for

    extracting

    collected

    data

    and

    displaying

    this

    data

    in

    a

    meaningful

    form.

    v

    Chapter

    7,

    Managing

    policies,

    on

    page

    69

    This

    chapter

    provides

    information

    and

    procedures

    for

    extracting

    collected

    security-related

    data

    and

    displaying

    this

    data

    in

    a

    meaningful

    form.

    v

    Chapter

    8,

    Managing

    the

    JAC

    Server,

    on

    page

    83

    Copyright

    IBM

    Corp.

    2003

    ix

  • This

    chapter

    provides

    information

    and

    procedures

    for

    managing

    the

    operation

    of

    the

    JAC

    Server.

    v

    Chapter

    9,

    Managing

    the

    JAC

    Client,

    on

    page

    89

    This

    chapter

    provides

    information

    and

    procedures

    for

    managing

    the

    operation

    of

    the

    JAC

    Client.

    v

    Chapter

    10,

    Setting

    up

    a

    server-to-client

    proxy,

    on

    page

    95

    This

    chapter

    provides

    information

    and

    procedures

    for

    setting

    up

    a

    proxy

    communication

    route

    between

    the

    JAC

    Server

    and

    client

    machines

    across

    one

    or

    more

    networks.

    v

    Appendix

    A,

    Security

    collectors

    reference,

    on

    page

    105

    This

    appendix

    provides

    a

    complete

    reference

    for

    collectors

    and

    tables

    used

    for

    security

    compliance

    checking.

    v

    Appendix

    B,

    General

    collectors

    reference,

    on

    page

    197

    This

    appendix

    provides

    a

    complete

    reference

    for

    collectors

    and

    tables

    used

    for

    general

    maintenance

    of

    the

    Tivoli

    Java

    Collector

    service.

    Publications

    Read

    the

    descriptions

    of

    the

    IBM

    Tivoli

    Java

    Collector

    library,

    the

    prerequisite

    publications,

    and

    the

    related

    publications

    to

    determine

    which

    publications

    you

    might

    find

    helpful.

    After

    you

    determine

    the

    publications

    you

    need,

    refer

    to

    the

    instructions

    for

    accessing

    publications

    online.

    IBM

    Tivoli

    Java

    Collector

    library

    The

    publications

    in

    the

    IBM

    Tivoli

    Java

    Collector

    library

    are:

    v

    IBM

    Tivoli

    Java

    Collector

    Installation

    Guide

    (SC32-1488-00)

    Explains

    how

    to

    install

    and

    configure

    Tivoli

    Java

    Collector

    software.

    v

    IBM

    Tivoli

    Java

    Collector

    Users

    Guide

    (SC32-1487-00)

    Explains

    how

    to

    manage

    and

    configure

    Tivoli

    Java

    Collector

    services

    using

    the

    JAC

    Administration

    GUI.

    v

    IBM

    Tivoli

    Java

    Collector

    Release

    Notes

    (GI11-4163-00)

    Provides

    late-breaking

    information,

    such

    as

    software

    limitations,

    workarounds,

    and

    documentation

    updates.

    Related

    publications

    This

    section

    lists

    publications

    related

    to

    the

    Tivoli

    Java

    Collector

    library.

    The

    Tivoli

    Software

    Library

    provides

    a

    variety

    of

    Tivoli

    publications

    such

    as

    white

    papers,

    datasheets,

    demonstrations,

    redbooks,

    and

    announcement

    letters.

    The

    Tivoli

    Software

    Library

    is

    available

    on

    the

    Web

    at:

    http://www.ibm.com/software/tivoli/library/

    The

    Tivoli

    Software

    Glossary

    includes

    definitions

    for

    many

    of

    the

    technical

    terms

    related

    to

    Tivoli

    software.

    The

    Tivoli

    Software

    Glossary

    is

    available,

    in

    English

    only,

    from

    the

    Glossary

    link

    on

    the

    left

    side

    of

    the

    Tivoli

    Software

    Library

    Web

    page

    http://www.ibm.com/software/tivoli/library/

    IBM

    DB2

    Universal

    Database

    IBM

    DB2

    Universal

    Database

    is

    required

    when

    using

    Tivoli

    Java

    Collector.

    Additional

    information

    about

    DB2

    can

    be

    found

    at:

    http://www.ibm.com/software/data/db2/

    x

    IBM

    Tivoli

    Java

    Collector:

    Users

    Guide

    http://www.ibm.com/software/tivoli/library/http://www.ibm.com/software/tivoli/library/http://www.ibm.com/software/data/db2/

  • Accessing

    publications

    online

    The

    publications

    for

    this

    product

    are

    available

    online

    in

    Portable

    Document

    Format

    (PDF)

    or

    Hypertext

    Markup

    Language

    (HTML)

    format,

    or

    both

    in

    the

    Tivoli

    software

    library:

    http://www.ibm.com/software/tivoli/library

    To

    locate

    product

    publications

    in

    the

    library,

    click

    the

    Product

    manuals

    link

    on

    the

    left

    side

    of

    the

    library

    page.

    Then,

    locate

    and

    click

    the

    name

    of

    the

    product

    on

    the

    Tivoli

    software

    information

    center

    page.

    Product

    publications

    include

    release

    notes,

    installation

    guides,

    users

    guides,

    administrators

    guides,

    and

    developers

    references.

    Note:

    To

    ensure

    proper

    printing

    of

    PDF

    publications,

    select

    the

    Fit

    to

    page

    check

    box

    in

    the

    Adobe

    Acrobat

    Print

    window

    (which

    is

    available

    when

    you

    click

    File

    Print).

    Accessibility

    Accessibility

    features

    help

    a

    user

    who

    has

    a

    physical

    disability,

    such

    as

    restricted

    mobility

    or

    limited

    vision,

    to

    use

    software

    products

    successfully.

    With

    this

    product,

    you

    can

    use

    assistive

    technologies

    to

    hear

    and

    navigate

    the

    interface.

    You

    also

    can

    use

    the

    keyboard

    instead

    of

    the

    mouse

    to

    operate

    all

    features

    of

    the

    graphical

    user

    interface.

    Contacting

    software

    support

    Before

    contacting

    IBM

    Tivoli

    Software

    Support

    with

    a

    problem,

    refer

    to

    the

    IBM

    Tivoli

    Software

    Support

    site

    by

    clicking

    the

    Tivoli

    support

    link

    at

    the

    following

    Web

    site:

    http://www.ibm.com/software/support/

    If

    you

    need

    additional

    help,

    contact

    software

    support

    by

    using

    the

    methods

    described

    in

    the

    IBM

    Software

    Support

    Guide

    at

    the

    following

    Web

    site:

    http://techsupport.services.ibm.com/guides/handbook.html

    The

    guide

    provides

    the

    following

    information:

    v

    Registration

    and

    eligibility

    requirements

    for

    receiving

    support

    v

    Telephone

    numbers,

    depending

    on

    the

    country

    in

    which

    you

    are

    located

    v

    A

    list

    of

    information

    you

    should

    gather

    before

    contacting

    customer

    support

    Conventions

    used

    in

    this

    book

    This

    reference

    uses

    several

    conventions

    for

    special

    terms

    and

    actions

    and

    for

    operating

    system-dependent

    commands

    and

    paths.

    Typeface

    conventions

    The

    following

    typeface

    conventions

    are

    used

    in

    this

    reference:

    Bold

    Lowercase

    commands

    or

    mixed

    case

    commands

    that

    are

    difficult

    to

    distinguish

    from

    surrounding

    text,

    keywords,

    parameters,

    options,

    names

    of

    Java

    classes,

    and

    objects

    are

    in

    bold.

    Italic

    Variables,

    titles

    of

    publications,

    and

    special

    words

    or

    phrases

    that

    are

    emphasized

    are

    in

    italic.

    Monospace

    Code

    examples,

    command

    lines,

    screen

    output,

    file

    and

    directory

    Preface

    xi

    http://www.ibm.com/software/tivoli/library/http://www.ibm.com/software/support/http://techsupport.services.ibm.com/guides/handbook.html

  • names

    that

    are

    difficult

    to

    distinguish

    from

    surrounding

    text,

    system

    messages,

    text

    that

    the

    user

    must

    type,

    and

    values

    for

    arguments

    or

    command

    options

    are

    in

    monospace.

    Operating

    system

    differences

    This

    book

    uses

    the

    UNIX

    convention

    for

    specifying

    environment

    variables

    and

    for

    directory

    notation.

    When

    using

    the

    Windows

    command

    line,

    replace

    $variable

    with

    %variable%

    for

    environment

    variables

    and

    replace

    each

    forward

    slash

    (/)

    with

    a

    backslash

    (\)

    in

    directory

    paths.

    If

    you

    are

    using

    the

    bash

    shell

    on

    a

    Windows

    system,

    you

    can

    use

    the

    UNIX

    conventions.

    xii

    IBM

    Tivoli

    Java

    Collector:

    Users

    Guide

  • Chapter

    1.

    IBM

    Tivoli

    Java

    Collector

    Overview

    IBM

    Tivoli

    Java

    Collector

    (JAC)

    is

    a

    security

    compliance

    and

    assurance

    product

    that

    can

    regularly

    monitor

    computer

    systems

    to

    detect

    security

    vulnerabilities.

    Tivoli

    Java

    Collector

    allows

    an

    organization

    to

    implement

    and

    manage

    consistent

    security

    policies

    across

    its

    network

    of

    computers

    and

    to

    ensure

    compliance

    with

    these

    policies.

    Security

    policies

    can

    include

    company-internal

    policies

    and

    policies

    set

    by

    industry-standard

    security

    and

    privacy

    regulations.

    Fundamentally,

    IBM

    Tivoli

    Java

    Collector

    is

    a

    data

    collection

    service

    that

    can

    gather

    and

    store

    a

    wide

    variety

    of

    information

    from

    multiple

    participating

    computer

    systems.

    Information

    types

    can

    include

    any

    data

    residing

    on

    a

    system,

    such

    as

    operating

    system

    versions,

    software

    patch

    levels,

    and

    security-related

    data.

    System

    administrators

    and

    security

    analysts

    can

    use

    the

    Tivoli

    Java

    Collector

    service

    to

    monitor

    specific

    data

    checkpoints

    on

    any

    given

    machine

    (or

    group

    of

    machines).

    Stored

    information

    can

    then

    be

    extracted

    by

    specially

    written

    data

    queries

    and

    assembled

    into

    reports

    ready

    for

    immediate

    analysis.

    This

    limited

    internal

    implementation

    of

    Tivoli

    Java

    Collector

    is

    used

    as

    a

    vulnerability

    detection

    service

    that

    collects

    security-related

    data

    and

    produces

    reports

    that

    can

    reveal

    adherence

    to

    or

    violation

    of

    internal

    and

    industry-standard

    security

    policies.

    Topic

    list:

    v

    Using

    Tivoli

    Java

    Collector

    to

    monitor

    security

    compliance

    on

    page

    1

    v

    Tivoli

    Java

    Collector

    architecture

    and

    specifications

    on

    page

    2

    v

    Securing

    the

    Tivoli

    Java

    Collector

    environment

    on

    page

    8

    Using

    Tivoli

    Java

    Collector

    to

    monitor

    security

    compliance

    Tivoli

    Java

    Collector

    is

    used

    to

    manage

    and

    monitor

    computer

    systems

    for

    compliance

    with

    defined

    security

    policies.

    Security

    policies

    can

    be

    based

    on

    both

    company-specific

    requirements

    and

    industry-standard

    regulations.

    Important

    recent

    examples

    of

    industry-standard

    privacy

    and

    security

    regulations

    include:

    v

    Health

    Insurance

    Portability

    and

    Accountability

    Act

    (HIPAA),

    1996

    v

    Gramm-Leach-Bliley

    Act

    (GLBA),

    1999,

    also

    known

    as

    Financial

    Services

    Modernization

    Act

    v

    Information

    Safeguards

    Regulation

    issued

    by

    the

    Federal

    Trade

    Commission,

    2002

    These

    regulations

    require

    implementation

    of

    effective

    administrative,

    technical,

    and

    physical

    security

    measures

    to

    protect

    customer

    records

    and

    information.

    The

    monitoring

    service

    provided

    by

    Tivoli

    Java

    Collector

    allows

    businesses

    to

    shift

    from

    a

    reactive

    mode

    to

    a

    proactive

    process

    by

    providing

    vulnerability

    assessments

    that

    identify

    problems

    with

    compliance

    before

    a

    potential

    incident

    (such

    as

    a

    security

    breach)

    can

    occur.

    For

    example,

    if

    a

    firewall

    policy

    has