cimtrak™ integrity & compliance suite 3 · installation guidance. ... enterprise worksheet...

60
CimTrak™ Integrity & Compliance Suite 3.2 Master Repository App Server File System Agent Network Device Agent Installation Guidance

Upload: trinhtruc

Post on 04-May-2018

217 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CimTrak™ Integrity & Compliance Suite 3.2

Master RepositoryApp ServerFile System AgentNetwork Device Agent

Installation Guidance

Page 2: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

2 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 3: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

LEGAL NOTICES

The software described in this document is furnished under a license agreement and may beused only in accordance with the terms of the agreement.

COPYRIGHT NOTICE

Copyright 2001-2018 CIMCOR, Inc. All Rights Reserved. This document may not, in whole or inpart, be copied, photocopied, reproduced, translated, or reduced to any electronic medium ormachine-readable form without prior consent in writing from CIMCOR Inc., 8252 Virginia StreetSuite C, Merrillville, IN 46410.

ALL EXAMPLES WITH NAMES, COMPANY NAMES, OR COMPANIES THAT APPEAR IN THISDOCUMENT ARE IMAGINARY AND DO NOT REFER TO, OR PORTRAY ANY ACTUALNAMES, COMPANIES, ENTITIES, OR INSTITUTIONS. ANY RESEMBLANCE TO ANY REALPERSON, COMPANY, ENTITY, OR INSTITUTION IS PURELY COINCIDENTAL.

Every effort has been made to ensure the accuracy of this document. However, CIMCOR Inc.makes no warranties with respect to this documentation and disclaims any implied warranties ofmerchantability and fitness for a particular purpose. CIMCOR Inc. shall not be liable for anyerrors or for incidental or consequential damages in connection with the furnishing, performance,or use of this document or the examples herein. The information in this document is subject tochange without notice.

TRADEMARKS

CimTrak™ is a trademark of CIMCOR Inc.

Microsoft, MS, Windows® operating systems are trademarks of Microsoft Corporation in theUnited States and/or other countries.

Macintosh and Mac OSX are registered trademarks of Apple Inc. in the USA and other countries.

Netscape is a registered trademark and Netscape Communicator is a trademark of Netscape Communications Corporation.

Installbuilder is a registered trademark of BitRock Inc.

Linux is a registered trademark of Linus Torvalds.

Solaris is a registered trademark of Sun Microsystems.

All other products mentioned are trademarks and/or registered trademarks of their respectiveowners.

User Guidance 3

Page 4: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

TABLE OF CONTENTS

Introduction..........................................................................................................................5

System Requirements...........................................................................................................8

CimTrak™ Master Repository Installation.......................................................................14

CimTrak™ File System Agent Installation.......................................................................29

CimTrak™ Network Device Agent Installation................................................................35

CimTrak™ App Server......................................................................................................43

Appendix A – Documentation History..............................................................................50

Appendix B – Technical Support Information...................................................................51

Appendix C – Available Encryption Types.......................................................................52

Appendix D – Key Exchange and Encryption Ciphers.....................................................54

Appendix E – Enterprise Worksheet..................................................................................55

Appendix F – FIPS Worksheet..........................................................................................57

Appendix G – Linux Dependencies...................................................................................59

4 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 5: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

INTRODUCTION

1.1. CIMCOR CIMTRAK™ INTEGRITY & COMPLIANCE SUITE INTRODUCTION

The CIMCOR CimTrak™ Integrity & Compliance Suite application provides a flexiblefile-based security solution that allows Administrators the capability to protectselected files, operating system components, and network device configurationsagainst unauthorized changes from a centralized location within the network.CimTrak™ immediately identifies the change, determines if it is authorized and theninstitutes corrective action based on the application configuration. Since CimTrak™maintains a master set of protected files, unauthorized changes can immediately bereversed to mitigate malicious activity or human error.

The CimTrak™ Integrity Suite presents a multifaceted approach to protecting keyinformation system resources and provides comprehensive change control tracking.The application consists of three required components:

CimTrak™ File System Agent – 1.3

Additionally, the CimTrak™ Integrity Suite has a combination of multiple (optional)components including:

CimTrak™ Network Device Agent - 1.4 CimTrak™ App Server (required for the Web Management Console) – 1.5

These required and optional components will be discussed in subsequent sectionsof the documentation.

Note: Additional CimTrak™ optional components may exist based on yourregion. Please contact an authorized CimTrak™ sales representative fordetails.

1.2. CIMTRAK™ MASTER REPOSITORY

The CimTrak™ Master Repository component maintains a centralized store ofprotected files and change history within a centralized server. This store provides anisolated, compressed, and encrypted copy of critical files that allows for restorationin the event of unauthorized change and provides a basis for identifying changesmade to protected files and configurations within the network. Additionally, theapplication supports a rollback capability which allows previous versions of aprotected file or configuration to be restored at a later date. For more information oninstalling the CimTrak™ Master Repository, please refer to section .

User Guidance 5

Page 6: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

1.3. CIMTRAK™ FILE SYSTEM AGENT

The CimTrak™ File System Agent is installed on protected resources within theOperational Environment. The File System Agent provides real-time or poll basedmonitoring of protected files and configurations and identifies changes made toprotected files. When a change is detected, the File System Agent communicateswith the CimTrak™ Master Repository to report change status and (whenconfigured) transfer the master file (Authoritative Copy) from the Master Repositoryto the File System Agent server to overwrite unauthorized changes. The FileSystem Agent utilizes CimTrak™ configuration data to determine if the change isallowed based on Administrator policy settings for the subject file or configuration.The File System Agent can then institute one of the following actions on the change:Allow the change and log the event, update the master file baseline stored within theMaster Repository, disallow the change and immediately overwrite the change withthe master file copy from the Master Repository, or Prompt the authorized user toeither allow or disallow the file change attempt. Additionally, the CimTrak™ FileSystem Agent can be configured to allow a combination of remediation settings. Formore information on installing the CimTrak™ File System Agent, please refer tosection .

In addition to file change detection and remediation, the File System Agent providesconfiguration monitoring remediation.1 Windows™ file system configurationmonitoring includes:

Read Access monitoring Monitoring and remediation of the Windows™ Registry Monitoring of Windows™ Local User accounts Monitoring of Windows™ Local Groups Monitoring of Windows™ Local Security Policy settings Monitoring of Windows™ Local Services Monitoring of Windows™ Local Device Drivers Monitoring of Windows™ Local Installed Software Monitoring of Windows™ Network Share Settings

1.4. CIMTRAK™ NETWORK DEVICE AGENT

The CimTrak™ Network Device Agent component is installed on device monitoringresources within the Operational Environment. The CimTrak™ Network DeviceAgent provides real-time (SNMPv3) or poll based (SSHv1, SSHv2, Telnet)monitoring of protected files and identifies changes made to protected files. When achange is detected, the CimTrak™ File System Agent communicates with theCimTrak™ Master Repository to report change status and/or transfer the master file(authoritative copy) from the Master Repository to the Agent Network Host server tooverwrite unauthorized changes. The CimTrak™ Network Device Agent utilizes

1 Monitoring of the Windows® registry allows for remediation when changes are detected. All other configuration monitoring features only provide monitoring capabilities.

6 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 7: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CimTrak™ configuration data to determine if the change is allowed based onAdministrator policy settings for the subject file. The Agent can then institute one ofthe following actions on the change: Allow the change and log the event, Update themaster file baseline stored within the Master Repository, Disallow the change andimmediately overwrite the change with the master file copy from the MasterRepository, or Prompt the authorized user to either allow or disallow the file changeattempt. For more information on installing the CimTrak™ Network Device Agent,please refer to section .

1.5. CIMTRAK™ APP SERVER

The CimTrak™ App Server is a host for web-based applications which allowAdministrators the capability to manage and configure the application from aseparate Administrator management workstation from virtually anywhere. Asvarious management applications are developed, these applications will be madeavailable through the App Server for use at any workstation. Of the applications forthe App Server, the Web Management Console acts as a web-based version of theclassical Management Console which supports all of the features of the classicalManagement Console. The Web Management Console supports the selection offiles and configurations on attached components to “lock” and configure an action totake in the event a change is detected. The Web Management Console providesaccess to a series of reports that detail changes made based on a series of savedbaselines stored in the Master Repository. This capability can be used tosuperimpose changes over the stored baselines to immediately identify whataspects of the “locked” file were changed. For more information of how to use theWeb Management Console, please review the Web Management Console UserGuide. For more information on installing the CimTrak™ App Server, please refer tosection .

User Guidance 7

Page 8: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

SYSTEM REQUIREMENTS

1.6. CIMTRAK™ MASTER REPOSITORY SYSTEM REQUIREMENTS

The following categories indicate the System Requirements necessary for the properconfiguration and operation of the CimTrak™ Master Repository component.

1.6.1. OPERATING SYSTEM REQUIREMENTS

Microsoft™ Windows XP SP2 or SP3 Microsoft™ Windows Server 2003 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2003 R2 Release, SP1, or SP2 Microsoft™ Windows Vista Release, SP1, or SP2 Microsoft™ Windows Server 2008 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2008 R2 Release, SP1, or SP2 Microsoft™ Windows 7 Release, SP1 Microsoft™ Windows 8.x Microsoft™ Windows 10 Microsoft™ Windows Server 2012 Microsoft™ Windows Server 2016 Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions)

1.6.2. SYSTEM REQUIREMENTS

Personal computer or server with Pentium-compatible processor Pentium 3 1.2 GHz or greater 512 MB RAM available 220 MB hard disk space 10/100/1000 Mbps Network Interface

1.6.3. MICROSOFT™ WINDOWS INSTALLATION PRE-REQUISITES

None

1.6.4. LINUX INSTALLATION COMPONENT PRE-REQUISITES

Redhat, CentOS, and Fedora: x32 System: sudo yum install readline libstdc++ glibc openldap which libXrender

fontconfig freetype libXext libX11 Redhat, CentOS, and Fedora: x64 System:

sudo yum install readline.i686 libstdc++.i686 glibc.i686 openldap.i686 which libXrender.i686 fontconfig.i686 freetype.i686 libXext.i686 libX11.i686

8 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 9: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Ubuntu 14.04 x32 and below System: sudo apt-get install whois binutils libncurses5 libbz2-1.0 libreadline6 slapd

ldap-utils libxrender1 libfontconfig1 libxext6 libxrender1 libfontconfig1 libxext6

Ubuntu 14.04 x64 and below System: sudo apt-get install whois binutils lib32ncurses5 lib32bz2-1.0

lib32readline6 slapd ldap-utils:i386 libxrender1:i386 libfontconfig1:i386 libxext6:i386 lib32stdc++6 libxrender1:i386 libfontconfig1:i386 libxext6:i386

Ubuntu 15.04 x32 and above System: sudo apt-get install whois binutils libncurses5 zlib1g libreadline6 slapd

ldap-utils libxrender1 libfontconfig1 libxext6 libstdc++6 libxrender1 libfontconfig1 libxext6

Ubuntu 15.04 x64 and above System: sudo apt-get install whois binutils lib32ncurses5 lib32z1 lib32readline6

slapd ldap-utils:i386 libxrender1:i386 libfontconfig1:i386 libxext6:i386 lib32stdc++6 libxrender1:i386 libfontconfig1:i386 libxext6:i386

1.6.5. CIMTRAK™ INSTALLED COMPONENT PRE-REQUISITES

None

1.7. CIMTRAK™ FILE SYSTEM AGENT SYSTEM REQUIREMENTS

The following categories indicate the System Requirements necessary for the properconfiguration and operation of the CimTrak™ File System Agent component.

1.7.1. OPERATING SYSTEM REQUIREMENTS

Microsoft™ Windows XP SP3 Microsoft™ Windows Server 2003 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2003 R2 Release, SP1, or SP2 Microsoft™ Windows Vista Release, SP1, or SP2 Microsoft™ Windows Server 2008 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2008 R2 Release, SP1, or SP2 Microsoft™ Windows 7 Release, SP1 Microsoft™ Windows 8.x Microsoft™ Windows 10 Microsoft™ Windows Server 2012 Microsoft™ Windows Server 2016 Sun SPARC/x86 Solaris 10 Update 8 and above ** Poll-Based Monitoring only OpenSolaris 2008.05 and above ** Poll-Based Monitoring only Linux Kernel 2.4.21 to 2.6.31 ** Poll-Based Monitoring only Linux Kernel 2.6.32 and above AIX 6.1 and above ** Poll-Based Monitoring only

User Guidance 9

Page 10: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

HP-UX Itanium 11i V2 (11.23) and above ** Poll-Based Monitoring only HP-UX PA-RISC 11i V2 (11.23) and above ** Poll-Based Monitoring only Mac Intel OS 10.4.4 and above ** Poll-Based Monitoring only

1.7.2. SYSTEM REQUIREMENTS

Personal computer or server with Pentium-compatible processor Pentium 3 1.2 GHz or greater 512 MB RAM available 200 MB hard disk space

1.7.3. MICROSOFT™ WINDOWS INSTALLATION PRE-REQUISITES

None

1.7.4. LINUX INSTALLATION PRE-REQUISITES

Redhat, CentOS, and Fedora: x32 System w x32 Agent: sudo yum install bc glibc libstdc++ audit-libs

Redhat, CentOS, and Fedora: x64 System w x32 Agent: sudo yum install bc glibc.i686 libstdc++.i686 audit-libs.i686

Redhat, CentOS, and Fedora: x64 System w x64 Agent: sudo yum install bc readline glibc libstdc++ audit-libs

Ubuntu 14.04 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libstdc++6:i386 whois bc binutils

libreadline6 libncurses5 libauparse0 Ubuntu 14.04 x64 System - w x32 AGENT:

sudo apt-get install auditd libaudit1:i386 libauparse0:i386 libstdc++6 whoisbc binutils lib32z1 lib32ncurses5 lib32readline6 52:i386

Ubuntu 14.04 x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libstdc++6 libicu52 whois bc binutils

libreadline6 zlib1g libncurses5 libauparse0 Ubuntu 15.04 x32 System - w x32 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g libncurses5 libreadline6 libicu52

Ubuntu 15.04 x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutils

lib32z1 lib32ncurses5 lib32readline6 libicu52:i386 Ubuntu 15.04 x64 System - w x64 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1 lib32ncurses5 libreadline6 libicu52

Ubuntu 16.04 Before Update 2 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g

libncurses5 libreadline6 libicu52 Ubuntu 16.04 Before Update 2 x64 System - w x32 AGENT:

10 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 11: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutilslib32z1 lib32ncurses5 lib32readline6 libicu52:i386

Ubuntu 16.04 Before Update 2 x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1

lib32ncurses5 libreadline6 libicu52 Ubuntu 16.04 After Update 2 x32 System - w x32 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g libncurses5 libreadline6 libicu55

Ubuntu 16.04 After Update 2 x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutils

lib32z1 lib32ncurses5 lib32readline6 libicu55:i386 Ubuntu 16.04 After Update 2 x64 System - w x64 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1 lib32ncurses5 libreadline6 libicu55

1.7.5. CIMTRAK™ INSTALLED COMPONENT PRE-REQUISITES

CimTrak™ Master Repository

1.8. CIMTRAK™ NETWORK DEVICE AGENT SYSTEM REQUIREMENTS

The following categories indicate the System Requirements necessary for the properconfiguration and operation of the CimTrak™ Network Device Agent component.

1.8.1. OPERATING SYSTEM REQUIREMENTS

Microsoft™ Windows XP SP2 or SP3 Microsoft™ Windows Server 2003 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2003 R2 Release, SP1, or SP2 Microsoft™ Windows Vista Release, SP1, or SP2 Microsoft™ Windows Server 2008 R1 Release, SP1, or SP2 Microsoft™ Windows Server 2008 R2 Release, SP1, or SP2 Microsoft™ Windows 7 Release, SP1 Microsoft™ Windows 8.x Microsoft™ Windows 10 Microsoft™ Windows Server 2012 Microsoft™ Windows Server 2016 Sun SPARC/x86 Solaris 10 Update 8 OpenSolaris 2008.05 and above Linux 2.4.21 and above AIX 6.1 and above HP-UX Itanium 11i V2 (11.23) and above HP-UX PA-RISC 11i V2 (11.23) and above Mac Intel OS 10.4.4 and above

User Guidance 11

Page 12: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

1.8.2. SYSTEM REQUIREMENTS

Personal computer or server with Pentium-compatible processor Pentium 3 1.2 GHz or greater 512 MB RAM available 200 MB hard disk space

1.8.3. MICROSOFT™ WINDOWS INSTALLATION PRE-REQUISITES

None

1.8.4. LINUX INSTALLATION PRE-REQUISITES

Redhat, CentOS, and Fedora: x32 System w x32 Agent: sudo yum install bc glibc libstdc++ audit-libs

Redhat, CentOS, and Fedora: x64 System w x32 Agent: sudo yum install bc glibc.i686 libstdc++.i686 audit-libs.i686

Redhat, CentOS, and Fedora: x64 System w x64 Agent: sudo yum install bc readline glibc libstdc++ audit-libs

Ubuntu 14.04 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libstdc++6:i386 whois bc binutils

libreadline6 libncurses5 libauparse0 Ubuntu 14.04 x64 System - w x32 AGENT:

sudo apt-get install auditd libaudit1:i386 libauparse0:i386 libstdc++6 whoisbc binutils lib32z1 lib32ncurses5 lib32readline6 52:i386

Ubuntu 14.04 x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libstdc++6 libicu52 whois bc binutils

libreadline6 zlib1g libncurses5 libauparse0 Ubuntu 15.04 x32 System - w x32 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g libncurses5 libreadline6 libicu52

Ubuntu 15.04 x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutils

lib32z1 lib32ncurses5 lib32readline6 libicu52:i386 Ubuntu 15.04 x64 System - w x64 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1 lib32ncurses5 libreadline6 libicu52

Ubuntu 16.04 Before Update 2 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g

libncurses5 libreadline6 libicu52 Ubuntu 16.04 Before Update 2 x64 System - w x32 AGENT:

sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutilslib32z1 lib32ncurses5 lib32readline6 libicu52:i386

Ubuntu 16.04 Before Update 2 x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1

lib32ncurses5 libreadline6 libicu52 Ubuntu 16.04 After Update 2 x32 System - w x32 AGENT:

12 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 13: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g libncurses5 libreadline6 libicu55

Ubuntu 16.04 After Update 2 x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutils

lib32z1 lib32ncurses5 lib32readline6 libicu55:i386 Ubuntu 16.04 After Update 2 x64 System - w x64 AGENT:

sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1 lib32ncurses5 libreadline6 libicu55

1.8.5. CIMTRAK™ INSTALLED COMPONENT PRE-REQUISITES

CimTrak™ Master Repository

User Guidance 13

Page 14: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CIMTRAK™ MASTER REPOSITORY INSTALLATION

1.9. CIMTRAK™ MASTER REPOSITORY PRE-INSTALLATION WORKSHEET

Prior to installing the CimTrak™ Master Repository, CIMCOR recommends theinstalling user fill out the “Pre-installation Worksheet” located in the Appendix of thisguide. Filling out the Pre-Installation Worksheet will provide the installing user withvaluable configuration data necessary for completing installation dialogs. CIMCORrecommends installing the CimTrak™ Master Repository on a secured server orpersonal computer with all current operating system patches in place. This securedserver or personal computer should be dedicated to only hosting the CimTrak™Master Repository. The CimTrak™ Master Repository is not designed to beinstalled on a server or personal computer running Microsoft™ Active Directory ordelegated to function as a Domain Controller.

Note: The installing user must have local or domain administrative privilegesto successfully complete the installation. Failure to have appropriateprivileges during the installation process may result in incorrect functionalityof the product.

1.10. CIMTRAK™ MASTER REPOSITORY PRE-INSTALLATION INTEGRITY VERIFICATION

Before beginning the installation process CIMCOR recommends verifying theauthenticity of the Installation file(s). Each CimTrak™ component has an associatedSHA1 hash value calculated on installation components. The associated SHA1hash value can be obtained from the CIMCOR downloads website. Please refer tothe email you received from your CIMCOR sales representative.

1.11. CIMTRAK™ MASTER REPOSITORY INSTALLATION – GRAPHICAL

Navigate to where the CimTrak™ install file is located and run it. The Install Wizardshould begin automatically.

The CimTrak™ Installation Welcome dialog will appear. Please click “Next” tocontinue the installation process.

14 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 15: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 1: CimTrak™ Installation Welcome dialog

The CimTrak™ End User License dialog will appear. Please read through theagreement in its entirety. Once you have completed reading the CimTrak™ EndUser License agreement it is necessary to indicate whether or not you agree with theterms and conditions. It is necessary to accept the terms of the CimTrak™ licenseagreement in order to continue with the CimTrak™ Installation Wizard. To acceptthe terms and conditions click the “I accept the agreement” radio button followed byclicking “Next”. To reject the terms and conditions click the “I do not accept theagreement” radio button and then contact your CIMCOR sales representativeimmediately.

User Guidance 15

Page 16: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 2: CimTrak™ End User License Agreement dialog

The installation location dialog will appear. CIMCOR recommends leaving theinstallation path as its default to facilitate with any future support needs or productupdate requirements. Changing the installation directory is possible by eithermanually typing the installation directory path in the “Directory Name” text box orgraphically selecting the installation location by clicking the “folder” icon. Select theintended installation destination and then click “Next” to continue the installationprocess.

16 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 17: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Note: Clicking “Back” on any CimTrak™ Installation Wizard dialog will returnthe installing user to the previous page of the installation.

Figure 3: CimTrak™ installation location dialog

The Master Repository Database Password key dialog will display. The installinguser is asked to set a Master Repository Database Password Key. This key can beused by CIMCOR CimTrak™ Technical Support Services to decrypt the contents ofthe Master Repository database in the event of a CimTrak™ Master Repository hostfailure. This password key should be saved in a secure location.

To create a Master Repository key, enter a password phrase in both the “DatabasePassword Key” and “Verify” text boxes, select the Internal Port for CimTrak™ to use,and then click “Next” to continue the installation process.

User Guidance 17

Page 18: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 4: Master Repository Database Password Key dialog

The CimTrak™ Installation Wizard will display the Master Repository DatabaseEncryption dialog. This dialog allows the installing user to indicate what encryption,Key Length, and HMAC method will be used for Master Repository encryption anddecryption of data stored in the Master Repository (see Appendix for availablecryptology settings for your version of CimTrak™), When finished, click “Next”continue the installation process. The Password Validation Requirements dialog willdisplay.

18 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 19: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

User Guidance 19

Page 20: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 5: CimTrak™ Database Encryption dialog

It is necessary to configure the Master Repository to match the needs of yourorganization. Specify the TCP/IP port number (default is 3749) on which the MasterRepository will communicate.

20 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 21: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 6: CimTrak™ Master Repository port selection

All communications between CimTrak™ components are encrypted using user-specified key exchange and encryption ciphers. It is necessary for the installing userto specify the encryption cipher to use for communications. Please note thatavailable cipher types vary for different CimTrak™ releases. Please see theAppendix for a complete list of available key exchange and encryption ciphers forCimTrak™ releases. When completed, click “Next” to continue the installationprocess. When finished, click “Next” continue the installation process. ThePassword Validation Requirements dialog will display.

User Guidance 21

Page 22: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

22 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 23: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 7: CimTrak™ Master Repository communication settings

The CimTrak™ Repository user account setup dialog will appear. It is necessary toset up the default administrator username and password for the CimTrak™Repository.

User Guidance 23

Page 24: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 8: CimTrak™ User Account Dialog

Note: The account you create is your first CimTrak™ Management Consoleadministrative account. Do not lose this username/password as it is currentlythe only account capable of connecting to your CimTrak™ ManagementConsole.

Note: All CimTrak™ user accounts are case sensitive.

Click “Next” to continue.

24 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 25: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

When the components have been completely installed, the installer will take you tothe Summary Information Screen.

Figure 9 – Summary Information Screen

Click “Finish” to complete the installation. Installation of the CimTrak™ MasterRepository is complete.

User Guidance 25

Page 26: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

1.12. CIMTRAK™ MASTER REPOSITORY INSTALLATION – UNATTENDED

Review the options listed below and prepare your unattended script for deployment.

NOTE: It is necessary to run the command prompt in administratormode for Windows Vista operating systems and later.

The unattended installer simplifies the deployment process of CimTrak™ to multipleservers. It reduces the time for deployment and allows administrators to more timeto concentrate on policy and configuration tasks. There is multiple platform supportfor the unattended installer. To install the Repository in unattended mode, simply add the necessary parametersafter the system’s appropriate file. Parameters:

--mode <mode>Default: win32

Windows: Allowed: win32 unattended Linux: Allowed: gtk xwindow text unattended --prefix <prefix> Windows: Default: C:\Program Files (x86)/Cimcor/CimTrak/CimTrakRepository Linux: Default: /opt/Cimcor/CimTrak/CimTrakRepositoryThe base directory for the installation (optional, and must not exceed 4096 characters)

--servicePassword <servicePassword>The password for the local service account that will manage the Master Repository (required for Linux Only)

--DBPassword <DBPassword>The password key that will be used to create the Master Repository database password

--DBPort <DBPort>Default: 53749

The port of the CimTrak™ Master Repository database to which the CimTrak™ Server will connect (must be between 1 & 605535)

--encryptionType <encryptionType> Default: 3Allowed: [1] AES-128[2] AES-192[3] AES-256[4] CAST-128[5] IDEA-128

26 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 27: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

[6] DES-64[7] DES EDE2-128[8] DES_EDE3-192[9] RC2-64[10] RC2-128[11] RC2-256[12] RC2-512[13] RC2-1024[14] RC4-64[15] RC4-128[16] RC4-256[17] RC4-512[18] RC4-1024[19] RC4-2048[20] BlowFish-64[21] BlowFish-128[22] BlowFish-160[23] BlowFish-192[24] BlowFish-224[25] BlowFish-256[26] BlowFish-288[27] BlowFish-320[28] BlowFish-352[29] BlowFish-384[30] BlowFish-416[31] BlowFish-448

--port <port>Default: 3749

The port of the CimTrak™ Master Repository to which the CimTrak™ File System Agent will connect (must be between 1 & 605535, default is "3749")

--sslv2 <sslv2>Default: 0Allowed: 0=Disabled 1=Enabled

--sslv3 <sslv3>Default: 0Allowed: 0=Disabled 1=Enabled

--tlsv10 <tlsv10>Default: 1Allowed: 0=Disabled 1=Enabled

--tlsv11 <tlsv11>Default: 1

User Guidance 27

Page 28: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Allowed: 0=Disabled 1=Enabled

--tlsv12 <tlsv12>Default: 1Allowed: 0=Disabled 1=Enabled

--cipherFilter <cipherFilter>Default:

ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS

--CimTrakUserAccount <CimTrakUserAccount> CimTrak User AccountThe primary admin account for the CimTrak™ Master Repository (required)

--CimTrakUserPassword <CimTrakUserPassword> PasswordThe password that will be used to log in to the CimTrak™ Master Repository (required)

NOTES: - If the Encryption is not specified, the default Encryption settings will be used. - Entering an invalid parameter name will cause the installer to exit immediately. - If the unattended installer is run and the Repository has been previously installed,the Repository will be upgraded regardless of any of the parameter values. Ifthe Repository is being upgraded, the parameters pertaining to the Repository willbe ignored and a log file entry will be added stating that the Repository will beupgraded.

NOTE: The unattended Installer will modify the Windows built-in firewall (ifactive) to allow the selected TCP PORT to facilitate CimTrak™Communications. You will not be prompted for permission to open this port.

28 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 29: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CIMTRAK™ FILE SYSTEM AGENT INSTALLATION

1.13. CIMTRAK™ FILE SYSTEM AGENT PRE-INSTALLATION INTEGRITY VERIFICATION

Before beginning the installation process CIMCOR recommends verifying theauthenticity of the Installation file(s). Each CimTrak™ component has an associatedSHA1 hash value calculated on installation components. The associated SHA1hash value can be obtained from the CIMCOR downloads website. Please refer tothe email you received from your CIMCOR sales representative.

1.14. CIMTRAK™ FILE SYSTEM AGENT INSTALLATION

The steps taken to begin the graphical installation of the CimTrak™ File SystemAgent will depend on the operating system on which the installation will occur. Afterthe installation is started, the process is the same for all operating systems.Determine which operating system you are using.

NOTE: Ensure that the CimTrak™ Master Repository is installed prior toCimTrak™ File System Agent installation and if the Agent is being installed ona remote system, make sure that both systems are set to the same UTC.

The first screen will be the CimTrak™ Setup Welcome Screen.

Figure 10 – CimTrak™ Welcome Screen

User Guidance 29

Page 30: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Click “Next” to continue.

The next screen will be the CimTrak™ End User License Agreement. You must readand accept the terms of the agreement to continue the installation.

Figure 11 – EULA

Once you accept the agreement, click “Next.”

30 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 31: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Now you will see the directory where the CimTrak™ File System Agent will beinstalled. You may leave the default directory in place (recommended) or changethe path to meet your specifications. (It is recommended to leave the defaultdirectory in place, to simplify future upgrades.)

Figure 12 – Installation Directory

Once you have selected the directory path, click “Next.”

User Guidance 31

Page 32: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

The confirmation screen will now be displayed.

Figure 13 – Confirmation Screen

Confirm the settings and then click “Install” to start the installation. A progressscreen will appear while the components are being installed.

32 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 33: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

After the CimTrak™ File System Agent is installed, the Agent Connection screen isdisplayed.

Figure 14 – Enter Repository information for File System Agent

1.15. CIMTRAK™ FILE SYSTEM AGENT INSTALLATION – UNATTENDED

The way in which the silent installation of the CimTrak™ File System Agent isstarted, will depend on what operating system you are installing it on. After theinstallation is started, the process is the same for all operating systems. Determinewhich operating system you are using. For All Platforms: Run the CimTrak™ install file for the system you are installingon. The Install Wizard should begin automatically.

To install the Agent in Unattended mode, simply add the necessary parameters afterthe system’s appropriate file.

User Guidance 33

Page 34: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Parameters: --prefix <prefix>The base directory for the installation (optional, default is "C:\ProgramFiles\Cimcor\CimTrak" for Windows and /opt/Cimcor/CimTrak for *NIX, must notexceed 4096 characters) --agentname <agentname>The unique identifier of CimTrak™ File System Agent that is being installed (mustnot exceed 20 characters, default is computer's host name) --repository <repository>The address of the CimTrak™ Master Repository to which the CimTrak™ FileSystem Agent will connect (required) --port <port>The port of the CimTrak™ Master Repository to which the CimTrak™ File SystemAgent will connect (must be between 1 & 605535, default is "3749") --user <user>The Install or admin account for the CimTrak™ Master Repository (required) --password <password>The password used to log in to the CimTrak™ Master Repository (required)

NOTES:

- If the unattended installer is run and the File System Agent has been previouslyinstalled, the File System Agent will be upgraded regardless of any of the parametervalues.

34 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 35: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CIMTRAK™ NETWORK DEVICE AGENT INSTALLATION

1.16. CIMTRAK™ NETWORK DEVICE AGENT PRE-INSTALLATION INTEGRITY VERIFICATION

Before beginning the installation process CIMCOR recommends verifying theauthenticity of the Installation file(s). Each CimTrak™ component has an associatedSHA1 hash value calculated on installation components. The associated SHA1hash value can be obtained from the CIMCOR downloads website. Please refer tothe email you received from your CIMCOR sales representative.

1.17. CIMTRAK™ NETWORK DEVICE AGENT INSTALLATION

The steps taken to begin the graphical installation of the CimTrak™ Network DeviceAgent will depend on the operating system on which the installation will occur. Afterthe installation is started, the process is the same for all operating systems.Determine which operating system you are using.

NOTE: In order for the Network Device Agent to function, two-waycommunication must exist between the Network Device and the computer theNetwork Device Agent will be installed on. To check if two-waycommunication is possible, the computer with the Network Device Agent mustbe able to successfully ping the Network Device, and vice versa (while loggedinto the Network Device, the user must be able to successfully ping thecomputer the Agent will be installed on.)

NOTE: Ensure that the CimTrak™ Master Repository is installed prior to aCimTrak™ Network Device Agent installation.

User Guidance 35

Page 36: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

After the Welcome screen you will see will have the CimTrak™ End User LicenseAgreement. You must read and accept the terms of the agreement to continueinstallation.

Figure 15 – EULA Once you accept the agreement, click “Next,” or press Enter.

36 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 37: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Now you will see the directory where the CimTrak™ Network Device Agent will beinstalled. You may leave the default directory in place (recommended) or changethe path to meet your specifications. (It is recommended to leave the defaultdirectory in place, to simplify future upgrades.)

Figure 16 – Installation Directory

Once you have selected the directory path, click “Next,” or press Enter.

User Guidance 37

Page 38: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

The confirmation screen will now be displayed.

Figure 17 – Confirmation Screen

Confirm the settings and then click “Install” to start the installation. A progressscreen will appear while the components are being installed.

38 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 39: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

After the CimTrak™ Network Device Agent is installed, screen is now displayed.

You must configure the Network Device Agent to communicate with the CimTrak™Master Repository. On the CimTrak™ Network Device Agent configuration screen,you will need to enter the following information:

• A unique name for the agent being configured (Default: HostName)• The IP Address or FQDN of your CimTrak™ Master Repository• The Port the CimTrak™ Master Repository uses (Default: 3749)• CimTrak™ Master Repository Install or Admin Username• CimTrak™ Master Repository Account Password

Figure 18 – Enter Repository information for Network Device Agent

The unique name for the CimTrak™ Network Device Agent allows the user to easilyidentify which Agent they are viewing in the Management Console, in the case thatmultiple Agents (a Repository can have multiple File System and/or Network Device

User Guidance 39

Page 40: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Agents) are installed.

Click “Next” or press Enter to continue.

The installer will ask the user if a firewall rule can be added to the Windows Firewall(see image below.) This allows communication between the CimTrak™ MasterRepository and other components on different computers.

Figure 19 – Add Firewall Rule

If Yes is chosen, the CimTrak™ installer will set up an Exception in the WindowsFirewall: all communication to and from the CimTrak™ Master Repository and theother CimTrak™ components will be allowed by the Windows Firewall, regardless ofthe port number used. This way any port number can be chosen during installation.

NOTE: This only affects the built-in Windows Firewall. If there are any otherthird-party firewalls, they must be configured so that communication betweenthe CimTrak™ Master Repository and the other CimTrak™ components will beallowed. If you are installing on a *NIX system, please configure that firewallpackage accordingly.

When the components have been completely installed, the installer will take you tothe Summary Information screen.

Click “Finish” to complete the installation. Installation of the CimTrak™ NetworkDevice Agent is complete.

40 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 41: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

1.18. CIMTRAK™ NETWORK DEVICE AGENT INSTALLATION – UNATTENDED

The way in which the silent installation of the CimTrak™ Network Device Agent isstarted, will depend on what operating system you are installing it on. After theinstallation is started, the process is the same for all operating systems. Determinewhich operating system you are using. For All Platforms: Run the CimTrak™ Install file for the system you are installingon. The Install Wizard should begin automatically.

To install the Network Device Agent in Unattended mode, simply add the necessaryparameters after the system’s appropriate file.

User Guidance 41

Page 42: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Parameters: --prefix <prefix>The base directory for the installation (optional, default is "C:\ProgramFiles\Cimcor\CimTrak" for Windows and /opt/Cimcor/CimTrak for *NIX, must notexceed 4096 characters) --agentname <agentname>The unique identifier of CimTrak™ Network Device Agent that is beinginstalled (must not exceed 20 characters, default is computer's host name) --repository <repository>The address of the CimTrak™ Master Repository to which the CimTrak™ NetworkDevice Agent will connect (required) --port <port>The port of the CimTrak™ Master Repository to which the CimTrak™ NetworkDevice Agent will connect (must be between 1 & 605535, default is "3749") --user <user>The Install or admin account for the CimTrak™ Master Repository (required) --password <password>The password used to log in to the CimTrak™ Master Repository (required) NOTES:

- If the unattended installer is run and the Network Device Agent has been previouslyinstalled, the Network Device Agent will be upgraded regardless of any of theparameter values.

42 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 43: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

CIMTRAK™ APP SERVER

1.19. CIMTRAK™ APP SERVER PRE-INSTALLATION INTEGRITY VERIFICATION

Before beginning the installation process CIMCOR recommends verifying theauthenticity of the Installation file(s). Each CimTrak™ component has an associatedSHA1 hash value calculated on installation components. Please refer to the emailyou received from your CIMCOR sales representative.

1.20. CIMTRAK™ APP SERVER INSTALLATION

Right click on the CimTrak™ App Server file and select “Run as Administrator.” Thiswill be sure to allow the CimTrak™ App Server complete access to all necessaryfiles and directories on the local computer.

You will be prompted by the CimTrak™ App Server Installer.

Figure 20: CimTrak™ App Server Installer

Click “Next” to continue with you install. You will then be prompted by the CimTrak™ App Server End User License Agreement (EULA).

User Guidance 43

Page 44: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 21: CimTrak™ App Server End User License Agreement (EULA)

Please agree to the Terms and Conditions by selecting “I accept the agreement” in order to continue with the installation. Failure to agree with the Terms and Conditions will prevent installation of the CimTrak™ App Server.

You will then be prompted by the CimTrak™ App Server’s Installation Directory screen.

44 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 45: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

You may change the installation path as you wish. Once your installation path has been decided, click “Next” to continue to the CimTrak™ App Server Port Configuration screen.

User Guidance 45

Page 46: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 22: CimTrak™ App Server Port Configuration

Select the Internal Ports for CimTrak™ App Server to use when accepting remote connections, and then click “Next” to continue to the CimTrak™ App Server Ready To Install screen.

46 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 47: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 23: CimTrak™ App Server Ready to Install screen

The CimTrak™ App Server is now ready to be installed on your local machine. Please click “Next” to continue with the installation.

A prompt will appear on the screen once the CImtrak™ App Server has completed installation. You may then run the application.

User Guidance 47

Page 48: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Figure 24: CimTrak™ App Server (Installation Complete)

1.21. CIMTRAK™ APP SERVER INSTALLATION – UNATTENDED

To begin the “unattended” installation of the CimTrak™ App Server, open acommand prompt window.

Within the command prompt window, navigate to the location of the CimTrak™ AppServer setup executable.

In order to launch the CimTrak™ App Server setup installation executable as aunattended installer, you will need to navigate to the CimTrak™ App Serverexecutable file and type the following parameters followed by their values:

--unattendedmodeui none--mode unattended

Upon pressing “Enter” the CimTrak™ App Server executable will launch and silentlyperform the installation. For a list of parameters, you may enter the parameter “—help.” Following is a list of the available parameters for the CimTrak™ App SeverSetup executable.

Parameter: --help Description: Display the list of valid options

48 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 49: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Parameter: --version Description: Display product information

Parameter: --unattendedmodeui <unattendedmodeui>Description: Unattended Mode UI

Default Value: none Allowed Values: none minimal minimalWithDialogs

Parameter: --optionfile <optionfile>Description: Installation option file

Parameter: --debuglevel <debuglevel>Description: Debug information level of verbosity

Default Value: 2 Allowed Values: 0 1 2 3 4

Parameter: --mode <mode>Description: Installation mode

Default Value: win32 Allowed Values: win32 unattended

Parameter: --debugtrace <debugtrace>Description: Debug filename

Parameter: --installer-language <installer-language>Descripton: Language selection

Default Value: en Allowed Values: en

Parameter: --prefix <prefix>Description: Installation Directory

Default Value:C:\ProgramFiles(x86)/Cimcor/CimTrak/CimTrakAppServer

User Guidance 49

Page 50: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX A – DOCUMENTATION HISTORY

1.22. CIMTRAK™ INSTALLATION GUIDANCE DOCUMENTATION HISTORY

The following table outlines the history of this documentation. Date Version Editor Modification5 May 2011 1.0 David Wheeler,

CIMCOR Technical Support Document Creation

29 Dec 2014 2.0 Ryan Rutkin,CIMCOR Support Staff

Document Upgrade

1 Feb 2016 3.0 Sam Conley, CIMCOR Technical Support

Document Upgrade

2 Feb 2017 3.1 Sam Conley, CIMCOR Technical Support

Document Upgrade

5 Feb 2018 3.2 Richard SlaughterCIMCOR Support Staff

DocumentUpdate

50 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 51: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX B – TECHNICAL SUPPORT INFORMATION

1.23. CIMTRAK™ TECHNICAL SUPPORT SERVICES

CimTrak™ Technical Support Services are here to help. Should you have any problems or questions please contact us using one of the following contact methods.

1.24. SUPPORT VIA ELECTRONIC MAIL

CimTrak™ Technical Support electronic mail: [email protected]

Please be sure to include the following information in your message:• Product name, version, and serial number• Operating system, version, and service pack number• Description of what you were doing when the error message occurred and

exactly what the error message stated.Any other pertinent information

1.25. SUPPORT VIA FAX

Should you choose this method, fax the same information as above to: CIMCOR, Inc. (219) 736-4401

In addition to the above information please be sure to include the following:• Your name and organization• Return phone number• Return fax number• Your E-mail address

1.26. SUPPORT VIA PHONE

Call CimTrak™ Technical Support at (877) 424-6267 Ext. 2Hours: Monday thru Friday 9 AM – 5 PM Central Standard TimeVoice Mail: Leave a voice mail during off hours

Include in your voice mail:• Your name and organization• Your phone number• Your question or a description of the problem• Your E-mail address

Our technical support staff will contact you with an answer as soon as possible.

User Guidance 51

Page 52: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX C – AVAILABLE ENCRYPTION TYPES

The following tables list available encryption types, key lengths, and HMAC typesavailable for all CimTrak™ releases.

Encryption Key LengthCimTrak™ Release VersionFIPS Enterprise International

AES 128 X XAES 192 X XAES 256 X XCAST256 128 XCAST256 256 XIDEA 128 XDES 64 X XDES_EDE3 192 X XDES_EDE2 192 XRC2 64 X XRC2 128 XRC2 256 XRC2 512 XRC2 1024 XBlowFish 64 X XBlowFish 128 XBlowFish 160 XBlowFish 192 XBlowFish 224 XBlowFish 256 XBlowFish 288 XBlowFish 320 XBlowFish 352 XBlowFish 384 XBlowFish 416 XBlowFish 448 XCAST128 64 X XCAST128 128 XRC4 64 X XRC4 128 XRC4 256 XRC4 512 XRC4 1024 XRC4 2048 XTable 1: Available encryption types for CimTrak™ releases

52 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 53: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

HMAC TypeCimTrak™ Release VersionFIPS Enterprise International

SHA1 X X XMD4 X XMD5 X XRIPEMD160 X XSHA1 X XSHA256 X XSHA384 X XSHA512 X XTable 2: Available HMAC types for CimTrak™ releases

User Guidance 53

Page 54: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX D – KEY EXCHANGE AND ENCRYPTION CIPHERS

The following table lists all available key exchange and encryption ciphers forCimTrak™ releases.

CipherCimTrak™ Release VersionFIPS Enterprise International

AES128-SHA X XAES256-SHA X XDES-CBC3-SHA X XDES-CBC-SHA XDHE-RSA-AES128-SHA X XDHE-RSA-AES256-SHA X XEDH-RSA-DES-CBC3-SHA X XEDH-RSA-DES-CBC-SHA XEXP-DES-CBC-SHA XEXP-EDH-RSA-DES-CBC-SHA X XEXP-RC2-CBC-MD5 XEXP-RC4-MD5 XIDEA-CBC-SHA XRC4-MD5 XRC4-SHA XFigure 25: Available key exchange and encryption ciphers

54 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 55: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX E – ENTERPRISE WORKSHEET

TCP/IP Port CimTrak™ Master Repository will use this port for network communication:

_________ (Default: 3749)

Determine Repository Location:_____________________________________________________________(i.e. C:\Program Files\Cimcor\CimTrak\CimTrakRepository\Repository)

Select Repository Encryption:Encryption Type: ___________

(Available Encryption Types: AES, CAST256, IDEA, DES, DES_EDE3,DES_EDE2, RC2, BlowFish, CAST128, SKIPJACK, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

Password Settings: None AR 25-2 Standard – User entered password AR 25-2 Standard – Randomly generated password Custom settings:

○ Require two lowercase, two uppercase, two numbers, and two specialcharacters

○ Random Password Generation○ Check against password dictionary○ Require minimum password length of ______ characters (0 for no minimum)○ Password expires after ______ days (0 to never expire)○ Prevent use of last ______ passwords (0 to allow all)○ Lock out user after ______ password failures (0 for never)○ Lock out failed user for ______ minutes (0 for indefinite)

Select Agent Data Encryption:Encryption Type: ___________

(Available Encryption Types: AES, CAST256, IDEA, DES, DES_EDE3,DES_EDE2, RC2, BlowFish, CAST128, SKIPJACK, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

User Guidance 55

Page 56: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Reset key every ___________ seconds (Default: 90)

Select Management Console Data Encryption:

Encryption Type: ___________(Available Encryption Types: AES, CAST256, IDEA, DES, DES_EDE3,DES_EDE2, RC2, BlowFish, CAST128, SKIPJACK, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

Reset key every ___________ seconds (Default: 90)

Syslog Server IP Address:

IP Address of Syslog Server: ___________________________Protocol (TCP/UDP): ______________Port ______________(Default Protocol/Port: [TCP: 1465][UDP: 514])

SNMP Server IP Address:

IP Address of SNMP Server: ___________________________SNMP Community: ______________ (Default: Public)Port ______________ (Default: 162)

SMTP Server IP Address:

IP Address of SMTP Server: ___________________________Port ______________ (Default: 25)Email From Address: ______________________________________Email Display Name: ______________________________________If needed, send email alerts every ___________ minutes (Default: 2)

CimTrak™ Serial Number:

Your CimTrak™ Serial Number:_______________________________________________________________

Repository Username and Password:

Username: _______________________________Password: _______________________________(NOTE: for security reasons, you may not wish to write these down!)

56 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 57: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX F – FIPS WORKSHEET

TCP/IP Port CimTrak™ Master Repository will use this port for network communication:

_________ (Default: 3749)

Determine Repository Location:_____________________________________________________________(i.e. C:\Program Files\Cimcor\CimTrak\CimTrakRepository\Repository)

Select Repository Encryption:

Encryption Type: ___________(Available Encryption Types: DES, RC2, BlowFish, CAST128, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

Password Settings: None AR 25-2 Standard – User entered password AR 25-2 Standard – Randomly generated password Custom settings:

○ Require two lowercase, two uppercase, two numbers, and two specialcharacters

○ Random Password Generation○ Check against password dictionary○ Require minimum password length of ______ characters (0 for no minimum)○ Password expires after ______ days (0 to never expire)○ Prevent use of last ______ passwords (0 to allow all)○ Lock out user after ______ password failures (0 for never)○ Lock out failed user for ______ minutes (0 for indefinite)

Select Agent Data Encryption:

Encryption Type: ___________(Available Encryption Types: DES, RC2, BlowFish, CAST128, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

User Guidance 57

Page 58: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Reset key every ___________ seconds (Default: 90)

Select Management Console Data Encryption:

Encryption Type: ___________(Available Encryption Types: DES, RC2, BlowFish, CAST128, RC4)

Key Length: ___________ (Key Length will depend on Encryption Type)HMAC Method: ___________

(Available HMAC Methods: MD2, MD4, MD5, RIPEMD160, SHA1, SHA256,SHA384, SHA512, Tiger)

Reset key every ___________ seconds (Default: 90)

Syslog Server IP Address:

IP Address of Syslog Server: ___________________________Protocol (TCP/UDP): ______________Port ______________(Default Protocol/Port: [TCP: 1465][UDP: 514])

SNMP Server IP Address:

IP Address of SNMP Server: ___________________________SNMP Community: ______________ (Default: Public)Port ______________ (Default: 162)

SMTP Server IP Address:

IP Address of SMTP Server: ___________________________Port ______________ (Default: 25)Email From Address: ______________________________________Email Display Name: ______________________________________If needed, send email alerts every ___________ minutes (Default: 2)

CimTrak™ Serial Number:

Your CimTrak™ Serial Number:_______________________________________________________________

Repository Username and Password:

Username: _______________________________Password: _______________________________

(NOTE: for security reasons, you may not wish to write these down!)

58 CIMCOR CimTrak™ Integrity & Compliance Suite

Page 59: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

APPENDIX G – LINUX DEPENDENCIES

Redhat, CentOS, and Fedora:x32 System w x32 Agent: sudo yum install bc glibc libstdc++ audit-libsx64 System w x32 Agent: sudo yum install bc glibc.i686 libstdc++.i686 audit-libs.i686x64 System w x64 Agent: sudo yum install bc readline glibc libstdc++ audit-libsx32 System w x32 Repo: sudo yum install readline libstdc++ glibc openldap which libXrender fontconfig freetype libXext libX11x64 System w x32 Repo: sudo yum install readline.i686 libstdc++.i686 glibc.i686 openldap.i686 which libXrender.i686 fontconfig.i686 freetype.i686 libXext.i686 libX11.i686xwindow mode for Installer: sudo yum install gtk2.i686

Ubuntu 12.04 w x32 AGENT or x64 AGENT: sudo apt-get install auditd libaudit0 libstdc++6 libicu48 whois bc binutils libreadline5 libncurses5

Ubuntu 13.04 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit0 libauparse0 whois bc binutils lib32z1 lib32ncurses5 lib32readline5 52x64 System - w x32 AGENT: sudo apt-get install auditd libaudit0:i386 libauparse0:i386 whois bc binutils lib32z1 lib32ncurses5 lib32readline5 52:i386x64 System - w x64 AGENT: sudo apt-get install auditd libaudit0 libauparse0 whois bc binutils lib32z1 lib32ncurses5 lib32readline5 52x32 System - w x32 REPO: sudo apt-get install whois binutils lib32ncurses5 lib32bz2-1.0 lib32readline5 slapd ldap-utilsx64 System - w x32 REPO: sudo apt-get install whois binutils lib32ncurses5 lib32bz2-1.0 lib32readline5 slapd ldap-utils:i386 libxrender1:i386 libfontconfig1:i386 libxext6:i386

User Guidance 59

Page 60: CimTrak™ Integrity & Compliance Suite 3 · Installation Guidance. ... Enterprise Worksheet ... Linux Kernel 2.6.32 and Above (Red Hat & CentOS Distributions) 1.6.2.SYSTEM REQUIREMENTS

Ubuntu 14.04 x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libstdc++6:i386 whois bc binutils libreadline6 libncurses5 libauparse0x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 libstdc++6 whois bc binutils lib32z1 lib32ncurses5 lib32readline6 52:i386x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libstdc++6 libicu52 whois bc binutils libreadline6 zlib1g libncurses5 libauparse0x32 System - w x32 REPO: sudo apt-get install whois binutils libncurses5 libbz2-1.0 libreadline6 slapd ldap-utils libxrender1libfontconfig1 libxext6 libxrender1 libfontconfig1x64 System - w x32 REPO: sudo apt-get install whois binutils lib32ncurses5 lib32bz2-1.0 lib32readline6 slapd ldap-utils:i386 libxrender1:i386 libfontconfig1:i386 libxext6:i386 lib32stdc++6

Ubuntu 15.04x32 System - w x32 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils zlib1g libncurses5 libreadline6libicu52x64 System - w x32 AGENT: sudo apt-get install auditd libaudit1:i386 libauparse0:i386 whois bc binutils lib32z1 lib32ncurses5 lib32readline6 libicu52:i386x64 System - w x64 AGENT: sudo apt-get install auditd libaudit1 libauparse0 whois bc binutils lib32z1 lib32ncurses5 libreadline6 libicu52x32 System - w x32 REPO: sudo apt-get install whois binutils libncurses5 zlib1g libreadline6 slapd ldap-utils libxrender1 libfontconfig1 libxext6 libstdc++6 libxrender1 libfontconfig1x64 System - w x32 REPO: sudo apt-get install whois binutils lib32ncurses5 lib32z1 lib32readline6 slapd ldap-utils:i386 libxrender1:i386 libfontconfig1:i386 libxext6:i386 lib32stdc++6 libxrender1:i386 libfontconfig1:i386

Resolution for Ubuntu xwindow mode for Installbuilder sudo apt-get install libgtk2.0-0

Resolution for Debian xwindow mode for Installbuilder sudo apt-get install libstdc++6 binutils

60 CIMCOR CimTrak™ Integrity & Compliance Suite