IBM Tivoli Software IBM Tivoli Software

[ Bottom of Page | Previous Page | Next Page | Contents ]


Documentation problems and corrections contained in this fix pack

Planning and Installation Guide

This section contains new and updated information for IBM(R) Tivoli(R) Configuration Planning and Installation Guide:

Defect 55431, 55432
In Chapter 3 "Component installation prerequisites", section "Using the Web Gateway component with Tivoli Access Manager", subsection "Installing and Configuring the Java(TM) Runtime Environment", replace the existing example for Windows(R) operating systems with the following example:
cd C:\Program Files\Tivoli\Policy Director\sbin pdjrtecfg -action  \
config -host hostname -java_home drive:%WAS_HOME%\java\jre 
-host /<access_manager_server_name>
and replace the command to be run on the Web Gateway server to create the SSL configuration file and keystores with the following example:
java com.tivoli.mts.SvrSslCfg userName Password pdmgrdHostname \ 
pdacldHostname pdmgrdPort pdacldPort configuration_file \
keystore_file create

where:

userName
The name of the Access Manager application to create and associate with the SSL communication. The application name must be unique. Other instances of the application, which are running on this or other systems, must each be given a unique name. A distinguished name can be used when an LDAP-based user registry is used with Access Manager.
Password
The password associated with the master security user.
pdmgrdHostname
The name of the system where the Access Manager policy server process, ivmgrd, is running.
pdacldHostname
The name of the system where the Access Manager authorization server process, ivacld, is running. This can be the same system as the policy server.
pdmgrdPort
The port used for SSL communication with the policy server. The default is 7135.
pdacldPort
The port used for SSL communication with the authorization server. The default is 7136.
configuration_file
The URL of the configuration file. The URL must use the file:/// format. The default is java_home/PdPerm.properties. The PDPerm.properties and PdPerm.ks files must be in the same directory.
keystore_file
The URL of the keystore file. The URL must use the file:/// format. The default is java_home/PdPerm.ks. The PDPerm.properties and PdPerm.ks files must be in the same directory.
APAR IY71740
In Chapter 1. Overview of Configuration Management, add the following information to the Software Distribution component description: You must install the Software Distribution component on the Tivoli server before you can install either the Software Distribution or Software Distribution Gateway component on any managed node in the local Tivoli region.

In Chapter 1. Overview of Configuration Management, at the end of section IBM Tivoli Configuration Manager Components and Services, delete the following paragraph: You must install these components on the Tivoli server before you can install them on a managed node or before you can install the associated gateway component on a gateway. For example, you must install the Software Distribution component on the Tivoli server before you can install either the Software Distribution or Software Distribution Gateway component on any managed node in the local Tivoli region.

APAR IY75134
In Chapter 3. Component Installation Prerequisites, add the following note under Table 5 and Table 6:
Note:
The index file for the Scalable Collection Service component does not appear in the table because it cannot be upgraded but must be fresh-installed.
APAR IY76046
In Chapter 5. IBM Tivoli Configuration Manager Installation and Upgrade, section "Custom Server Installation", step 10, add the following information to the - Directory description:

For more details on these files, refer to the IBM Tivoli Configuration Manager 4.2.3 Patch Management Guide.

User's Guide for Inventory

This section contains new and updated information for IBM Tivoli Configuration User's Guide for Inventory:

APAR IY76046
In Chapter 3. Working with Inventory profiles, section "Software patch scan options for PC", add at the end of the section the following paragraph:

For more details on these files, refer to the IBM Tivoli Configuration Manager 4.2.3 Patch Management Guide.

Defect 182301
In Chapter 4. Distributing Inventory profiles, section "Performing an endpoint initiated scan"', add the following information at the end of the third paragraph:

As software scan options for PC and UNIX, ensure you select Run the scan to perform a scan on the endpoint, and Send the results to the configuration repository to create the DAT file on the endpoint. If the upload of the results is needed, you can run the wepscan -s command.

Defect 179423
In Appendix B "Commands", replace the usage of the wloadiso command with the following usage:

wloadiso [-d { 1 | 2 | 3 }] -f filename | -l listfilename

and replace the description of the -f DAT file option with the following two options:
-f filename
The name of the .DAT file to be sent to the configuration repository. You can specify more than one .DAT file.
-l listfilename
The name of a file containing a list of .DAT files.
APAR IY70039
In Appendix B "Commands", section wcollect, replace the description of the -n option with the following text:
-n
Enables a threshold for the number of entries that can be added to the Wan entry Point Collector input and output queue. When the threshold is exceeded, entries are rejected. Entries are added again when the threshold is no longer reached.
Defect 55686, 55847
In section "Scanning disconnected system" replace Step 4, Step 9, and Step 11 with the following:

Step 4:

On the endpoint, locate the zip file (for example w32-ix86.zip) in the $LCFROOT/inv/ISOLATED/common/ directory, and manually copy the file from this directory to the directory on the disconnected system that you created in step 3.

Step 9:

On the disconnected system unzip the zip file, from the directory that you created in Step 3, and run:

wepscan -i -n DAT_file_name

where:

DAT_file_name
Is the name of the DAT file.
Note:
On Solaris, before running the wepscan command, set the library path to the local directory. From the local directory run:
export LD_LIBRARY_PATH=.:$LD_LIBRARY_PATH

Step 11:

Run the wloadiso command from the $LCFROOT/inv/ISOLATED/depot directory on the endpoint to send the scan data to the configuration repository. Before running the wloadiso -f file.dat command, set up the lcf environment to access the shared libraries needed by the command. See wepscan for the procedure on how to set the environment.

Defect 55565
If you installed the WSUS Patch Automation solution, in Appendix B "Commands", replace the current usage of the wsetinvpcsw command with the following usage:
wsetinvpcsw [-b {SCAN | UPDATE | BOTH | NO}] 
[-c {QUICK | FULL | MD5 | NONE}] [-f {Y | N}] 
[-h {SCAN | UPDATE | BOTH | NO}] [-r {SCAN | UPDATE | BOTH | NO}] 
[-s {SCAN | UPDATE | BOTH | NO}] [-x {Y | N}] [-m {Y | N}] 
[-d {Y | N} [-n file_ name]] profile_name
and add the following entries at the end of the Options list:
-d
Specifies whether the swsigs.txt file must be downloaded to the endpoint. The default value is N, which means that the file is downloaded to the endpoint with every profile distribution. To prevent the file from being downloaded, set the option to Y. You can use the -n option to select a different file to be downloaded.
-n file_name
Specifies the name of the file to be downloaded to the endpoint. You can choose one of the following two files:
swsigs.txt
Contains Inventory signatures.
wsusscan.cab
Contains the security policy catalog.
This option can be used only with the -d option.
In Appendix B "Commands", replace the current usage of the wgetinvpcsw command with the following usage:
wgetinvpcsw [-b] [-c] [-f] [-h] [-r] [-s] [-x] [-m] [-d] profile_name
and add the following entry at the end of the Options list:
-d
Specifies whether the swsigs.txt file must be downloaded to the endpoint.
In Appendix B "Commands", replace the current usage of the wsetinvunixsw command with the following usage:
wsetinvunixsw [-b {SCAN | UPDATE | BOTH | NO}] 
[-c {QUICK | FULL | MD5 | NONE}] [-f {Y | N}] 
[-p {SCAN | UPDATE | BOTH | NO}] 
[-s {SCAN | UPDATE | BOTH | NO}] [-x {Y | N}] [-d {Y | N}] profile_name
and add the following entry at the end of the Options list:
-d
Specifies whether the swsigs.txt file must be downloaded to the endpoint. The default value is N, which means that the file is downloaded to the endpoint with every profile distribution. To prevent the file from being downloaded, set the option to Y.
In Appendix B "Commands", replace the current usage of the wgetinvunixsw command with the following usage:
wgetinvunixsw [-b] [-c] [-f] [-p] [-s] [-x] [-d] profile_name
and add the following entry at the end of the Options list:
-d
Specifies whether the swsigs.txt file must be downloaded to the endpoint.
APAR IY76815
In Appendix B "Commands", section "wcancelscan", replace the description of the Authorization sub-section with the following text: Super and senior.
WSUS Automated Patch Management Solution
If you installed the WSUS Patch Automation solution, replace the mssecure.cab, mbsacli.exe, and ApprovedItems.txt files with the following files everywhere:
Table 22. WSUS patch management files
SUS Files WSUS Files
mssecure.cab wsusscan.cab
mbsacli.exe WindowsUpdateAgent20-x86.exe
ApprovedItems.txt ApprovedChanges.txt

User's Guide for Deployment Services

Defect 55898
Add at the end of Chapter 4. Troubleshooting, the following section:

APM login failure on Linux(TM)

If Activity Planner fails and the following message is displayed

AMN0121E Activity Planner initialization failed. Check whether 
the Activity Planner user has been created correctly and/or 
the user and password maintained by Activity Planner are syncronized 
with the corresponding values of the operating system.

and the oservlog contains reports similar to the following:

2005/09/19 10:50:58 -01: PAM: pam_acct_mgmt failed=User account has expired (13)
2005/09/19 10:50:58 -01: @verify_password: Invalid username or password
2005/09/19 10:50:58 -01: @rconnect:  Login failed for tivapm from host 100007f
Go to /etc/pam.d and edit the oserv file
#%PAM-1.0
# Created by etc-tivoli.cfg for DS/Win and JCF login on systems with Pluggable
# Authentication Modules (PAM). Install will not overwrite this file if it
# exists. See the PAM doc for your platform for details on modifying this file.
auth    required        /lib/security/pam_unix.so
Add the following line:
account required        /lib/security/pam_unix.so
APAR IY74288
In Chapter 3. Using the Command Line, section "Managing Activity Plans", sub-section "wapmfltr", add the -u user@hostname.domain parameter to the syntax of the wapmfltr command.

At the end of the "Option" section add the following option description:

-u user@hostname.domain
Enables you to specify the owner of the filter you create when you have the APM_View role.
APAR IY66346
In Chapter 1. Using Activity Planner, section Before You Start, modify the sentence: as follows: In Understanding the Activity Planner Environment sub-section, modify Table 1. Activity Planner roles and operations by adding the RIM_view and RIM_Update roles in all the cells of the Required roles column.
Defect 55797, 55826
In Chapter 19 "Using the command line", section "wresgw", replace the existing usage for the wresgw discover syntax with the following usage:
wresgw discover [-v] [-C resource_gateway_type] endpoint...
Change the endpoint description in the Options list as follows:
endpoint
Specifies the endpoint on which the resource gateway is installed.

For the wresgw ls command, lists all known resource gateway types on the endpoint that you specify.

For the wresgw update command, indicates the endpoint for which the object ID or endpoint label is being updated. This option is mandatory.

Add the following options at the end of the Options list:
-f
Discovers all devices on the specified endpoint. If you do not specify this option, the discovery operation returns only devices added since the last discovery operation.
-a
Discovers devices asynchronously. The results of the operation are saved to the discover.log file located in the /work directory. This operation is provided with a distribution ID and you can view its status with the wmdist command. For more information on this command, refer to Tivoli Management Framework Reference Manual.
APAR IY75060
In Chapter 4 "Troubleshooting", section "Activity Planner Core Trace", add the following information:

The APM_RPC_MAX_THREADS environment variable has been added to the APM_core process. This variable sets the maximum number of concurrent remote procedure call threads handled by the dispatcher. The default value is 250.

Reference Manual for Software Distribution

This section contains new and updated information for IBM Tivoli Configuration Reference Manual for Software Distribution:

Feature 55186
In chapter "Editing the software package definition file", section "System actions", add the following text after the "check_disk_space" section:

logoff stanza

To perform a logoff operation on Windows endpoints, use the logoff stanza, the format of which is as follows:

logoff
			force = y/n    (default = n)
			force_if_locked = y/n   (default = n)
			during_install = y/n   (default = n)
			during_commit = y/n   (default = n)
			during_undo = y/n   (default = n)
			during_remove = y/n   (default = n)
end
Table 23. SPD file attribute of the logoff stanza
Attribute Comments
Values Required Default Stanza
force The logoff operation is forced also if any applications are currently active on the workstation.
String expression No n logoff
force_if_locked The logoff operation is forced if the workstation is locked.
String expression No n logoff
during_install The logoff operation is performed during the during_install phase.
String expression No n logoff
during_commit The logoff operation is performed during the during_commit phase.
String expression No n logoff
during_undo The logoff operation is performed during the during_undo phase.
String expression No n logoff
during_remove The logoff operation is performed during the during_remove phase.
String expression No n logoff

SPD File Example: logoff

The following section shows an example of a software package definition file containing a logoff stanza:

'TIVOLI Software Package v4.2.3 - SPDF'

package
  ##
  ## Package attributes
  ##
  	logoff
			force = y
			force_if_locked = n
			during_install = n
			during_commit = y
			during_undo = n
			during_remove = n
		end
end
APAR IY66515
In Chapter 1. Editing the Software Package Definition File, section Software Package Name and Version , add the following sentence after the first list:

The length of the string that defines the name and version of a software package can vary depending on how you distribute it:

User's Guide for Software Distribution

This section contains new and updated information for IBM Tivoli Configuration User's Guide for Software Distribution:

APAR IY73165
In chapter 11 "Configuring a Network Topology", section "Scenario 3: Distributing from a Source Host through Repeater Depots" remove the following sentence:

However, do not use depots for extremely large distributions.

APAR IY73289
In chapter 15 "Troubleshooting", section "Hints and tips", add the following entry at the end of the list:

Error while generating a software package using Autopack

During the creation of the first Autopack snapshot, some system resources might be included in the snapshot. This might cause a failure when Autopack generates the software package. If the creation of the software package fails with one or both of the following error messages:

DISSP6018E Failed to build file_name
DISSE0282E Error compressing the file file_name in the 
Software Package Block.

generate the software package again excluding the files listed in the error messages, as explained in "Creating the first snapshot" in Chapter 8.

APAR IY74801:
In Chapter 15 "Troubleshooting", section "Base Configuration Information on the Endpoint", add to table 17 "Directory assignments in swdis.ini file" the following key and its description:
Table 24. Directory assignments in swdis.ini file
Key Description
resinit_one_reboot Defines the endpoint behavior in processing software packages. If you change the default value resinit_one_reboot=y and set it to resinit_one_reboot=n, the packages are processed one by one, and if a package requires a reboot, the endpoint is rebooted immediately.
Defect 55498
Add the following section at the end of the Chapter 15. Troubleshooting:

Using the Save option of the Software Package Editor

Software Package Editor is unable to save a software package on an AIX(R) endpoint that has Software Package Editor Version 4.2.3 and fix pack 1 installed. No error message is displayed. The workaround is to select a file between those displayed in the panel. Then the Save option works properly. This problem is a known issue of JRE 1.3.1.

Database Schema Reference

If you install the Patch Management fix pack component, see the updated version of the Patch Management Guide to see the new patch management tables and views.

Patch Management Guide (for the SUS configuration)

This section contains new and updated information for IBM Tivoli Configuration Patch Management Guide:

Feature 55260
In chapter 6 "Automated patch management command line", in the description of the wseccfg command, add the following parameter to the list under the -s option:
workflow_activities
Specifies whether workflows are completed in one step or are separated into two steps. Supported values are as follows:
sync
Performs all operations in the workflows without creating software packages and plans.
preparation
Creates software packages and plans without performing any other operation.
all
Performs all operations contained in the workflows. This is the default value.
Defect 53932
In chapter 6 "Automated patch management command line", in the description of the wseccfg command, add the following parameter to the list under the -s option:
catalog_proxy_enabled
Enables or disables proxy support. You can use an HTTP proxy to access the Microsoft(R) Web site, or your local HTTP server where the mssecure.cab file has been downloaded. Proxy parameters are defined at installation time in the tpm_update.req file, as described in Upgrading the Patch Management component.
Defect 55470
In chapter 7 "Troubleshooting", section "Other common problems", add the following entry at the end of the section:

The activity plan fails on targets deleted from the Tivoli database

Deleting endpoints from the Tivoli database does not delete those endpoints from the configuration repository. This might cause the activity plan to fail on the deleted endpoints because targets for the workflow are defined based on the information in the configuration repository.

To prevent this problem, after deleting the endpoints using the wdelep command, run the winvrmnode command to remove hardware and software scan information from the configuration repository. For more information on these commands refer to Tivoli Management Framework: Reference Manual and IBM Tivoli Configuration Manager: User's Guide for Inventory.

Defect 55340
In chapter 7 "Troubleshooting", section "Other common problems", add the following entry at the end of the section:

SUS server synchronization problem

Cause:If you work with the SUS server, during the SUS server synchronization on the Microsoft web site, the following error message INVCC0264E No files to transfer is displayed.

Solution: To avoid the problem you can perform one of the following tasks:

Defect 55799
In chapter 7 "Troubleshooting", section "Other common problems", add the following entry at the end of the section:

Cause: ITCM 4.2.3 plus interim fix 0001. If you set delete_plans=yes in the patch management configuration and run the workflow when there are no entries in the APM database, the following error message is logged in the execution log of the workflow: ERROR: Command >wlstpln< failed.

Solution: The process completed successfully. Ignore the error message.

Defect 55832
In "Chapter 5. Patch Management Command Line", section "wsecgensp", change the RUR lang option into RURU and add HEEN (hebrew enabled) to the list of lang option values.

Messages and Codes

This section contains new and updated information for IBM Tivoli Configuration Manager Messages and Codes:

Defect 55666

CMYSE0265E
You cannot create the software package because the SWD-Inventory integration is currently disabled.
Explanation:

The command you are using requires integration with Inventory.

System Action:

The operation failed.

Operator Response:

If inventory integration is required, use the wswdmgr software distribution command and the wsetinvswd Inventory command to enable integration. See: IBM Tivoli Configuration Manager: Reference Manual for Software Distribution, SC23-4712 and IBM Tivoli Configuration Manager: User's Guide for Inventory, SC23-4713 for more information.

Defect 55824

DISSE0624E
An error occurred contacting the managed node `managed node'. Make sure the managed node is defined as a gateway or stand-alone repeater and is working properly.
Explanation:

See message.

System Action:

The install operation failed.

Operator Response:

Ensure you defined the source host as a Tivoli gateway or a repeater. Check that the Tivoli gateway or the repeater is running. See the wrpt or wgateway commands in the Tivoli Management Framework: Reference Manual, GC32-0806.

Software Package Editor online help

This section contains new information for the Software Package Editor online help:

Feature 55186
The following is the help panel for the Logoff Properties dialog box:

Use this dialog box to specify whether you want a logoff operation to be performed on Windows endpoints and to define the settings for the logoff operation. You can select one or more of the following options:

Logoff during install
The logoff operation is performed during the during_install phase.
Logoff during undo
The logoff operation is performed during the during_undo phase.
Logoff during remove
The logoff operation is performed during the during_remove phase.
Logoff during commit
The logoff operation is performed during the during_commit phase.
Force
The logoff operation is forced also if any applications are currently active on the workstation.
Force if locked
The logoff operation is forced if the workstation is locked.

For more information on defining conditions, see the Conditions help panel.

Defect 55461
The Maintain existing value check box has been added to the Add Directory Properties and Add File Properties dialogs. The following is the help panel for this check box:

Select this check box to maintain the file or directory access attributes and the ownership if the file or directory already exists on the target. If the file or directory does not exist, the check box selection has no effect, and the default value (Use system value check box), or the ones that you selected, are assumed.


[ Top of Page | Previous Page | Next Page | Contents ]