HP-UX Host Intrusion Detection System Release 4.0 Release Notes for HP-UX 11i v1 | HP-UX 11i v2 | HP-UX 11i v3
Clarifications
Perform Updates Instead of Cold Reinstalls
HP-UX HIDS is designed to support updates. If users cold reinstall the newer version
by first removing the older version (swremove), two reboots (instead of just one or
possibly none) will occur and there is the possibility of losing some configuration data.
Do not Change Permissions
Do not change the permissions on files and directories owned by ids. Opening up the
permissions to be world writable or readable causes the agent to fail security checks
and to exit. Changing file permissions also results in swverify errors.
Known Problems
SSH does not Perform a Clean Exit after idsagent is Started
After starting idsagent from an ssh login, logging out of the agent system results in
the ssh session hanging indefinitely. As a workaround, log in by entering:
ssh -l root <machine> /usr/dt/bin/dtterm
Then type in the /sbin/init.d/idsagent start commands interactively.
Error Encountered When Installing HP-UX HIDS 4.0
The following error can appear when installing HP-UX HIDS 4.0 even though J2SE 5.0
is installed:
swinstall error: * Reading source for file information. The corequisite
"Jre15.JRE15,r>=1.5.0.02" for fileset "IDS.IDS-ADM-RUN, r=E.04.00.01"
cannot be successfully resolved.ERROR:The dependencies for fileset
"IDS.IDS-ADM-RUN,r=E.04.00.01" cannot be resolved (see previous lines). You
must resolve the above dependencies before operating on this fileset or
change the "enforce_dependencies" option to "false".
If this error is encountered and J2SE 5.0 is already installed, disable the enforcement
of dependencies by deselecting the swinstall Enforce dependency analysis errors
in agent option. Otherwise, install the latest version of J2SE 5.0 from
http://www.hp.com/go/java.
Known Problems and Limitations
Following are the known limitations with HP-UX HIDS 4.0:
Predefined Schedules and Groups are not Clearly Marked
The predefined (read-only) surveillance schedules and groups are not well distinguished
in the System Manager screens. You are allowed to modify them for the purpose of
creating a new schedule, but you cannot save the modified schedule or group over the
Known Problems, Limitations, and Fixes 15