HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
Agent and System Manager cannot communicate with each other
(No errors are being generated by the HP-UX HIDS processes and everything seems to be running
fine otherwise.) See also “No Agent Available” (page 221).
Make sure the check sums on the following two files are identical:
On the Administration system, run:
/usr/bin/cksum /etc/opt/ids/certs/admin/cacert.pem
On the Agent system, run:
/usr/bin/cksum /etc/opt/ids/certs/agent/cacert.pem
If the results are different, the Administration and Agent certificates are not signed by the
same trusted certificate authority and the communication handshake fails.
To correct this, regenerate the agent certificate and install the new certificate bundle on the
agent system. Verify that the check sums match.
If there is a firewall positioned between the administration system and an agent system, be
sure the HP-UX HIDS ports are enabled. See “Working with Firewalls” (page 40).
If you are using NIS on these systems, it is likely the port information is not being retrieved
from your /etc/services file.
Inform the NIS Master about the HP-UX HIDS ports. See “Working with NIS” (page 40).
Launch the System Manager and verify that the agent is now available.
Increase the response timeout in the Preferences screen. See “General Preferences” (page 105).
Increase the value for IDS_SSL_TIMEOUT in the agent configuration file, ids.cf. See
“Remote Communication Configuration” (page 195).
If the agent system is multihomed, make sure the agent and administration systems are
properly configured. See “Configuring a Multihomed Agent System” (page 35).
If the administration system is multihomed, make sure the agent and administration systems
are properly configured. See “Configuring a Multihomed Administration System” (page 37).
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds
is present
If your lsdev result shows /dev/idds is present, and yet the idsagent debug-enabled
log file (run with /opt/ids/bin/idsagent -d -l log_file_name) complains about
idds not being enabled, it is probable that there is an installation or kernel-build error. To
verify this, run the following on your machine:
$ /usr/sbin/kctune -q enable_idds
There are three possible results:
If the value of the kernel tunable enable_idds is 0, that means IDDS is not enabled.
You’ll need to run the following to rebuild the kernel:
$ /usr/sbin/kctune -s enable_idds=1
$ mk_kernel
Then, reboot the machine and verify again with:
$ /usr/sbin/kctune -q enable_idds
If the result is enable_idds=1, then the kernel was built correctly with idds enabled.
The problem lies elsewhere. Contact HP Support.
Agent does not start on system boot
When the agent system boots, the Starting HP-UX HIDS agent startup entry displays
“SKIP” or FAIL”.
SKIP means the communications certificates have never been generated for the agent system.
214 Troubleshooting