Specifications
19
ObjectDirectoryMaintenance
MaintenanceIntroduction
Tokeepthedatabasecleanandhealthy,maintenanceisrequiredonaregularbasis.Thismaintenancecanbe
donemanuallyusingtheEndpointEncryptionManager,or,withtheEEPCcommandLineTool(SBADMCL),
whichisthepreferredwayforlargerObjectDirectories.
Thisguidedescribestheprocessesneededformaintenance.ItiswrittenforEndp
ointEncryption
administrators.
NOTE:Thesearegenericrecommendationsbasedonexperiencebutnotalwaysbesuitableforyourspecific
environment.Fordatabasemaintenanceandperformance,itisalwaysrecommendedtoengageMcAfee
Professionalservicespriortoimplementinganyofthesesuggestions.Itispossibleonalreadyi
nstalled
environmentstohaveaMcAfeeprofessionalperformconsultancyandprovidea“healthcheck”onthesetup
andperformancesettingsoftheObjectDirectory
Environment
ThisguideappliestoMcAfeeEndpointEncryptionV5andup,howevermanystepsinthisguidecanbeapplied
toV4(build4770).
Auditmaintenance
Auditcangrowunlimitedinthedatabase.Thiscanslowdownthedatabasedramatically.TheEndpoint
Encryptionadministratorhastomakesurethattheauditiscleanedupeveryyearoreveryhalfyeardepending
onthedatabaseperformance.FormoreinformationonthecommandlinetoolSBADMCL.exeorits
commandsple
aseseetheEndpointEncryptionScriptingToolUserGuide,whichisfoundinmostnormal
installationsoftheEndpointEncryptionManager.
ExtractingandClearingAuditfromtheDatabase
Theauditfromusersandsystemsneedstobeclearedatleastonceayearforsmallerimplementationsand
frequentlyforlargerdeploymentsbecauseitgrowsfast.Heavilyusedobjectssuchasanadministrator’s
accountoruserobjectfrequentlyusedbyascriptarelikelytobecommonlargeauditcreators.
Thenee
dtoclearauditscanvarydependingonconfiguration,usageandrequirements.However,theSecurity
Managementteamshoulddecidewhentocleartheaudit.Inlaterversionsofthetool,theClearDaysOld
commandwasadded.Thisoptiongivestheadministratorthepossibilitytoclearauditsthatare,forexample,
90da
ysandolder.ThisoptionmustbeusedinsteadoftheClearoption,becausetheClearoptionwilloverride
theClearDaysOldoptionifusedtogether.
Theauditwillalwaysbeexportedbeforeitisdeleted.Thiswillgivetheadministratorthepossibilitytolook
backatolderauditsusingMicrosoftEx
celorsimilartools.
ClearingtheAudit
SBADMCLisusuallyrunfromthedirectorywheretheEndpointEncryptionManagerisinstalled.Anadmin
accountwithhigh‐levelcredentialswillbeneededforthescript.
Someofthecommandsneededbelowaredatabaseintensiveprocesses,sorunthesecommandduringnon
workinghoursonly,or,doitinmor
econtrolledsessions(onegroupatatimeforexample)duringdaytimeifthe
groupsaresmall.