User guide

11
entered, answer the questions for the OS type, client type, and descriptive name for the policy. Once that information is
entered, it will be imported for use.
[n] Assign a Sensor Name to Client(s)
The “n” option allows the user to assign custom sensor names to clients. Sensor names are displayed in SecurityCenter
or LCE Manager to identify LCE Client sensors with names identifiable in the organization. By default, the sensor name is
set to the DNS hostname if identified from the LCE server, otherwise it is listed as “unknown”. This option allows for
customization of one or more sensor names to something meaningful for users within the organization.
When selected, a list of available clients is displayed. Select the IP address or ID of the client(s) followed by “0”. Then
enter the sensor name to use for the selected client(s). Once the sensor name is entered, the user is returned to the main
menu and the changes will be applied on exit.
[x] Remove a Client
Selecting “xfrom the main menu begins the process to remove a client. When selected, a list of all available clients is
listed. Enter the IP address or ID of the client(s) to remove. Once completed, select “0to save the changes. On exiting
the LCE Client Manager, the selected clients will be removed from the Policy Map and no longer be accepted by the LCE
server as valid clients.
[q] Exit
The “qcommand will cleanly exit the LCE Client Manger, apply pending changes to the Policy Map file, and reload the
Policy Map to apply the new changes to the running file.
LCE Client Manager Command Line Options
The options for the LCE Client manager can also be invoked on the command line as in, for example:
/opt/lce/daemons/lce_client_manager --remove-client <client ID> (to remove a client). The
command /opt/lce/daemons/lce_client_manager h will display all the available options that can be invoked
from the command line.
Usage Example (Interactive Mode)
Shown below is an example of how to copy a default policy, customize it, and use it for LCE Client installations. The
RHEL LCE Client policy will be copied and customized for use on RHEL systems running the Apache Web server, where
it will monitor any file changes (recursively) in the configuration directory (/etc/https).
# /opt/lce/daemons/lce_client_manager
**********************************************
* LCE Client Manager 1.0
* Please select an option from the menu below
**********************************************
[g] Grant authorization to a client or clients to connect to LCE
[r] Revoke a client or clients access to connect to LCE
[d] Display clients by policy assignment
[p] Display available policies
[a] Add a new policy
[c] Copy a policy
[m] Modify an existing policy
[s] Assign a policy to a client or clients
[v] Assign a client or clients to a new LCE server
[i] Import a file as a policy
[n] Assign a custom sensor name to a client or clients
[x] Remove a client
[q] Exit