Download
Abstract
This fix upgrades the IBM Global Security Kit (GSKit) provided with IBM Tivoli Monitoring (ITM).
Download Description
The following patches are provided to address security vulnerabilites listed in the IBM Tivoli Monitoring Security Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21673715.
The patches upgrade the GSKit version to the level listed below:
Patch Name | IBM Tivoli Monitoring Version | Installer Lvl / Ver | Upgraded GSKit Version |
6.2.2-TIV-ITM-FP0009-IV56302 | 6.22 | 06.22.xx.yy | 7.0.4.50 |
6.2.3-TIV-ITM-FP0005-IV56302 | 6.23 | 06.23.xx.yy | 7.0.4.50 |
6.3.x-TIV-ITM-GSK-8.0.50.20-IV58966 | 6.30 | 06.30.xx.yy | 8.0.50.20 |
The updated GSKit will also be included in the following Fix Pack: 6.3.0-TIV-ITM-FP0003. Refer to this link for status on availability.
IBM Tivoli Monitoring components and agents built for ITM 6.22 and 6.23 are shipped with GSKit version 7.
IBM Tivoli Monitoring components and agents built for ITM 6.30 are shipped with GSKit version 8.
To determine which patch to install, the following local or remote methods can be used.
Determine locally which patch to install
UNIX/Linux system:
Make sure that the environment variable CANDLEHOME is set to the IBM Tivoli Monitoring installation directory. The command to determine the version of the IBM Tivoli Monitoring installation would be:
$CANDLEHOME/bin/cinfo -t gs
The first two values after "Installer Lvl:" in the heading of the "cinfo" output indicates which ITM version is installed and therefore which patch should be used. In the example below, the 6.3.x-TIV-ITM-GSK-8.0.50.20-IV58966 should be used since the Installer Lvl starts with 6.30:
*********** Thu May 29 14:00:57 CDT 2014 ******************
User: root Groups: system bin sys security cron audit lp idsldap itmgroup
Host name : hostname1 Installer Lvl:06.30.02.00
CandleHome: /opt/IBM/ITM
Version Format: VV.RM.FF.II (V: Version; R: Release; M: Modification; F: Fix; I: Interim Fix)
***********************************************************
...Product inventory
PC PRODUCT DESC PLAT VER BUILD INSTALL DATE
gs IBM GSKit Security Interface aix523 08.00.50.05 d2031a -
gs IBM GSKit Security Interface aix526 08.00.50.05 d3221a -
Windows system:
The command to determine the version of the IBM Tivoli Monitoring endpoint would be:
kincinfo -t gs
The first four digits after "Installer : Ver:" in the heading of the "kincinfo output indicates the IBM Tivoli Monitoring version. In the example output below, the 6.3.x-TIV-ITM-GSK-8.0.50.20-IV58966 should be used since the Installer : Ver: starts with 0630:
************* Thursday, May 29, 2014 3:01:55 PM *************
User : Administrator Group : NA
Host Name : hostname2 Installer : Ver: 063002000
CandleHome : C:\IBM\ITM
Installitm : C:\IBM\ITM\InstallITM
*************************************************************
...Product Inventory
PC APPLICATION SUPPORT DESC PLAT APP VER BUILD INSTALL DATE
GS KGS(32-bit) GSK/IBM GSKit Security Interface WINNT 08.00.50.05 d4106a 20140528 0923
Determine remotely which patch to install
UNIX/Linux Monitoring Enterprise Server system:
Ensure that the environment variable CANDLEHOME is set to the IBM Tivoli Monitoring installation directory for this Monitoring Enterprise Server. The commands to determine the versions of the IBM Tivoli Monitoring endpoints would be:
$CANDLEHOME/bin/tacmd login -t 1440 -s <server>
$CANDLEHOME/bin/tacmd listsystems -t lz ux nt
The version information (third field) for an endpoint listed indicates the IBM Tivoli Monitoring version. In the example below it is 6.22.
Managed System Name Product Code Version Status
systema:LZ LZ 06.22.09.00 Y
Windows Monitoring Enterprise Server system:
The command to determine the versions of the IBM Tivoli Monitoring endpoints would be:
tacmd login -t 1440 -s <server>
tacmd listsystems -t lz ux nt
The version information (third field) for an endpoint listed indicates the IBM Tivoli Monitoring version. In the example below there are three ITM versions across the systems.
Managed System Name Product Code Version Status
systema:KUX UX 06.30.02.00 Y
systemb:LZ LZ 06.23.05.00 Y
Primary:systemc:NT NT 06.22.09.00 Y
Prerequisites
The prerequisite level for this fix is as follows:
- IBM Tivoli Monitoring, version 6.2.2 Fix Pack 9 (6.2.2-TIV-ITM-FP0009)
- OR -
- IBM Tivoli Monitoring, version 6.2.3 Fix Pack 5 (6.2.3-TIV-ITM-FP0005)
- OR -
- IBM Tivoli Monitoring, version 6.3.0 Fix Pack 2 (6.3.0-TIV-ITM-FP0002)
Product Synonym
ITM
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg24037451