Change Guardian 6.2.1.0 Release Notes

May 2022

Change Guardian 6.2.1.0 includes security fixes, usability improvements, and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us to ensure that our product meets all your needs.

The documentation for this product is available on the Micro Focus website in HTML and PDF formats on a page that does not require you to log in. If you have suggestions for documentation improvements, click comment on this topic at the bottom of any page in the HTML version of the documentation posted at the Change Guardian Documentation page. To download this product and patches, see the Micro Focus Downloads website.

1.0 What is New?

The following issues have been resolved in this release:

1.1 OpenSSL Fix

This release resolves an issue where a vulnerability in OpenSSL certificate parsing leaves systems open to denial-of-service attacks.(CVE-2022-0778)

2.0 Software Fixes

The release includes software fixes that resolve several previous issues:

2.1 Change Guardian Web Login Page does not Allow Pasting of Password

Issue: The Change Guardian Web Login page does not allow pasting of password and the users need to type the passwords manually. (Defect 483062)

Fix: The users can use the ‘paste’ functionality to enter the passwords in the web login page.

2.2 Change Guardian Web Login Page does not Allow Passwords with Specific Special Characters

Issue: Change Guardian Web interface login page does not allow/accept passwords with the special character ‘&’. (Defect 482023)

Fix: Passwords with the special character ‘&’ are accepted.

2.3 License Import does not Reflect the ‘Never Expires’ Key

Issue: When a user tries to import an application license key with the expiry date set to ‘Never Expires’, the license import does not update the License Valid Upto timelines or shows an older date.(Defect 495286)

Fix: Application license imports with License Valid Upto option reflecting ‘Never Expires’.

2.4 License Import Fails if the File Name contains Space

Issue: When a user tries to import a license with file name containing space as a character, the file is invalidated and the import fails.(Defect 494035)

Fix: License with file name containing space imports successfully.

2.5 Auditing Flags are Missing in ACE SACL

Issue: When the user tries to monitor policy, the auditing flags <\flag_value> in ACE SACL for <directory_path> report error.(Defect 495315)

Fix: The auditing flags are now properly reporting SACL checks.

3.0 System Requirements

For more information about hardware requirements, supported operating systems, and browsers, see the System Requirements for Change Guardian 6.2.

4.0 Installing Change Guardian 6.2.1.0

The steps for the installation of 6.2.1.0 are same as that of 6.2. For more information about the installation procedure, see Change Guardian Installation and Administration Guide.

5.0 Upgrading to Change Guardian 6.2.1.0

Traditional Installer: You can upgrade to Change Guardian 6.2.1.0 from Change Guardian 6.2, 6.2.0.1, 6.2.0.2, 6.1, 6.1.0.1, or 6.0.

Appliance Installer: You can upgrade to Change Guardian 6.2.1.0 from Change Guardian 6.2, 6.2.0.2, 6.1, or 6.0.

NOTE:When you apply appliance patches on Change Guardian appliance, you will see a conflict for 2 OS patches (SUSE-SU-2021:3649, SUSE-SU-2022:0323). Ensure to select Solution 1 to perform deinstallation of packages to proceed with upgrade for the conflicts.

For information about the upgrade procedure, see Upgrading Change Guardian in the Change Guardian Installation and Administration Guide.

6.0 Known Issues

Micro Focus strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

6.1 UNIX Agent goes Offline after Installing on SLES Platform

Issue: When you import and assign UNIX policies using the latest version of policy editor, the Change Guardian Agent for UNIX 7.6.4.1 shows offline after few hours.(Defect 500024)

Workaround: Delete the imported policies that were created using the previous version of Policy Editor and recreate them using the current version.

6.2 Windows Agent Upgrade to 6.2.x.x fails

Issue: When you install Windows Agent 6.1, 6.1.0.1, or 6.0 and upgrade it to a newer version, the upgrade fails with the message Failed to install NetIQChangeGuardianAgent.msi. (Defect 479131)

Workaround: Remove/delete assets from the Agent Manager. Add the assets again and install a new version of the agent package. After installing the new version, reassign the policy to the Agent.

6.3 Common Appliance Framework Page Shows Error RemoteLookupFailureException

Issue: Upon launching, the CAF page fails to load and shows RemoteLookupFailureException error.(Defect 379090)

Workaround: Restart the datamodel service on the Change Guardian Appliance server with: rcvabase-datamodel restart. Ensure that it shows active (running) with: rcvabase-datamodel status and open the Change Guardian Appliance Management Console Page with: https://IPAddressOfServer:9443.

6.4 Events Do Not Show Command Line Details

Issue: If a process is terminated within a second of its creation, the Change Guardian Agent for Windows cannot collect the command line details such as Command Line, Command Line Length, Command Line Parameter, and Command Line Parameter Length. Events that are generated for these processes do not display the command line details.(Defect 292163)

Workaround: None.

6.5 FIPS Enabled Solaris Agent Shows Offline in Agent Health Tab

Issue: When you assign policies to Solaris UNIX Agent machine, the VigilEntAgent service may go down. (Defect 353077)

Workaround: When the server receives the next heartbeat, the Agent turns online and sends events normally.

6.6 Appliance Reports Errors During Boot

Issue: When the Change Guardian appliance boots after installation, the appliance reports that some services have failed to start: (Defect 174273)

Failed to start LSB: NetIQ LDAP Expander.
Failed to start LSB: Sentinel Server.

Workaround: The services start correctly. You can ignore such error messages.

6.7 Launching Alerts Dashboard Displays Conflict Error Message in FIPS Mode

Issue: After installing or upgrading Change Guardian in FIPS mode, when you launch Alerts Dashboard for the first time, a conflict error message is displayed. (Defect 302233)

Workaround: Refresh the page and ignore the conflict error message as there is no functionality impact.

6.8 Events Do Not Show the Windows Process Description

Issue: The assembly path for certain Windows processes is not available to the Change Guardian Agent for Windows, due to which the agent cannot collect the Windows process description. Events that are generated as a result of such processes do not display the process description.(Defect 290154)

Workaround: None.

6.9 Internet Explorer 11 Does Not Save Events Dashboard Customizations

Issue: If you use certain versions of Internet Explorer 11, such as versions 11.0.10240.16384 and 11.1098.17763.0, to view and modify Events Dashboard settings, Internet Explorer does not display the saved settings.(Defect 155003)

Workaround: Use a different web browser that is supported.

6.10 Events Dashboard Appears Blank

Issue: If you click DASHBOARDS > EVENTS, the Events Dashboard is displayed. If you click on DASHBOARDS again, the Event Dashboard appears blank.(Defect 189391)

Workaround: Refresh the page to view the Events Dashboard.

7.0 Legal Notice

For information about Micro Focus legal notices, see https://www.microfocus.com/about/legal/

Copyright © 2022 Micro Focus or one of its affiliates.