==== RELEASE NOTES FOR F-Secure Linux Security 9.20 build 2520 ==== This Release Notes document is for F-Secure Linux Security. This document contains late-breaking information about the product. Please refer to the Administrator's Guide for more information. * To provide feedback or send problem report follow instructions on page: http://support.f-secure.com/ * Sales World-wide web: Your local contact: F-Secure contact: http://www.f-secure.com/solutions/ <country>@f-secure.com Anti-Virus-Sales@F-Secure.com * F-Secure USA F-Secure Europe F-Secure Inc. F-Secure Corporation 100 Century Center Court Tammasaarenkatu 7 Suite 700 San Jose, CA 95112, USA FIN-00180 Helsinki, Finland tel (408) 938 6700 tel +358 9 2520 0700 fax (408) 938 6701 fax +358 9 2520 5001 http://www.f-secure.com/ http://www.europe.f-secure.com/ Please do not call F-Secure directly if you have a local F-Secure Business Partner in your area. For an up-to-date listing of F- Secure Business Partners world-wide, see http://www.f- Secure.com/partners/. ==== Overview ==== The Linux Security 9 product is a complete Anti-Virus solution for Linux clients and servers. The product can be installed in full or command line only mode, and the installation can be further configured as a Client or Server Edition, depending on the license key code used. In the 30-day evaluation mode enabled by not using a keycode at all, the product will be configured in full-featured "Server Edition" mode. Automated, real time anti-virus scanning makes sure viruses cannot infect your Linux servers or inadvertently be moved on to susceptible Windows hosts. The firewall component makes sure viruses, hackers and other intruders are not entering the servers by using network worms. Furthermore, the intrusion prevention functionality keeps crackers from entering and opening backdoors, changing important files, system's or personal or saving unwanted files on corporate servers. By integrating to F-Secure's centralized management systems, Policy Manager
or PSB, the product will automatically notify the administrators of any security incidents or virus activity. Administrators can easily change and enforce the security policies via Policy Manager. The product also contains an API that can be used to connect to the scanner daemon directly, thus providing an easy and efficient way of integrating the product into an existing system. ==== What's New in This Release? ==== The Linux Security 9.20 supports integration with F-secure's PSB (Protection Service for Business) solution, which provide security as a service. PSB allows administrators to centrally manage the computers from any location using the PSB web portal. This version only supports PSB with Linux Security full installation. Please refer to the manual for how to install Linux Security in PSB managed mode. Fedora 8, Ubuntu 10.10 and Debian 5 Linux distributions are no longer supported. For a complete list of distributions supported by Linux Security 9.20, please see 'System Requirements'. The following problems have been fixed in 9.20.2520 since 9.14.1942 CTS-88281: Linux Security WebUI help files are out of date CTS-87264: When using Dazuko, when files under long paths are accessed it causes a kernel oops. CTS-87265: When using RedirFS, accessing files with very long path names can cause fsoasd to crash. CTS-87222: Fsavpmd uses old file descriptor for logfile log rotation. CTS-86312: Updating the product to a new version in centrally managed mode fails, if --auto flag is used. CTS-85409: The firewall pages in Linux Security WebUI show german text even if WebUI language switched to English. CTS-63950: Linux Security causes fatal error alerts on shutdown. CTS-54154: In Centrally managed mode, scheduled scanning hangs if Linux Security cannot connect to Policy Manager Server. ==== Changes in previous Linux Security 9 releases ==== What was new in Linux Security 9.14:
This is a maintenance release of Linux Security. Since the previous 9.13.1893 release the following problems have been fixed: CTS-86303: When using RedirFS, excluding external filesystems from scanning in WebUI may not work, and can prevent the filesystems from being unmounted later. CTS-86229: Certain non-fatal errors in RedirFS event handling could disable real-time scanning when RedirFS is used. CTS-85126: Firewall profiles created in Policy Manager can not be selected on the Linux Security WebUI Summary page. What was new in Linux Security 9.13: This is a maintenance release of Linux Security. It contains the following enhancements since the previous maintenance release: Support for using RedirFS based real-time scanning has been reintroduced on RHEL 5.5 32-bit and 64-bit versions. It can be used to avoid compatiblity issues between Dazuko and some third-party security products. Please see Known Problems below for more information. The following problems have been fixed in 9.13.1893 since 9.12.1818: CTS-86101: Fsavd is not able to scan some files with invalid UID and GUID values. CTS-84149: Unmounting file systems manually excluded from real-time scanning may fail on system shutdown, if RedirFS based real-time scanning is used. CTS-84045: Modifying the list of paths excluded from real time scanning in WebUI may remove some of the default path settings from the real-time scanning driver's internal path list. The following describes the changes introduced in Linux Security 9.12: Support for CentOS 6 32-bit and 64-bit versions has been added. Support for Red Hat Enterprise Linux 6 now includes versions 6.1 and 6.2. Asianux 2.0 and TurboLinux 10 Server are no longer supported. See 'System Requirements' for a complete list of supported distributions. To provide consistent real-time scanning performance on all supported distributions, the range of Linux kernel versions supported by Dazuko was extended. Dazuko is now used by default for real-time scanning on all distributions, replacing RedirFS on those which were previously using it. CPU-intensive virus database update processes are now run with a lower scheduling priority. This makes the system more responsive while database update is in progress. The Dazuko driver now provides more diagnostic information via the
proc file system. Upgrading from an earlier version: This version of Linux Security contains an updated version of Dazuko. Additionally, the real-time scanning driver changes from RedirFS to Dazuko on some distributions. To ensure that an up-to-date version of the driver is loaded, and unneccessary modules get removed in a safe manner, a reboot is strongly recommended after upgrading from any earlier release, including previous Linux Security 9 maintenance releases. Problems fixed in Linux Security 9.12.1818 from 9.11.1311: A scanning bypass vulnerability described in F-Secure Security Advisory FSC-2012-1 was fixed in this release. Please see http://www.f-secure.com/en/web/labs_global/fsc-2012-1 for further information. CTS-72508: A race condition occurring when querying fsavd version information immediately after it has been started can lead to multiple fsav processes running. CTS-83351: Potential invalid memory access in string handling in fsoasd. CTS-83722: Linux security WebUI cannot display long OID values. Configuration values exceeding 1kB in size, such as long lists of directories excluded from scanning, are shown truncated in the WebUI. CTS-85323: Actions for Suspected Files and Riskware in Realtime Scanning have incorrect translations in Japanese WebUI. CTS-84399: Both previous version and new version of fsupdate script are running after upgrade from 9.00/9.10 to 9.11. CTS-84071: LS MIB file gives a warning when loaded with Policy Manager Console 9 The following describes the new features of Linux Security since version 9.00: This release of F-Secure Linux Security introduces a new RedirFS based implementation of real-time scanning. The old dazuko based scanning will still be used on the older platforms that do not have RedirFS support. In effect, with the RedirFS based implementation several new Linux distribution versions have been added as supported platforms. Please see the System Requirements below for the exact list of supported platforms. Since RedirFS does not provide syscall hooks for kernel module loading, the Kernel Module Loading Verification feature of Integrity Checking has been removed from the product. Other than that, the Integrity Checking feature can be used for monitoring and protecting file system integrity just as before.
It is now possible to specify "nofirewall" option for the installer. This option will install the product with firewall completely disabled. This means that whatever iptables settings are in place before installation, will remain as they are. If you later decide to start using firewall, you can enable it with /opt/f-secure/fsav/sbin/fschooser tool. Problems fixed in Linux Security 9.11.1311 from 9.10.886: CTS-80892: [LS9.10] file descriptor leak in fsupdated "fsupdated" causes file descriptor leak when it write error message (ex: when aua is not running) to /var/opt/fsecure/fssp/aua_api.log. CTS-80717: [LS 9.0/9.1] fsupdated is restarted when stoping fsupdated by SIGKILL in stop_fsupdated(). "/etc/init.d/fsupdated stop" or "/etc/init.d/fsma stop" may not stop "fsupdated" but restart "fsupdated". CTS-78330: Unclean shutdown preventing updates from being applied If the database update crashes or is rebooted in the middle of an update because it hangs for other reasons, it won't recover from that. Even a reboot won't help. In this situation file: "/var/opt/f-secure/fssp/databases/incomingupdate.signal" exists and blocks updating. CTS-78931: "Maximum allowed compression ratio" MIB maximum value restriction needs adjusting (1000-> 2000) Some clean files caused "file compresion ratio too high" error during manual scan before this changing maximum compression ratio from 1000 to 2000. CTS-75746: If fsupdated crashes, it will not start again until stale pid file is removed by hand. In this situation, file: "/var/opt/fsecure/fssp/run/fsupdated.pid" was left and need to be removed manually, otherwise database updating fails. CTS-68303: there is no file which is referred by symbolic link /opt/f-secure/fssp/man/fsavd.h.3 referred by /usr/share/man/man3/fsavd.h.3 didn't exist. CTS-79064: Reboot is required after update in case from 9.00 to 9.10 Not bug but updated release notes. CTS-70352: Linux Security Command Line could not open an rpm file (related SR: 1-156611122) CTS-79404: [LS9] plugins.htm file under root directory "plugins.htm" was made under root directory. This issue was fixed by updating Aquarius database, on 26/Sep/2011 or before. CTS-80085: [LS 7.04/9.0/9.10] inconsistent for location of fsaua.pid between fsaua-ctrl and /etc/init.d/fsaua. (SR 1-466880879, 1-472049265)
fsaua might not start because "/etc/init.d/fsaua stop does not remove PID file:"/var/run/fsaua.pid". CTS-62262: DebugLogfile, debugloglevel settings not working This setting was removed from configuration file(fssp.conf). CTS-78877: Active Security Level could not be changed from WebUI. Firewall setting was not updated if extra "space" character is added to port number. Now, the space character is trimmed automatically. CTS-80799: fsaua cpu usage spikes "fsaua" might use up cpu. This issue would be related to CTS- 80847. CTS-63978: Scanning errors reported upstream as Security Alerts. Now, scanning errors are reported as "Error" alerts intead of "Security" alerts as well as windows clients. CTS-67599: fsaua-ctrl stop doesn't remove fsaua.pid Same issue as "CTS-80085" CTS-81038: [LSFE9.10] Setup does not set MIB version correctly (SR# 1-473216652) On central management mode, policy settings under "F-Secure Security Platform 2.50" did not work, and client settings were not updated. CTS-80904: [LSFE9.10] Integrity Checking icon display problem/missing (SR# 1-474654622) Integrity Checking could not display a modified icon on the WebUI of LSFE9.10.886 in case of file modification. There was no "INTEGRITY_MODIFIED.png" file in the status directory as below. "/opt/f-secure/fsav/tomcat/webapps/fsecure/web-inf/lib/themes/fsecure/img/status/" CTS-79305: Kernel panic with Oops 0010 code in LSFE 7.04 when running CA Access Control after staring LSFE first (SR# 1-464796931) Now, RedHat EL 5 uses "redirfs" hooker instead of "dazuko" hooker. CTS-80847: [LSCE 9.10] fsupdated daemon is not restarted during upgrade from LSCE 9.00. CTS-60962: DOC/man fsav/missing information about "none" and "report" action. Manaul page is updated. Problems fixed in Linux Security 9.10.886: CTS-59916: SELinux error on installation/uninstallation.(red Hat EL5) CTS-59945: DOC: System requirements does not include Miracle/Turbo. CTS-61438: DOC: List of used system resources has been updated in manual. CTS-63675: Sending bogus commands to the daemon via the socket,
crashes fsavd CTS-72824: redirfs hooking may hang to get symbolic lik using readlink(/proc/pid/exe) CTS-75281: [Documentation] "--show-scan-time" option is not mentioned in fsav man page. CTS-75283: [Documentation] "Appendix H: Config Files" has old information CTS-77093: [Linux Security 9.10 Beta] fsav-config shows error message of awk. CTS-77190: During product version upgrade, old databases were deleted causing a full database set to be downloaded instead of just latest changes. SR:1-395600216: dbupdate return code with fsdbupdate9.run always 2. The return code is now output correctly. * F-Secure Update Daemon (fsupdated) does not log into syslog by default anymore and unneccessary log output has been removed. * Man pages are no longer in the pdf manual. * Log file for fsupdated (fsupdated.log) is now collected for diagnostics by fsdiag command. * When upgrading from Linux Security 7, a reboot is now needed before real time scanning becomes active. This is because the newer dazuko shipped with this version is not fully compatible with the old one and unloading the old version is known to possibly cause a system hang. Note that this affects only those older Linux distributions where RedirFS cannot be used. However, since removing the old dazuko module is risky, the installer will recommend the administrator to reboot the computer on any upgrade from Linux Security 7. Problems fixed in Linux Security 9.00.907: CTS-75746: If fsupdated crashes, it will not start again until stale pid file is removed by hand. SR:1-171690342: FSMA SMTP protocol parsing improved so that it will not crash when receiving SMTP reply in two or more parts Linux Security 9 introduces following new features since the previous release: Improved scanning capabilities: This version includes a new scanning engine that brings more up-to-date scanning capabilities into the product and enhances the scanning performance. The new engine replaces the AVP engine used in previous versions.
New database updating mechanism: A new database update daemon, fsupdated, has been introduced. The daemon stays in the background and checks updates automatically. No configuration or administration are needed as this is a totally automated process. Why the version number jump from 7 to 9? The version number was changed to bring it in line with other F-Secure corporate products. ==== System Requirements ==== F-Secure Linux Security should be installed on a computer that meets the following minimum system requirements: System requirements: Processor: 686 Memory (command-line only): 512 MB RAM (1024 MB recommended) Memory (full install): 1024 MB RAM Disk space: At least 3GB recommended Having sufficient swap memory is highly recommended. Required components: Linux kernel 2.6 or later glibc 2.3.4 or later 32-bit compatibility libraries on 64-bit distributions The following 32-bit Linux distributions are supported: Asianux 3.0 CentOS 4 CentOS 5 CentOS 6 Debian 6.0 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6.0, 6.1, 6.2 SUSE Linux Enterprise Server 9 SUSE Linux Enterprise Server 10 SUSE Linux Enterprise Server 11 Turbolinux 11 Server Ubuntu 8.04 (Hardy Heron) Ubuntu 10.04 (Lucid Lynx) The following 64-bit (AMD64/EM64T) distributions are supported with 32-bit compatibility packages: Asianux 3.0 CentOS 5 CentOS 6 Debian 6.0 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6.0, 6.1, 6.2 SUSE Linux Enterprise Server 9 SUSE Linux Enterprise Server 10 SUSE Linux Enterprise Server 11 Turbolinux 11 Server Ubuntu 8.04 (Hardy Heron) Ubuntu 10.04 (Lucid Lynx)
There may be some prerequisites that need to be fulfilled in order to let the product install successfully on your Linux distribution. Please consult the following web page for the latest available information: http://community.f-secure.com/t5/end-point-security/preinstallation-checklist-for-f-secure-linux-security/td-p/4125 ==== Installation Instructions ==== IMPORTANT INFORMATION - READ THIS BEFORE INSTALLING use To completely disable parts of the product (e.g. the firewall), the command-line tool /opt/f-secure/fsav/sbin/fschooser. Quick installation instructions: 1. Extract the installation file: tar zxvf f-secure-linux-security-9.20.2520.tgz 2. Make sure that the installation file is executable: chmod a+x f-secure-linux-security-9.20.2520 3a. Run the command:./f-secure-linux-security-9.20.2520 3b. To install the command line only version, run the command:./f-secure-linux-security-9.20.2520 --command-line-only This will start the installation. When the installation is completed, Linux Security 9 is running with default settings. You can do further configuration (change Web UI access, default language, input keycode, etc.) by running /opt/f-secure/fsav/fsav-config Note! You may need to reboot your computer after upgrade from previous Linux Security installation on some Linux distributions. This happens because the dazuko kernel module in previous Linux Security is not compatible with the one in this new version, and unloading the previous version might hang the computer. ==== Known problems ==== WebUI login does not work on 64-bit Ubuntu 10.04.
Because 64-bit Ubuntu 10.04 does not ship the 32-bit versions of PAM modules anymore, WebUI login will not work. As a workaround, please copy /lib/security/pam_unix.so from a 32-bit Ubuntu 10.04 to /lib32/security/pam_unix.so on the 64-bit computer. If you do not have a 32-bit Ubuntu 10.04 installation available, you can run the following commands: # wget http://security.ubuntu.com/ubuntu/pool/main/p/pam/libpammodules_1.1.1-2ubuntu5.4_i386.deb # dpkg -x libpam-modules_1.1.1-2ubuntu5.4_i386.deb tmp # cp tmp/lib/security/pam_unix.so /lib32/security Note that the actual package name might be different if there has been upgrades to the package. Also note that you will not get security updates automatically to the PAM module installed like this. WebUI login does not work on 64-bit CentOS 6 Because 64-bit CentOS 6 does not have the 32-bit versions of PAM modules, WebUI login will not work. As a workaround, please install 32-bit pam modules. Run following commands: # rpm -qa pam (This will give version number of 64-bit pam installed) e.g pam-1.1.1-10.el6.x86_64 # yum install pam-1.1.1-10.el6.i686 (replace x86_64 with i686 from the output of above command) This will install 32-bit pam libraries in 64-bit CentOS 6 Note that actual package version might be different if there has been upgrades to the package. Using Linux Security simultaneously with Computer Associates Access Control (CAAC) may cause system instability or degraded performance The Computer Associates Access Control product is known to conflict with the Dazuko driver which is used by default for real-time scanning by Linux Security. On some distributions, such problems can be avoided by using RedirFS based real-time scanning instead. Support is provided for configuring Linux Security and CAAC to coexist on RHEL 5.5 32-bit and 64-bit versions. Please see http://community.f-secure.com/t5/end-point- Security/Placeholder/td-p/10581 for details. ==== Technical Support ==== To provide feedback or send problem report follow instructions on page:
http://support.f-secure.com/ ==== F-Secure Web Club ==== F-Secure Web Club is open to all F-Secure customers. Web Club pages contain a great deal of useful information on latest software versions, user documentation, release notes, etc. To connect to the Web Club directly from within your Web browser, go to: http://www.f-secure.com/webclub/ ==== Copyrights ==== For copyright information, please refer to the About page in the Web User Interface, OR files /opt/f-secure/fsav/about and /var/opt/f-secure/fssp/databases/*/license*.txt ==== Trademarks ==== F-Secure and the triangle symbol are registered trademarks of F- Secure Corporation and F-Secure product names and symbols/logos are either trademarks or registered trademarks of F-Secure Corporation. ==== End of RELEASE NOTES ====