Avatier Identity Management Suite AIMS Versin 9 System Requirements Versin 9 2603 Camin Ramn Suite 110 San Ramn, CA 94583 Phne: 800-609-8610 925-217-5170 FAX: 925-217-0853 Email: supprt@avatier.cm Page 1
Table f Cntents 1 AIMS VERSION 9 SYSTEM REQUIREMENTS... 3 1.1 AIMS SERVER - OPERATING SYSTEM, CPU, AND RAM... 3 1.2 AIMS SERVER BUILD STEPS... 3 1.3 CREATE THE AIMS SERVICE ACCOUNT... 5 1.4 DETERMINE THE LOCATION OF THE AIMS AUDIT LOGS AND AIMS CONFIGURATION FILES... 5 1.5 OPTIONAL COMPONENTS DEPENDANT ON SELECTED CONNECTORS TO TARGET SYSTEMS... 6 1.6 IMPORTANT.NET AND ASPNET CONSIDERATIONS... 6 1.7 DR. WATSON PROCESS AND AIMS... 6 1.8 IMPORTANT INFORMATION FOR WEB AGENT BASED CONNECTORS... 7 1.9 AIMS TELEPHONY SERVER... 7 Page 2
1 AIMS Versin 9 System Requirements 1.1 AIMS Server - Operating System, CPU, and RAM The AIMS architecture leverages the Micrsft.NET framewrk t deliver web services-based crss platfrm supprt and enrllment dmain perating system independence. The AIMS sftware is installed n a Windws 2003/2008 member server. The AIMS server requires: Operating System: 32 Bit Operating System (2 ptins) Windws Server 2008 and all current Micrsft Security Patches Windws Server 2003 Standard SP2 and all current Micrsft Security Patches. 64 Bit Operating System Windws Server 2008 Standard r Enterprise Editin SP1 Windws Server 2008 R2 Standard r Enterprise Editin Additinal Cmpnents: NET 4.0 Runtime ASPNET 4.0 CPU and RAM: Physical Server Physical Server Minimum: Single CPU 3.0 GHz, 4 GB RAM Physical Server Recmmended: Dual CPU 3.0 GHz, 8 GB RAM Virtual Server Virtual Server Minimum: Single CPU 3.0 GHz, 4 GB RAM Virtual Server Recmmended: Multiple CPU 3.0 GHz, 8 GB RAM Nte: Allcatin f Multiple CPUs t a virtual guest perating system des nt guarantee an imprvement in perfrmance since virtualizatin technlgies use shared CPU cycles f the hst machine. Check with yur virtualizatin system administratr fr the limitatins f yur virtual envirnment 1.2 AIMS Server Build Steps It is extremely imprtant that the server preparatin tasks be perfrmed in the fllwing rder Build the base server If Server 2003 Install IIS 6 fr server 2003 Page 3
Install.NET 4.0 Runtime Envirnment. The.NET 4.0 Runtime envirnment will autmatically install ASPNET 4.0 If Windws Server 2008 r Windws Server 2008 R2 Install IIS 7 r IIS 7.5 with the fllwing rle cmpnents and features: Cmmn HTTP Features Static Cntent Default Dcument Directry Brwsing HTPP Errrs HTTP Redirectin Applicatin Develpment ASP.NET.Net Extensibility ISAPI Extensins ISAPI Filters Health And Diagnstics HTTP Lgging Custm Lgging ODBC Lgging Security Basic Authenticatin Windws Authenticatin Perfrmance (use if installing Exchange 2007 Management Cnsle) Static Cntent Cmpressin Dynamic Cntent Cmpressin Management Tls IIS Management Cnsle IIS Management Scripts and Tls Management Service IIS 6 Management Cmpatibility IIS 6 Metabase Cmpatibility IIS 6 WMI Cmpatibility IIS 6 Scripting Tls IIS 6 Management Cnsle Install.NET 4.0 Runtime Envirnment. The.NET 4.0 Runtime Envirnment will autmatically install ASPNET 4.0 In additin, yu may want t verify that the fllwing is nt enfrced in yur envirnment fr the AIMS Server r the AIMS service accunt that will be created: Are there any grup plicies in place that will prevent annymus access t the web structure directries that require annymus access in AIMS? If yes, yu will need t make exceptins t the GPO, t allw annymus access t the needed directry structure in AIMS Has any baseline security prduct been installed n the server, either fr the Operating System, r IIS that wuld prevent annymus access? If yes, this security plicy will need adjustment. Page 4
1.3 Create the AIMS Service Accunt Create an accunt that will be used t start the Avatier Identity Management Server service, and prxy all requests fr the AIMS Suite f prducts. This accunt needs t be: A member f the "dmain admins" grup A member f the AIMS server's lcal administratr s grup Granted the "lgn as service" rights. 1.4 Determine the Lcatin f the AIMS Audit Lgs and AIMS Cnfiguratin Files AIMS Versins prir t 8.0 differ in their base installatins with regard t the light weight database architecture used t stre AIMS Audit Lg and AIMS cnfiguratin settings. AIMS versins prir t versin 8.0 stred their data in Micrsft Access frmat. Beginning with AIMS 8.0 all cnfiguratin and audit data is stred in VistaDB file frmat. After the initial installatin f the AIMS suite, migrate the cnfiguratin and audit data t a mre pwerful database engine. AIMS supprts its cnfiguratin files laded t Micrsft SQL Server versins 2003, 2005, 2008, 2010 Custmers wh have already migrated their audit lg data t MS SQL Server in a prir versin f AIMS can cntinue t write their audit lg data t their existing database. Upn an upgrade f AIMS t versin 9.0, all lcal Micrsft Access files used in the previus versins f AIMS will be cnverted t VistaDB frmat. Once yu have upgraded t 9.0 r have installed AIMS 9.0 frm scratch, please cntact supprt@avatier.cm fr cmplete instructins n migrating yur cnfiguratin and audit lg data t Micrsft SQL Server. Page 5
1.5 Optinal Cmpnents Dependant n Selected Cnnectrs t Target Systems Dependant n which prducts f the AIMS suite yu are installing, and what back end systems yu are targeting, will determine the ptinal cmpnents yu will need t install n the AIMS server. Fr mst targeted systems, AIMS will make API calls t thse systems that are available thrugh the target system s client sftware. Ltus Dmin Web Mail and Ltus Ntes ID Files passwrd reset: The Ltus Ntes Administratin sftware and Ltus Ntes client sftware must be installed n the AIMS server. Nte: The resetting f Ltus Ntes ID file passwrds can nly be effected by running AIMS n a 32 bit Micrsft Operating system. SAP Passwrd Reset: The latest SAP client sftware must be installed n the AIMS server. IBM iseries (AS400) passwrd reset: The IBM Client Access sftware must be installed n the AIMS server. If AIMS is installed n a 32 Bit Operating System, the IBM iseries Client Access sftware must be 32 Bit. If AIMS is installed n a 64 Bit Operating System, the IBM iseries Client Access sftware must be the 64 bit versin. 1.6 Imprtant.NET and ASPNET Cnsideratins AIMS is a.net applicatin running in cnjunctin with ASPNET. As web pages are accessed the first time, IIS must cmpile the cde that renders that page befre the page is served in the client s web brwser. After an initial installatin f AIMS, r after upgrading AIMS t a new build, AIMS will pre-cmpile the ASP pages t imprve verall perfrmance f the prduct. This task is perfrmed as the last item in an installatin r upgrade, and can take several minutes. 1.7 Dr. Watsn Prcess and AIMS Dr. Watsn is a prcess that is installed by default n all Windws Server perating systems that intercepts key applicatin crash dump infrmatin. In certain instances, Dr. Watsn incrrectly detects the state f an applicatin, ften a web applicatin, and prceeds t create its dump file fr analysis. While cllecting the dump infrmatin, Dr. Watsn will grab all data cntained in RAM and write the diagnstic infrmatin t disk. This has the effect f pegging the CPU utilizatin f the server, freezing access t Randm Access Memry, and causing disk cntentin while writing the dump file. Multiple instances f Dr. Watsn crash dump cllectin gives the server a "hung" appearance. It is strngly recmmended that the Dr. Watsn prcess be disabled n the server running the AIMS applicatin. Instructins fr disabling and re-enabling the Dr. Watsn service n a Windws 2003 server can be fund in the fllwing Micrsft Knwledge Base article: http://supprt.micrsft.cm/kb/188296 Page 6
1.8 Imprtant Infrmatin fr Web Agent Based Cnnectrs The fllwing infrmatin is fr custmers wh have installed and cnfigured the AIMS web agent fr the fllwing targeted systems, and whse AIMS server is restricted frm accessing the Micrsft Windws Update web site either d t firewall r ther crprate restrictins. The AIMS server uses SOAP ver SSL t cmmunicate with the installed web agents n the fllwing platfrms: IBM iseries (AS400) IBM AIX LINUX HP-UX SUN SOLARIS Micrsft s Internet Explrer running n Windws Server 2003 SP2 des rt certificate checking fr items that cmmunicate with a server ver SSL. If the ability t access the internet t check the rt certificate that is installed n the AIMS server is restricted r prhibited by crprate plicy, yu will need t turn ff rt certificate checking n the AIMS server t avid perfrmance degradatin f the prduct. T turn ff rt certificate checking (Windws Server 2003 Only: Frm the AIMS server, click the start menu, then Settings/ Cntrl Panel / Add-Remve Prgrams Select Add/Remve Windws Cmpnents Uncheck Update Rt Certificates frm the list and click the next buttn and fllw the nscreen instructins. 1.9 AIMS Telephny Server The AIMS Telephny mdule may be installed n the same physical server as the AIMS suite r n a secnd server. The Telephny server requires at the minimum: Micrsft Windws 2003 Server With Service Pack 2 Micrsft.NET v2.0 Micrsft Data Access Cntrl (MDAC) v2.8 The mst current Micrsft Updates fr all cmpnents abve The installatin f the chsen Intel Dialgic PCI/X Telephny card and Drivers IP cnnectivity t the AIMS server Page 7