Avatier Identity Management Suite



Similar documents
AIMS Installation and Licensing Guide

MS SQL Server Database Management

Creating a New Database and a Table Owner in SQL Server 2005 for exchange@pam

Password Reset Server Installation Guide Windows 8 / 8.1 Windows Server 2012 / R2

Secret Server Installation Windows 8 / 8.1 and Windows Server 2012 / R2

Video Administration Backup and Restore Procedures

How To Create An Easybelle History Database On A Microsoft Powerbook (Windows)

Training module 2 Installing VMware View

FaxCore Ev5 Database Migration Guide :: Microsoft SQL 2008 Edition

Avatier Identity Management Suite

Table of Contents SQL Server Option

In this topic we will cover the security functionality provided with SAP Business One.

NSi Mobile Installation Guide. Version 6.2

Moving the TRITON Reporting Databases

1 of 10 1/31/2014 4:08 PM

QUANTIFY INSTALLATION GUIDE

Configuring User Identification via Active Directory

Integrating LANGuardian with Active Directory

ECA IIS Instructions. January 2005

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

FaxCore 2007 Database Migration Guide :: Microsoft SQL 2008 Edition

Migrating helpdesk to a new server

Installation Guide v3.0

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

WhatsUp Gold v16.3 Installation and Configuration Guide

Moving a Romexis Database to an Existing SQL Instance

Click Studios. Passwordstate. Installation Instructions

GO!NotifyLink. Database Maintenance. GO!NotifyLink Database Maintenance 1

Delegated Administration Quick Start

0651 Installing PointCentral 8.0 For the First Time

Secret Server Installation Windows Server 2008 R2

SQL Server 2008 R2 Express Edition Installation Guide

Upgrading from MSDE to SQL Server 2005 Express Edition with Advanced Services SP2

RSA Security Analytics

Security Guidelines for MapInfo Discovery 1.1

LT Auditor Windows Assessment SP1 Installation & Configuration Guide

Configuring.NET based Applications in Internet Information Server to use Virtual Clocks from Time Machine

Setup and configuration for Intelicode. SQL Server Express

E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide. E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide

aims sql server installation guide

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

Installation Steps for PAN User-ID Agent

Setting up an MS SQL Server for IGSS

WhatsUp Gold v16.1 Installation and Configuration Guide

Secure Messaging Server Console... 2

TECHNICAL TRAINING LAB INSTRUCTIONS

Microsoft SQL Server Security Best Practices

How to Copy A SQL Database SQL Server Express (Making a History Company)

Metalogix SharePoint Backup. Advanced Installation Guide. Publication Date: August 24, 2015

MadCap Software. Upgrading Guide. Pulse

WebSpy Vantage Ultimate 2.2 Web Module Administrators Guide

Moving the Web Security Log Database

DigiVault Online Backup Manager. Microsoft SQL Server Backup/Restore Guide

Cloud Services ADM. Agent Deployment Guide

Server Manager Help 10/6/2014 1

System Administration Training Guide. S100 Installation and Site Management

Click Studios. Passwordstate. Installation Instructions

Contents CHAPTER 1 IMail Utilities

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Lepide Active Directory Self Service. Configuration Guide. Follow the simple steps given in this document to start working with

Secret Server Installation Windows Server 2012

NovaBACKUP xsp Version 15.0 Upgrade Guide

WhatsUp Gold v16.2 Database Migration and Management Guide

SonicWALL CDP 5.0 Microsoft Exchange User Mailbox Backup and Restore

Using Microsoft Windows Authentication for Microsoft SQL Server Connections in Data Archive

System Area Management Software Tool Tip: Integrating into NetIQ AppManager

WhatsUp Gold v16.2 Installation and Configuration Guide

Version 14.5 Inmagic DB/Text for SQL Administrator s Guide [12/09/13]

ProSystem fx Document

Click Studios. Passwordstate. Installation Instructions

Sitecore Ecommerce Enterprise Edition Installation Guide Installation guide for administrators and developers

Installing CaseMap Server User Guide

PriveonLabs Research. Cisco Security Agent Protection Series:

SpectraPro. SLQ Server databases

National Fire Incident Reporting System (NFIRS 5.0) Configuration Tool User's Guide

Wireless Network Configuration Guide

Backup/Restore Microsoft SQL Server 7.0 / 2000 / 2005 / 2008

Requirements & Install. Module 2 Single Engine Installation

WhatsUp Gold v16.1 Database Migration and Management Guide Learn how to migrate a WhatsUp Gold database from Microsoft SQL Server 2008 R2 Express

Basic SQL Server operations

LDAP User Guide PowerSchool Premier 5.1 Student Information System

Deploying System Center 2012 R2 Configuration Manager

File Auditor for NAS, Net App Edition

Advantage for Windows Copyright 2012 by The Advantage Software Company, Inc. All rights reserved. Client Portal blue Installation Guide v1.

APNS Certificate generating and installation

These notes are for upgrading the Linko Version 9.3 MS Access database to a SQL Express 2008 R2, 64 bit installations:

Information Systems Services. Configuring Entourage 2008 to connect to the University s Exchange service Version 2.2 February 2009

Active Directory Authentication Integration

LifeSize Control Installation Guide

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Installation Guide

Tutorial: How to Use SQL Server Management Studio from Home

Sophos Mobile Control Installation guide. Product version: 3.5

Migrating MSDE to Microsoft SQL 2008 R2 Express

HELP DOCUMENTATION SSRPM WEB INTERFACE GUIDE

Content Filtering Client Policy & Reporting Administrator s Guide

Upgrade ProTracker Advantage Access database to a SQL database

Active Directory Management. Agent Deployment Guide

Approved SCOM Health Check Report Installation Guide

SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit

Lepide Software. LepideAuditor for File Server [CONFIGURATION GUIDE] This guide informs How to configure settings for first time usage of the software

Transcription:

Avatier Identity Management Suite Migrating AIMS Configuration and Audit Log Data To Microsoft SQL Server Version 9 2603 Camino Ramon Suite 110 San Ramon, CA 94583 Phone: 800-609-8610 925-217-5170 FAX: 925-217-0853 Email: support@avatier.com Page 1

Table of Contents 1 AIMS 9.0 INSTALLATION OR UPGRADING FROM A PREVIOUS VERSION OF AIMS... 3 2 PREPARING THE AIMS SERVER FOR MICROSOFT SQL SERVER... 4 2.1 RUNNING THE AIMSSQLSERVER SCRIPT TO CREATE THE AIMS CONFIGURATION DATABASES.. 4 3 CONFIGURING AIMS TO USE THE MICROSOFT SQL SERVER DATABASES... 7 3.1 FOR AUDIT LOG DATA... 7 3.2 FOR USERID MAPPING DATA... 8 3.3 FOR AIMS CONFIGURATION DATA... 9 3.4 FOR AIMS DIRECTORY SHADOW REPOSITORY (DSR) DATA... 10 3.5 FOR AIMS GROUP ENFORCER DATA... 11 3.6 TESTING THE CONNECTIONS... 11 4 MIGRATING THE VISTADB FILES TO MS SQL SERVER... 12 4.1 TO MIGRATE THE MAPPED IDS DATA... 12 4.2 MIGRATING AIMS CONFIGURATION, DSR, GROUP ENFORCER, AND AUDIT LOG DATA... 13 4.2.1 When the services are stopped... 13 4.2.2 When the migration is complete... 13 Page 2

1 AIMS 9.0 Installation or Upgrading From a Previous Version of AIMS On a default AIMS 9.0 installation, AIMS configuration and audit data is stored locally on the AIMS server in VistaDB format. VistaDB is a lightweight database engine that supports both 32 bit and 64 bit versions of AIMS 9.0. AIMS versions prior to version 8.0 used Microsoft Access database files. Microsoft Access files cannot be accessed by AIMS 9.0, therefore, VistaDB has been selected as the default local database engine for AIMS 9.0 providing the most flexibility in meeting the varying needs of Avatier's customers. If you are upgrading from a previous version of AIMS that stored its configuration data in Microsoft Access file format, the data will automatically be converted to the VistaDB format during the upgrade process. Page 3

2 Preparing the AIMS Server for Microsoft SQL Server The following are the requirements for using MS SQL Server as the database repository for AIMS Configuration and Audit Log data: Port 1433 must be opened between the AIMS server and the MS SQL Server. The Microsoft SQL Server must be running in Mixed (hybrid) Mode, meaning it needs to accept both Windows and SQL Server Logons. You must be running AIMS Version 9.0. 2.1 Running the AIMSSQLSERVER Script to Create the AIMS Configuration Databases In the aims/admin directory (default path = c:\inetpub\wwwroot\aims\admin) is a file called AIMSSQLSERVER.SQL. Have your SQL DBA review the contents of this file and make any needed changes to database names that will be created during the execution of this script. Have the SQL DBA access the MS SQL Server with an account that has the privileges to create databases on the server, and copy the contents of the AIMSSQLSERVER.SQL file into a query window inside of SQL Management Studio. Execute the query to create the AIMS databases. By default, the script creates the following databases: Database AIMSAUDIT AIMSCONFIG AIMSDSR AIMSGE AIMSMAPIDS Comments AIMS Audit Log database and tables AIMS Configuration database. Note: Only the database is created. The schema will be created when SQLSERVERMIGRATE /AIMS is run from the command line. Collected data from target systems for orphaned accounts, Identity Enforcer managed user cache, and Identity Analyzer product. Note: Only the database is created. The schema will be created when SQLSERVERMIGRATE /DSR is run from the command line. AIMS Group Enforcer database. Note: Only the database is created. The schema will be created when SQLSERVERMIGRATE /GROUPENFORCER is run from the command line. User Mapping database and tables Create a SQL Logon that will be used for all five databases o Access The SQL Management Studio s Object Browser o Expand the tree o Expand Security o Right Click on Logins and select New Login from the menu Page 4

o Enter a new login name, enable the SQL Server Authentication radio button, enter the password and confirm password values, then uncheck the Enforce password policy checkbox. The reason for overriding the SQL password policy, is Microsoft's SQL password policy expires the password on first use. Since the SQL login name and password will be used in the configuration of the repository page on the AIMS server, you do not want subsequent connections to fail after the initial connection is made. Go back to the SQL Management Studio Object Browser and expand Databases. o Expand AIMSAudit o Expand Security Page 5

o Right Click on Users and select New User from the menu. o o o o o Enter the SQL Login name you created in the User name field, and in the Login name field. Under the Owned Schemas section, enable the db_owner checkbox. Under the Database role membership section, enable the db_owner checkbox. Click the OK button. Repeat the assignment of the database user and db_owner database role and owned schema for the AIMSCONFIG, AIMSDSR, AIMSGE, and AIMSMAPIDS databases. Page 6

3 Configuring AIMS to Use The Microsoft SQL Server Databases Prior to converting the existing AIMS configuration data and AIMS Audit Log data to be written to the Microsoft SQL Server databases you created, you must configure the AIMS Repository settings to those databases. Access the main AIMS configuration screen, and click on the Repository option in the center pane. 3.1 For Audit Log Data Enable the Log system activity to Microsoft SQL Server radio button Enter the fully qualified domain name or the IP address of your MS SQL Server. If you are using a named SQL instance, specify the address as SQLSerrverName\InstanceName. Enter the name of the Audit Log database. By default, this is AIMSAUDIT. Enter the SQL Login name for the database. Enter the SQL Login password. Page 7

3.2 For UserID Mapping Data Export your Mapped IDs from AIMS / User Mapping. Save the file on the AIMS server in a temporary directory. Enable the Use Data in MS SQL Server radio button. Enter the fully qualified domain name or the IP address of your MS SQL Server. If you are using a named SQL instance, specify the address as SQLSerrverName\InstanceName. Enter the name of the Mapped ID database. By default, this is AIMSMAPIDS. Enter the SQL Login name for the database. Enter the SQL Login password. Page 8

3.3 For AIMS Configuration Data Enable the Log system activity to Microsoft SQL Server radio button Enter the fully qualified domain name or the IP address of your MS SQL Server. If you are using a named SQL instance, specify the address as SQLSerrverName\InstanceName. Enter the name of the Identity Enforcer configuration database. By default, this is AIMSCONFIG. Enter the SQL Login name for the database. Enter the SQL Login password. Page 9

3.4 For AIMS Directory Shadow Repository (DSR) Data Enable the "Store data in Microsoft SQL Server radio button Enter the fully qualified domain name or the IP address of your MS SQL Server. If you are using a named SQL instance, specify the address as SQLSerrverName\InstanceName. Enter the name of the DSR configuration database. By default, this is AIMSDSR. Enter the SQL Login name for the database. Enter the SQL Login password. Page 10

3.5 For AIMS Group Enforcer Data Enable the "Store data in Microsoft SQL Server radio button Enter the fully qualified domain name or the IP address of your MS SQL Server. If you are using a named SQL instance, specify the address as SQLSerrverName\InstanceName. Enter the name of the Group Enforcer configuration database. By default, this is AIMSGE. Enter the SQL Login name for the database. Enter the SQL Login password. 3.6 Testing the Connections At the bottom of the Repository configuration page is a Test Connections button. When you have configured the repository sections for AIMS Configuration, Audit, MapIDs, and AIMSDSR the connections should show Connection Succeeded. If you receive your success confirmation, press the save button at the top of the screen to save your configuration settings, then press the Restart button to restart the web application. Page 11

4 Migrating the VistaDB files to MS SQL Server Data contained in the VistaDB files created during a default installation of AIMS can now be migrated to the Microsoft SQL Server databases. To accomplish this, you must use a combination of utilities dependant on the data you are migrating. 4.1 To migrate the Mapped IDs Data Access the AIMS / User Mapping configuration page Click on the Browse button Locate the exported MapIDs file you created earlier and select the file. Click the Add Entries button and the data will be imported into the MS SQL Server AIMSMAPIDS database. Page 12

4.2 Migrating AIMS Configuration, DSR, Group Enforcer, and Audit Log Data AIMS comes with a command line utility to migrate the AIMS configuration and audit data from the c:\inetpub\wwwroot\aims\admin directory to the AIMSCONFIG, AIMSDSR, AIMSGE, and AIMSAUDIT databases on MS SQL Server. In order to use this utility, you must stop the following services on the AIMS server: Avatier Identity Management Suite IIS Admin Service (Stopping IIS Admin will also stop the World Wide Web Publishing Service and the HTTP SSL service) 4.2.1 When the services are stopped Open a command line on the AIMS server and change directories to c:\inetpub\wwwroot\aims\bin From the command line type SQLServerMigrate.exe /AIMS The utility will first create the tables in the AIMSCONFIG database on the Microsoft SQL Server, then migrate the configuration information contained in the AIMS.vdb3 file. From the command line type SQLServerMigrate.exe /DSR The utility will first create the tables in the AIMSDSR database on the Microsoft SQL Server, then migrate the configuration information contained in the AIMSDSR.vdb3 file. From the command line type SQLServerMigrate.exe /GROUPENFORCER The utility will first create the tables in the AIMSGE database on the Microsoft SQL Server, then migrate the configuration information contained in the AIMSGE.vdb3 file. From the command line type o SQLServerMigrate.exe /AUDITREPLACE o Or SQLServerMigrate.exe /AUDITADD The utility migrates data from AIMSAUDIT.vdb3 on the AIMS Server to the AIMSAUDIT database on the Microsoft SQL Server. AUDITREPLACE will drop the destination table and replace it with the contents of AIMSAUDIT.vdb3. AUDITADD will append the records from AIMSAUDIT.vdb3 to the SQL AIMSAUDIT database. Please note: Using AUDITADD may create duplicate records in the SQL AIMSAUDIT database if run multiple times. 4.2.2 When the migration is complete Start the IIS Admin Service Start the World Wide Web Publishing Service (starting this service automatically starts the HTTP SSL service) Start the Avatier Identity Management Suite service Access the AIMS Configuration Screens and test your configuration. o Access the audit logs and make sure items are being recorded to the Microsoft SQL Server o Access your licensed AIMS product modules and validate the configuration settings Page 13