G06.29 Software Installation and Upgrade Guide

Overview of Installing G06.29
G06.29 Software Installation and Upgrade Guide542744-003
1-44
Password Enhancements and OSS ACL Support
3. Use SAFECOM to build an OBEY file to save the current policy. To create an
OBEY file, enter these SAFECOM commands:
TACL> safecom/out $system.saef.safevalu
=display as commands on
=info safeguard, detail
The output from these commands is retained in a file named SAFEVALU located in
$SYSTEM.SAFE.
4. Once the new Safeguard version is installed, run the OBEY file, SAFEVALU,
created in step 3 in SAFECOM.
For more details, see Section 10 of the Safeguard Administrator's Manual.
Fallback Considerations for Password Encryption
Because of the new password encryption algorithm, fallback requires advance
planning.
In all cases, fall back to the previous version of security software.
If PASSWORD-ENCRYPT is OFF or PASSWORD-ALGORITHM is set to DES, no
extra fallback steps are required.
If PASSWORD-ENCRYPT is HMAC256, extra fallback steps are required. When users
first change their password after HMAC256 is enabled, they must remember their
immediate previous password. This is especially important for the system
administrator. After installing the previous version of Safeguard and Standard Security:
1. Before starting Safeguard, the system administrator must log in with the old
password. The old password is the one used before the algorithm was changed to
HMAC256.
2. Start Safeguard.
3. The system administrator must set a grace period for users to change their expired
passwords.
4. Users are prompted to change their password when logging into the system if:
Their user account existed before the installation of the G03 version of
Safeguard.
or
Note. When migrating to the enhanced password feature, if you do not follow the preceding
migration steps or if you do not want to accept the new password configuration default values,
use SAFECOM to modify the appropriate attributes after the new version is installed.
Note. The Safeguard configuration attribute AUDIT-CLIENT-OSS is set to ON by default. If you
do not want to audit client subsystems other than OSS, you can disable the AUDIT-CLIENT-
GUARDIAN attribute after migration. To roll the audit file, use the SAFECOM NEXTFILE
command.