立即与支持人员聊天
与支持团队交流

Safeguard for Privileged Passwords On Demand Hosted - Release Notes

Appliance LCD and controls

The front panel of the Safeguard for Privileged Passwords 3000 Appliance and 2000 Appliance contain the following controls for powering on, powering off, and scrolling through the LCD display.

  • Green check mark button: Use the Green check mark button to start the appliance. Press the Green check mark button for NO more than one second to power on the appliance.

    Caution: Once the Safeguard for Privileged Passwords Appliance is booted, DO NOT press and hold the Green check mark button. Holding this button for four or more seconds will cold reset the power of the appliance and may result in damage.
  • Red X button: Use the Red X button to shut down the appliance. Press and hold the Red X button for four seconds until the LCD displays POWER OFF.

    Caution: Once the Safeguard for Privileged Passwords Appliance is booted, DO NOT press and hold the Red X button for more than 13 seconds. This will hard power off the appliance and may result in damage.
  • Down, up, left, and right arrow buttons: When the appliance is running, the LCD home screen displays: Safeguard for Privileged Passwords <version number>. Use the arrow buttons to scroll through the following details:
    • Serial: <appliance serial number>
    • X0: <appliance IP address>
    • MGMT: <management IP address>
    • MGMT MAC: <media access control address>
    • IPMI: <IP address for IPMI>
Table 11: Appliance LCD and controls
Control Description

Green check mark button

Use the Green check mark button to start the appliance. Press the Green check mark button for NO MORE THAN one second to power on the appliance.

Caution: Once the Safeguard for Privileged Passwords Appliance is booted, DO NOT press and hold the Green check mark button. Holding this button for four or more seconds will cold reset the power of the appliance and may result in damage.

Red X button

Use the Red X button to shut down the appliance. Press and hold the Red X button for four seconds until the LCD displays POWER OFF.

Caution: Once the Safeguard for Privileged Passwords Appliance is booted, DO NOT press and hold the Red X button for more than 13 seconds. This will hard power off the appliance and may result in damage.
Down, up, left, and right arrow buttons

When the appliance is running, the LCD home screen displays:

  • Safeguard for Privileged Passwords <version number>

Use the arrow buttons to scroll through the following details:

  • Serial: <appliance serial number>
  • X0: <appliance IP address>
  • MGMT: <management IP address>
  • MGMT MAC: <media access control address>
  • IPMI: <IP address for IPMI>

Product licensing

The Safeguard for Privileged Passwords 3000 Appliance and 2000 Appliance ship with the following modules, each requiring a valid license to enable functionality:

  • One Identity Safeguard for Safeguard for Privileged Passwords (SPP)
  • One Identity Safeguard for Privileged Sessions (SPS)
    SPS is a separate product. To update the SPS license, see the Safeguard for Privileged Sessions Administration Guide, Updating the SPS license.

To add a Safeguard for Privileged Passwords module license

The first time you log in to the Safeguard for Privileged Passwords desktop client as the Appliance Administrator, it prompts you to add a license. In addition, you can add additional Safeguard for Privileged Passwords module licenses.

  1. Navigate to Administrative Tools | Settings | Appliance | Licensing in the desktop client.
  2. Click .
  3. Browse to select the license file.

    Once you add a license, Safeguard for Privileged Passwords displays the current license information and additional links that allow you to update the license.

  4. To add another module license, click Add Another License from the Success dialog.

NOTE: To avoid disruptions in the use of Safeguard for Privileged Passwords, the Appliance Administrator must configure the SMTP server, and define email templates for the License Expired and the License Expiring Soon event types. This ensures you will be notified of an approaching expiration date.

Update and installation instructions

The Safeguard for Privileged Passwords 3000 and 2000 Appliances are built specifically for use only with the Safeguard for Privileged Passwords privileged management software, which is pre-installed and ready for immediate use on the hardened appliances.

Safeguard for Privileged Passwords virtual appliances and cloud applications are also available.

To set up a new deployment: 3000 Appliance, 2000 Appliance, Virtual Machine, or Cloud

If this is a new physical appliance, virtual machine, or cloud deployment, see the Safeguard for Privileged Passwords Appliance Setup Guide. The guide is also included in the package with a physical appliance.

To update an existing physical appliance or virtual appliance with this patch

It is the responsibility of the Appliance Administrator to upgrade Safeguard for Privileged Passwords by installing an update file (patch). Consider the following:

  • Minimum patch version: 6.0.0.12276. If you are running an earlier version of the Safeguard for Privileged Passwords Appliance, you must upgrade to this version before applying the 6.13.1 patch.
  • Clustered environment: See the Patching cluster members section in the Safeguard for Privileged Passwords Administration Guide for instructions on how to deploy a patch so all appliances in the cluster are on the same version.
  • During initial installation and when applying a patch, make sure the desktop client file is the one supplied with the appliance version. If the versions are not compatible, errors may occur. For more information, see To install the desktop client.

Prepare to install a patch

  1. Backup your appliance before you install a patch. Once you install a patch, you cannot uninstall it. See the Safeguard for Privileged Passwords Administration Guide, Backup and restore topic.
  2. Download the latest physical appliance patch or virtual appliance patch from the One Identity Support Portal:
    https://support.oneidentity.com/one-identity-safeguard-for-privileged-passwords/download-new-releases

To install the hardware patch

  1. As an Appliance Administrator, log in to the Safeguard for Privileged Passwords desktop client.
  2. From the Home page, select Administrative Tools.
  3. Select Settings | Appliance | Updates.

    The current appliance and client versions are displayed.

  4. Click Upload a File and browse to select the update file you downloaded from the One Identity support web site.

    NOTE: When you select a file, Safeguard for Privileged Passwords uploads it to the server, but does not install it.

  5. Once the file has successfully uploaded, click Install Now.

To install the virtual machine patch

  1. Make adequate resources available. The virtual appliances default deploy does not provide adequate resources. The minimum resources required are: 4 CPUs, 10GB RAM, and a 500GB disk. Without adequate disk space, the patch will fail and you will need to expand disk space then re-upload the patch.
  2. Go to the web management console and click Setup and follow the wizard.
To install the desktop client

Be sure to update the desktop client when you apply a new patch. The version of the appliance and desktop client must be compatible.

To define and enforce security policy for your enterprise, install the Windows desktop client application, which gives you access to the Administrative Tools. You install the Windows desktop client by means of an .msi package that can be downloaded from the appliance web client portal. You do not need administrator privileges to install the desktop client.

NOTE: PuTTY is used to launch the SSH client for SSH session requests and is included in the install. The desktop client looks for any user-installed PuTTY in the following locations:

  • Any reference to putty in the PATH environment variable
  • c:/Program Files/Putty
  • c:/Program Files(x86)/Putty
  • c:/Putty

If PuTTY is not found, the desktop client uses the version of PuTTY that it installed at:

<user-home-dir>/AppData/Local/Safeguard/putty.

If the user later installs PuTTY in any of the locations above, the desktop client uses that version which ensures the user has the latest version of PuTTY.

Installing the Safeguard for Privileged Passwords desktop client application

CAUTION: The Safeguard for Privileged Passwords client version must match the installed Safeguard for Privileged Passwords version.

  1. To download the Safeguard for Privileged Passwords desktop client Windows installer .msi file, open a browser and navigate to:

    https://<Appliance IP>/Safeguard.msi

    Save the Safeguard.msi file in a location of your choice.

  2. Run the MSI package.
  3. Select Next in the Welcome dialog.
  4. Accept the End-User License Agreement and select Next.
  5. Select Install to begin the installation.
  6. Select Finish to exit the desktop client setup wizard.
  7. Check your desktop resolution. The desktop client works the best at a resolution of 1024 x 768 or greater.

Installing the Desktop Player

CAUTION: If the Desktop Player is not installed and a user tries to play back a session from the Activity Center, a message like the following will display: No Desktop Player. The Safeguard Desktop Player is not installed. Would you like to install it now? The user will need to click Yes to go to the download page to install the player following step 2 below.

  1. Once the Safeguard for Privileged Passwords installation is complete, go to the Windows Start menu, Safeguard folder, and click Download Safeguard Player to be taken to the One Identity Safeguard for Privileged Sessions - Download Software web page.
  2. Follow the Install Safeguard Desktop Player section of the player user guide found here:

    1. Go to One Identity Safeguard for Privileged Sessions - Technical Documentation.
    2. Scroll to User Guide and click One Identity Safeguard for Privileged Sessions [version] Safeguard Desktop Player User Guide.
  3. For Safeguard Desktop player version 1.8.6 and later, ensure your signed web certificate has a Subject Alternative Name (SAN) that includes each IP address of each of your cluster members. If the settings are not correct, the Safeguard Desktop Player will generate a certificate warning like the following when replaying sessions: Unable to verify SSL certificate. To resolve this issue, import the appropriate certificates including the root CA.

New Desktop Player versions

When you have installed a version of the Safeguard Desktop Player application, you will need to uninstall the previous version to upgrade to a newer player version.

Verify successful installation

You can verify that the correct version has been successfully installed from the Safeguard for Privileged Passwords desktop client or the LCD on the Safeguard for Privileged Passwords Appliance.

To verify the uploaded patch was installed

  1. Log in to the Safeguard for Privileged Passwords desktop client as an Operations Administrator or an Appliance Administrator.
  2. Select Administrative Tools.
  3. Select Settings | Appliance | Appliance Information.
  4. Verify the correct appliance version is displayed in the appliance properties pane.

In addition, when the appliance is running, the LCD home screen on the front panel of the appliance displays Safeguard for Privileged Passwords <version number>. Therefore, you can verify the correct appliance version is running from there, as well.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级