IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Changing shared secret

    Posted Wed February 05, 2020 03:12 AM
    Hi,

    I am in need of changing the Shared secrect for the CM and collectors but before proceeding I would like to know if my actions are correct.

    • Click Setup > Tools and Views > System
    • Enter the prefered Shared secrect under System Shared Secrect (same Shared Secrect for CM and Collector)
    • Click Apply 
    • Click Restart
    Is there anything more that I should take into consideration?

    I have been following this: https://www.ibm.com/support/knowledgecenter/en/SSMPHH_11.1.0/com.ibm.guardium.doc.admin/config/system_configuration.html

    Current Guardium versions 11.1


  • 2.  RE: Changing shared secret

    Posted Thu February 06, 2020 11:42 AM

    Shared Secret is not synchronized

    Must be replaced on all appliances

    Please remember that archives use shared secret to encrypt files - store previous shared secret in password vault or use catalog export to be able to match shared secret with archives files.



    ------------------------------
    Zbigniew Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 3.  RE: Changing shared secret

    Posted Fri February 07, 2020 10:05 AM
    Ok, if you have forgotten the Shared secret then I assume the catalogs will not be accessible after changing the Shared Secret?

    Is there any way to extract the current Shared secrect and make the catalogs accessible after changing the Shared secrect?


  • 4.  RE: Changing shared secret

    Posted Fri February 07, 2020 10:22 AM

    I think that catalog contains shared secret for each generated archive
    So if you would like to import some archives with different shared secrets you should before:

    - set correct shared secret, corresponding to particular archive file (assumption that you have them in password vault)

    - or import catalog which contains information about imported archive

    There is another general assumption that data import is managed of separate aggregator - not on production system (Investigation Center)



    ------------------------------
    Zbigniew Szmigiero
    IBM
    Warsaw
    ------------------------------



  • 5.  RE: Changing shared secret

    Posted Tue May 23, 2023 02:23 PM

    Dear Sir(s), Good Day!

    I have couple of doubts related to shared secret key.  If we set shared secret on Central Manager then, same will be sync to other managed units ? OR do we need to manually set the same SS on each MUs ....? Does the Exported Archive catalog contains the related SS ..? If we import this exported Archive catalog to another appliance, then, do we need to set the SS of source appliance ?

    Also, how do we keep copies of all SS...? Does SS automatically changed after some period of time OR each reboot of appliance ...? OR remain same.

    Apologize for the so many questions. But, I need to clear it. since, I am getting some error while importing Archive files even on same appliance from which Archive data generated. Thanks a lot !  



    ------------------------------
    Akash Parmar
    ------------------------------



  • 6.  RE: Changing shared secret

    Posted Fri September 08, 2023 03:02 AM

    1. If we set shared secret on Central Manager then, same will be sync to other managed units ? - No. Shared Secret will not be SYNCED. 
    2. OR do we need to manually set the same SS on each MUs ....? - Yes. You need to set it on all MUs from CLI. 
    3. Does the Exported Archive catalog contains the related SS ..? - Tes.
    4. If we import this exported Archive catalog to another appliance, then, do we need to set the SS of source appliance ? - Yes.
    5. Also, how do we keep copies of all SS...? - You need to have a safe tracker. 
    6. Does SS automatically changed after some period of time OR each reboot of appliance ...? OR remain same. - It remains same. It does not change until the appliance is rebuilt, or SS is changed manually. 



    ------------------------------
    GIRISH RAMESH BABU
    ------------------------------