1. If we set shared secret on Central Manager then, same will be sync to other managed units ? - No. Shared Secret will not be SYNCED.
2. OR do we need to manually set the same SS on each MUs ....? - Yes. You need to set it on all MUs from CLI.
3. Does the Exported Archive catalog contains the related SS ..? - Tes.
4. If we import this exported Archive catalog to another appliance, then, do we need to set the SS of source appliance ? - Yes.
5. Also, how do we keep copies of all SS...? - You need to have a safe tracker.
6. Does SS automatically changed after some period of time OR each reboot of appliance ...? OR remain same. - It remains same. It does not change until the appliance is rebuilt, or SS is changed manually.
------------------------------
GIRISH RAMESH BABU
------------------------------
Original Message:
Sent: Tue May 23, 2023 02:22 PM
From: Akash Parmar
Subject: Changing shared secret
Dear Sir(s), Good Day!
I have couple of doubts related to shared secret key. If we set shared secret on Central Manager then, same will be sync to other managed units ? OR do we need to manually set the same SS on each MUs ....? Does the Exported Archive catalog contains the related SS ..? If we import this exported Archive catalog to another appliance, then, do we need to set the SS of source appliance ?
Also, how do we keep copies of all SS...? Does SS automatically changed after some period of time OR each reboot of appliance ...? OR remain same.
Apologize for the so many questions. But, I need to clear it. since, I am getting some error while importing Archive files even on same appliance from which Archive data generated. Thanks a lot !
------------------------------
Akash Parmar
Original Message:
Sent: Fri February 07, 2020 10:22 AM
From: Zbigniew (Zibi) Szmigiero
Subject: Changing shared secret
I think that catalog contains shared secret for each generated archive
So if you would like to import some archives with different shared secrets you should before:
- set correct shared secret, corresponding to particular archive file (assumption that you have them in password vault)
- or import catalog which contains information about imported archive
There is another general assumption that data import is managed of separate aggregator - not on production system (Investigation Center)
------------------------------
Zbigniew Szmigiero
IBM
Warsaw
Original Message:
Sent: Fri February 07, 2020 10:05 AM
From: Herman
Subject: Changing shared secret
Ok, if you have forgotten the Shared secret then I assume the catalogs will not be accessible after changing the Shared Secret?
Is there any way to extract the current Shared secrect and make the catalogs accessible after changing the Shared secrect?
Original Message:
Sent: Thu February 06, 2020 11:42 AM
From: Zbigniew Szmigiero
Subject: Changing shared secret
Shared Secret is not synchronized
Must be replaced on all appliances
Please remember that archives use shared secret to encrypt files - store previous shared secret in password vault or use catalog export to be able to match shared secret with archives files.
------------------------------
Zbigniew Szmigiero
IBM
Warsaw
Original Message:
Sent: Wed February 05, 2020 03:11 AM
From: Herman
Subject: Changing shared secret
Hi,
I am in need of changing the Shared secrect for the CM and collectors but before proceeding I would like to know if my actions are correct.
Is there anything more that I should take into consideration?
I have been following this: https://www.ibm.com/support/knowledgecenter/en/SSMPHH_11.1.0/com.ibm.guardium.doc.admin/config/system_configuration.html
Current Guardium versions 11.1