Security manager service account appears in clear text (NETIQKB70313)

  • 7770313
  • 17-May-2007
  • 31-Dec-2007

Environment

Security manager 5.6

Situation

How do I remove the log files containing the username and password displayed in clear text?
SMServiceHost.InstallLog and NetIQ.SM.LogHandler.InstallLog contain usernames and passwords in clear text.

Resolution

Apply Security Manager 5.6 Service Pack 1 or simply delete log files SMServiceHost.InstallLog and NetIQ.SM.LogHandler.InstallLog.

 

Executing the service account password change article is recommended as detailed in NETIQKB42271

Cause

The installation log file is not deleted in installation cleanup.

Additional Information

Formerly known as NETIQKB70313

During the installation of NetIQ Security Manager version 5.6, the service account and password are captured in the installation log file on the central computer. This log file is only stored on the central computer.

Under normal circumstances, the installation log file should be deleted after a successful installation. This service pack will delete the C:\Program Files\NetIQ Security Manager\NetIQ Security Manager Core\SMServiceHost.InstallLog and NetIQ.SM.LogHandler.InstallLog  log files. Because this directory inherits its permissions from its parent directory, you need to be a member of the Administrators group or OnePointOp Users group to access this file. It is also recommended that you change the password on the service account.

For assistance, please contact NetIQ Technical Support