23 September 2009

Software Managed Delivery Tasks

To test some of the features of Managed Software Delivery (MSD) and not to create be afraid the job is scheduled then you can create a MSD using a scheduled time, leave it on 00:00 with no repeat. Then you can launch the MSD using the agent. It will appear in the Policy Pane of the agent as being “Not Scheduled”.

When Using “Depends On” it will install the depended package if it is not detected (Not Compliant)
“Supersedes” will (if checked) uninstall the “old” packages before it installs the depended package and then the actual one.

image

When you have installed CMDB and activated the Flash player Active X you can see a Resource Association Diagram of this packagesimage

21 September 2009

CMS and SMS SP1 released today (21/09)

Article ID: 48420 : Altiris™ Client Management Suite 7.0 SP1 Release Notes

Changes in Client Management Suite from 6.x to 7.0 SP1
  • The functions of Software Delivery Solution and Application Management Solution are combined in the new Software Management Solution.
  • The functions of Application Metering Solution are now included in Inventory Solution.
  • Inclusion of SVS application technology in Software Management Solution.
  • Deployment Solution for Clients is integrated into the Symantec Management Platform.
  • Real-Time System Management Solution is included in Client Management Suite.
  • Carbon Copy is replaced with pcAnywhere Solution.
  • Addition of Ghost Imaging Foundation (both DS 6.9, and 7.0)
Changes in Client Management Suite from 7.0 to 7.0 SP1

Except for Deployment Solution for Clients 7.0, all components of Client Management Suite SP1 have been updated. For information about the new features of the solutions and components, see the individual release notes. To access the solution release notes, use the links that are in the Components of Client Management Suite section.

Article ID: 48733 : Altiris™ Server Management Suite 7.0 SP1 Release Notes

Changes in Server Management Suite from 6.x to 7.0 SP1
  • The functions of Software Delivery Solution and Application Management Solution are combined in the new Software Management Solution.
  • The functions of Application Metering Solution are now included in Inventory Solution.
  • Inclusion of SVS application technology in Software Management Solution.
  • Deployment Solution for Clients is integrated into the Symantec Management Platform.
  • Real-Time System Management Solution is included in Server Management Suite.
  • Addition of Ghost Imaging Foundation (both DS 6.9, and 7.0)
Changes in Server Management Suite from 7.0 to 7.0 SP1

All components of Server Management Suite SP1 have been updated. For information about the new features of the solutions and components, see the individual release notes. To access the solution release notes, use the links that are in the Components of Server Management Suite section.

19 September 2009

NS7 SP2 HF2 Available

NS7 SP2 HF2 Available as of today

as well as a hotfix for Agent Unix, Linux, Mac – Network discovery – PLugable Protocol Architecure

Release notes not yet public available

How do I create a new database or change the database being used by Symantec Management Platform 7.0?

NSSetup is no longer supported in SMP / Notification Server 7.

There are two supported methods to alter database settings.

  1. Within the console: If you are able to access the Symantec Management Console, go to Settings - Notification Server Settings - Database Settings. Use the options on this page to create a new database or to change the database currently being used by Notification Server.
  2. Using AeXConfig.exe: When you don't have access to the SMC, Run AeXConfig.exe /db from a command prompt. It is found in the directory \Program Files\Altiris\Notification Server\bin.  Syntax examples are shown below:
    1. To connect to the SQL Server using Windows Integrated Security, under the account credentials of the current cmd.exe process:
      AeXConfig.exe /db dbserver:<SQLServerName> dbname:<DBName> dbusername: dbpassword: dbtimeout:<DBTimeout>
    2. To connect to the SQL Server using a SQL Login:
      AeXConfig.exe /db dbserver:<SQLServerName> dbname:<DBName> dbusername:<SQLLoginName> dbpassword:<SQLLoginPassword> dbtimeout:<DBTimeout>

NOTE: You must use all of the parameters for the command to work, but for Integrated Security to work using the account credentials of the currently executing cmd.exe process, do not put the user name or password after the dbusername: and dbpassword: parameters.

12 September 2009

Altiris PC Transplant 6.8 SP3 from Symantec Release Notes

Introduction

PC Transplant Solution uses its wizard-driven interface to capture a computer's personality—user accounts; desktop, network, and application settings; files; folders; and personal data. The solution then transplants the personality to another computer. You can transplant a personality through a self-extracting executable file called a Personality Package, or you can perform a real-time migration from one computer to another.

PC Transplant Solution simplifies the deployment and migration of new computers or Windows operating systems by facilitating the migration of data and settings. It complements existing desktop management tools, meeting an easily identified need that none of these tools currently address. With PC Transplant Solution, you can not only migrate to a new computer quickly and efficiently, but you can also transfer key aspects of a computer's personality on an on-going basis. PC Transplant Solution is an ideal solution for IT administrators, consultants, VARs, resellers, computer vendors, and configuration centers.

PC Transplant Solution is part of the following suites:

  • Altiris™ Client Management Suite from Symantec
    For release notes, see Knowledge Base article 40929.
  • Altiris™ Server Management Suite from Symantec
    For release notes, see Knowledge Base article 45893.
Features in this Release

This version includes the following features:

  • Support for Windows 7.
  • Support for EFS RAW. Added the -efsraw command-line switch to enable the RAW migration of EFS encryption.
  • Support for Microsoft Internet Explorer 8.
  • Support for PC Transplant Web Store installation on Windows Vista and Windows 7 computers.
  • Support for migration of power setting from Windows Vista to Windows Vista, Windows Vista to Windows 7, and Windows 7 to Windows 7.

10 September 2009

What are the new features in Patch Management Solution 7

Maintenance windows

By default, Software Update agents will respect Maintenance Windows if one is configured and applies to the agent computer. This is controlled by the ‘Override Maintenance Window’ setting on the Agent Configuration Policy.  If this setting is not enabled, and a Maintenance Window applies to the agent computer, it will only install updates and trigger required reboots when that Window is Open. If the Window is not Open, the installations and reboots are deferred until the Window next opens. If the setting is enabled, the agent will ignore Maintenance Windows and use the installation and reboot options defined in the configuration policy. Software Update policies set to run ASAP or at a Custom time can be set to override Maintenance Windows.

Reporting Changes in 7.0

The number of reports and reporting infrastructure has improved with Notification Server 7.0, resulting in fewer reports and an improved dashboard user interface. Patch Management Solution 7.0 for Windows includes the following default reports:

  • Microsoft Compliance by Bulletin
  • Microsoft Compliance by Computer
  • Microsoft Compliance by Update
  • Microsoft Compliance Summary
  • Microsoft Vulnerability Analysis Summary 
  • Software Bulletin Details
  • Superseded Bulletins
  • Windows Software Update Agent Rollout Status
  • Reboot Status
  • Software Update Delivery Summary

All other existing reports, including custom reports, will not be included or upgraded to 7.0.

Retired managed computers no longer consume a license nor do they appear in vulnerability reports

Managed computers with a “Retired” status will release their license, freeing it up for new computers coming online. These computers will also no longer appear in the Compliance and vulnerability reports.

Notification Server 7.0 hierarchy and organizational view features are supported

Notification Server 7.0 has new hierarchy features that let you manage a group of Notification Servers by simply configuring a parent that passes all configuration settings and resources to child Notification Servers. This functionality is supported in Patch Management Solution for Windows through two separate replication rules: one to allow the replication of Patch Management Import data based on the managed languages of the child Notification Server and one to allow the selection of Software Update policies to replicate to the child. Summary compliance information is also sent up the hierarchy daily and can be viewed in the Microsoft Compliance Summary report.

Distribute software updates across multiple time zones

You can now simultaneously distribute software updates to managed computers across multiple time zones, at a time specified on a single Notification Server. Previously, software updates were installed according to the time on managed computers’ clocks. The new user interface control is found in the Software Update Policy Wizard scheduling options, with the choice to distribute packages at server time, client time, or UTC time.

Offline Microsoft Patch Management Import files are now supported

Notification Servers without Internet access can now download Microsoft Patch Management Import files from a local caching server. Taking advantage of new Notification Server 7.0 hierarchy features, enabling software bulletins on a child Notification Server (without Internet access) will download the relevant files from a parent Notification Server, where the files are cached.

Disable superseded software updates

The field, Disable all Advertisements for Superseded Software Updates, on the Microsoft Patch Management Import task lets you disable any Software Update policies with superseded software updates. You can also control this function and set a schedule for it in the Disable Superseded Software Update Advertisements server task. After PMImport has run, any Software Update policies with superseded software updates are disabled and the administrator is notified by the Disabled Advertisements Notification Server policy (which must be enabled). An obsolete Software Update policy is disabled only if you created a new one from the superseding software update.

Inventory rules only run against applicable inventory and have increased performance

To reduce bandwidth use, inventory rules that run on managed computers only run against applicable inventory items. For example, if a managed computer has Windows XP SP2 installed, the Software Update Agent will run inventory against and report on items only applicable to Windows XP SP2. The inventory rules are now contained in an SQLite database increasing the speed of the inventory process of reading of the xml file used previously.

New task 'Check Software Update Package Integrity'

This is a Task server task and has 3 functions it can perform; Delete physical packages for discovered orphaned software packages, Delete physical files for packages with no associated advertisements and Relocate existing packages if default software update package location has changed

Notification can be sent when new Bulletins are available 

Administrators can configure the Microsoft Patch Management Import task to send a customized message to specified recipients at the completion of Microsoft Patch Management Import downloads.

Quicker distribution of software updates

Behind-the-scenes modifications have increased the distribution time of updates being rolled out to computers.  Resource targeting has been modified to be more efficient, it is only looking at the applicable dataclass now.  The inventory rule process has been streamlined.

NOTE: This information was taken from the release notes and modified slightly to remove entries that were not new features and clarify the information.

From the beta site : CMS 7.0 SP1 New Feature Highlights

 

Canned commercial software application definitions are included to more accurately identify installed software in the environment.

Inventory policies are greatly simplified.

Collection of detailed file inventory has been optimized

Inventory policy management and status monitoring has been added to the improved Inventory Portal.

Patch Admins can use a consolidated “worker view” (page or portal) from which they can accomplish or access primary Patch functions; similar views are also provided for software delivery functions and monitoring functions (via Altiris Server Management Suite).

Software packages and software data can be imported from Wise Package Studio into the library and catalog, respectively.

Patch Admins can identify missing software updates on Mac OS X and can use the console to distribute and install the missing updates.

Automated patching is added for Adobe applications: Reader, Acrobat and Flash.

pcAnywhere solution adds custom port configuration for console and client and expanded approve connection control with a super user that can bypass approval

Important change: How is the Software Management Framework Software Discovery task utilized by Inventory Solution in 7.0 SP1?

Question

In 7.0 GA for CMS, the Software Discovery component that captures Add/Remove Program data was only included as part of the Software Management Framework.  In Inventory Solution 7.0 SP1 this component will now be launched by Inventory Solution as part of the Inventory Solution Policies or Tasks.  The following information will help provide understanding to how Inventory uses this component.

Answer

Software Discovery will be executed by the Inventory Solution Policies or Tasks in SP1.  The option is labeled 'Software - Windows Add/Remove Programs and UNIX/Linux/Mac software packages' when an Inventory Policy or Task is edited or created.  When this is checked, we'll run the Software Discovery as part of the Policy or Task, with the following intelligence as far as if we will send all data or only delta data.  We've built in logic to look to see if the Resource GUID of the system has changed or not:

 

Machine GUID

Send Delta Only flag

Result

Same

True

Don’t Delete SMF Cache

Same

False

Delete SMF Cache

Changed

True

Delete SMF Cache

Changed

False

Delete SMF Cache

 

The SMF cache holds all Add/Remove Program data, and leaving the cache means only a small subset of changed data will be sent up.  It's important to delete this cache if the server, for whatever reason (the record was deleted, the agent was directed to a new NS, etc...) no longer has the data for the system.

05 September 2009

Altiris™ Deployment Solution 6.9 SP3 from Symantec Release Notes

In SP3, support for Windows 7 and Windows Server 2008 R2 was added. See also added the Features in this Release section.

To see the Release Notes for the Deployment Solution 6.9 SP1 and SP2 releases, see Knowledge Base articles 42696 and 46383.

Deployment Solution is part of the following suites:

  • Altiris™ Client Management Suite from Symantec
    For release notes, see Knowledge Base article 48420.
  • Altiris™ Server Management Suite from Symantec
    For release notes, see Knowledge Base article 48733.
Features in this Release

The following are features of this release:

  • We added support for the Windows 7 and Windows Server 2008 R2 operating platforms. For detailed information on supported platforms, please see Knowledgebase article 47794
  • PC Transplant (included with Deployment Solution) was updated to support Windows 7 migrations from Windows XP and Vista. For more information, see the PC Transplant Release Notes article 48704.
  • DAgent can now be uninstalled from the DS Console. To access the uninstall option, right-click the client in the DS Console.
  • DAgent supports the customdata.ini file.
  • The DS Linux preboot automation environment now uses the openSUSE 11.1 Linux kernel, which is the kernel 2.6.27.7 version.
  • The Deployment Solution installation adds the Ghost Walker tool that you can use manually. There are no integrated tasks or jobs in Deployment Solution for Ghost Walker, however.
  • New options were added to the evaluation mode DeployAnywhere. You can now specify a file name for the report and log files, so that multiple computers write to separate files. The logPath option and the logId option can be used together or individually. logPath contains the fully qualified path to where the DeployAnywhere log files are written. logId is a string that is prepended to the log file names. For example, Ghdplyaw32.exe /target=c: /eval /logPath=z:\logs /logId=zzz.