Using Compaq Survey Utility from a Browser

Browser Requirements

The minimum browser requirements include support for tables, frames, Java, JavaScript, and Java Development Kit (JDK) 1.1.

Additional browsers, or the browsers mentioned, used with different operating systems, may or may not work correctly, depending upon the specific implementations of the required browser technologies.

The requirements are TCP/IP and one of the following browsers listed in the following table:

Systems

Client Based Browser Requirements

Novell NetWare 4.x, and 5.x

Linux

  • Microsoft Internet Explorer 4.0 version 4.72.2106.8 or higher

  • Netscape Navigator 4.05 or higher

Windows 95/98 Windows NT 4.0 and Windows 2000

  • Microsoft Internet Explorer 4.01 version 4.72.2106.8 or higher

NOTE: Internet Explorer 4.0 requires service pack 3 on Windows NT 4.0. and Windows 2000

  • Netscape Navigator 4.04 or higher

NOTE: Navigator requires the JDK 1.1 patch.

Installing JDK 1.1 Patch for Netscape Communicator on Windows NT or Windows 2000

  1. Run Navigator.

  2. Go to http://help.netscape.com/filelib.html?#smartupdate

  3. Click the JDK Update Button.

  1. Download JDK 1.1 support for Netscape Communicator 4.04 from ftp://ftp.netscape.com/pub/communicator/smartupdate/english/windows/windows95ornt/awt/404awt.zip

  2. Shut down Netscape Communicator.

  3. Restart your computer.

  4. Unzip 404awt.zip into the Netscape Program directory of the Communicator software.

    The following table lists the files that are replaced and their locations.

    File Name

    Directory

    jrt3240.dll

    Program

    ifc11.jar

    Program\Java\Classes

    java40.jar

    Program\Java\Classes

    jio40.jar

    Program\Java\Classes

    awt3240.dll

    Program\Java\Bin

    jit3240.dll

    Program\Java\Bin

Pointing the Browser to the System Management Homepage  

Microsoft Operating Systems

Compaq Survey Utility allows you to view information from a Web browser, locally or remotely.

IMPORTANT:  You must have all of the following browser options enabled for the Web-enabled Compaq Survey Utility to work properly:

  • Enable Java

  • Enable JavaScript

  •  Accept all cookies

1. Determine the address of the target machine for the Survey Utility information that you want to view.

2. Enter the IP address in the URL field of the browser.   A login page will be displayed.  Select the user and enter the password configured during installation or previously configured for Compaq Web-based Management.  Refer to the section Logging In for more information.

3. The Compaq Insight Manager Web-Based Management System Management Homepage displays for that machine.

4. You may select the Log-in Account link to log in as another user. Use this option if you need to perform operations that require additional access rights, such as capturing a new configuration sample.

5. Select Compaq Survey Utility. The most recent Survey report for the selected machine displays. Refer to the examples in the section Web-Based Survey Utility Report in Chapter 5 for more information about the report.

Pointing to the System Management Homepage

For Operating Systems other then those from Microsoft

Other Operating Systems

For operating systems other than those from Microsoft, Compaq Survey Utility allows you to view information from a Web browser, locally or remotely.


IMPORTANT: You must have all of the following browser options enabled for the Web-enabled Compaq Survey Utility to work properly:


  1. Determine the address of the target machine for the Survey Utility information that you want to view.

  1. Enter the IP address in the URL field of the browser. The Compaq Insight Manager Web-Based Management Device Home page displays for that machine.

  2. You may select the Log-in Account link to log in as another user. Use this option if you need to perform operations that require additional access rights, such as capturing a new configuration sample.

  3. Select Compaq Survey Utility. The most recent Survey report for the selected machine displays. See Survey Utility Report Example for more information about the report.

Security for Other Operating Systems

For Operating Systems other then those from Microsoft, Compaq Web-based Management supports the following login accounts. Passwords shown are the default settings. For maximum security Compaq recommends that these passwords be changed immediately after the installation of the Survey Utility.

Account

User Name

Password

user

user

public

operator

operator

operator

administrator

administrator

administrator

NOTE:These are the only user accounts available and the names cannot be changed. Only  the passwords can be changed.

Anonymous access to information is available without logging in, when the device home page is launched for the first time.

NOTE: You must have Operator or Administrator access to capture a new configuration sample.

Logging In

The Login dialog box allows you to access any of the available web agents. You can access the desired agent by following these steps.

1. Navigate to https://devicename:2381. The first time you navigate to this link, the Security Alert dialog box displays asking you to indicate whether or not to trust the server.

NOTE:  The Security Alert dialog box shown is specific to Internet Explorer, however Netscape 4.0 and later is supported as well.

NOTE:  If you want to implement your own PKI or install your own generated certificates into each managed device, you can install a Certificate Authority Root Certificate into each browser to be used for management. If this is implemented, the Security Alert dialog box, shown below, should not be displayed. If the alert displays when you do not expect it, you may have browsed to the wrong device. You can refer to the online help in your browser for more information about installing the Certificate Authority Root Certificate.

 

2. Click Yes. The Login page displays.

NOTE:  If you have enabled Anonymous access, then the System Management Homepage displays.

3. Select the appropriate account from the User drop-down list. The choices include administrator, operator, or user.

4. Enter the correct password in the Password field.

5. Click OK. The System Management Homepage displays.

NOTE:  In reference to the Compaq Version Control Repository Manager, the Anonymous login, if enabled, and the User login both allow you to access all pages, but you cannot configure a repository, delete/copy/create Support Paqs, install components, or clear the log. The Anonymous login is disabled by default.

System Management Homepage

The System Management Homepage displays all Compaq Web-enabled System Management software that provides information. In addition, the System Management Homepage displays various boxes that have borders defining the status of the items contained in that box. See Status Box Indicators for more information. The System Management Homepage is separated into two frames to include:

 Header frame

The header frame is constantly visible regardless of the page you are viewing. A navigation vector, located in the top section, displays the path you are currently viewing.

The System Management Homepage displays the following:

System Status

The System Status icon indicates the overall health of the Compaq Web-enabled Management software.

System Status icons legend

Icon

Key Word

Unknown

OK

Degraded

 Failed

 System Model

The System Model displays the model of the system. In some cases, the System Model may display Unknown if no Compaq Web-enabled Management Agents are installed on the system.

Current User

The Current User displays the user who is currently logged in. If the current user is Administrator, Operator, or User, then there is a Logout link. If you have Anonymous access enabled and you are accessing the page anonymously, then the Current User displays Anonymous, and the Login link displays. If Local Access is enabled and you are accessing the Compaq Web-enabled System Management software from a local machine, the Current User displays Administrator or Anonymous (depending on what level of access has been enabled) and Local Access.

Agent Help link

The Agent Help link launches the help files in a separate window. The help contains a combination of all help files related to the Compaq Management software and utilities.

Data frame

The data frame displays the status for all Compaq Management software and utilities on the system.

Tabs

The System Management Homepage provides up to five tabbed pages that allow you to access and/or configure settings related to participating Compaq Web-enabled System Management software. The Tools tab and the Tasks tab are only visible if Compaq Web-enabled System Management software provides data for them.

The tabs that are available are:

Home

The Home tab is displayed on the System Management Homepage. The following information displays on the Home tab.

Failed and Degraded Items box

The Failed and Degraded Items box displays all items, with a failed or degraded status, provided by the Compaq Web-enabled System Management software. If there are no agents installed or no failed or degraded items, then the Failed and Degraded Items box displays None.

Status boxes

The information that is configured to display in Compaq HTTP Server is provided by the Compaq Web-enabled System Management software. The information provided by the Compaq Web-enabled System Management software displays in a box. Each box contains links that allow you to drill down into the Compaq Web-enabled System Management software that is providing the data. In addition, each box has a border that indicates the status of the Compaq Web-enabled System Management software information contained in the box.

Status Box Indicators

Indicator

Description

Blue

Unknown

Green

OK

Yellow

Degraded

Orange

Failed

Gray

No Status

Left Organizational Menu

The left organizational menu displays on the Home tab. The left organizational menu contains links to the Compaq Web-enabled Management software to include:

About this page

The About this page link launches an introduction help file that provides an overview of System Management Homepage.

Integrated Agents

The Integrated Agents section contains participants and links to their entry points if applicable.

NOTE:  Participants are agents that are contributing information contained in the System Management Homepage.

Other Agents

The Other Agents section lists the visible Compaq Web-enabled System Management software that are not participating in the System Management Homepage. The name of the Compaq Web-enabled System Management software provides a link so you can still access the agents if they provide a user interface.

Management Processor

The Management Processor section displays a link to either the Remote Insight Lights-Out Edition Board or the Integrated Lights-Out Board. This information is provided by Web-enabled Compaq Management Agents. If no Compaq Web-enabled System Management software is installed that provides this information, then None displays.

Other Software

The Other Software section provides information regarding Value Added software as well as link(s) to pages on www.compaq.com that contain software information including Proliant Essentials Value Added Software. See www.compaq.com/proliantessentials for detailed information regarding Proliant Essentials Value Added Software.

Key Legend

The Key legend displays a listing of status icons and a brief description of each. For more information regarding the status icons, see Table 1﷓11.

Settings

The Settings tab provides you with the ability to access the agent options, and define the Compaq HTTP Server security settings.

Settings Section

The Settings section provides a listing of participating agents. Each of the participating agents has options already defined.

HTTP Server Section

The HTTP Server section provides links that allow you to configure your Compaq HTTP Server settings. The HTTP Server section provides links to the following:

Change Password

The Change Password option allows you to change the Compaq HTTP Server password.

 

To change the Compaq HTTP Server password:

1. Click Change Password to change the password for Compaq HTTP Server.

2. In the User field, select the user level from the drop-down list.

3. In the Password field, enter the new password for the user level you selected.

4. In the Confirm Password field, enter the same password you entered in the Password field.

5. Click Change Password. A dialog box displays indicating whether or not the password was successfully changed.

Credits

The Credits link displays information regarding licensing and credit information.

 

Options

The Options link takes you to the Options page. The Options page allows you to change various Web-Based System Management settings. The Compaq Web-Based System Management Setup Wizard initially allows you to set many of the options from this page, however you can access the Options page in order to edit any of the initial settings. The Page Sections divide the available options into three groups:

Configuration Options

The Configuration Options section allows you to select the appropriate settings to include:

To enable Anonymous Access:

a. Select Anonymous Access on the Configuration Options page.

b. Click Save Configuration in the Configuration Options section to save your settings. The Configuration Options page will refresh.

NOTE:  If this Compaq HTTP Server is running on the same machine as Compaq Insight Manager 7, Local Access (Anonymous) must be enabled for certain features of Compaq Insight Manager 7 to work. If Local Access (Administrator) or Anonymous Access is enabled, that will also work, but is not necessary.

To set the Logging options:

a. Select Logging to record information in the log file.

b. Select the types of logs to be recorded.

c. Click Save Configuration in the Configuration Options section to save your settings.

IP addresses can be explicitly excluded or explicitly included for each type of user. If an IP address is explicitly excluded it will be excluded even if it is also explicitly included. If there are any IP addresses in the inclusion list, then only those IP addresses will be allowed login access. If there are no IP addresses in the inclusion list, then login access will be allowed to any IP addresses not in the exclusion list.

IP address ranges should be listed with the lower end of the range followed by a hyphen followed by the upper end of the range. All ranges are inclusive in that the upper and lower bounds are considered part of the range. IP address ranges and single addresses are separated by semi-colons.

IP address ranges should be entered in the following format:

122.23.44.1-122.23.44.255;172.84.100.35;127.0.0.0-127.0.0.255

 NOTE:  You can click Default Configuration, located in the Configuration Options section, to return all options back to their original settings.

— Trust By Certificate — The Trust by Certificate mode will setup the HTTP Server to only accept certain requests from Compaq Insight Manager 7 servers with Trusted Certificate as shown. This mode will require the submitted server to provide authentication by means of certificates. This mode is the strongest method of security, since it requires certificate data and verifies the digital signature before allowing access.

— Trust All — The Trust All mode will setup the HTTP Server to accept certain requests from any server. An example of why you may want to use Trust All would be if you have a secure network, and everyone in the network is trusted.

NOTE:  The Trust All option leaves your system vulnerable to security attacks.

— Trust By Name — The Trust by Name mode will setup the HTTP Server to only accept certain requests from servers with the Compaq Insight Manager 7 names designated in the Trust By Name field: The Trust by Name option is easy to configure, and will prevent non-malicious access. An example of why you may want to use Trust by Name would be if you have a secure network but your network has two groups of administrators in two separate divisions, it would prevent one group from installing software to the wrong system. This option will not verify anything other than the Compaq Insight Manager 7 server name submitted.

To use the Trust By Name option:

1. Select Trust By Name.

2. Enter the name of the server you want to allow access. If you want to trust more than one Compaq Insight Manager 7 servers, then you can separate the server names with a semi-colon.

NOTE:  Although Trust By Name mode is a slightly stronger method of security than the Trust All mode, it still leaves your system vulnerable to security attacks.

Trusted Certificates

The Trusted Certificates section allows you to manage your certificates in the Trusted Certificates list.

 

To use the Trusted Certificates option:

a. In the Compaq Insight Manager 7 Server Name field, enter the name of the server you wish to receive a certificate from.

b. Click Get Cert. The certificate data displays.

c. Click Add Cert to add the displayed certificate to the Trusted Certificates List.

NOTE:  If Compaq Insight Manager 7 is reinstalled or re-generated a new certificate, you must remove the trusted servers and start again with step a. Even though the Compaq Insight Manager 7 server name is the same in the list, the underlying certificate has changed.

Customer Generated Certificates

The Customer Generated Certificates option allows you to use certificates that are not generated by Compaq. If this option is selected, the self-signed certificate that was originally generated by the Compaq HTTP Server will be replaced with one that was issued by a Certificate Authority. The first step of the process is to cause the Compaq HTTP Server to create a Certificate Request (PKCS #10). This request utilizes the original private key that was associated with the self-signed certificate and generates the appropriate data for certificate request (the private key never leaves the server during any of this process). Once the PKCS #10 data has been created, the next step is for the user to send that off to a Certificate Authority. Once the Certificate Authority has returned PKCS #7 data, the final step is to import this into the Compaq HTTP Server. Once the PKCS #7 data has been successfully imported, the original \compaq\wbem\cert.pem certificate file will be overwritten with the device’s certificate from that PKCS #7 envelope. The same private key is used for the new imported certificate as was used with the previous self signed certificate.

To use the Customer Generated Certificate option:

1. Click Create PKCS #10 Data. A screen displays indicating that the PKCS #10 Certificate Request data has been successfully generated.

2. Copy the certificate data.

3. Send PKCS #10 certificate request data to a Certificate Authority and ask them to send you the certificate request reply data in the form of PKCS #7 format. Request that the reply data be in base64 encoded format. If you organization has its own PKI/Certificate Server implemented, send the PKCS#10 data to the Certificate Authority manager and request the PKCS#7 reply data.

NOTE:  The selected certificate signer generally charges a fee.

4. When the certificate signer sends the PKCS#7 certificate request reply data to you, copy the data from the PKCS#7 certificate request reply and paste the copied data in the PKCS #7 Data field.

5. Click Import PKCS #7 Data. A message displays indicating whether or not the “customer generated certificate” was successfully imported.

6. Stop the services.

7. Restart the services.

8. Browse to the managed device that contains the imported certificate.

9. Select view the certificate when prompted by the browser. Be sure the signer is listed as the signer you used, and not listed as Compaq, before importing the certificate into your browser. Alternatively, you can import root CA cert into all the browsers on your network to avoid being prompted.

NOTE:  If the certificate issuer’s organizational unit (OU) is still listed as ‘Compaq Management HTTP Server’, you will need to start over with step a.

NOTE:  If the certificate signer of your choice sends you the certificate data in base64 encoded form instead of PKCS #7 data, you must copy the base64 encoded file to the filename /Compaq/WBEM/Cert.pem and reboot the machine.

NOTE:  Click Default Configuration to revert to default settings. This will not remove imported Trusted Compaq Insight Manager 7 certificates or imported Customer Generated certificates.

NOTE:  Once you have successfully imported the PKCS#7 certificate, you may see a dialog box. In order to eliminate this box, you will need to import the Certificate.

NOTE:  Authority’s certificate into your browser as a Trusted Root Certification Authority. Your Certificate Authority can provide you with their certificate and you can import it into your browser via the normal process. Refer to the help files that came with your browser for details on how to import a certificate.

Tasks

The Tasks tab displays links to task oriented pages provided by participating Compaq Web-enabled System Management software.

NOTE:  If no tasks are provided by the Compaq Web-enabled System Management software, the Tasks tab will not be visible.

 

Tools

The Compaq Web-enabled System Management software provides information that displays on the Tools tab. For example, the Compaq Survey Utility displays on this tab.

NOTE:  If no information is provided by the Compaq Web-enabled System Management software, the Tools tab will not be visible.

 

Logs

The Logs tab includes various log information. Any logs contained in the installed Compaq Web-enabled System Management software can be displayed on this tab. For example, if the Compaq Version Control Agent is installed, a link to the Compaq Version Control Agent log displays on the Logs page. You can access the entry point to the log shown by clicking on the link.

 

HTTP Server Log

The HTTP Server Log contains primarily security related events. This log is helpful when troubleshooting security problems in participating Compaq Web-enabled System Management software.

How to Replicate Passwords and Configuration Data Across Multiple Devices

If your enterprise has numerous devices and you wish to share common passwords, configuration information, and certificates of trusted Compaq Insight Manager 7 servers, this can be accomplished by copying certain files from the desired device to the other devices.

To replicate the user passwords, replicate the following file:

\compaq\wbem\cpqhmmd.acl

To replicate the HTTP Server configuration information, replicate the following files:

\compaq\wbem\homepage\cpqhmmd.ini

\compaq\wbem\homepage\cpqhmmdx.ini

To replicate the certificates of the trusted Compaq Insight Manager 7 servers, replicate all files that exist in the following subdirectory:

\Compaq\wbem\certs

After the desired file(s) have been replicated to a given device, the HTTP server will need to be restarted before the changes will take affect.

Navigation

Depending on the browser you are using, the display for this version of Compaq Survey Utility may differ. With Internet Explorer 4.0 or greater, you will be able to view either the Dynamic HTML Interface or the Framed Interface.

Dynamic HTML Interface

You can view the Dynamic HTML Interface if you are using Compaq Survey Utility with Microsoft Internet Explorer. The Dynamic HTML interface contains the following three areas:

Title Area— located in the upper middle portion of the browser window, contains the following links:

Navigation Area—located underneath and to the left of the Title Area, allows navigation of the report in the Data Area below. This area contains the following links:

Data Area—comprises the remainder of the browser window and is used for setting configuration options or displaying a Survey Utility Report.

Framed Interface

The Framed Interface is displayed when using Compaq Survey Utility with Netscape Navigator. If you are using Compaq Survey Utility with Microsoft Internet Explorer, you can choose to display this view by clicking the Disable DHTML link on the Options page. The Framed Interface contains the following three frames:

Title Frame—located in the upper left corner of the browser window, contains the following links:

Navigation Frame—located below the Title Frame on the left side of the window, contains a tree applet that allows navigation of the report in the Data Frame on the right. Click a tree item to open it, and the report in the Data Frame on the right is positioned to place the selected data at the top of the window. All data in the report remains available in the data window.

The keyboard can also be used to navigate the tree applet. Use the up and down arrows to navigate vertically through the tree. Use the right arrow to open a branch or subfolder. After one second of inactivity, the data window is automatically repositioned to the selected item.

Data Frame—comprises the remainder of the browser window and is used for setting configuration options or displaying a Survey Utility Report.

Related Topics:

Survey Utility Report Example

Troubleshooting Web-enabled Compaq Survey Utility

Using the Compaq Survey Utility Options