IT PAM 3.0 SP1 Installation Steps

book

Article ID: 50485

calendar_today

Updated On:

Products

CA Workload Automation AE - Business Agents (AutoSys) CA Workload Automation AE - Scheduler (AutoSys) CA Workload Automation Agent CA Process Automation Base

Issue/Introduction

Description:

This doc walks the user though the installation of IT PAM 3.0 SP1

Solution:

This doc covers step-by-step directions for:

  • Installing CA IT PAM and its prerequisites

  • Accessing the user interface to verify the install

Installer for ITPAM

The ITPAM installer can be downloaded from the CA Support site at support.ca.com. Once you have copied the installation package proceed to the next step.

NOTE: If this is an upgrade and EEM is already installed, you can skip the EEM installation instructions. But make sure to follow the Create IT PAM Security Objects instructions for upgrading your EEM security objects using the itpam_eem_upgrade3.0SP01.xml file.

Step 1: Install and Configure CA Embedded Entitlements Manager (EEM)

Install EEM

Locate the file "EEMServer_8.4.244_win32.exe" from the DVD2\EEM folder location shown below and double click it.

<Please see attached file for image>

Figure 1

<Please see attached file for image>

Figure 2

Click the Next button.

<Please see attached file for image>

Figure 3

Read the license agreement and highlight acceptance radio button and hit Next.

Enter a password for the EiamAdmin user. Here we will use 'itpam'

<Please see attached file for image>

Figure 4

Take the default on the next screen for the install location of EEM

Select the Java Home location. The installation should detect it and display the folder name. If not, please provide the Java directory.

<Please see attached file for image>

Figure 5

The installation will continue for some time

At the end of the installation, the screen shown below will inform you that the installation of EEM is complete.

<Please see attached file for image>

Figure 6

Verify that you can login to EEM.

<Please see attached file for image>

Figure 7

Start--> Programs --> CA --> Embedded Entitlements Manager --> EEM UI.

Provide password as 'itpam' that you specified during the installation and hit "Log In" button.

<Please see attached file for image>

Figure 8

You should be able to see the screen shown above

This means that EEM has been installed successfully

Create IT PAM Security Objects

  1. Copy the IT PAM security configuration XML file ("ITPAM_eem.xml") from the \EEM sub-directory on DVD 2 of the CA IT PAM installation media to the \iTechnology sub-directory that was created when EEM was installed. By default this is:

    C:\Program Files\CA\SharedComponents\iTechnology

    NOTE: If this is an upgrade, copy the itpam_eem_upgrade3.0SP01.xml instead of the itpam_eem.xml file for the above step. And substitute that file name in the command below.

  2. Open a command window and traverse to the location where the ITPAM_eem.xml file was copied in the previous step.

    Safex.exe -h <hostname> -u EiamAdmin -p <Password> -f ITPAM_eem.xml

    Hit Enter and you should see the following as the output of that command. (host name whited out)

    <Please see attached file for image>

    Figure 9

  3. The above result also creates the "itpamcert.p12" file in the \iTechnology sub-directory and populates the required security objects for ITPAM in EEM which we will verify next.

    TIP: Should you encounter a problem the ITPAM objects created can easily be removed by copying the "UnRegisterITPAM.xml" (also located in the \EEM sub-directory on CD 2 of the CA IT PAM installation media) to the \iTechnology sub-directory then running the command:

    safex.exe -h <hostname> -u EiamAdmin -p <Password> -f UnRegisterITPAM.xml

  4. Proper execution of the "safex.exe" command creates the following required IT PAM security groups and users in EEM:

    • ITPAMAdmins group

    • ITPAMUsers group

    • ITPAMAdmin user

    • ITPAMUser user

      Verify IT PAM Security Objects in EEM

      <Please see attached file for image>

      Figure 10

      Use the EEM UI shortcut created by the EEM installation (All Programs -> CA -> Embedded Entitlements Manager -> EEM UI) to launch the application

      When the EEM login screen is displayed, choose "ITPAM" from the Application drop down list. Specify "EiamAdmin" in the user text box. Provide the "EiamAdmin" password that was set when EEM was installed which is 'itpam'.

      <Please see attached file for image>

      Figure 11

      The Home tab is displayed by default. Click on 'Manage Identities'

      <Please see attached file for image>

      Figure 12

      <Please see attached file for image>

      Figure 13

      Click Users and hit Go. You should see 2 users 'itpamadmin' and 'itpamuser.

      Click Groups and click on Go. You should see 2 groups 'ITPAMAdmins' and 'ITPAMUsers.

      <Please see attached file for image>

      Figure 14

      Logout and exit the EEM GUI.

Step 2: Install Third Party components for ITPAM

CA IT PAM relies on the following third party components:

  • JBoss

  • Hibernate

  • JDBC

Locate the file called as "Third_Party_Installer_windows_32.exe" from the Media1 as shown below and double click it.

<Please see attached file for image>

Figure 15

Click "Next" on the Welcome screen

<Please see attached file for image>

Figure 16

Accept agreement and hit Next button.

<Please see attached file for image>

Figure 17

Take the default installation folder and hit Next button

<Please see attached file for image>

Figure 18

Hit Next button on the next Prerequisites screen

<Please see attached file for image>

Figure 19

The next screen shows the default location for JBoss installer. Hit Next.

<Please see attached file for image>

Figure 20

The JBoss installation starts as seen below.

<Please see attached file for image>

Figure 21

Once the JBoss install completes it prompts for the Hibernate install

<Please see attached file for image>

Figure 22

Once the install of hibernate is complete, it prompts for the JDBC jar files. For the purposes of this doc we will use Sql Server 2005 as the database. Select the "Add Files" button. Drop down and select MS SQL 2005. The jar file location automatically appears as shown below. Hit the Next button.

<Please see attached file for image>

Figure 23

We will not be using/configuring the telephony services for purposes of this doc so click Next to continue without making any changes

<Please see attached file for image>

Figure 24

The next screen shows the status of this installer. Hit Next button.

<Please see attached file for image>

Figure 25

The installation of the third party components is now complete. Next step is to proceed to the install of ITPAM. Click Browse to select the location of the second media (DVD2). Click the Finish button.

<Please see attached file for image>

Figure 26

The installation media is copied to a temp location by this installer which can take some time. Click the Finish button to start the ITPAM installation.

Step 3: Install ITPAM

Select Next on the Welcome screen for the ITPAM Domain setup

<Please see attached file for image>

Figure 27

Accept the Agreement and click the Next button

<Please see attached file for image>

Figure 28

Provide the location of Java Home as shown below (note: if Java Home is set on your machine, you may not see this screen)

<Please see attached file for image>

Figure 29

<Please see attached file for image>

Figure 30

We will not configure the load balancer nor the SSO here. So hit the Next button.

<Please see attached file for image>

Figure 31

Next enter the company name

<Please see attached file for image>

Figure 32

Next you will enter a certificate password for ITPAM. For consistency we can use 'itpamcertpass' which is also the certificate password in the ITPAM_eem.xml file which was used to create users/groups earlier. If you have changed this password, you will need to enter the correct password here.

<Please see attached file for image>

Figure 33

Take the default on the folder name for the Start Menu

<Please see attached file for image>

Figure 34

Take the defaults for the next screen and check the option for "Install as a Windows Service" as shown. You can also check Support Secure Communication here to use the SSL certificate that comes with ITPAM.

<Please see attached file for image>

Figure 35

Select a temp directory that your user has read/write access to and click next.

<Please see attached file for image>

Figure 36

Change the Security Type from LDAP to EEM and hit the Next button

<Please see attached file for image>

Figure 37

Enter your machine name as the EEM Server Name, ITPAM as the EEM Application Name (it is case sensitive), location of EEM Certificate file and its password (itpamcertpass)as shown below and hit the "Test EEM Settings" button.

<Please see attached file for image>

Figure 38

<Please see attached file for image>

Figure 39

The username and password will be itpamadmin/itpamadmin for the Verify Settings box and click OK.

<Please see attached file for image>

Figure 40

<Please see attached file for image>

Figure 41

Enter the details about the database server. Select the database as MS SQL, the username and password to access it and then click the "Create Database" button. (Note: this user must have create db privledges)

<Please see attached file for image>

Figure 42

You should see a message about successful database creation. Click OK button.

<Please see attached file for image>

Figure 43

Now click the 'Test Database Settings" button. You should see a successful message as below. Click the OK button

<Please see attached file for image>

Figure 44

For the next screen, just check the box for "copy from main repository" and click the Next button

<Please see attached file for image>

Figure 45

<Please see attached file for image>

Figure 46

Check the only box on the next screen to specify the JAR files and click Next

<Please see attached file for image>

Figure 47

Check the appropriate connectors and hit Next and continue

<Please see attached file for image>

Figure 48

The installation starts

<Please see attached file for image>

Figure 49

When the install is complete, you will see the following screen

<Please see attached file for image>

Figure 50

This confirms the installation of ITPAM is complete.

Step 4: Verifying installation of ITPAM

Open Windows Services and verify that the ITPAM services is created, and start it if it is not already started

<Please see attached file for image>

Figure 51

Go to Start > Programs > CA > ITPAM Domain > Start ITPAM Client. Then enter the username and password as itpamadmin/itpamadmin. Select Log In.

<Please see attached file for image>

Figure 52

You will see the ITPAM Management Console as below

<Please see attached file for image>

Figure 53

Click the ITPAM Client link at the top and wait for the Client to download

<Please see attached file for image>

Figure 54

Once the ITPAM Client downloads you will see as below

<Please see attached file for image>

Figure 55

If the client does not load or gives an error, make sure to add the URL for ITPAM to your browser's trusted sites.

Congratulations! You have successfully completed ITPAM install and configuration.

Environment

Release:
Component: ITPAM

Attachments

1558698413888000050485_sktwi1f5rjvs16o7p.gif get_app
1558698412072000050485_sktwi1f5rjvs16o7o.gif get_app
1558698410368000050485_sktwi1f5rjvs16o7n.gif get_app
1558698408687000050485_sktwi1f5rjvs16o7m.gif get_app
1558698406781000050485_sktwi1f5rjvs16o7l.gif get_app
1558698405057000050485_sktwi1f5rjvs16o7k.gif get_app
1558698403432000050485_sktwi1f5rjvs16o7j.gif get_app
1558698401649000050485_sktwi1f5rjvs16o7i.gif get_app
1558698399894000050485_sktwi1f5rjvs16o7h.gif get_app
1558698397714000050485_sktwi1f5rjvs16o7g.gif get_app
1558698396119000050485_sktwi1f5rjvs16o7f.gif get_app
1558698394359000050485_sktwi1f5rjvs16o7e.gif get_app
1558698392643000050485_sktwi1f5rjvs16o7d.gif get_app
1558698390962000050485_sktwi1f5rjvs16o7c.gif get_app
1558698389263000050485_sktwi1f5rjvs16o7b.gif get_app
1558698387629000050485_sktwi1f5rjvs16o7a.gif get_app
1558698385940000050485_sktwi1f5rjvs16o79.gif get_app
1558698384124000050485_sktwi1f5rjvs16o78.gif get_app
1558698382320000050485_sktwi1f5rjvs16o77.gif get_app
1558698380306000050485_sktwi1f5rjvs16o76.gif get_app
1558698378497000050485_sktwi1f5rjvs16o75.gif get_app
1558698376651000050485_sktwi1f5rjvs16o74.gif get_app
1558698374729000050485_sktwi1f5rjvs16o73.gif get_app
1558698373057000050485_sktwi1f5rjvs16o72.gif get_app
1558698371407000050485_sktwi1f5rjvs16o71.gif get_app
1558698369627000050485_sktwi1f5rjvs16o70.gif get_app
1558698367910000050485_sktwi1f5rjvs16o6z.gif get_app
1558698365947000050485_sktwi1f5rjvs16o6y.gif get_app
1558698364191000050485_sktwi1f5rjvs16o6x.gif get_app
1558698362325000050485_sktwi1f5rjvs16o6w.gif get_app
1558698360476000050485_sktwi1f5rjvs16o6v.gif get_app
1558698358387000050485_sktwi1f5rjvs16o6u.gif get_app
1558698356402000050485_sktwi1f5rjvs16o6t.gif get_app
1558698354661000050485_sktwi1f5rjvs16o6s.gif get_app
1558698352975000050485_sktwi1f5rjvs16o6r.gif get_app
1558698351215000050485_sktwi1f5rjvs16o6q.gif get_app
1558698349367000050485_sktwi1f5rjvs16o6p.gif get_app
1558698347695000050485_sktwi1f5rjvs16o6o.gif get_app
1558698346019000050485_sktwi1f5rjvs16o6n.gif get_app
1558698344158000050485_sktwi1f5rjvs16o6m.gif get_app
1558698342485000050485_sktwi1f5rjvs16o6l.gif get_app
1558698340673000050485_sktwi1f5rjvs16o6k.gif get_app
1558698339063000050485_sktwi1f5rjvs16o6j.gif get_app
1558698337254000050485_sktwi1f5rjvs16o6i.gif get_app
1558698335564000050485_sktwi1f5rjvs16o6h.gif get_app
1558698333851000050485_sktwi1f5rjvs16o6g.gif get_app
1558698331912000050485_sktwi1f5rjvs16o6f.gif get_app
1558698329880000050485_sktwi1f5rjvs16o6e.gif get_app
1558698328221000050485_sktwi1f5rjvs16o6d.gif get_app
1558698326392000050485_sktwi1f5rjvs16o6c.gif get_app
1558698324667000050485_sktwi1f5rjvs16o6b.gif get_app
1558698322862000050485_sktwi1f5rjvs16o6a.gif get_app
1558698321197000050485_sktwi1f5rjvs16o69.gif get_app
1558698319288000050485_sktwi1f5rjvs16o68.gif get_app
1558698317520000050485_sktwi1f5rjvs16o67.gif get_app