Operating System - HP-UX
1752525 Members
4976 Online
108788 Solutions
New Discussion

IDSv2 + CA Access Control performance issue

 
Alex Gayainsky
Occasional Contributor

IDSv2 + CA Access Control performance issue

Hi,

I succeeded to install IDS/9000 v2 on our
server & run it. But now I have performance
problem.

Process "idssysdsp" that tracks log files does "su root" all the time. We have "CA Access
Control" installed on server. "Access Control"
catches every "su" & proceede it thru its own
checks. As a result, CPU usage jumps to the
sky.

Do you know any way to run "idssysdsp" as root and not "ids" to prevent su execution ?

Thanks a lot,
Alex
Alex
1 REPLY 1
Stephanie Miller
Occasional Advisor

Re: IDSv2 + CA Access Control performance issue

Hi Alex,

I was just browsing through the ITRC posts, and noticed you didn't get a reply to your message. Sorry this response wasn't sooner.

We designed the IDS/9000 product with security of the product in mind. For this reason every IDS/9000 process must run from a non-priveleged account, the user ids was created at install time. So the answer is that it is not possible to change the ownership of any IDS process. If you have another product monitoring "su", you can modify the IDS/9000 template to filter out this particular event.


Cheers,
-Stephanie