Allowing Scripted Uninterrupted Uninstall
When you attempt to run a silent command-line uninstallation, you often run into issues when the currently installed CSA policy queries prompt the user. These queries are typically related to stopping the agent service and running installation programs. You can circumvent these issues through CSA policy implementation and a tool like SysInternals PSEXEC, which allows you to run commands on local and remote systems as another user.
To accomplish this, follow a few simple steps to make an additional policy that allows you to perform the unattended uninstallation without prompts.
Step 1 Create two rule modules called Unattended CSA Uninstallation Rule Module and Unattended CSA Uninstallation Rule Module 2.
Step 2 Set these rule modules to be enforced only when a User/Group state set is active.
For our example, use the Administrator state set for Unattended CSA Uninstallation Rule Module and System Account state set for Unattended CSA Uninstallation Rule Module 2. Figure 7-11 shows an example of setting the state set.
Figure 7-11 New Rule Module with State Set Applied
Figure 7-11 New Rule Module with State Set Applied
Step 3 Create a new policy called Unattended CSA Uninstallation Policy and associate the previously created rule modules from step 1 to this policy.
Step 4 Add the necessary rules to the new rule modules:
(a) Add an Agent Service Control rule to the Unattended CSA Uninstallation Rule Module, which will Allow <All Applications> (or specifically the csacontrol.exe application) to disable the Agent Service.
(b) Add an Application Control rule to allow SVCHOST.EXE to run SETUP.EXE in the specified agent installer path in the Unattended CSA Uninstallation Rule Module 2.
(c) Add any other rules necessary per your own testing and currently deployed policy. You can see the rules in the sample rule modules in Figures 7-12 and 7-13.
Figure 7-12 Rules Applied when Administrator State Set Matches
|
File Edit View Favorites Tools help |
yai»i ["J |
||
|
^Back - * - © ® dl 1 ^Search [¿] Favorites Media ¡J | S^ |
|||
|
Address h t tp s: i / ci am c45/csa mc 45/w ebad mi n |
zl t><- |
||
|
ClSC^YSTtHS Management Center for Cisco Security Agents V4.5 |
Close 1 He |
p 1 About |
|
|
Configuration > Rule Modules » Windows Rule Modules > CSA Unattended Uninstaller Module > Rules |
other rule mod |
J |
|
|
Rules: 1 fl enforce; □ detectl |
|||
|
r ID Type Events Status Action Log Description |
|||
|
I- 1017 Add licati on control Enabled ^ Allow ad mi nistrator to allow svchost.exe to ri |
n C:\CSA-Agent-Files\setup.exe |
||
|
•»■Add rule a (Copy) |to rule module | CSA Unattended Uninstaller Module |
|||
|
'1 |
|||
|
Delete I Enable I Disable I ■ No rule changes pendin^~~l^^^^BOTranPH Management Center For Cisco Security Agents V4.5 |
1 11 Lnral Intranet |
„ admin |
|
Figure 7-13 Rules Applied when System User State Set Matches
Figure 7-13 Rules Applied when System User State Set Matches
Step 5 Add your new policy to the appropriate groups to propagate the policy as necessary.
Step 6 Change your command line to use the SysInternals psexec tool that allows specification of the user that should run the command on the system as displayed in the DOS command that follows and also in Figure 7-14.
psexec -u administrator -p cisco123 setup.exe /s --mt=removeall --autolevel=3
Figure 7-14 PSEXEC Uninstalling the Agent as Administrator
Figure 7-14 PSEXEC Uninstalling the Agent as Administrator
It is important to note that this succeeded because of the use of state sets. If you need to see the active state sets on a system from the CSA MC console, simply navigate to the specific agent page and select Detailed Status and Diagnostics. You can see from Figure 7-15 that the test system did in fact have the local Administrator account logged in, which allowed completion of the uninstallation without CSA queries.
Figure 7-15 Diagnostics Displays Current State Sets
Figure 7-15 Diagnostics Displays Current State Sets
NOTE The CSA product is extremely flexible. The use of devices, such as state sets and dynamic application classes, allow you to create policies that are granular and secure without opening permanent security holes in your systems.
Continue reading here: Web Serveri PlanetSolaris
Was this article helpful?