Novell ZENworks Endpoint Security Management 3.5 Manuale Utente

Pagina di 245
ZENworks® ESM 3.5
Administrator’s Manual
73
Note:
The machine must be a member of the Policy Distribution Service's domain for the first policy sent down. 
Occasionally, Microsoft will not generate the SID immediately, which can prevent the ZSC on that machine 
from receiving its credential from the Management Service. When this occurs, reboot the machine 
following complete ZSC installation to receive the credentials
When switching an ZSC from accepting user-based policies to accepting machine-based policies, 
it will continue to enforce/use the LAST policy downloaded by the current user, until credentials 
are provided. If multiple users exist on the machine, it will use only the policy assigned to the 
currently logged in user. If a new user logs in, and the computer SID is unavailable, it will use the 
default policy included at installation, until the computer SID is available. Once the computer SID 
is available for the endpoint, all users will have the machine-based policy applied.
Distributing Unmanaged Policies
To distribute polices to unmanaged ZSCs, perform the following steps: 
Step 1: Locate and copy the Management Console's setup.sen file to a separate folder. 
The setup.sen file is generated at installation of the Management Console, and placed in 
\Program Files\Novell\ESM Management Console\
Step 2: Create a policy in the Management Console (see Chapter 7)
Step 3: Use the Export command (see page 116) to export the policy to the same folder containing 
the setup.sen file. 
All policies distributed MUST be named policy.sen for an unmanaged ZSC to accept 
them.
Step 4: Distribute the policy.sen and setup.sen files. These files MUST be copied to the \Program 
Files\Novell\ZENworks Security Client\ directory for all unmanaged clients. 
The Setup.sen file only needs to be copied to the unmanaged ZSCs once, with the first policy. 
Afterwards, only new policies need to be distributed.