26 ZENworks Endpoint Security Management Installation Guidenovdocx (en) 17 September 2009Please check off the following prerequisites prior to beginning the installation: Ensure Management Service (MS) to Policy Distribution Service (DS) server name resolution:make sure that the target computer where the MS is installed can ping the DS server name(NETBIOS if the DS is configured inside the network firewall or FQDN if installed outside inthe DMZ). If successful, this is the server name to enter during installation. If unsuccessful, you mustresolve this issue before continuing with the installation. Ensure Endpoint Security Client to DS server name resolution: validate that the endpointclients (where the Endpoint Security Client is installed) can ping the same DS server name usedabove. If unsuccessful, you must resolve this issue before continuing with the installation. Enable or install Microsoft Internet Information Services (IIS), ensure that ASP.NET isenabled, and configure it to accept Secure Socket Layer (SSL) Certificates.IMPORTANT: Do not enable the Require secure channel (SSL) check box on the SecureCommunictions page (in the Microsoft Computer Management utility, expand Services andApplications > expand Internet Information Services (ISS) Manager > expand Web Sites >right-click Default Web Site > click Properties > click the Directory Security tab > click theEdit button in the Secure communications group box). Enabling this option breaks thecommunication between the ZENworks Endpoint Security Management server and theZENworks Endpoint Security client on the endpoint. If you are using your own SSL certificates, ensure that the Web service certificate is loaded onthe machine and that server name validated in the previous steps (whether NETBIOS orFQDN) matches the Issued to value for the certificate configured in IIS. If you are using your own SSL certificates, validate the SSL from the MS server to the DSserver: open a Web browser on the Management Service and enter the following URL:https://DSNAME (where DSNAME is the server name of the DS). This should return valid dataand not certificate warnings (valid data may be "Page under Construction"). Any certificatewarnings must be resolved before installation, unless you opt to use Novell Self SignedCertificates instead. Ensure access to a supported RDBMS (Microsoft SQL Server 2000 SP4, SQL Server Standard,SQL Server Enterprise, SQL Server 2005). Set the database to Mixed mode. This databaseshould be either hosted on the Management Service server or on a shared server secured behindthe enterprise firewall.5.1 Installation StepsClick Policy Distribution Service Installation from the Installation interface menu. The PolicyDistribution Service installation begins.At launch, the installer verifies that all required software is present on the server. If any software isabsent, it is installed automatically before the installation continues to the Welcome Screen (licenseagreements for the additional software might need to be accepted). If Microsoft Data AccessComponents (MDAC) 2.8 need to be installed, the server must reboot following that installationbefore ZENworks Endpoint Security Management installation can continue. If you are usingWindows 2003 Server, ASP.NET 2.0 is configured to run by the installer.After Policy Distribution Service installation begins, perform the following steps: