Installing Management and Orchestration (v9.0.0 and up)

You have to first install CxSAST. For further information and instructions, refer to Installing CxSAST. While installing CxSAST, Management and Orchestration is installed and configured as well. The following Management and Orchestration setup and synchronize performs the Management and Orchestration/CxSAST Database synchronization.

The CxSAST services will be stopped during initial synchronization. Initial synchronization may take some time depending on the size of the database and the amount of data being synchronized. The estimated synchronization time is based on the following:

  • For every 1M CxSAST results/CxOSA libraries, the estimated synchronization time is approximately 5 minutes. This is also relevant also for incremental synchronization.
  • The estimated synchronization time is also effected by the environment resource utilization - connection to the database, Server memory and CPU, etc.
    For example, synchronization of a CxSAST environment with 5M CxSAST results and 2M CxOSA libraries will take approximately 35 minutes.

To set up and synchronize Management and Orchestration:

 1. Once the Installation Completed Successfully dialog indicates that the CxSAST installation is completed, verify that Start Database Synchronization is checked.

 

 2. Click <Close>. The Risk Management Installation setup preparation wizard appears.

 

 3. Once the Risk Management Installation preparation wizard is complete, the Risk Management Welcome screen is displayed.

 

 4. Click <Next> to continue. The Management and Orchestration setup starts.

 

5. Once the Management and Orchestration/CxSAST Database Configuration screen is displayed, enter the database credentials.

 

Database credentials are only required, if a connection using SQL Server Authentication has been defined during the CxSAST installation. Provide the SQL user name and password for login with SA permissions.

 6. Enter the following database credentials:

  • Risk Management DB Password – Password used to access the Risk Management database
  • CxSAST DB Password – Password used to access the CxSAST database

The Username and Password should be the same as was used when the Management and Orchestration / CxSAST database in SQL Server was configured.

 7. Once the Management and Orchestration setup is complete, click <Next> to continue. The database connection verification starts; first for the Checkmarx Risk Management database and then for the CxSAST database.

 

 8. Once the Database Synchronization screen is displayed, click <Next> to continue. The Log File Content screen appears.

 

Clearing the checkbox hides the Log File Content screen.

 9. Once the Log File Content screen is displayed, click <Next> to continue.

 

 10. Once complete, the Management and Orchestration Setup Completed Successfully screen is displayed.

 

If the installation failed, the reason can usually be found in the installation log file, see Installation Logs.

 11. Click <Finish> to complete the installation and close the wizard.

For details about configuring Management & Orchestration for SSL and FIPS compliancy, refer to Configuring Management & Orchestration for SSL and FIPS Compliancy.

Installation Logs

If the installation failed for any reason, the cause can be found in the following log files: 

Management and Orchestration logs:

C:\Program Files\Checkmarx\Logs\CxArm

Tomcat Logs:

C:\Program Files\Checkmarx\Logs\CxARM\Tomcat\....

  • cxarm<date>.log
  • eventsReport<date>.log

ETL logs (initial sync + incremental sync):

C:\Program Files\Checkmarx\Logs\CxARM\ETL\....

  • SyncETL.log
  • IncrementalSyncETL.log
  • i4j_log_Risk Management_<some number>.log (successful installation)

For unsuccessful Installation: C:\Program Files\Checkmarx\Logs\CxARM\ETL\.install4j\....

  • Installation.log

For details about configuring a non-default location for Management and Orchestration component data and logs, refer to Configuring a Non-default Location for Management and Orchestration Component Logs and Configuring a Non-default Location for Management and Orchestration and CxSAST Component Data.

.