# Documentation Nexus IQ Server 1.26

**Nexus IQ Server 1.26**

Our documentation site has moved. For the most current version, please see [http://help.sonatype.com](http://help.sonatype.com)

# Chapter 5. Quick Start Guide - Nexus Lifecycle

This guide can help you get IQ Server up and running for the purpose of trying out its features before installing it in your development environment. It should take approximately 15 minutes to complete using sample policies and applications.

|  |  |
| Nexus Lifecycle requires a license in order to experience the functionality described in this guide. If you are<br>looking to try or purchase, Nexus Lifecycle, [schedule a demo](/content/nexus-lifecycle-demo/index.html)<br>or [contact us](/content/contact-us/index.html), and we’ll be happy to assist. |

### Step 1: Installing and Starting IQ Server

Installing the IQ server is really a case of downloading the archived server, picking a location, and unpacking the contents. Since we won’t be focused on mimicking a production experience, most laptop and desktop configurations should run IQ Server with no problem. If you are looking to plan for the future though, be sure to review the [server requirements](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/requirements-installation.html#requirements-server "3.2.1. IQ Server") section of the [Requirements](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/chapter-requirements.html "Chapter 3. Requirements") chapter.

1. Create an installation directory in your desired location.
2. [Download the latest version of IQ Server](http://links.sonatype.com/products/clm/download) to the installation directory.
3. Extract the `tar.gz` or `.zip` file.

Once you’ve extracted the contents, follow the steps below to run IQ Server:

1. Using a command line interface, switch to the nexus-iq-server bundle directory in your installation directory e.g. `nexus-iq-server-x.xx.x-xx-bundle`.
2. Run one of the following commands to start IQ Server:
   - Linux or Mac: `./demo.sh`
   - Windows: `demo.bat`
3. Open IQ Server in a browser using the default URL: [http://localhost:8070](http://localhost:8070/)
4. Log in using the default Administrator account:
5. Install the required product license supplied to you by the [Sonatype Support team](mailto:support@sonatype.com).
   1. Click _Install License_.
   2. Navigate to the license file (`.lic`) and click _Open_.
   3. Click _I Accept_ to accept the End User License Agreement.

|  |  |
| IQ Server needs access to an external data service to perform evaluations, which may be blocked in your<br>internal environment. For a workaround, see [Running IQ Server Behind a HTTP Proxy Server](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/main-configuration.html#proxy-configuration "6.2.2. Running the IQ Server Behind a HTTP Proxy Server")<br>in the IQ Server documentation. |

### Step 2: Importing Sample Policies

Policy is at the core of IQ Server’s automation capabilities. While you can create a completely custom set of policies, importing the [Sonatype Sample Policy set](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/policy-getting-started.html#sample-policy-set "9.2.1. Downloading the Sample Policy Set") set is the quickest way to get started. This set includes multiple policies for triggering violations on security vulnerabilities, licensing issues, architecture issues, and more.

1. In a separate browser tab or window, download the [Sonatype Sample Policy set](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/policy-getting-started.html#sample-policy-set "9.2.1. Downloading the Sample Policy Set") (`.json` file) from the IQ Server documentation.
2. In IQ Server, click the _Organization & Policies_ icon  on the IQ Server toolbar.
3. The _Root Organization_ should be selected in the sidebar. Click the _Actions_ menu and select _Import_ _Policies_.
4. In the _Import Policies_ dialog, click _Choose File_, select the `.json` file you downloaded, and click _Open_.
5. Click the _Import_ button.

**Figure 5.1. Import Policy Dialog**

### Step 3: Configuring Organizations and Applications

When evaluating applications, understanding IQ Server’s system hierarchy is critical: Root Organization, organization, and application. This means policies and other configuration items are inherited from the Root Organization on down. This allows for easier policy management especially when you have multiple organizations and applications. Thus, in order to evaluate an application, you must have at least one organization and a corresponding application.

Creating an organization:

1. In the _Organization & Policies_ area, with the _Root Organization_ selected in the sidebar, click the _New_ _Organization_ button.
2. In the _New Organization_ dialog, enter a name into the _Organization Name_ text box.
3. Click the _Create_ button.

**Figure 5.2. New Organization Dialog**

Creating an application:

1. With your newly created Organization selected in the sidebar, click the _New Application_ button.
2. In the _New Application_ dialog, enter an _Application Name_ and _Application ID_.
3. Click the _Create_ button.

**Figure 5.3. New Application Dialog**

### Step 4: Evaluating Applications

After you install, start, and configure IQ Server, you are ready to evaluate applications. If you need a sample application, you can download WebGoat (`webgoat-container-x.x.x-war-exec.jar`) at [https://github.com/WebGoat/WebGoat/releases](https://github.com/WebGoat/WebGoat/releases).

To evaluate an application:

1. In the _Organization & Policies_ area, select your application in the sidebar. The file that you evaluate will be associated with this application.
2. Go to the _Actions_ menu, and click _Evaluate Binary_.
3. In the _Evaluate a Binary_ dialog:
   1. Click the _Choose File_ or _Browse_ button, select the file to evaluate, and click _Open_.
   2. Click to select any stage to associate with the evaluation (e.g. Build).
   3. Click _No_ to prevent sending notifications of policy violations as defined in the policy’s configuration settings.
   4. Click the _Upload_ button to begin evaluating the selected application. An _Evaluation Status_ message is displayed.
   5. When the evaluation is complete, click the _View Report_ button to open the Application Composition Report for the application.

### Step 5: Reviewing Results

Once evaluated, the results of a binary evaluation are displayed in the Application Composition Report, which you can always access by clicking the Reporting icon  on the IQ Server toolbar.

The report’s information is divided into four tabs:

- _Summary_ - An overview of identified components and their policy alerts, security issues, and license analysis.
- _Policy Violations_ - A list of violated policies and the components that triggered them sorted by threat level from highest to lowest.
- _Security Issues_ - A list of security vulnerabilities and the components that triggered them sorted by threat level from highest to lowest.
- _License Analysis_ - A list of license issues and the components that triggered them sorted by license threat from highest to lowest.

For a more thorough explanation of the report, see the [Application Composition Report](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/report.html "Chapter 12. The Application Composition Report") chapter in the [Nexus IQ Server Documentation](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/index.html).

**Figure 5.4. Application Composition Report**

### Step 6: Investigating & Remediating Violations

In the Application Composition Report, you can drill down to learn specific details about a violation. In every tab (except the Summary tab), you can click an individual component to open the _Component Information Panel_ (CIP). The CIP displays many details, which are divided into different sections or tabs. To get you started using the CIP, take a look at these sections:

- _Component Info_ - In the graph, you can move the vertical bar to learn the differences between versions of a component.
- _Policy_ - You can click the Waive button to force IQ Server to ignore a policy violation.
- _Licenses_ - You can track your research about a particular license and even override one.
- _Vulnerabilities_ - You can click _Info_ for a thorough explanation of a component’s vulnerability and a recommended action.
- _Claim Component_ - You can tell IQ Server to recognize a component even though it was previously identified as unknown.

This is just a small sample of the component information available in the CIP. For a complete discussion of the CIP, see [Component Information Panel](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/component-information-panel.html "12.4. The Component Information Panel (CIP)") in the [Nexus IQ Server Documentation](https://books.sonatype.com/sonatype-clm-book/1.26/html/book/index.html).

**Figure 5.5. Component Information Panel**
