01.10.2015 Views

HP Operations Manager for UNIX Administrator’s Reference

HP Operations Manager for UNIX Administrator's Reference

HP Operations Manager for UNIX Administrator's Reference

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About <strong>HP</strong>OM Security<br />

About Security in <strong>HP</strong>OM<br />

}<br />

About Java GUI Permissions<br />

This section describes permissions in the Java-based operator GUI.<br />

Accessing the Java-based Operator GUI<br />

The <strong>HP</strong>OM Java-based operator GUI communicates with the <strong>HP</strong><br />

<strong>Operations</strong> management server through port 2531. The inetd listens at<br />

port 2531 and starts the process /opt/OV/bin/OpC/opcuiwww when it<br />

receives a request <strong>for</strong> the service ito-e-gui.<br />

By default, the <strong>HP</strong> <strong>Operations</strong> management server accepts connections<br />

from any client. You can restrict client acceptance to specific systems by<br />

editing the /var/adm/inetd.conf file on the management server. Make<br />

sure to specify the systems <strong>for</strong> the service ito-e-gui.<br />

About Program Security<br />

This section describes security <strong>for</strong> <strong>HP</strong>-UX and MPE/iX programs.<br />

Accessing <strong>HP</strong>-UX Programs<br />

The <strong>HP</strong>-UX 11.x programs /opt/OV/bin/OpC/opc and<br />

/opt/OV/bin/OpC/opcuiadm) have the s-bit (set user-ID on execution).<br />

Accessing MPE/iX Programs<br />

For MPE/iX, the job OPCSTRTJ.BIN.OVOPC contains the readable<br />

password of AGENT.OVOPC if the standard STREAM facility is used. If the<br />

managed node has a customized stream command specified, no password<br />

is inserted in OPCSTRTJ.BIN.OVOPC. This entry is only established<br />

during first-time installation, or if the <strong>HP</strong>OM entry is found in<br />

SYSSTART.PUB.SYS.<br />

Change the job according to your security policies. The job is streamed<br />

during system boot by SYSSTART.PUB.SYS and is responsible <strong>for</strong> starting<br />

the Local Location Broker (if not yet running) and the <strong>HP</strong>OM agents.<br />

362<br />

Chapter 11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!