01.10.2015 Views

HP Operations Manager for UNIX Administrator’s Reference

HP Operations Manager for UNIX Administrator's Reference

HP Operations Manager for UNIX Administrator's Reference

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About <strong>HP</strong>OM Security<br />

About Security in <strong>HP</strong>OM<br />

About Database Security<br />

Security of the database is controlled by the operating system and by the<br />

database itself. Users must have an operating system logon <strong>for</strong> either<br />

remote or local access to the data. After a user is logged on, security<br />

mechanisms of the database control access to the database and tables.<br />

For more in<strong>for</strong>mation about database security, see Using Relational<br />

Databases with <strong>HP</strong> Network Node <strong>Manager</strong> and the vendor’s manuals<br />

supplied with the database.<br />

Starting Applications<br />

Applications run under the account (user and password) specified by the<br />

administrator during application configuration. The action agent uses<br />

the in<strong>for</strong>mation in this account be<strong>for</strong>e executing an application, that is, it<br />

switches to the user specified and then uses the name and password<br />

stored in the application request to start the application.<br />

About User Root<br />

If the user account under which the <strong>HP</strong>OM agents are running has been<br />

switched to a user other than root, you have to carry out additional<br />

configuration steps. For more in<strong>for</strong>mation, see the man page<br />

opcswitchuser(1M).<br />

About Password Aging<br />

Application execution can be compromised by the use of password aging.<br />

Password aging is a feature of some system security standards such as<br />

C2 that requires passwords to expire after:<br />

❏<br />

❏<br />

❏<br />

Specified period of time has passed.<br />

Specified date has been reached.<br />

Specified number of unsuccessful login attempts have been made.<br />

If password aging is enabled, application startup failures may occur due<br />

to the account that a given application uses being temporarily<br />

inaccessible. Such failures can be avoided by implementing the <strong>HP</strong>OM<br />

pluggable authentication module (PAM) interface, which enables<br />

third-party authentication methods to be used while preserving existing<br />

system environments.<br />

Chapter 11 363

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!