01.10.2015 Views

HP Operations Manager for UNIX Administrator’s Reference

HP Operations Manager for UNIX Administrator's Reference

HP Operations Manager for UNIX Administrator's Reference

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About <strong>HP</strong>OM Security<br />

About Security in <strong>HP</strong>OM<br />

About PAM Authentication<br />

You can use PAM (pluggable authentication modules) to retrieve and<br />

check user and password in<strong>for</strong>mation. The user in<strong>for</strong>mation is saved into<br />

a central repository and is accessed by a PAM module. To use PAM <strong>for</strong><br />

authentication, use the command-line tool ovconfchg on the <strong>HP</strong><br />

<strong>Operations</strong> management server. For more in<strong>for</strong>mation, refer to the<br />

ovconfchg man page.<br />

Setting up PAM User Authentication<br />

The <strong>HP</strong>OM user model requires users (humans or programs) to log on to<br />

the <strong>HP</strong> <strong>Operations</strong> management server be<strong>for</strong>e being able to use any<br />

further functionality. This mainly applies to the Java-based graphical<br />

user interface, but also to some of the <strong>HP</strong> <strong>Operations</strong> management<br />

server APIs and command line tools.<br />

The log-in procedure is necessary <strong>for</strong> the following checks:<br />

❏ Authenticate the user and verify access permission.<br />

❏ Determine the user's capabilities.<br />

<strong>HP</strong>OM provides the possibility to use PAM alternatively to the built-in<br />

authentication.<br />

Using PAM has the following major advantages:<br />

❏<br />

❏<br />

Use of a common user database shared with the operating system<br />

and other applications. User accounts and passwords have to be set<br />

up and maintained only in one place.<br />

Higher security measures like stronger encryption, password aging,<br />

account expiration etc. are available and can be en<strong>for</strong>ced.<br />

NOTE<br />

This only applies to the user authentication itself; the <strong>HP</strong>OM user<br />

accounts must still exist to determine the user's capabilities.<br />

To Configure PAM User Authentication<br />

1. To enable PAM user authentication in <strong>HP</strong>OM, set the variable<br />

OPC_USE_PAM_AUTH to TRUE:<br />

364<br />

Chapter 11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!