13.12.2012 Views

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About OVO Security<br />

About Network Security<br />

484<br />

About DCE Security<br />

Network security involves the protection of data that is exchanged<br />

between the management server and the managed node. This security is<br />

intimately related to DCE. OVO addresses the problem of network<br />

security by controlling the authenticity of the parties, in this case the<br />

RPC client and the server, before granting a connection and ensuring the<br />

integrity of data passed over the network during the connection.<br />

OVO carries out its own, basic authorization checks for communication<br />

between the management server and the managed nodes. However, DCE<br />

allows you to implement more stringent security at the process level<br />

between an RPC client and an RPC server, specifically in the areas of<br />

authentication and privacy, or data protection.<br />

The level of data protection is chosen by the RPC client, although the<br />

RPC server has the option of deciding whether a chosen level is<br />

sufficient. OVO authentication is handled by RPC clients and servers.<br />

For example, in the same way that an RPC server needs to determine<br />

whether or not an incoming request is from a genuine OVO client, an<br />

RPC client also needs to be sure that the server it is calling really is an<br />

OVO server.<br />

Configuring DCE<br />

If you want to protect communication between the OVO management<br />

server and managed nodes using DCE security mechanisms, you need to<br />

carry out some extra configuration steps:<br />

❏ DCE Server<br />

Make a DCE server installation available on your local network.<br />

❏ DCE Nodes<br />

Make sure all participating nodes are members of DCE cells that are<br />

configured to trust one another.<br />

OVO does not require a particular DCE configuration.<br />

For more detailed information on DCE, see the product-specific<br />

documentation and “To Configure DCE Nodes to use Authenticated<br />

RPCs” on page 486.<br />

Chapter 12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!