13.12.2012 Views

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About OVO Security<br />

About Security in OVO <strong>Operations</strong><br />

500<br />

About PAM Authentication<br />

You can use PAM (pluggable authentication modules) to retrieve and<br />

check user and password information. The user information is saved into<br />

a central repository and is accessed by a PAM module. To use PAM for<br />

authentication, use the command-line tool ovconfchg on the OVO<br />

management server. For more information, refer to the ovconfchg man<br />

page.<br />

Setting up PAM User Authentication<br />

The OVO user model requires users (humans or programs) to log on to<br />

the OVO management server before being able to use any further<br />

functionality. This mainly applies to the graphical user interfaces (Motif<br />

and Java based) but also to some of the OVO management server APIs<br />

and command line tools.<br />

The log-in procedure is necessary for the following checks:<br />

❏ Authenticate the user and verify access permission.<br />

❏ Determine the user's capabilities.<br />

OVO provides the possibility to use PAM alternatively to the built-in<br />

authentication.<br />

Using PAM has the following major advantages:<br />

❏ Use of a common user database shared with the operating system<br />

and other applications. User accounts and passwords have to be set<br />

up and maintained only in one place.<br />

❏ Higher security measures like stronger encryption, password aging,<br />

account expiration etc. are available and can be enforced.<br />

NOTE This only applies to the user authentication itself; the OVO user<br />

accounts must still exist to determine the user's capabilities.<br />

Chapter 12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!