13.12.2012 Views

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

HP OpenView Operations Administrator's Reference - filibeto.org

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About OVO Security<br />

About Security in OVO <strong>Operations</strong><br />

512<br />

❏ Detecting Faked IP Addresses or Secret Keys<br />

If you have installed the OVO Advanced Network Security (ANS)<br />

extension, you can also check for mismatched sender addresses by<br />

using the command-line tool ovconfchg on the OVO management<br />

server:<br />

ovconfchg -ovrg -ns opc -set \<br />

OPC_CHK_SENDER_ADDR_MISMATCH TRUE<br />

Where is the name of the management<br />

server resource group.<br />

This check reinforces OPC_DISABLE_REMOTE_ACTIONS TRUE by<br />

detecting any attempts to use faked IP addresses or secret keys that<br />

were generated by another node.<br />

If the check detects an IP address and hostname mismatch, all<br />

actions that are to be executed on a node other than the message<br />

originator are removed from the message. Only local actions that<br />

were already started on the message originator are not removed.<br />

Failed action requests are documented in annotations, which are<br />

added to the message automatically.<br />

About Queue Files<br />

The commands opcmsg and opcmon us the queue files for the message<br />

interceptor (msgiq) and the monitor agent (monagtq) to communicate<br />

with their corresponding processes. The queue files grant read/write<br />

permission to all users. You can read sensitive messages by displaying<br />

these queue files as a regular user.<br />

CAUTION The opcmsg and opcmon commands allow any user to send a message<br />

triggering an automatic action, even on another node.<br />

Chapter 12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!