19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

<strong>The</strong> SECURE.NCF file and its options<br />

To enable a Novell Netware 4.11 server to utilise the extended security<br />

mechanisms, attention should be paid to the following points:<br />

- <strong>The</strong> SECURE.NCF file must be stored on the server in SYS:SYSTEM.<br />

- <strong>The</strong> SECURE.NCF file is an executable file similar to a batch file under<br />

DOS, and should therefore only be edited with an ASCII editor (e.g.<br />

ED<strong>IT</strong>.NLM).<br />

- <strong>The</strong> line "SET ENABLE SECURE.NCF=ON" must be inserted into<br />

AUTOEXEC.NCF to call the SECURE.NCF file. Alternatively, the<br />

command "SECURE" can also be inserted into AUTOEXEC.NCF or this<br />

command can be issued on the server console.<br />

<strong>The</strong> extract from the SECURE.NCF file given below shows only the<br />

commands contained in the file. <strong>The</strong> original file contains a brief explanation<br />

of each command.<br />

SET ALLOW UNENCRYPTED PASSWORDS = OFF<br />

SET ALLOW AUD<strong>IT</strong> PASSWORDS = OFF<br />

SET AUTOMATICALLY REPAIR BAD VOLUMES = ON<br />

SET REJECT NCP PACKETS W<strong>IT</strong>H BAD LENGTHS = ON<br />

SET REJECT NCP PACKETS W<strong>IT</strong>H BAD COMPONENTS = ON<br />

SET IPX NETBIOS REPLICATION OPTION = 0<br />

SET ADD<strong>IT</strong>IONAL SECUR<strong>IT</strong>Y CHECKS = ON<br />

# SET CHECK EQUIVALENT TO ME = ON<br />

# SET NCP PACKET SIGNATURE = 3<br />

# SECURE CONSOLE<br />

## DISPLAY NCP BAD COMPONENT WARNINGS<br />

## DISPLAY NCP BAD LENGTH WARNINGS<br />

All command lines that are commented out with "#" are additional security<br />

parameters and are not necessary for observance of the C2 or F-C2/E2<br />

provisions. Command lines that are identified by "##" do not form part of the<br />

standard scope of the SECURE.NCF file, but they represent a meaningful<br />

benefit in everyday use.<br />

<strong>The</strong> commands in detail<br />

All commands and SET statements can also be issued at the console or be set<br />

using the SERVMAN.NLM or MON<strong>IT</strong>OR.NLM program.<br />

All SET parameters in the SECURE.NCF file are described below, and the<br />

default values are also specified.<br />

SET ALLOW UNENCRYPTED PASSWORDS = OFF (Default=OFF)<br />

<strong>The</strong> purpose of this parameter is to ensure the compatibility of Netware 2.x<br />

clients and print servers. <strong>The</strong> consequence of setting the parameter to ON is<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!