19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.99 Secure set-up of Novell Netware servers<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

<strong>The</strong> security features within Novell Netware 3.x are not automatically<br />

activated after initial start of the SERVER.EXE file. <strong>The</strong>y must be individually<br />

installed and configured via the system administration.<br />

By using the program SYS:PUBLIC\SETPASS.EXE, the supervisor should<br />

allocate a password to this account immediately after the first login. A<br />

password should also be provided for the Guest account available as standard.<br />

If the guest account is not needed during later use, it should be deleted.<br />

Unauthorised login attempts should be prevented during the set-up phase via<br />

DISABLE LOGIN (server console).<br />

With the help of Novell Utilities SYS:PUBLIC\SYSCON.EXE under the menu<br />

Supervisor Options most of the Novell security mechanisms can be installed<br />

and configured. It should be considered that the settings made in the Default<br />

Time Restrictions menu are only valid for all Novell Netware accounts on the<br />

server, if these settings are made before the setting up of users and groups.<br />

Relevant security menu points are listed below:<br />

Default Account Balance/Restrictions<br />

With the help of this menu item the following security settings for the Novell<br />

Netware server are activated.<br />

- Account has Expiration Date: With this function the validity of an<br />

account can be limited to a certain time. Since an account is normally setup<br />

on a long-term basis this feature will generally be activated only for a<br />

guest account.<br />

- Limit Concurrent Connections: With this function it is possible to limit<br />

the number of simultaneous connections from one account to the Novell<br />

Netware server. Generally, the number "One" should be selected here.<br />

- Create Home Directory for User: An option to create a personal<br />

directory for every user. <strong>The</strong> option "Yes" should be selected here.<br />

- Require Password: Require Password installs the password entry<br />

requirement for every user and, upon activation, rules for password<br />

entry can be set. <strong>The</strong> option "yes" should be selected here.<br />

- Minimum Password Length: With this function the required<br />

minimum length of a password can be set. <strong>The</strong> minimum length should<br />

be set to six characters (see below S 2.11 Provisions governing the use<br />

of passwords). If the minimum length is set to less than five characters,<br />

this will be shown when activating SYS:\SYSTEM\SECUR<strong>IT</strong>Y.EXE<br />

(see S 2.101 Revision of Novell Netware servers).<br />

- Force Periodic Password Changes: With the setting "Yes" users will<br />

be forced to change their passwords regularly. As a rule, this option<br />

should be left active.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!