The Security Manager service enables you to control remote access to the services on your system. This is done by assigning passwords to specific User IDs, and then selecting which services this User ID/Password combination will be allowed to access. By default, no security is present. By using the Incoming UserID and Outgoing Password Destinations, you can control which services are accessible to local and remote users. If an unauthorized remote user attempts to access your system, a screen will appear asking for a valid User ID/Password combination. If a valid User ID/Password combination is not provided, remote access to your system is not granted.
The Incoming User ID screen contains a list of all User ID/Password combinations and the list of Netfinity services that are enabled for each User ID/Password combination that your Security Manager is currently configured to use when attempting to connect with a remote system. Use the Incoming User ID screen to:
The Outgoing Password Destinations screen contains a list of all Network Addresses and User IDs that your Security Manager is currently configured to use when attempting to connect with a remote system. Use the Outgoing Password screen to:
The Netfinity Security Manager is designed to limit remote access to some or all of the Netfinity services installed on an individual system. Irresponsible or careless use of the Netfinity services can lead to data loss or system damage. To avoid this, limit remote access to some or all of these services on the Netfinity systems in your network.
Note: The following Netfinity Services pose the most potential risk if used irresponsibly:
- File Transfer
- Process Manager
- Remote Session
- Remote System Manager
The Netfinity Security Manager uses a User ID/Password combination to determine security clearance on a system. Incoming User ID/Password combinations determine which of your Netfinity Services are available to a user accessing your system remotely. Outgoing User ID/Password combinations can be set to provide default User ID/Password combinations when you attempt to remotely access other systems.
If your outgoing User ID/Password combination for a target system matches a configured incoming User ID/Password combination on the target system, you are automatically granted access to the services that have been selected for that User ID/Password combination. If you have configured appropriate outgoing User ID/Password combinations for all Netfinity systems operating in your network, all security checking is done passively and without interruption.
Security Manager features a default incoming User ID/Password feature. It is called the <PUBLIC> setting, and automatically allows access to any services that you select.
Once you have established incoming and outgoing User ID/Password combinations on all of the systems in your network, security operates passively. When a user attempts to gain access to another system, the outgoing User ID/Password combination is automatically checked against the target system's incoming User ID/Password combinations.
You will encounter security checks only if:
Use the Login System action to establish multiple levels of security for the Netfinity systems within your network. For example, you might want to configure a <PUBLIC> incoming User ID/Password combination on the Netfinity systems within your network that permits access to all Netfinity services except the System Partition Access.
However, you want to be able to access the File Transfer Service when necessary. You would then set an incoming User ID/Password combination on each of the systems in your network that would allow access to the File Transfer Service. Once this configuration is saved, all Netfinity systems in your network automatically receive the limited <PUBLIC> access to the other system's Netfinity Services.
To access the File Transfer Service, you would have to select Remote System Manager's Login System action and enter the User ID/Password combination you created. You would then receive access to all Netfinity Services, including File Transfer Service.
Netfinity Security Manager also generates Security Access Alerts alerts to help you maintain a record of who has accessed or attempted to access your system.
To add a new Incoming User ID/Password combination, and determine access to services:
The Add User screen will be displayed.
Enter the User ID that you would like to add.
Enter the password that, when used in combination with the specified User ID, will allow access to all selected Services. This password will not be displayed.
Note: The Password and Password Verify field entries must match in order to be valid.
Select one or more Services from the selection list. The selected services will be available to users who provide the configured User ID/Password combination.
Select the All Services check-box to enable access to all the available Netfinity services.
Select the Security Manager Access Check-box to enable Security Manager access from this User ID/Password combination.
Warning: Allowing access to the Security Manager enables the remote system to alter your incoming and outgoing User ID/Password combinations, and will also enable the Remote System Manager's Restart System action on your system. This will allow the remote user to restart your system on demand.
Select Add User to save your configuration.
Select Cancel to exit the Add User screen without saving any changes and return to the Security Manager screen.
To Delete an existing incoming User ID/Password combination:
The Incoming User ID list is updated and displayed reflecting the requested deletions.
To Edit an existing incoming User ID/Password combination, and determine access to services:
Select the User ID that you are allowing access to from the Incoming User ID selection list. The Change User screen will be displayed.
Enter the password that, when used in combination with the specified User ID, will allow access to all selected Services. This password will not be displayed.
Note: The Password and Password Verify field entries must match in order to be valid.
Select one or more Services from the selection list. The selected services will be available to users who provide the configured User ID/Password combination.
Select the All Services check-box to enable access to all the available Netfinity services.
Select the Security Manager Access to enable Security Manager access from this User ID/Password combination.
Select Change User to save your configuration.
Select Cancel to exit the Change User screen without saving any changes and return to the Security Manager screen.
To add a new Outgoing User ID/Password combination
The Add Destination screen will be displayed.
Enter the network address of the system for which you are creating the outgoing User ID/Password combination in Network Address entry field. This must by identical to the network address used by the Remote System Manager to locate the remote system.
Enter the User ID that, when used in combination with the specified Password, will be checked against the remote system's (determined by the Network Address) configured incoming User ID/Password combinations to determine access to its services.
Enter the Password that, when used in combination with the specified User ID, will be checked against the remote system's (determined by the Network Address) configured incoming User ID/Password combinations to determine whether access to its services is granted.
Note: The Password and Password Verify field entries must match in order to be valid.
Select Add Destination to save your configuration.
To Delete an existing outgoing User ID/Password combination:
The Outgoing Password Destinations list is updated and displayed reflecting the requested deletions.
To Edit an existing outgoing User ID/Password combination:
Select the Network Address that is configured for remote access from the Outgoing Password Destinations selection list. The Change Destination screen will be displayed.
Enter the User ID that, when used in combination with the specified Password, will be checked against the remote system's (determined by the Network Address) configured incoming User ID/Password combinations to determine access to its services.
Enter the Password that, when used in combination with the specified User ID, will be checked against the remote system's (determined by the Network Address) configured incoming User ID/Password combinations to determine whether access to its services is granted.
Note: The Password and Password Verify field entries must match in order to be valid.
Select Change Destination to save your configuration.
The Security Manager can generate three alerts in response to specific security access conditions. These alerts are:
Generated when Security Manager allows non-public access to a remote user.
Generated when Security Manager allows public access to one or more services to a remote user.
Generated when Security Manager denies access to the system to a remote user.
To exit the Security Manager service, select the "Netfinity" image on the top or bottom of the Security Manager service to return to the Netfinity services screen.