The root account is not used to run any services. Users cannot log in as root. The appliance’s root password is not shared with customers. The password is restricted to authorized personnel on the appliance development team. The secret root password is changed with every major release.
Appliances control access to the Console Program using a dedicated user authentication mechanism, which is separate from the one described under Security features in Foglight . The user authentication mechanism is built on the Linux® Pluggable Authentication Modules (PAM). Account passwords are stored in encrypted form in Linux system files.
In addition to the root and foglight accounts described under No root access, the appliances ship with a default user account called setup.
The person configuring the appliances initially uses the default setup account to run the setup menu facility (hereafter called the Console Program) on an appliance. This text-mode application is the setup user’s shell, and the user is logged out when this shell is exited. The Console Program uses Yast to configure network cards and has menus to configure and start/stop Foglight® services. The setup account does not have read access to any directory where Foglight stores sensitive customer data. The setup user can create additional user accounts as necessary.
• |
To use SSH, the user’s account on the appliance needs to be configured to enable SSH. By default, the setup account and all new accounts have SSH disabled. If SSH is enabled, the user account requires a strong password, which must contain at least the following elements: |
For instructions, see the Foglight APM Installation and Setup Guide.
The following TCP ports are left open to detect port-scanning programs: 1, 11, 110, and 143. For more information, see Layer 2: Port scan detection and blocking tool. When time synchronization with a time server using NTP is enabled, UDP port 123 is open.
To use port 8443 instead of 8080, set the Management Server’s httpsonly option to true. When the Management Server is hosted on an appliance, the setting is located in the appliance.config file, which you can access from the command line.
2 |
Select Advanced Options. |
3 |
Select Access Shell. |
4 |
Type: vi /opt/quest/foglight/config.appliance/appliance.config |
5 |
Enable the following code by removing the leading hash symbol (#): server.console.httpsonly = "true"; |
6 |
7 |
Type: rcfoglight restart |
To enable remote access using SSH, open port 22 for individual Console Program user accounts.
2 |
Select Console User Accounts. |
3 |
Select Modify Console User. |
5 |
Select Enable/Disable SSH. |
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Conditions d’utilisation Confidentialité Cookie Preference Center