
A-223
Chapter 15 Using RA 6300 Security
Remote Annex 6300 Supplement to the Remote Annex Administrator’s Guide for UNIX
Book A
Overview of Host-based Security
ACP security has three requirements: 1) at least one UNIX host on the
network must act as a security server running RA 6300 security software;
2) security must be enabled on the RA 6300 (the enable_security
parameter is set to Y); and 3) a security regime, such as acp or securid,
must be defined for authenticating RA 6300 users.
The security server maintains a database of files that reside by default in
the directory /usr/annex. These files include:
•
acp_keys (encryption key information).
•
acp_dialup (user names and addresses for dial-up connections).
•
acp_group (user-group associations for security).
•
acp_regime (security authentication system and associated
password file name).
•
acp_passwd (security passwords).
Do not specify port passwords for the RA 6300.
•
acp_userinfo (initial login environment and start-up CLI
commands).
•
acp_restrict (restricted hosts and host ports).
•
acp_logfile and acp_logfile.Annex_IPaddress (security audit
trails).
The contents of these files should match on all security
servers (except for acp_logfile).
Summary of Contents for 6300
Page 4: ...Remote Annex 6300 Supplement to the Remote Annex Administrator s Guide for UNIX iv ...
Page 20: ...Remote Annex 6300 Supplement to the Remote Annex Administrator s Guide for UNIX Figures xx ...
Page 24: ...Remote Annex 6300 Supplement to the Remote Annex Administrator s Guide for UNIX Tables xxiv ...