40
4-, 8-, AND 16-PORT SERVSWITCH PS2/USB IP KVM SWITCH
VNC Password Policy
When a new VNC connection is established, the remote user must be
authenticated. Standard VNC protocol does not support username; it only
supports passwords. As long as all users have unique passwords, you can determine
which user is connecting based on the password provided. Or, you may enable a
second login screen that will require a valid username and password. You must first
establish a VNC connection using menus and prompts generated by the firmware.
If it is enabled, a second login screen will be required from Java VNC clients as
well. This is unfortunate because the one-time password scheme cannot be used,
and Java VNC clients have already logged into the Web server securely. Also, VNC
normally encrypts passwords and uses a challenge/hashed response system that is
more secure than the second login method. This isn’t a concern if the entire
connection is encrypted with SSH or SSL, however.
Trust SSH Tunnels
If the incoming VNC connection is coming in over an SSH tunnel, the SSH
user/password combination is used and no password is required. Disable this
behavior if you suspect that your SSH client machine is not secure and you are
concerned that your SSH tunnels may be used by other people.
Access Sharing Policy
There are 3 modes available:
1. Disables—Use regular give/take method (default). By default, all users can
take keyboard and mouse control of the system (after connecting via VNC)
using a single mouse click.
2. Enforce single-user access policy (visible screen). Some circumstances require
more strict control of this capability, so the admin user can select this mode
for the highest priority access. With a single-user access policy, only one user
may control the host computer(s). New connections are permitted, but they
will be able to view the screen
only
, but not control the host computer(s).
Once the first user disconnects (or otherwise gives up control), the second
user will be able to access the system immediately.
3. Enforce single-user access policy (blank screen contents). Some
circumstances require more strict control of this capability. The admin user
can select this mode for the highest privacy; no one can see what the admin
user is doing from the VNC screen. That is, the admin user can blank the
screen contents when another user is connected but not controlling the
keyboard and mouse.
Summary of Contents for KV9404A
Page 3: ......