Additional Server Security Considerations
146
Netscape Enterprise Server Administrator’s Guide
Unix
Carefully choose the processes started from
inittab
and
rc
scripts. Don’t run
telnet
or
rlogin
from the server machine. You also shouldn’t have
rdist
on the server machine (this can distribute files but it can also be used to update
files on the server machine).
Windows NT
Carefully consider which drives and directories you share with other machines.
Also, consider which users have accounts or Guest privileges.
Similarly, be careful about what programs you put on your server or allow
other people to install on your server. Other people’s programs might have
security holes. Worst of all, someone might upload a malicious program
designed specifically to subvert your security. Always examine programs
carefully before you allow them on your server.
Prevent Clients from Caching SSL Files
You can prevent pre-encrypted files from being cached by a client by adding
the following line inside the
<HEAD>
section of a file in HTML:
<meta http-equiv="pragma" content="no-cache">
Limit Ports
Disable any ports not used on the machine. Use routers or firewall
configurations to prevent incoming connections to anything other than the
absolute minimum set of ports. This means that the only way to get a shell on
the machine is to physically use the server’s machine, which should be in a
restricted area already.
Know Your Server’s Limits
The server offers secure connections between the server and the client. It can’t
control the security of information once the client has it, nor can it control
access to the server machine itself and its directories and files.
Summary of Contents for Netscape Enterprise Server
Page 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Page 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Page 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Page 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Page 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Page 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Page 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Page 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Page 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Page 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Page 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Page 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Page 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Page 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Page 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Page 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Page 504: ...504 Netscape Enterprise Server Administrator s Guide ...