S o n o m a U s e r M a n u a l
41
"Smarter Timing Solutions"
Chapter
Five
Security
Your Sonoma incorporates several important security features to prevent unauthorized tampering
with its operation. Many of these are standard multiple-user access control features of the underlying
Linux operating system which controls the Sonoma. Others are provided by the additional protocol
servers selected for inclusion in your Sonoma, and the way that they are configured.
Secure user authentication and session privacy while performing routine monitoring and maintenance
tasks are provided by the OpenSSH implementations of the “secure shell” daemon,
sshd
and its com-
panion “secure copy” utility,
scp
. The Apache implementation of the Hyper Text Transport Protocol
(HTTP) with Secure Sockets Layer (SSL) daemon (
httpd
) provides for a secure, encrypted session
with a digital certificate. The NET-SNMP implementation of the Simple Network Management
Protocol (SNMP) daemon,
snmpd
conforms to the latest Internet standard, known as SNMPv3, which
also supports secure user authentication and session privacy. In addition, the Network Time Proto-
col daemon,
ntpd
supports client-server authentication security measures to deter spoofing of NTP
clients by rogue NTP servers. This chapter describes these security measures and gives the advanced
network administrator information that will allow custom configuration to fit specific security needs.
SSH, Telnet, SNMP and HTTP are all enabled with default passwords. To ensure security, change the pass-
words or disable the protocols. To change the passwords for SSH, Telnet and HTTP use the
passwd
com-
mand. To change the passwords/community strings for SNMP see
Chapter 6 - SNMP
.
By default all hosts are allowed access via SSH, Telnet and SNMP. To restrict access via these protocols to
specific hosts, see
Restrict Access - Telnet, SSH and SNMP
below. All hosts are allowed access via
HTTP as well. To restrict access via HTTP, see
Restrict Access - HTTP
below.
To completely disable any or all of these protocols see
Disable Protocols
below.
Linux Operating System
The Linux operating system versions are shown in
Appendix H - Specifications
. Linux supports a
complete set of security provisions:
•
System passwords are kept in an encrypted file,
/etc/shadow
which is not accessible by users other
than
root
.
IMPORTANT
Содержание Sonoma D12
Страница 2: ......
Страница 20: ...S o n o m a U s e r M a n u a l 4 C H A P T E R O N E This page intentionally left blank...
Страница 32: ...S o n o m a U s e r M a n u a l 16 C H A P T E R T W O This page intentionally left blank...
Страница 48: ...S o n o m a U s e r M a n u a l 32 C H A P T E R T H R E E This page intentionally left blank...
Страница 70: ...S o n o m a U s e r M a n u a l 54 C H A P T E R S I X This page intentionally left blank...
Страница 82: ...S o n o m a U s e r M a n u a l 66 C H A P T E R S E V E N This page intentionally left blank...
Страница 104: ...S o n o m a U s e r M a n u a l 88 C H A P T E R N I N E This page intentionally left blank...
Страница 128: ...S o n o m a U s e r M a n u a l 112 A P P E N D I X A This page intentionally left blank...
Страница 138: ...S o n o m a U s e r M a n u a l 122 A P P E N D I X B This page intentionally left blank...
Страница 154: ...S o n o m a U s e r M a n u a l 138 A P P E N D I X E FIGURE 1B CDMA ANTENNA MOUNTING GUIDELINES WITH PREAMPLIFIER...
Страница 160: ...S o n o m a U s e r M a n u a l 144 A P P E N D I X G This page intentionally left blank...
Страница 166: ...S o n o m a U s e r M a n u a l 150 A P P E N D I X H...
Страница 167: ...151 S o n o m a U s e r M a n u a l S P E C I F I C AT I O N S...
Страница 168: ...S o n o m a U s e r M a n u a l 152 A P P E N D I X H This page intentionally left blank...
Страница 170: ...S o n o m a U s e r M a n u a l 154 S P E C I A L M O D I F I C AT I O N S This page intentionally left blank...
Страница 171: ......