Additional Server Security Considerations
144
Netscape Enterprise Server Administrator’s Guide
Limit Administration Access
If you use remote configuration, be sure to use access control to allow
administration from only a few users and computers. If you want your
Enterprise Administration Server to provide end-user access to the LDAP server
or local directory information, consider maintaining two Enterprise
Administration Servers and using cluster management so that the SSL-enabled
Enterprise Administration Server acts as the master server and the other
Enterprise Administration Server is available for end-users’ access. For more
information regarding clusters, see “About Clusters,” on page 149 in Chapter 6,
“Managing Server Clusters.”
You should also turn on encryption for the Enterprise Administration Server. If
you don’t use an SSL connection for administration, then you should be
cautious when performing remote server administration over an unsecure
network. Anyone could intercept your administrative password and reconfigure
your servers.
Choose Good Passwords
You use a number of passwords with your server—the administrative
password, the private key password, database passwords, and so on. Your
administrative password is the most important password of all, since anyone
with that password can configure any and all servers on your computer. Most
important after that is your private key password. If someone gets your private
key and your private key password, they can create a fake server that appears
to be yours, or intercept and change communications to and from your server.
A good password is one you’ll remember but others won’t guess. For example,
you could remember
MCi12!mo
as “My Child is 12 months old!” A bad
password is your child’s name or birthdate.
Guidelines for Creating Hard-to-Crack Passwords
There are some simple guidelines that will help you create a stronger password.
It is not necessary to incorporate all of the following rules in one password, but
the more of the rules you use, the better your chances of making your
password hard to crack:
Содержание Netscape Enterprise Server
Страница 30: ...Contacting Technical Support 30 Netscape Enterprise Server Administrator s Guide ...
Страница 31: ...Part 1 Server Basics 31 1 Server Basics Introduction to Enterprise Server Administering Enterprise Servers ...
Страница 32: ...32 Netscape Enterprise Server Administrator s Guide ...
Страница 56: ...Sending Error Information to Netscape 56 Netscape Enterprise Server Administrator s Guide ...
Страница 64: ...Migrating a Server From a Previous Version 64 Netscape Enterprise Server Administrator s Guide ...
Страница 66: ...66 Netscape Enterprise Server Administrator s Guide ...
Страница 112: ...Managing a Preferred Language List 112 Netscape Enterprise Server Administrator s Guide ...
Страница 158: ...158 Netscape Enterprise Server Administrator s Guide ...
Страница 182: ...Using the Watchdog uxwdog Process Unix 182 Netscape Enterprise Server Administrator s Guide ...
Страница 196: ...Viewing Events Windows NT 196 Netscape Enterprise Server Administrator s Guide ...
Страница 218: ...Enabling the Subagent 218 Netscape Enterprise Server Administrator s Guide ...
Страница 266: ...266 Netscape Enterprise Server Administrator s Guide ...
Страница 302: ...Enabling WAI Services 302 Netscape Enterprise Server Administrator s Guide ...
Страница 310: ...310 Netscape Enterprise Server Administrator s Guide ...
Страница 390: ...Customizing the Web Publisher User Interface 390 Netscape Enterprise Server Administrator s Guide ...
Страница 446: ...Customizing the Search Interface 446 Netscape Enterprise Server Administrator s Guide ...
Страница 448: ...448 Netscape Enterprise Server Administrator s Guide ...
Страница 454: ...Responses 454 Netscape Enterprise Server Administrator s Guide ...
Страница 464: ...Referencing ACL Files in obj conf 464 Netscape Enterprise Server Administrator s Guide ...
Страница 504: ...504 Netscape Enterprise Server Administrator s Guide ...