14 Securing the Configuration Change Console

This section outlines various configurations that can be made after installing the Agents or server to secure your Configuration Change Console installation.

Securing Agent Files

The directory where the agent is installed must be set to readable only by the user the agent is running as. These files should not be world readable as they contain information that could be used to compromise the security of the agents.

On Unix, the installation will set all files to have Read, Write and Execute permissions revoked for Group or Others.

On Windows, the permissions are not set out of the box. The administrator must set the security rules either locally or from a domain controller to block any other users from reading files in the agent installation directory.

Securing Server Files

The directory where the server is installed must be set to readable only by the user the server is running as and privileged administrators. These files should not be world readable as they contain information that could be used to compromise the security of the server or agent to server communication.

The permissions are not set out of the box. The administrator must set the security rules either locally or from a domain controller to block any other users from reading files in the server installation directory.