Go to main content

Oracle® SuperCluster M8 and SuperCluster M7 Security Guide

Exit Print View

Updated: June 2020
 
 

Index

A

access controlindex iconAccess Control
access restrictionsindex iconAccess Restrictions
activation keysindex iconSerial Numbers
algorithms
cryptographicindex iconData Protection
FIPS approvedindex iconFIPS-140-2 Level 1 Compliance
ASLR, enablingindex iconEnable ASLR
asymmetric keysindex iconFIPS-140-2 Level 1 Compliance
auditing
enablingindex iconEnable Auditing
for security complianceindex iconAuditing for Compliance
auditing and monitoring
index iconMonitoring Security
index iconMonitoring and Compliance Auditing

B

banners
Exadata storage serversindex iconConfigure a Login Warning Banner (Storage Server)
Oracle ILOMindex iconConfigure Login Warning Banners (Oracle ILOM)
browser inactivity timeout configurationindex iconConfigure Administrative Browser Interface Inactivity Timeout

C

certificates, self-signed
IB switchesindex iconReplace Default Self-Signed Certificates (IB Switch)
Oracle ILOMindex iconReplace Default Self-Signed Certificates (Oracle ILOM)
changing
Ethernet switch passwordsindex iconChange the Ethernet Switch Password
Exadata storage server passwordsindex iconChange Storage Server Passwords
IB switch passwords (Oracle ILOM)index iconChange IB Switch Passwords (Oracle ILOM)
root and nmuser passwords on IB switchesindex iconChange root and nm2user Passwords
ZFS storage appliance root passwordindex iconChange the ZFS Storage Appliance root Password
client access networkindex iconSecure Isolation
community strings on
IB switchesindex iconConfigure SNMP Community Strings (IB Switch)
Oracle ILOMindex iconConfigure SNMP v1 and v2c Community Strings (Oracle ILOM)
ZFS storage applianceindex iconConfigure SNMP Community Strings
compliance auditing
index iconAuditing for Compliance
index iconMonitoring and Compliance Auditing
compliance reports
generating real-timeindex iconGenerate a Compliance Assessment
generating with a cron jobindex icon(Optional) Run Compliance Reports with a cron Job
compliance commandindex iconGenerate a Compliance Assessment
compute servers
disabling unnecessary servicesindex iconDisable Unnecessary Services (Compute Servers)
exposed network servicesindex iconDefault Exposed Network Services (Compute Servers)
hardening the security configurationindex iconHardening the Compute Server Security Configuration
logging in toindex iconLog into a Compute Server
securingindex iconSecuring the Compute Servers
configuring
compute servers
immutable global zonesindex iconCreate Immutable Global Zones
immutable non-global zonesindex iconConfigure Immutable Non-Global Zones
secure shell serviceindex iconConfigure the Secure Shell Service
TCP connectionsindex iconConfigure TCP Connections
Exadata storage servers
account lockoutindex iconConfigure System Account Lockout
boot loader passwordsindex iconConfigure a System Boot Loader Password
failed authentication lock delaysindex iconConfigure a Failed Authentication Lock Delay
login shell inactivity timeoutsindex iconConfigure the Administrative Interface Inactivity Timeout (Login Shell)
login warning bannersindex iconConfigure a Login Warning Banner (Storage Server)
password agingindex iconConfigure Password Aging Control Policies
password complexity rulesindex iconConfigure Password Complexity Rules
password history policiesindex iconConfigure a Password History Policy
SSH interface inactivity timeoutsindex iconConfigure the Administrative Interface Inactivity Timeout (Secure Shell)
IB switches
CLI session timeoutsindex iconConfigure the Administrative CLI Session Timeout (IB Switch)
HTTP redirection to HTTPSindex iconConfigure HTTP Redirection to HTTPS (IB Switch)
SNMP community stringsindex iconConfigure SNMP Community Strings (IB Switch)
Oracle ILOM
browser inactivity timeoutindex iconConfigure Administrative Browser Interface Inactivity Timeout
CLI timeoutsindex iconConfigure the Administrative Interface Timeout (Oracle ILOM CLI)
HTTP redirection to HTTPSindex iconConfigure HTTP Redirection to HTTPS (Oracle ILOM)
login warning bannersindex iconConfigure Login Warning Banners (Oracle ILOM)
SNMP v1 and v2c community stringsindex iconConfigure SNMP v1 and v2c Community Strings (Oracle ILOM)
ZFS storage appliance
interface inactivity (HTTPS)index iconConfigure the Administrative Interface Inactivity Timeout (HTTPS)
SNMP authorized networksindex iconConfigure SNMP Authorized Networks
SNMP community stringsindex iconConfigure SNMP Community Strings
confirming home directory permissionsindex iconEnsure That User Home Directories Have Appropriate Permissions
core dumps, protectingindex iconProtect Core Dumps
creating encrypted ZFS data setsindex iconCreate Encrypted ZFS Data Sets
cryptographyindex iconData Protection

D

data link protection
featuresindex iconAccess Control
on global zonesindex iconEnable Data Link (Spoofing) Protection on Global Zones
on non-global zonesindex iconEnable Data Link (Spoofing) Protection on Non-Global Zones
data protectionindex iconData Protection
database activity monitoringindex iconDatabase Activity Monitoring and Auditing
default security configurationindex iconReviewing the Default Security Configuration
default security settingsindex iconDefault Security Settings
default user accounts and passwords on
all componentsindex iconDefault User Accounts and Passwords
determining
Exadata storage server software versionsindex iconDetermine the Exadata Storage Server Software Version
IB switch firmware versionsindex iconDetermine the IB Switch Firmware Version
Oracle ILOM versionsindex iconDetermine the Oracle ILOM Version
SuperCluster software versionsindex iconDetermine the SuperCluster Software Version
ZFS storage appliance software versionsindex iconDetermine the ZFS Storage Appliance Software Version
disabling
compute servers
GSSindex iconDisable GSS (Unless Using Kerberos)
unnecessary servicesindex iconDisable Unnecessary Services (Compute Servers)
Exadata storage servers
Oracle ILOM console accessindex iconDisable Oracle ILOM System Console Access
IB switches
unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols (IB Switch)
unnecessary servicesindex iconDisable Unnecessary Services (IB Switch)
Oracle ILOM
SSL weak and medium-strength ciphers for HTTPSindex iconDisable SSL Weak and Medium-Strength Ciphers for HTTPS
SSLv2 protocol for HTTPSindex iconDisable the SSLv2 Protocol for HTTPS
SSLv3 protocol for HTTPSindex iconDisable the SSLv3 Protocol for HTTPS
unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols (Oracle ILOM)
unapproved TLS protocols for HTTPSindex iconDisable Unapproved TLS Protocols for HTTPS
unnecessary servicesindex iconDisable Unnecessary Services (Oracle ILOM)
ZFS storage appliance
dynamic routingindex iconDisable Dynamic Routing
unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols
unnecessary servicesindex iconDisable Unnecessary Services (ZFS Storage Appliance)
displaying Exadata storage server security configurationsindex iconDisplay Available Security Configurations With host_access_control
drivesindex iconDrives

E

enabling
ASLRindex iconEnable ASLR
auditing on compute serversindex iconEnable Auditing
data link protection on global zonesindex iconEnable Data Link (Spoofing) Protection on Global Zones
data link protection on non-global zonesindex iconEnable Data Link (Spoofing) Protection on Non-Global Zones
encrypted swap spaceindex iconEnable Encrypted Swap Space
FIPS-140 compliant operation (Oracle ILOM)index icon(If Required) Enable FIPS-140 Compliant Operation (Oracle ILOM)
IP filter firewallsindex iconEnable the IP Filter Firewall
NTP servicesindex iconEnable Sendmail and NTP Services
secure verified boot (Oracle ILOM CLI)index iconEnable Secure Verified Boot (Oracle ILOM CLI)
secure verified boot (Oracle ILOM Web interface)index iconSecure Verified Boot (Oracle ILOM Web Interface)
sendmail servicesindex iconEnable Sendmail and NTP Services
strict multi-homingindex iconEnable Strict Multi-homing
encrypted
swap space, enablingindex iconEnable Encrypted Swap Space
ZFS data sets, creatingindex iconCreate Encrypted ZFS Data Sets
encryption keysindex iconData Protection
enforcing nonexecutable stacksindex iconEnforce Nonexecutable Stacks
Ethernet switch
changing passwordsindex iconChange the Ethernet Switch Password
securingindex iconSecuring the IB and Ethernet Switches
Exadata storage servers
changing passwordsindex iconChange Storage Server Passwords
configuring
boot loader passwordsindex iconConfigure a System Boot Loader Password
failed authentication lock delaysindex iconConfigure a Failed Authentication Lock Delay
login warning bannersindex iconConfigure a Login Warning Banner (Storage Server)
password agingindex iconConfigure Password Aging Control Policies
password complexity rulesindex iconConfigure Password Complexity Rules
password history policiesindex iconConfigure a Password History Policy
system account lockoutsindex iconConfigure System Account Lockout
disabling Oracle ILOM console accessindex iconDisable Oracle ILOM System Console Access
displaying available security configurationsindex iconDisplay Available Security Configurations With host_access_control
Exadata storage serversindex iconLog into the Storage Server OS
exposed network servicesindex iconDefault Exposed Network Services (Storage Servers)
hardening the security configurationindex iconHardening the Storage Server Security Configuration
interface inactivity timeouts
login shellindex iconConfigure the Administrative Interface Inactivity Timeout (Login Shell)
SSHindex iconConfigure the Administrative Interface Inactivity Timeout (Secure Shell)
limiting remote network accessindex iconLimiting Remote Network Access
management network isolationindex iconStorage Server Management Network Isolation
restricting remote SSH root accessindex iconRestrict Remote root Access Using SSH
securingindex iconSecuring the Exadata Storage Servers
security configuration restrictionsindex iconSecurity Configuration Restrictions
exposed network services on
compute serversindex iconDefault Exposed Network Services (Compute Servers)
Exadata storage serversindex iconDefault Exposed Network Services (Storage Servers)
IB switchesindex iconDefault Exposed Network Services (IB Switch)
Oracle ILOMindex iconDefault Exposed Network Services (Oracle ILOM)
ZFS storage applianceindex iconDefault Exposed Network Services (ZFS Storage Appliance)

F

FIPS-140
approved algorithmsindex iconFIPS-140-2 Level 1 Compliance
compliant operation (Oracle ILOM), enablingindex icon(If Required) Enable FIPS-140 Compliant Operation (Oracle ILOM)
Level 1 complianceindex iconFIPS-140-2 Level 1 Compliance
firewallindex iconAccess Control
firmware updatingindex iconSoftware and Firmware Updating

G

generating compliance reportsindex iconGenerate a Compliance Assessment
with a cron jobindex icon(Optional) Run Compliance Reports with a cron Job
GSS, disablingindex iconDisable GSS (Unless Using Kerberos)

H

hardening
compute server security configurationindex iconHardening the Compute Server Security Configuration
Exadata storage servers security configurationindex iconHardening the Storage Server Security Configuration
IB switch security configurationindex iconHardening the IB Switch Configuration
Oracle ILOM security configurationindex iconHardening the Oracle ILOM Security Configuration
ZFS storage appliance security configurationindex iconHardening the ZFS Storage Appliance Security Configuration
hash-based message authenticationindex iconFIPS-140-2 Level 1 Compliance
home directories, ensuring appropriate permissionsindex iconEnsure That User Home Directories Have Appropriate Permissions
HTTP redirection to HTTPS on
IB switchesindex iconConfigure HTTP Redirection to HTTPS (IB Switch)
Oracle ILOMindex iconConfigure HTTP Redirection to HTTPS (Oracle ILOM)

I

IB service networkindex iconSecure Isolation
IB switches
changing
root and nmuser passwordsindex iconChange root and nm2user Passwords
the Oracle ILOM passwordindex iconChange IB Switch Passwords (Oracle ILOM)
configuring
CLI session timeoutsindex iconConfigure the Administrative CLI Session Timeout (IB Switch)
HTTP redirection to HTTPSindex iconConfigure HTTP Redirection to HTTPS (IB Switch)
SNMP community stringsindex iconConfigure SNMP Community Strings (IB Switch)
determining the firmware versionindex iconDetermine the IB Switch Firmware Version
disabling
unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols (IB Switch)
unnecessary servicesindex iconDisable Unnecessary Services (IB Switch)
exposed network servicesindex iconDefault Exposed Network Services (IB Switch)
hardening the security configurationindex iconHardening the IB Switch Configuration
logging in toindex iconLog Into an IB Switch
network isolationindex iconIB Switch Network Isolation
replacing default self-signed certificatesindex iconReplace Default Self-Signed Certificates (IB Switch)
securingindex iconSecuring the IB and Ethernet Switches
immutable global zones, configuringindex iconCreate Immutable Global Zones
immutable non-global zones, configuringindex iconConfigure Immutable Non-Global Zones
IP Filter firewall
index iconEnable the IP Filter Firewall
index iconAccess Control
isolation, secureindex iconSecure Isolation

K

keeping the system secureindex iconKeeping SuperCluster M8 and SuperCluster M7 Systems Secure
key store access, setting a passphrase forindex icon(Optional) Set a Passphrase for Key Store Access

L

limiting remote network access on Exadata storage serversindex iconLimiting Remote Network Access
logging in to
compute server PDomainsindex iconLog into a Compute Server
Exadata storage servers OSindex iconLog into the Storage Server OS
IB switchesindex iconLog Into an IB Switch
Oracle ILOM CLIindex iconLog in to the Oracle ILOM CLI
the ZFS storage applianceindex iconLog into the ZFS Storage Appliance
login warning banners
Exadata storage serversindex iconConfigure a Login Warning Banner (Storage Server)
Oracle ILOMindex iconConfigure Login Warning Banners (Oracle ILOM)

M

management networkindex iconSecure Isolation
managing SuperCluster securityindex iconManaging SuperCluster Security
monitoringindex iconMonitoring Security
database activityindex iconDatabase Activity Monitoring and Auditing
networksindex iconNetwork Monitoring
workloadsindex iconWorkload Monitoring
monitoring and auditingindex iconMonitoring and Compliance Auditing
multi-homing, strictindex iconEnable Strict Multi-homing

N

name services using only local filesindex iconEnsure That Name Services Only Use Local Files
network isolation on IB switchesindex iconIB Switch Network Isolation
network monitoringindex iconNetwork Monitoring
network services exposed on
compute serversindex iconDefault Exposed Network Services (Compute Servers)
Exadata storage serversindex iconDefault Exposed Network Services (Storage Servers)
IB switchesindex iconDefault Exposed Network Services (IB Switch)
Oracle ILOMindex iconDefault Exposed Network Services (Oracle ILOM)
ZFS storage applianceindex iconDefault Exposed Network Services (ZFS Storage Appliance)
networks in SuperClusterindex iconSecure Isolation
non-executable stacks, enforcingindex iconEnforce Nonexecutable Stacks
NTP services, enablingindex iconEnable Sendmail and NTP Services

O

OpenBoot, securingindex iconOpenBoot
Oracle Engineered Systems Hardware Manager
index iconOracle Engineered Systems Hardware Manager
index iconPasswords Known by Oracle Engineered Systems Hardware Manager
default accounts and passwordsindex iconDefault User Accounts and Passwords
Oracle Enterprise Managerindex iconOracle Enterprise Manager
Oracle Enterprise Manager Ops Centerindex iconOracle Enterprise Manager Ops Center (Optional)
Oracle Identity Management Suiteindex iconOracle Identity Management Suite
Oracle ILOM
configuring
browser inactivity timeoutsindex iconConfigure Administrative Browser Interface Inactivity Timeout
CLI timeoutsindex iconConfigure the Administrative Interface Timeout (Oracle ILOM CLI)
login warning bannersindex iconConfigure Login Warning Banners (Oracle ILOM)
SNMP community stringsindex iconConfigure SNMP v1 and v2c Community Strings (Oracle ILOM)
determining the versionindex iconDetermine the Oracle ILOM Version
disabling
SSL ciphers for HTTPSindex iconDisable SSL Weak and Medium-Strength Ciphers for HTTPS
the SSLv2 protocol for HTTPSindex iconDisable the SSLv2 Protocol for HTTPS
the SSLv3 protocol for HTTPSindex iconDisable the SSLv3 Protocol for HTTPS
unapproved TLS protocols for HTTPSindex iconDisable Unapproved TLS Protocols for HTTPS
unnecessary servicesindex iconDisable Unnecessary Services (Oracle ILOM)
disabling unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols (Oracle ILOM)
exposed network servicesindex iconDefault Exposed Network Services (Oracle ILOM)
hardening the security configurationindex iconHardening the Oracle ILOM Security Configuration
HTTP redirection to HTTPSindex iconConfigure HTTP Redirection to HTTPS (Oracle ILOM)
logging into the CLIindex iconLog in to the Oracle ILOM CLI
replacing default self-signed certificatesindex iconReplace Default Self-Signed Certificates (Oracle ILOM)
secure managementindex iconOracle ILOM for Secure Management
securingindex iconSecuring Oracle ILOM
security on the ZFS storage applianceindex iconImplement Oracle ILOM Security Configuration Hardening
Oracle Key Manager
index iconOracle Key Manager
index iconData Protection

P

passphrase for key store access, settingindex icon(Optional) Set a Passphrase for Key Store Access
password aging on Exadata storage serversindex iconConfigure Password Aging Control Policies
password logs and policies, settingindex iconSet Password History Logs and Password Policies for PCI Compliance
passwords, changing
Exadata storage serversindex iconChange Storage Server Passwords
IB switchesindex iconChange root and nm2user Passwords
passwords, default
all componentsindex iconDefault User Accounts and Passwords
PDU firmware updatingindex iconSoftware and Firmware Updating
physical restrictionsindex iconAccess Restrictions
principles, securityindex iconUnderstanding Security Principles
protecting core dumpsindex iconProtect Core Dumps
Python versionindex iconMonitoring and Compliance Auditing

R

random number generatorsindex iconFIPS-140-2 Level 1 Compliance
replacing default self-signed certificates on
IB switchesindex iconReplace Default Self-Signed Certificates (IB Switch)
Oracle ILOMindex iconReplace Default Self-Signed Certificates (Oracle ILOM)
resources, additional
compute serversindex iconAdditional Compute Server Resources
Exadata storage serversindex iconAdditional Storage Server Resources
hardwareindex iconAdditional Hardware Resources
IB switchesindex iconAdditional IB Switch Resources
Oracle ILOMindex iconAdditional Oracle ILOM Resources
ZFS storage applianceindex iconAdditional ZFS Storage Appliance Resources
restricting
remote SSH root access on Exadata storage serversindex iconRestrict Remote root Access Using SSH
root as a roleindex iconVerify That root Is a Role

S

sanitation of drivesindex iconDrives
secure hashing standardindex iconFIPS-140-2 Level 1 Compliance
secure isolationindex iconSecure Isolation
secure management
Oracle Identity Management Suiteindex iconOracle Identity Management Suite
Oracle ILOMindex iconOracle ILOM for Secure Management
secure shell service, configuringindex iconConfigure the Secure Shell Service
secure verified boot, enabling
index iconSecure Verified Boot (Oracle ILOM Web Interface)
index iconEnable Secure Verified Boot (Oracle ILOM CLI)
securing
compute serversindex iconSecuring the Compute Servers
Ethernet switchindex iconSecuring the IB and Ethernet Switches
Exadata storage serversindex iconSecuring the Exadata Storage Servers
hardware, theindex iconSecuring the Hardware
IB switchesindex iconSecuring the IB and Ethernet Switches
OpenBoot, theindex iconOpenBoot
Oracle ILOMindex iconSecuring Oracle ILOM
ZFS storage applianceindex iconSecuring the ZFS Storage Appliance
security
configuration restrictions for storage serversindex iconSecurity Configuration Restrictions
default settingsindex iconDefault Security Settings
managingindex iconManaging SuperCluster Security
principlesindex iconUnderstanding Security Principles
self-signed certificates on
IB switchesindex iconReplace Default Self-Signed Certificates (IB Switch)
Oracle ILOMindex iconReplace Default Self-Signed Certificates (Oracle ILOM)
sendmail services, enablingindex iconEnable Sendmail and NTP Services
serial numbersindex iconSerial Numbers
setting
passphrases for key store accessindex icon(Optional) Set a Passphrase for Key Store Access
password logs and policiesindex iconSet Password History Logs and Password Policies for PCI Compliance
sticky bitsindex iconSet the Sticky Bit for World-Writable Files
Silicon Secured Memoryindex iconData Protection
SNMP protocols, disablingindex iconDisable Unapproved SNMP Protocols (Oracle ILOM)
SNMP v1 and v2c community strings, disablingindex iconConfigure SNMP v1 and v2c Community Strings (Oracle ILOM)
software updatingindex iconSoftware and Firmware Updating
SPARC M7 processorindex iconData Protection
SPARC M8 processorindex iconData Protection
SSL ciphers for HTTPS, disablingindex iconDisable SSL Weak and Medium-Strength Ciphers for HTTPS
SSLv2 protocol, disabling for HTTPSindex iconDisable the SSLv2 Protocol for HTTPS
SSLv3 protocol, disablingindex iconDisable the SSLv3 Protocol for HTTPS
sticky bit, settingindex iconSet the Sticky Bit for World-Writable Files
strategies, securityindex iconSecure Isolation
SuperCluster software version, determining theindex iconDetermine the SuperCluster Software Version
swap space, encryptedindex iconEnable Encrypted Swap Space
symmetric keysindex iconFIPS-140-2 Level 1 Compliance

T

TCP connections, configuringindex iconConfigure TCP Connections
TLS protocols for HTTPS, unapprovedindex iconDisable Unapproved TLS Protocols for HTTPS

U

user accounts and passwordsindex iconDefault User Accounts and Passwords

V

verifying that root is a roleindex iconVerify That root Is a Role
version of
IB switch firmwareindex iconDetermine the IB Switch Firmware Version
Oracle ILOMindex iconDetermine the Oracle ILOM Version
SuperCluster softwareindex iconDetermine the SuperCluster Software Version
ZFS storage appliance softwareindex iconDetermine the ZFS Storage Appliance Software Version

W

workload monitoringindex iconWorkload Monitoring

Z

ZFS data sets, encryptingindex iconCreate Encrypted ZFS Data Sets
ZFS storage appliance
configuring
interface inactivity timeouts (HTTPS)index iconConfigure the Administrative Interface Inactivity Timeout (HTTPS)
SNMP authorized networksindex iconConfigure SNMP Authorized Networks
SNMP community stringsindex iconConfigure SNMP Community Strings
disabling
dynamic routingindex iconDisable Dynamic Routing
unapproved SNMP protocolsindex iconDisable Unapproved SNMP Protocols
unnecessary servicesindex iconDisable Unnecessary Services (ZFS Storage Appliance)
exposed network servicesindex iconDefault Exposed Network Services (ZFS Storage Appliance)
hardening the security configurationindex iconHardening the ZFS Storage Appliance Security Configuration
implementing Oracle ILOM securityindex iconImplement Oracle ILOM Security Configuration Hardening
logging in to theindex iconLog into the ZFS Storage Appliance
root password, changingindex iconChange the ZFS Storage Appliance root Password
securingindex iconSecuring the ZFS Storage Appliance
software versions, determiningindex iconDetermine the ZFS Storage Appliance Software Version