B Security Compliance for Advanced Management Console

The security recommendations help in improving the processes of installing, configuring, and deploying the Advanced Management Console server and its components.

All the security recommendations are applicable to Windows, macOS, and Linux operating systems. The following sections list the recommendations for each component of the AMC:

Security Recommendations for Advanced Management Console Server

Follow these security recommendations for the Advanced Management Console server installation, configuration, and deployment:

  • Protocol: The AMC uses HTTPS for communication between the AMC server and clients (agent, web UI, Deployment Rule Set tool, and Java installer configuration).

  • Server deployment protection: The AMC server deployment and initialization web page is not protected and does not require a password to set up. Therefore, the initialization page can be accessed by any user. Administrators should restrict access to the server or lock the server behind a firewall until initialization is complete.

  • Java Usage Tracker communication protection: The Advanced Management Console should be run behind a firewall, which should be supported by the administrators. Administrators need to run the agent and server communication within the same intranet segment behind the firewall. The Advanced Management Console agents send Java Usage Tracker data to the server over https.

Security Recommendations for Advanced Management Console WebLogic Server

Follow these security recommendations for the Advanced Management Console WebLogic Server installation, configuration, and deployment:

  • Java Security Manager: Consider enabling the Java Security Manager in WebLogic Server to provide protection for resources running in a Java Virtual Machine (JVM) and to improve the AMC security. See Java Security Manager.

  • WebLogic Server Logs: AMC leverages WebLogic Server logs to report all the security errors and warnings. Check the WebLogic Server domain logs for any reported errors.

  • Critical Patch Updates: AMC requires that you keep your WebLogic Server instance up-to-date with security patches. We also recommend that you subscribe to receive Oracle’s Critical Patch Update Advisories and Security Alerts notifications. See Instructions for subscribing to email notifications.

Security Recommendations for Advanced Management Console Agent

Follow these security recommendations for the Advanced Management Console agent installation, configuration, and deployment:

  • Secure file permissions: The AMC doesn’t restrict the locations where system administrators can install the agents in a Windows environment. However, agents should be installed in a protected location, such as Program Files (x86), where regular users cannot make changes. In addition, system administrators should ensure that all installed files have secure permissions.

  • Agent logs: Check the AMC agent service logs for reported logins, events, and errors located in the following Windows directory: %PROGRAMDATA%\Oracle\Java_AMC\agent.log. In a macOS environment, locate the agent logs here:/Library/Application Support/Oracle/Java_AMC/agent.log.0.

Security Recommendations for Advanced Management Console Databases: MySQL or Oracle

Follow these security recommendations for Advanced Management Console installation, configuration, and deployment of Oracle database or MySQL database:

  • Secure database setup : This installation guide does not provide details about secure database configuration and database security management.

  • User credentials: The user credentials provided for MySQL or Oracle databases in the sections are examples. Oracle highly recommends that you use a different name and strong password for production use.