Understanding HP SIM 5.1 and 5.2 security (481362-003, January 2009)

Browser.............................................................................................................................................. 7
SSL................................................................................................................................................. 7
Cookies .......................................................................................................................................... 7
Passwords....................................................................................................................................... 7
Browser warnings ............................................................................................................................ 8
Untrusted system........................................................................................................................... 8
Invalid certificate .......................................................................................................................... 8
Host name mismatch..................................................................................................................... 8
Signed applet .............................................................................................................................. 8
Internet Explorer zones ..................................................................................................................... 8
System link format ............................................................................................................................ 9
Operating-system dependencies ............................................................................................................ 9
User accounts and authentication....................................................................................................... 9
File system....................................................................................................................................... 9
Background processes .................................................................................................................... 10
Windows Cygwin .......................................................................................................................... 10
HP-UX/Linux.................................................................................................................................. 10
Database.......................................................................................................................................... 10
SQL Server/MSDE ......................................................................................................................... 10
Remote SQL Server......................................................................................................................... 10
PostgreSQL.................................................................................................................................... 10
Oracle.......................................................................................................................................... 10
Auditing ........................................................................................................................................... 11
Command-line interface...................................................................................................................... 11
How-to: configuration checklist ............................................................................................................ 11
General ........................................................................................................................................ 11
Configure CMS.............................................................................................................................. 11
Strong security ........................................................................................................................... 11
Configure managed systems............................................................................................................ 11
Configure CMS for managed systems...............................................................................................12
How-to: lockdown versus ease of use ................................................................................................... 12
Moderate...................................................................................................................................... 12
Strong .......................................................................................................................................... 13
Port listing......................................................................................................................................... 14
Vulnerability and Patch Management Pack firewall ports ........................................................................ 16
HP SIM Server ............................................................................................................................... 16
VPM Server ................................................................................................................................... 16
MSDE ....................................................................................................................................... 16
Harris STAT® Scanner Engine...................................................................................................... 18
Radia Patch Manager ................................................................................................................. 18
Target nodes ................................................................................................................................. 18
Scanner Access (Target Nodes).................................................................................................... 18
HP SIM ..................................................................................................................................... 19
Radia Patch Manager ................................................................................................................. 19
Virtual Machine Management Pack ports.............................................................................................. 19
Integrated Lights-Out (iLO) ports........................................................................................................... 20