User guide

Technical notes
EMC Avamar 7.0 Release Notes 61
Immediately change your password if you expect another person has access to your
account, or knows your password.
Always change your password as soon as you receive an account.
Password protection best practices
You should always create a password that you can remember without needing to store it.
However, if the password must be stored, follow these recommendations:
Use a password vault application to protect and help manage your passwords.
If passwords must be written down on a piece of paper, store the paper in a secure
place and destroy it when it is no longer needed.
Do not put your username and password on a post-it note under your keyboard.
Do not write down your username and password in the same place.
Use caution regarding where passwords are saved on computers. Some dialog boxes,
such as those for remote access and other telephone connections, present an option
to save or remember a password. Selecting this option poses a potential security
threat.
Never share your passwords with anyone and do not give your password to anyone
over the phone.
Avamar server technical notes
The following technical notes apply to the Avamar server.
Remove test data
Before starting the server or starting a new node for the first time, ensure that all test data
has been removed from /data*/partitions. In particular, if you ran disk tests before
startup, you might need to delete directories named QA.
Do not use the avmgr command
Improper use of the avmgr command line utility can destroy all access to data in the
Avamar system. Use this command only at the explicit direction of EMC Customer Service.
Vulnerability scanning
As part of every Avamar release, the product is scanned for vulnerabilities using at least
two common vulnerability assessments tools. This release was scanned with Foundstone
and Nessus. The Avamar solution has also been scanned by various customers by using
tools such as eEye Retina without issue. However, it is possible that the usage of other
port/vulnerability scanners might cause disruption to normal operation of the Avamar
server. Therefore, it might be necessary to disable scanning of the Avamar server if
problems occur.