User's Manual

On-Ramp Wireless Confidential and Proprietary 6 010-0059-00 Rev. A
4 Installing the Software
4.1 System Requirements
The system requirements for an LKS are as follows:
An enterprise-level server running CentOS 5.5 (or later) or Red Hat® Enterprise Linux®
(RHEL) 5.5 (or later) operating system (OS)
NOTE: The LKS has been tested by On-Ramp Wireless on a system running CentOS/RHEL
5.5 operating system.
Python 2.6 including the module for PyCrypto (version 2.0.1 or 2.1.0). For Python and
PyCrypto software installation instructions, refer to sections 4.3 and 4.4.
4.2 Security Requirements
As with any enterprise-level server, a number of basic and commonly accepted security
precautions should be taken to protect the LKS server and its contents from unauthorized
access. The following security precautions are recommended for the LKS server. Additional
precautions can be taken as deemed appropriate.
The LKS server should be placed in a physically secured environment (for example, a locked
server room).
The LKS server should use an operating system that has been configured to restrict access to
only authorized and authenticated users with well-established access control mechanisms
(for example, username/password with appropriate group permissions, etc.).
Services on the LKS server that do not use a secure protocol should be disabled (for
example, Telnet, FTP).
Unneeded and unused services on the LKS server should be disabled.
For additional security measures, refer to the following NSA documentation which contains
hardening tips and security configuration recommendations for RHEL 5, which are also
applicable to CentOS 5 systems.
www.nsa.gov/ia/_files/factsheets/rhel5-pamphlet-i731.pdf
www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf
4.3 Installing Python Software
To install Python 2.6 on a Linux-based computer (CentOS/RHEL 5.5 or later), follow the steps
below.
NOTE 1: In the CentOS 5.5 (or later) operating system, Python 2.4 is used by default. Python
2.6 must be installed but must not replace the existing Python 2.4 as it prevents the