{"id":864,"date":"2009-08-17T07:55:32","date_gmt":"2009-08-16T21:55:32","guid":{"rendered":"http:\/\/nsrd.wordpress.com\/?p=864"},"modified":"2009-08-17T07:55:32","modified_gmt":"2009-08-16T21:55:32","slug":"whats-wrong-with-the-nmc-installation-process","status":"publish","type":"post","link":"https:\/\/nsrd.info\/blog\/2009\/08\/17\/whats-wrong-with-the-nmc-installation-process\/","title":{"rendered":"What&#8217;s wrong with the NMC installation process?"},"content":{"rendered":"<p>There is, in my opinion, an unpleasant security hole in the NMC installation\/configuration process.<\/p>\n<p>The security hole is simple: it does not prompt for the administrator password on installation. This is inappropriate for a data protection product, and I think it&#8217;s something that EMC should fix.<\/p>\n<p>The NMC installation process is slightly different depending on whether you&#8217;re working with 7.5.x or 7.4.x and lower.<\/p>\n<p>For 7.4.x and lower, the process works as follows:<\/p>\n<ul>\n<li>Install NetWorker management console.<\/li>\n<li>(On Unix platforms, manually run the \/opt\/lgtonmc\/bin\/nmc_config file to initialise the configuration.)<\/li>\n<li>Launch NMC.<\/li>\n<li>Use the default username\/password until you get around to changing the password.<\/li>\n<\/ul>\n<p>For 7.5.x and higher installations, the process works as follows:<\/p>\n<ul>\n<li>Install NetWorker management console.<\/li>\n<li>First person to logon gets to set the administrator password.<\/li>\n<\/ul>\n<p>In both instances, this represents a clear security threat to the environment, <em>particularly when installing NetWorker on the backup server or another host that already has administrator access to the datazone<\/em>, and needs to be managed carefully. Two clear options, depending on the level of trust you have within your environment are:<\/p>\n<ul>\n<li>Use firewall\/network security configuration options to restrict access to the NMC console port (9000) to a single, known and trusted host, until you are able to log on and change the password.<\/li>\n<\/ul>\n<p><em>or<\/em><\/p>\n<ul>\n<li>Be prepared to log onto NMC as soon as the installation (or for Unix, installation\/configuration) is complete and trust that you &#8220;get there first&#8221;.<\/li>\n<\/ul>\n<p>In reality, the second option would not be declared secure by any security expert, but for small environments where the trust level is high, it <em>may <\/em>be acceptable for local security policies.<\/p>\n<p>The real solution though is simple: EMC <strong>must <\/strong>change the NMC installation process to force the input of a secure administrator password <em>at install time<\/em>. That way, by the time the daemons are first started, they are already secured.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is, in my opinion, an unpleasant security hole in the NMC installation\/configuration process. The security hole is simple: it&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[16,21],"tags":[96,97,633,638,1254],"class_list":["post-864","post","type-post","status-publish","format-standard","hentry","category-networker","category-security","tag-administrator","tag-administrator-password","tag-networker-management-console","tag-nmc","tag-security"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pKpIN-dW","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/comments?post=864"}],"version-history":[{"count":0,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/posts\/864\/revisions"}],"wp:attachment":[{"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/media?parent=864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/categories?post=864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsrd.info\/blog\/wp-json\/wp\/v2\/tags?post=864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}