8.4 Securing the Messenger Agents

8.4.1 Updating SSL Certificates for the Messenger Agents

SSL is enabled by default during the install. You can use your own certificates or have Messenger create the certificates for you. You can update the certificates for Messenger in the GroupWise Admin console at Messenger > MessengerService > Objects > Servers > selected server > SSL Settings. You can then upload new certificates to Messenger.

8.4.2 Enabling SSL for the Web Console

The Web Console should already be configured to use SSL when SSL is configured during the installation. However, additional configuration is needed to enable SSL for the Web Console. For information on how to secure and configure the Web Console, see Setting Up the Messaging Agent Web Console and Using the Archive Agent Web Console and GroupWise Monitor.

8.4.3 Enabling Password Protection for the Web Console

The Web Console should be configured to use SSL and password protection, but password protection needs to be enabled. For information on how to enable password protection for the Web Console, see Setting Up the Messaging Agent Web Console and Using the Archive Agent Web Console and GroupWise Monitor.

8.4.4 Securing the Data Files

Reference these sections to learn how to secure data files.

Securing the Data Store

The data store files should be protected from access by unauthorized persons. The data store files are identified by an eight-digit hexadecimal number followed by either .maf or .mai. They are found in the following default locations:

Table 8-1 Messenger Data Store File Locations

Platform

Directory

Store Files

Linux

/var/opt/novell/messenger/aa/store
xxxxxxxx.maf
xxxxxxxx.mai

Securing the Queue Files

The queue files should be protected from access by unauthorized persons. The queue files are identified by an eight-digit hexadecimal number followed by three numbers. They are found in the following default locations:

Table 8-2 Messenger Queue File Locations

Platform

Directory

Queue Files

Linux

/var/opt/novell/messenger/ma/queue
/var/opt/novell/messenger/aa/queue
                      xxxxxxxx.nnn
                    

Securing the Log Files

The log files for all Messenger agents should be protected from access by unauthorized persons. Some contain very detailed information about your Messenger system and Messenger users. They are found in the following default locations:

Table 8-3 Messenger Agent Log File Locations

Platform

Directory

Log Files

Linux

/var/opt/novell/log/messenger/ma/
/var/opt/novell/log/messenger/aa
mmddnma.nnn
mmddnaa.nnn

Securing the Startup Files

The startup files for all Messenger agents should be protected from access by unauthorized persons. They are found in the following default locations:

Table 8-4 Messenger Agent Startup File Locations

Platform

Directory

Startup Files

Linux

/etc/init.d
novell-nmma
novell-nmaa

Securing the Root Certificate

The root certificate files should be protected from access by unauthorized persons. The root certificate files are copied to the following default locations:

Table 8-5 Root Certificate File Locations

Platform

Directory

Startup Files

Linux

/opt/novell/messenger/certs
certname.der