16.1 Security Features

The following table contains the security features of Novell Remote® Manager on NetWare® OES.

Table 16-1 Security Features of NRM

Feature

Yes/No

Details

Users are authenticated

Yes

Users must log in to Novell Remote Manager. They are authenticated through Novell eDirectory™. User Admin can restrict all users without the Supervisor right to the Server object from logging in.

You can also require users to read specific information before they log in to Novell Remote Manager.

For more information, see Logging In to Novell Remote Manager for NetWare, Setting Up a Customized Disclaimer or Text Screen, and Controlling User Access to the Server through Novell Remote Manager.

Servers, devices, and services are authenticated

Yes

When gathering information with inventory or group operations, NRM authenticates to other servers.

Access to information is controlled

Yes

Access to information is restricted to valid users that have rights to access the server through eDirectory.

The port for accessing the login dialog box must be open through a firewall if you want the server to be accessible outside the firewall. You can restrict access to specific workstations or a range of IP addresses.

For more information, see Logging In to Novell Remote Manager for NetWare, Controlling User Access to the Server through Novell Remote Manager, and Changing User Access by Using the IP Address Access Control Page.

Roles are used to control access

No

Novell Remote Manager does not have role-based management. The non-Admin NRM User access to the file system on the server is governed by eDirectory.

Logging and security auditing is done

Yes

All connections to the server can be monitored and are logged. See Managing Connections to the Server.

Access to the server console screen through the Novell Remote Manager Java Applet is also monitored and logged. See Running the Server Console Screens from the Dynamic Java Applet Pages.

Alerts are shown and notification is available when a specified amount of logins have failed through the Failed Logins Per Hour parameter on the Health Monitor page. See the online help for this page in the utility and Monitoring Overall Server Health or the Health of a Specific Item.

Data on the wire are encrypted by default

Yes

The following data are encrypted on the wire:

  • Administration via browser UI

  • When logging in the administration is switching to the HTTPS protocol.

Data is stored encrypted

No

Passwords, keys, and any other authentication materials are stored encrypted

Yes

Security is on by default

Yes