Setting Up Security for Remote Management

The following sections provide information about setting up security for the Remote Management sessions:


Configuring the Remote Management Policies

To configure the Remote Management policies, you must perform the following tasks:


Creating the Policy Packages

ZfS 3 requires policy packages in the eDirectory tree that can hold the server policies. You can later configure and enable the server policies.

Policy packages are eDirectory objects that contain collections of policies grouped according to the object types. You should create an Organizational Unit (OU) for holding the policy packages. Consider the following when determining where to place this OU:

If you install ZENworks for Desktops (ZfD) to your tree, you may want to keep the ZfS and ZfD policies in separate containers, such as ZfS_Policies and ZfD_Policies.

For ZfS 3 Remote Management, create two containers, one for Tiered Electronic Distribution (TED) objects and the other for the Remote Management policy package.

To create a container:

  1. In ConsoleOne, right-click the container where you want the container for the policy packages placed.

  2. Click New > Object > Organizational Unit > OK.

  3. Name the container, for example, ZfS_Policies > click OK.

IMPORTANT:  If you have partitions that are accessed across a WAN, make sure that the Policy Package objects are in the same partition as the Server object so that the Policy/Package Agents will load. Also make sure that the Search policy does not require searching outside the partition where the Server object exists.

For Remote Management, you must create the Distributed Server package. The Distributed Server package is required to distribute the Remote Management policies among the managed servers for enforcement.

To create the Distributed Server package:

  1. Right-click the policy package's container > click New > click Policy Package.

    The Policy Package Wizard is displayed.

  2. From the Policy Packages list, select Distributed Server Package > click Next.

  3. Enter a name for the Distributed Server Package > click Next > click Finish.


Creating and Configuring the TED Objects

For ZfS 3 Remote Management, you must create and configure the following TED objects:

To create and configure the TED objects, see Configuring TED Objects .


Configuring the Server Remote Management Policy

The Server Remote Management policy defines the behavior of the Remote Management Agent. This policy is distributed to the specified Windows managed servers using the TED, which helps the remote operator to associate the Remote Management policy to a group of Windows managed servers from the management console.

To configure the Server Remote Management policy:

  1. In ConsoleOne, right-click the Distribute Server Package object > click Properties.

  2. Click the Policies tab > select the Windows sub-option.

  3. Select the check box under the Enabled column for the Server Remote Management Policy.

  4. Click the Properties button > the Remote Management tab.

  5. Click the General tab.

  6. Click Display Remote Management Agent Icon To Users for Remote Control and Remote View sessions.

  7. Click the Remote Control tab > select the options that you want to use. Your choices are:

  8. Click the Remote View tab > select the options that you want to use. Your choices are:

  9. Click Apply > Close.

  10. Right-click the Server Remote Management policy > select Edit Schedule.

  11. Modify the schedule > click Apply > click Close.

  12. To associate the Server Remote Management policy with a managed server, click the Distribution tab.

  13. Click Add > browse for and select the Distribution object > click OK.

  14. Click Apply > click Close.


Configuring the Distribution Object for Remote Management

You must configure the Distribution object for distributing the Remote Management policies.

To configure the Distribution object:

  1. In ConsoleOne, right-click the Distribution object > click Properties.

  2. Click the Type tab.

  3. Select Policy Package from the Select Type drop-down list.

  4. Click Add > select the Distributed Server package that has the Server Remote Management policy.

  5. Click the Schedule tab.

  6. Modify the schedule > click Apply > click Close.


Configuring the Distributor and the Subscriber Objects

To configure the Distributor and the Subscriber objects, see Configuring TED Objects .

If the managed servers are residing on a different eDirectory tree or the Windows NT server does not have the eDirectory installed, you must create and configure an External Subscriber object for sending Distributions to Subscribers residing on managed servers in other trees. For more information on External Subscribers, see Configuring TED Objects .


Setting Up the Agent Password at the Managed Server

The user at the managed server can change the password of the Remote Management Agent to make sure that the Remote Management sessions are secure.

To change the agent password:

  1. Right-click the Remote Management Agent icon from the system tray of the Windows NT/2000 managed server.

  2. Click Security > click Set Password.

    Use a password of ten or fewer alphanumeric characters. The password is case-sensitive and cannot be blank.

The new password must be communicated to the remote operator each time it is changed.