cc/td/doc/product/rtrmgmt/cw2000/camp_mgr/cwsi_2x/cwsi_2_3
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Essentials Security

Essentials Security

Essentials provides two levels of security:

This appendix describes both of these security levels.

Server Security

There are two aspects of Essentials server security:

Essentials relies on the security features and capabilities of the Windows NT operating system to protect the data and programs used by Essentials from unapproved access.

Caution Essentials can provide security only when installed on an NTFS filesystem.

Server-Imposed Security

The Essentials server provides the following security mechanisms:

Files installed by Essentials are readable by anyone logged into the Windows NT system but files created in the install directory\CSCOpx\files folder are readable only by the bin and administrator users.

System Administrator-Imposed Security

To maximize Essentials server security, follow these system administration guidelines:

Application Security

Essentials provides application-level security that allows the Essentials administrator to dictate which applications an Essentials user can access. Essentials provides this security through a set of five built-in roles:

Each role allows access to a predetermined set of applications, tools, and product features. Refer to the "Getting Started" section of the Essentials online help for a detailed chart showing the relationship of user role to application functionality.

When you create an Essentials login (every Essentials user must log in to the application to use its features), you assign one or more roles to the login. The role or combination of roles dictates which Essentials applications are available to the user in the Essentials navigation tree (refer to the "Setting Up Essentials" chapter for an explanation of the navigation tree).

Only the system administrator user can assign roles to Essentials logins. Essentials users can use the administrative tools to change their own password or other aspects of their login.

Essentials comes with two predefined logins:


Note The login named admin is the equivalent of the superuser login for Essentials. This login provides access to all Essentials tasks.

We recommended that you change the passwords for these predefined logins immediately after installation. Unless you want to allow everyone read-only access to Essentials, change the guest login password to something other than the default null string.

To prevent anyone from typing a full path to an Essentials URL to avoid the security system, Essentials applications will run only in the presence of an authenticated session between the server and client. The session is authenticated as a part of the login process so attempting to avoid the login by entering a URL will fail and the user will be returned to the Essentials Login Manager dialog box. The Essentials desktop terminates a login session after a period of no use. After termination, attempting to perform any operation returns the user to the Login Manager dialog box.


hometocprevnextglossaryfeedbacksearchhelp
Posted: Wed Dec 22 13:05:07 PST 1999
Copyright 1989-1999©Cisco Systems Inc.