| United States-English |
|
|
|
![]() |
HP Visual User Environment 3.0 User's Guide > Chapter 22 Networking and Distributed ComputingConfiguring Network Security |
|
There are several security considerations in HP VUE, determining:
The default is the login user and root. Regardless of the value of the resource, root can always unlock the display. Example. This resource specifies the users who can unlock the display.
Example. This entry in /etc/exports permits remote host hpthere to mount volume /doc.
The Sub-Process Control Daemon (SPCD or softspcd) supports remote execution. When an action on a local host invokes an application on a remote host, the local HP VUE sends a message to the remote SPCD specifying the execution string for the application. For security reasons, the SPCD does not allow root to perform remote execution; root can't perform the file-based authentication over NFS. By default, the mserve (Message Server) and spc (Sub-Process Control) services provided by HP VUE are restricted in /var/adm/inetd.sec to the host name of the system.
Example. The following lines in /var/adm/inetd.sec specify the hosts permitted to access the local host's BMS: hostA, hostB, hostC, and all hosts on subnet 192.6.36.
The mechanism for restricting access to the local display depends on whether the display connection is requested by an action or by some other mechanism. Display access with actions. When an action executes a remote application, the application server is automatically given permission to connect to the local display (the xhost command is executed automatically). To turn off automatic authorization, use the resource
Display access by other mechanisms. When a remote application is started in ways other than by actions, the remote host must have explicit permission to connect to the local display. There are two ways to provide (and limit) remote access to a local display:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||