ADSM-L

Re: [ADSM-L] Can a TSM server admin purloin client backups?

2011-10-25 18:07:52
Subject: Re: [ADSM-L] Can a TSM server admin purloin client backups?
From: Hans Christian Riksheim <bullhcr AT GMAIL DOT COM>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Tue, 25 Oct 2011 23:56:55 +0200
I think the real problem is not with the administrator.

The real problem is that an owner of client A can restore data from
client B only by knowing the TSM admin password. Think many customers
hooked up to the same TSM server.

And how often is that particular password changed in a lib/config
manager environment? Fair chance that it is "out there".

Hans Chr.

On Tue, Oct 25, 2011 at 10:07 PM, Keith Arbogast <warbogas AT indiana DOT edu> 
wrote:
> This question came up again here. If a TSM admin with system authorization 
> knows the client password for a certain TSM node, what keeps him from 
> restoring files from that node to another server of his choosing?
>
> Sorry to resuscitate this old horse.
>
> With many thanks,
> Keith
>