ADSM-L

ADSM security

1996-09-24 12:07:48
Subject: ADSM security
From: Tom Denier <tom AT STAFF.UDC.UPENN DOT EDU>
Date: Tue, 24 Sep 1996 12:07:48 -0400
I have been looking into the security implications of ADSM. Our server
is an AIX system. At present all our clients are also AIX systems. All
client-server communications use TCP/IP. I have checked the ADSM manuals
and have so far found nothing that would help me evaluate ADSM's
resistance to such attacks as password sniffing, session hijacking,
rogue servers, and eavesdropping on files in transit. Is there a source
for this kind of information?

I am also concerned about potential abuses of legitimate access. The ADSM
Version 2 server can schedule execution of operating system commands on
clients that run the scheduler processes used to support centrally
scheduled backups. Am I correct in concluding that this has the same
security implications as telling the ADSM administrator the root password
for every UNIX client that runs centrally scheduled backups?
<Prev in Thread] Current Thread [Next in Thread>
  • ADSM security, Tom Denier <=