Page 1
Dell EMC Open Manage Enterprise 3.7 Security Configuration Guide July 2021 Rev. A00
Page 2
Notes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either potential damage to hardware or loss of d...
Page 3
Contents Figures..........................................................................................................................................4 Tables.........................................
Page 4
Figures OME security control map....................................................................................................................................... Security settings..................
Page 5
Tables Open Manage Enterprise Supported protocols and ports on management stations................................ Open Manage Enterprise supported protocols and ports on the managed nodes...............
Page 6
Preface As part of an effort to improve its product lines, Dell EMC periodically releases revisions of its software and hardware. Some functions that are described in this document might not be suppor...
Page 7
3. Verify your country or region in the Choose a Country/Region drop-down list at the bottom of the page. 4. Select the appropriate service or support link based on your need. Reporting security vulne...
Page 8
Security quick reference Topics: Deployment models Security profiles Deployment models Dell EMC Open Manage Enterprise is designed to be deployed as a virtual appliance for a variety of supported hype...
Page 9
Product and subsystem security Topics: Security controls map Authentication Login security settings Authentication types and setup considerations Authorization Data security Cryptography Security cont...
Page 10
Login security settings Dell EMC Open Manage Enterprise supports only secure connections to appliance over TLS v1.2 channel. OME redirects all HTTP requests to HTTPS and ensures that credentials are c...
Page 11
Figure 3. Application settings Figure 4. Configuration settings for timeouts/max concurrent sessions Inactive sessions are deleted when the admin configured inactivity timeout expires, and the user is...
Page 12
Configuring active directory User can configure active directory by navigating to Application Setting > Directory Service. Figure 6. Configuring active directory OIDC authentication User can config...
Page 13
Figure 7. OIDC authentication User and credential management Administrator can create and manage users accounts from the Users page by navigating to Application Settings > Users in Open Manage Ente...
Page 14
Pre-loaded accounts Open Manage Enterprise has admin as the default user. On first boot, after the EULA has been accepted, the password for the default admin account has to configured. Default credent...
Page 15
Changing admin password from Text User Interface Figure 9. Admin password change from TUI Securing credentials User credentials are one-way hashed using the Open BSD bcrypt scheme and stored in the da...
Page 16
Authentication to external systems Open Manage Enterprise saves device credentials encrypted with AES encryption with a 128-bit key size using encryption key generated on Open Manage Enterprise. Devic...
Page 17
Network security Supported protocols and ports on management stations Table 1. Open Manage Enterprise Supported protocols and ports on management stations Port Protocol Port Type Maximum Source Direct...
Page 18
Table 1. Open Manage Enterprise Supported protocols and ports on management stations (continued) Port Protocol Port Type Maximum Source Direction Destination Usage Number Encryption Level 111, 2049 NF...
Page 19
Table 2. Open Manage Enterprise supported protocols and ports on the managed nodes (continued) Port Protocol Port Maximum Source Directio Destinatio Usage Number Type Encryption Level SNMP UDP None Op...
Page 20
Data security OME stores all sensitive data encrypted with the OME generated encryption key. All user credentials are stored with a one-way hash and cannot be decrypted. All Device credentials are enc...
Page 21
A group is assigned, or access permission is changed. User role is modified. Actions that were performed on the devices monitored by Open Manage Enterprise. The audit log files can be exported to the ...
Page 22
SSL certificate cannot be trusted Security scans on OME may show the SSL certificate issues with the default certificate on OME. As a best practice, SSL certificate chain ends in an unrecognized self-...
Page 23
Contacting Dell Prerequisites NOTE: If you do not have an active Internet connection, you can find contact information on your purchase invoice, packing slip, bill, or Dell product catalog. About this...