Page 1
Dell EMC Open Manage Enterprise 3.8.3 Security Configuration Guide February 2022 Rev. 1
Page 2
Notes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either potential damage to hardware or loss of d...
Page 3
Revision history The following table shows the revision history of this document: Revision Date Description February 2022 Content updated for this release of Open Manage Enterprise. Revision history
Page 4
Preface As part of an effort to improve product lines, we periodically release revisions of software. Therefore, some functions described in this document might not be supported by all versions of the...
Page 5
Vertical bar indicates alternate selections - the bar means "or" { } Braces enclose content that the user must specify, such as x or y or z Ellipses indicate nonessential information omitted...
Page 6
Dell EMC Open Manage Enterprise Events Management Dell EMC Open Manage Enterprise Scale and Performance Dell EMC Open Manage Enterprise Advanced Server Configuration Dell EMC Open Manage Enterprise En...
Page 7
Contents Revision history..........................................................................................................................................................................3 Pre...
Page 8
Tables Open Manage Enterprise Supported protocols and ports on management stations................................ Open Manage Enterprise supported protocols and ports on the managed nodes...............
Page 9
Figures OME security control map...................................................................................................................................... Security settings...................
Page 10
Security quick reference Topics: Deployment models Security profiles Deployment models Dell EMC Open Manage Enterprise is designed to be deployed as a virtual appliance for a variety of supported hype...
Page 11
Product and subsystem security Topics: Security controls map Authentication Login security settings Authentication types and setup considerations Authorization Data security Cryptography Security cont...
Page 12
Login security settings Dell EMC Open Manage Enterprise supports only secure connections to appliance over TLS v1.2 channel. OME redirects all HTTP requests to HTTPS and ensures that credentials are c...
Page 13
Figure 3. Application settings Figure 4. Configuration settings for timeouts/max concurrent sessions Inactive sessions are deleted when the admin configured inactivity timeout expires, and the user is...
Page 14
Configuring active directory User can configure active directory by navigating to Application Setting > Directory Service. Figure 6. Configuring active directory OIDC authentication User can config...
Page 15
Figure 7. OIDC authentication User and credential management Administrator can create and manage users accounts from the Users page by navigating to Application Settings > Users in Open Manage Ente...
Page 16
Pre-loaded accounts Open Manage Enterprise has admin as the default user. On first boot, after the EULA has been accepted, the password for the default admin account has to configured. Default credent...
Page 17
Changing admin password from Text User Interface Figure 9. Admin password change from TUI Securing credentials User credentials are one-way hashed using the Open BSD bcrypt scheme and stored in the da...
Page 18
Authentication to external systems Open Manage Enterprise saves device credentials encrypted with AES encryption with a 128-bit key size using encryption key generated on Open Manage Enterprise. Devic...
Page 19
Network security Supported protocols and ports on management stations Table 1. Open Manage Enterprise Supported protocols and ports on management stations Port Protocol Port Type Maximum Source Direct...
Page 20
Table 1. Open Manage Enterprise Supported protocols and ports on management stations (continued) Port Protocol Port Type Maximum Source Direction Destination Usage Number Encryption Level 111, 2049 NF...
Page 21
Table 2. Open Manage Enterprise supported protocols and ports on the managed nodes (continued) Port Protocol Port Maximum Source Directio Destinatio Usage Number Type Encryption Level SNMP UDP None Op...
Page 22
Once the switch to use HTTPS for the internal file share is made, smbd is shutdown, and the OME appliance no longer functions as a CIFS server. OME supports 12-15G servers, but only the later versions...
Page 23
Field service debug (FSD) In Open Manage Enterprise, you can authorize console debugging by using the Field Service Debug (FSD) option. FSD enables root level access to appliance via SSH. This process...
Page 24
Figure 10. Certificate management User can also generate CSR, get it signed, and then upload the signed certificate to Open Manage Enterprise console. Auditing and logging Auditing provides a historic...
Page 25
Figure 12. Export audit log Administrator can change log levels from Text User Interface. Figure 13. Debug log Open Manage Enterprise has a size-based log roll-over policy. The maximum size of the log...