HCL Connections
  • 主页
  • 个人档案 ▼
  • 社区 ▼
  • 应用程序 ▼
  • 统计
  • 审核
  • ▼
  • 登录
  • 共享
  • ?
  • HCLHCL

博客

  • 我的博客
  • 公共博客
  • 我的更新
  • 管理
  • 登录以进行参与

▼ 标签

 

▼ 归档

  • 2021年3月
  • 2020年10月

▼ 博客作者

Brad Sexton

查看所有条目
单击此按钮可以刷新整个页面。 用户可以转至“条目列表”区域查看新内容。) 条目列表

-BigFix - Add extra security controls to your environment

Brad Sexton 64576A77-B31D-BF00-0025-86070027DBEC bsexton@hcltechsw.com | ‎ | 967 次访问

 

 

With great power comes great responsibility! While having domain admin rights on your workstation, you do not want to log in to it and use it to check your email or do your day-to-day activities. The same goes with your BigFix Master Operator. Your Master Operator account is needed for configuring your environment; your day-to-day job of patching and pushing out software should be used with a least privileged one.  For details, see my earlier article on how to set up roles and grant your account the access privileges it needs. You can also set additional security controls in your accounts. For details, see the official documentation.

In this article however, I will walk you through the steps for setting up some of these features to keep additional checks in place so they fit your organizational needs. 

  1. On your BigFix Server computer, open BigFix Administration Tool (BESAdmin).

image

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

  1. Enter the site key and password when prompted.

image

 

 

 

 

 

 

 

  1. Open the Advanced Option tab and select Add.

The first setting to add is requireConfirmAction - set the value to true and click OK.

image

 

 

 

 

 

 

 

 

A summary of the action is displayed. Click OK to proceed.

image

 

 

 

 

 

 

 

 

 

 

 

 

disableNmoDynamicTargeting

image

 

 

 

 

 

This action prevents non-master operators (NMO) from targeting dynamically and sending out mass deployments. It only allows them to target either by using a list or by entering the device names manually.

image

 

 

 

 

 

 

 

 

 

loginTimeoutSeconds

image

 

 

 

 

 

 

This forces the operator including master operators to re-authenticate before each action is taken.

image

 

 

 

 

 

 

 

 

 

 

 

 

 

targetBySpecificListWarning

image

 

 

 

 

 

 

This issues a warning to the console operator when they target more machines than a predefined value.

image

 

 

 

 

 

 

 

 

 

 

 

 

 

 

useFourEyesAuthentication

image

 

 

 

 

 

 

  1. Go to roles settings and create an "approver" role and add the operators you want to be able to approve actions.

image

 

 

 

 

 

 

 

  1. Set the operator that you want to be able to force an approval before the actions can be run.

image

 

 

 

 

 

 

 

 

Once this is done, you are prompted to enter the approver's credentials before taking an action.

image

 

 

 

 

 

 

 

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Author

Brad Sexton is a BigFix technical advisor for the mid-Atlantic region. He was a BigFix administrator in a global enterprise for 7 years where he was using BigFix for OSD, Software Deployments, and patching. Brad joined the HCL BigFix team in 2018.

Review and editorial credits

Shivi Sivasubramanian is a senior-level technical author and editor with a demonstrated history of working in the technology industry. A firm believer in the magical power of words, she loves helping the community deliver expressive, minimalist, and user-friendly content. Shivi currently leads a team of information developers in BigFix.

 

 

由 Brad Sexton 64576A77-B31D-BF00-0025-86070027DBEC bsexton@hcltechsw.com 于 修改
  • 添加评论 添加评论
  • 编辑
  • 更多操作 v
  • 隔离此条目
通知其他人
notification

发送电子邮件通知

+

隔离此条目

deleteEntry
duplicateEntry

标记为重复项

  • 上一个条目
  • 主页
  • 下一个条目
“博客条目”的订阅源 | “博客评论”的订阅源 | 此条目评论的订阅源
  • 主页
  • 帮助
  • 书签工具
  • 服务器统计
  • 移动 UI
  • 关于
  • hcl.com 上的 HCL Connections
  • 提交反馈