Users Guide
86 Ensuring a Secure Dell OpenManage IT Assistant Installation
Ensuring Database Security When Using IT Assistant
If no SQL Server database is detected when IT Assistant is installed, the process installs a copy of
MSDE 2000, which is set to an authentication mode of trusted or Windows only. However, other
applications that may have previously installed MSDE or SQL Server, including previous versions of
IT Assistant, frequently chose either an authentication mode of SQL or mixed mode, which allows
SQL Server to manage its own user IDs and passwords. In the case of early versions of IT Assistant, the
supervisor or account password was set to either null or dell. At a minimum, decrease the exposure to
a network break-in by changing these passwords to strings that correspond to the best practices
mentioned previously. A better option is to change the database authentication mode to trusted or
Windows only.
Running IT Assistant Behind a Firewall
Figure 6-1 illustrates a typical installation in which both IT Assistant and the systems being managed
reside behind a firewall. The firewall denies passage to traffic on specified ports between the protected
network and the rest of the world while still allowing an administrator to communicate freely with both
IT Assistant and the managed system.
Typical security for the system running IT Assistant in an environment behind a firewall includes
the following:
• Use trusted accounts instead of named or mixed for the database.
• Limit user interface connections to a known system.