Read me
file:///T|/htdocs/SOFTWARE/svradmin/5.2/en/readme/readme_sa.txt[10/23/2012 1:34:18 PM]
displayed. The following warnings have been investigated by Dell
engineering and are determined to be "false positives"
(invalid security warnings) that you can safely ignore:
* "The Web server on 1311 allows scripts to read sensitive
configuration and / or XML files." Dell has determined that this
warning is a false positive.
* "The Web server on 1311 allows to delete " / " which implies that
the Web server will allow a remote user to delete the files in
root on the server." Dell has determined that this warning is a
false positive.
* "The Web server on 1311 might be susceptible to a 'WWW Infinite
Request' attack." Dell has determined that this warning is a false
positive.
* "It is possible to make the remote thttpd server execute arbitrary
code by sending a request like: GET If-Modified-Since:AAA[...]AAAA
Solution: If you are using thttpd, upgrade to version 2.0. If you
are not, then contact your vendor and ask for a patch, or change
your Web server. CVE on this one is CAN-2000-0359". Dell has
determined that this warning is a false positive.
* Enabling Integrated Windows Authentication in Internet Explorer
is not required to activate the Single Sign-On feature.
* Server Administrator security settings are not applicable for Active
Directory users. Active Directory users with read-only login can
access Server Administrator, even after access is blocked in the
preferences page of Server Administrator.
* Dell SNMP MIB Files for PowerEdge Systems
Dell SNMP MIB files for PowerEdge systems allow customers to obtain
and verify information provided by supported software agents. The
current MIB files supported by PowerEdge software agents are located
at "\support\mib" on the "Systems Management Consoles" CD.
NOTE: A MIB-II-compliant, SNMP-supported network management station
is required to compile and browse MIB files.
* OpenManage support for Encrypting File System
To improve security, Microsoft provides the capability to encrypt
files using Encrypting File System (EFS). Note that Server
Administrator will not function if its dependent files are encrypted.
======================================================================
NOTES FOR THE INSTRUMENTATION SERVICE
======================================================================
* On certain systems, user-defined thresholds set under Server
Administrator become the default thresholds after uninstalling
Server Administrator.
After you change the threshold value of a probe on certain systems