Insight Remote Support 7.0.9 Security White Paper

Virtual CAS
The Virtual CAS is provided by HP for free and is the HP preferred method for customers installing CAS functionality within
their network. The Virtual CAS provides enhanced security and management functionality. It is a software-only solution
based on a VMware image of a virtual machine running Ubuntu Server. Virtual CAS features include:
Runs on VMware Server ESX; ESXi or Oracle VM VirtualBox
It can run on the Hosting Device of the HP Insight Remote Support 7.X solution
Based on open source software
An easy-to-use administration web interface
Implements SSH authentication using X.509 certificates
The authentication is compatible with HP’s VeriSign-administered internal Public Key Infrastructure (PKI) (known
internally as HP DigitalBadge)
Certificate Revocation List (CRL) access is available either via file or Online Certificate Status Protocol (OCSP)
Fine-granularity access control customers can specify user level access to targets including TCP ports
Easy-to-use software update mechanism based on apt-get. The virtual CAS will poll the HP Advanced Packaging Tool
repository for software updates and security patches. The customer has full control on how and when these updates
may be applied to the Virtual CAS
Can be used with SSH-Direct or IPSec VPN solutions