Integrating HP Insight Management WBEM (WMI) Providers for Windows with HP System Insight Manager, 4th edition
3
Security
Switching from SNMP-based server management to server management based on WBEM Providers
can help increase system security. If attackers can intercept SNMP packets, they can get the data
carried by SNMP, including system hardware information. Since you can encrypt WBEM, it is less
vulnerable to attacks based on network snooping.
HP WBEM Providers use Windows-based authentication for local and remote access to server
management data. You can control access by using the restrictions in the standard Windows account.
An administrator account has sufficient rights and security group memberships to access the HP
WBEM Providers’ management information for both local and remote access.
For a standard user account, WMI namespace security and Distributed COM User group membership
may affect security when accessing WMI. WMI namespace security settings govern access to WMI
information. You can allow or deny Windows user accounts specific privileges only through WMI
namespace. For more information about namespace security, see “Access to WMI Namespaces” at
http://msdn2.microsoft.com/en-us/library/aa822575.aspx. Another resource is the “HP Insight
Management WBEM Providers User Guide.” It is available at
http://h20000.www2.hp.com/bc/docs/support/SupportManual/c02219794/c02219794.pdf?ju
mpid=reg_R1002_USEN.
Only users who belong to the Distributed COM (DCOM) User group can connect remotely to WMI
and access management information. This group includes administrators by default. You must add
non-administrator users to the Distributed COM Users group for remote WMI connectivity. For more
information, read the Microsoft article “Connecting to WMI on a Remote Computer.” Find it at
http://msdn2.microsoft.com/en-us/library/aa389290.aspx.
HP WBEM Providers deployment and SNMP agent removal
The HP WBEM Providers are independent of SNMP agents. If you currently depend on SNMP to
provide your management infrastructure, you can remove the agents when you install HP WBEM
Providers. On the other hand, you can remove the SNMP agents later because there are no
interdependencies.
Integration with HP SIM
We integrated HP SIM 7.0 or later and HP WBEM Providers for identification, inventory, reporting,
event monitoring, disk thresholding, and status polling.
HP SIM provides many capabilities:
• A mechanism to identify a Windows server that hosts HP WBEM Providers
• A variety of WBEM data on the Systems page that characterizes the managed node
• WBEM indications including subscribing for CIM (Common Interface Model) alerts and user-defined
disk thresholds
• The ability to set disk thresholds from within the WBEM-based System Management Homepage
• A module that keeps status up to date and makes it easy to find an individual component that is
experiencing problems
• WBEM consolidated status (an indicator of overall server health) as a component of Health Status
• A link to the System Management Homepage
• A variety of reports that include inventory and configuration information