User guide

Chapter 2: Security Measures
2-20
Security Measures for Portable-ORB
Portable-ORB can be used with the following products:
Interstage Application Server Enterprise Edition
Interstage Application Server Standard Edition
Interstage Application Server Plus
Unauthorized Access to Resource Files
Portable-ORB service has environment definition files as listed below:
Portable-ORB environment definition file (config) (*1)
Host information file (initial_hosts) (*1)
Initial service file (initial_services) (*1)
*1 For the locations where the files are stored, refer to "Backing Up and Restoring Resources" -
"Outline and Applicable Resources" in Maintenance (Resource Backup) in the Operator's Guide.
These files may be exposed to the threat of unauthorized access from an ill-intentioned person.
To protect these files from this threat, make these files inaccessible by end users. For this purpose, it is
recommended to allow access only by users having administrator authorization (superuser for a Solaris
OE/Linux system, and Administrator for Windows(R) system).
Notes on Communication Data
There is a possible threat that an ill-intentioned person furtively reads communication data between the
server and a user who has proper access permission. Another threat is that the data is altered and
transmitted as the right data.
It is recommended to use SSL encryption to encrypt data for retaining security.