Chapter 15: Securing Deployment Solution; Part 1: Deployment Server Accounts - Symantec ALTIRIS DEPLOYMENT SOLUTION 6.9 SP4 - V1.0 Manual

Table of Contents

Advertisement

Chapter 15
Securing Deployment Solution

Part 1: Deployment Server Accounts

Deployment Solution
To effectively manage computers, Altiris® Deployment Solution™ software requires
access beyond the files and database owned by the application. Example: Deployment
Solution requires rights to install software on managed computers and rights to join
computers to a domain during configuration.
The broad range of tasks performed by Deployment Solution enables simplified
management but also introduces a greater need for strong security policies.
This guide walks you through the phases of security planning, including setting access
rights, database security, and securing communications.
This guide is divided into the following parts:
Deployment Server
Accounts
Administrator Accounts
and Role and Scope-
based security
Database Security
Securing
Communication
Appendix A: Agent
Installation Rights
Appendix B: Managing
Task Passwords
Appendix C: Managing
Key-based
Authentication
To run the Deployment services, perform domain tasks, and provide automation access
to the Deployment Share, we recommend creating separate accounts with minimal
privileges to perform each of these tasks. This minimizes security risks while still
allowing Deployment Solution to manage computers.
We recommend creating the following accounts:
Account
Service
Contains instructions to set up the accounts you use to
run Deployment Server services, join domains, and
connect to the Deployment Share in automation.
These security policies control administrator access to
computers, jobs, and settings within the Deployment
Console.
Provides the information you need to secure and control
database access.
Explains how to secure communication between your
Deployment Server and Agent.
Explains the privileges needed to rollout the Deployment
Agent.
Explains how to manage the passwords associated with
specific tasks.
Contains information on backing up authentication keys
and enabling server redirection when using key-based
authentication.
Description
The main account used to run the Deployment services,
manage the database, and mange the Deployment Share.
202

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Altiris deployment solution 6.9 sp4

Table of Contents