
Driver for Linux - Configuration Section Page 70
HBAnyware Security
Introduction
After HBAnyware, which includes the HBAnyware utility and remote server, is installed on a group of
systems, HBAnyware can remotely access and manage the HBAs on any systems in the group. This
may not be a desirable situation, because any system can perform actions such as resetting boards or
downloading firmware.
The HBAnyware security package can be used to control which HBAnyware systems can remotely
access and manage HBAs on other systems in a Fibre Channel network. HBAnyware security is
systems-based, not user-based. Anyone with access to a system that has been granted HBAnyware
client access to remote HBAs can manage those HBAs. Any unsecured system is still remotely
accessible by the HBAnyware client software (HBAnyware utility).
The HBAnyware security software is designed to provide two main security features:
1. Prevent remote HBA management from systems that the adminstrator does not want to have
this capability.
2. Prevent an accidental operation (such as firmware download) on a remote HBA. In this case, the
administrator does not want to have access to HBAs in systems he or she is not responsible for
maintaining.
The first time the HBAnyware Security Configurator is run on a system in an environment where no
security as been configured, the initial Access Control Group (ACG) is created. At this point, only this
system has remote access to the HBAs in the systems in the ACG. They are no longer remotely
accessible from any other system.
Subsequently, additional Access Sub-Groups (ASGs) can be created. This grants systems in the ACG
the ability to remotely access the HBAs of other selected systems in the ACG.
Start the HBAnyware Security Configurator
Prerequisites
Before you can start the HBAnyware Security Configurator, you must have the following items installed
on your system. See the online Installation manual for more information.
• The Emulex driver for Linux
• The HBAnyware and lputil Utilities
• The HBAnyware Security Configurator
Note: Before you start the Configurator, you must make sure that all of the systems that are
part of, or will be part of, the security configuration are online on the Fibre Channel
network so that they receive updates or changes made to the security configuration.
Any system that is already part of the security installation might not run with the
proper security attributes, if updates to the security configuration are made while it is
offline.
Any system that is part of the security installation and that is offline when the
HBAnyware Security Configurator starts will not be available for security configuration
changes even if it is brought online while the Configurator is running.
Kommentare zu diesen Handbüchern