More Info > Security > Installation Security > Application Server Security Recommendations

Application Server Security Recommendations

When configuring TLS/SSL on the ITBA Server, keep your Java keystore file in a private directory with restricted access. The keystore is password protected. Although the Java keystore is password protected, it is vulnerable as long as the default value of changeit was not changed.

Note:

  • Always change default passwords.
  • Always use the minimal possible permissions when installing and running ITBA.
Action Permissions Needed for User
Installing/Running ITBA You can install and run with non-root permissions using the sudo command.
Database connection The logon user permissions must be set properly according to the recommendations in the . Do not use a higher level of permissions than required. Do not use the default password when creating the schema.