Administer > Administer the ITOM Platform > Security > Secure Implementation and Deployment

Secure Implementation and Deployment

This section provides information on implementing and deploying the Suite Management Portal container-based platform in a secure manner.

Technical system landscape

The Suite Management Portal platform is a container that integrates with other Suites. The Suite Management Portal container-based platform is written in Java and JavaScript and Go.

For more information about typical deployment schemes and options, see Overview of the ITOM Platform.

Security in Suite Management Portal container-based platform configurations

The Suite Management Portal platform configurations may be deployed in the following three implementations.

  • Single mode.
  • Distributed mode 1 (one master node and multiple worker nodes).
  • Distributed mode 2 (multiple master nodes and multiple worker nodes).

All of these implementations share the same basic out-of-the-box security configuration options.

  1. In an out-of-the-box default installation, the Transport Layer Security/Secure Socket Layer (TLS/SSL) security is enabled between the browser and the Suite Management Portal platform server by default.
  2. In an out-of-the-box default installation, the Suite Management Portal platform requires users to enter username and password credentials to gain access to the application.

External Authentication

With additional configuration, it is possible to supplement or replace the default authentication & authorization provider for the Suite Management Portal platform by using a variety of industry-standard protocols and tools such as LDAP and Single Sign-On.

Common Security Considerations

The Suite Management Portal platform can only be deployed on supported operating systems.

HPE recommends to follow vendor-provided best practices and security hardening guides for each of the third-party components used in support of your Suite Management Portal platform deployment, which includes Docker, Kubernetes, Vault and Nginx, NFS. Below are some resources that can serve as a starting point for researching these recommended security considerations:

Docker Security Tips

https://www.docker.com/docker-security

Kubernetes Security Tips

http://kubernetes.io/docs/troubleshooting/

Vault Security Tips

https://www.hashicorp.com/security.html

Nginx Security Tips

http://nginx.org/en/security_advisories.html

NFS Security Tips

http://www.cert.org/historical/advisories/