Use > Server Automation > Manage the Server Agent > View SA Agent information > Agent functionality on managed servers

Agent functionality on managed servers

The SA Agent:

  • Only discovers information about its own managed server and no others.
  • Cannot make changes on a server unless explicitly instructed to do so by the SA core.

SA runs with administrator privileges (root on UNIX servers and Local System on Windows servers), because it performs tasks that require administrator privileges, such as installing patches and rebooting.

The core performs client authentication and checks to see if the presenting certificate belongs to that particular server. Server Automation does this by comparing the certificate to the server’s IP address that is generated when the agent is initially installed. If the certificate is not valid or the originating IP address does not match the IP address stored in the Model Repository, authentication fails and the agent cannot continue communication with Server Automation. If an unauthorized user were able to log on to a managed server with administrator privileges and compromise a server’s security, the user would have only limited access to the following information in the SA core:

  • The server’s hardware inventory (already available to someone logged on with administrator privileges)
  • The server’s software inventory (already available to someone logged on with administrator privileges)
  • The custom attribute information