3.2 Data ONTAP (Software) Mgmt - 'httpd.admin.hostsequiv.enable = off'

Information

System Manager is a graphical management interface that enables you to manage most storage system functions through a telnet session, the rsh command, or scripts or configuration files rather than by entering commands at the console. You can also use System Manager to view information about the storage system; its physical storage units, such as adapters, disks, and RAID groups; and its data storage units, such as aggregates, volumes, and LUNs.

Solution

Disable the use of /etc/hosts.equiv for administrative HTTP authentication. If enabled, the authentication of administrative HTTP (for APIs) will use the contents of /etc/hosts.equiv to allow access to the storage controller without the need to provide a password.

See Also

http://media.netapp.com/documents/tr-3649.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(12), CSCv6|9.2

Plugin: NetApp

Control ID: 06d2fb3ccb064bbd3e13478e12ed287d11b0ad2334b6c189839a9359b2bae3aa