Newsletter   FREE GlobalSpec e-Newsletters
Receive the latest news, trends, and technology relevant to your work.
(See Titles)

Establishing a Management Console

By Brian Wotring
From Host Integrity Monitoring Using Osiris and Samhain

Establishing a Management Console

This examines everything that you need to know to establish a management console. Specifically, we examine the anatomy of the management console, look at its components and features, and discuss how the management console can be configured. Then, we walk through a typical installation. Finally, we configure and do some post-installation tasks.

By now, you should have decided which operating system you will use for your console. In addition, you should have installed the base operating system and locked it down. (For more information see Chapter 4.) The host that you are using as a management console is the most important part of the Osiris system; a compromised management host will render the entire integrity monitoring system useless. Make sure that this host is fully patched and locked down before installing the console software.

Management Console Components

The management console consists of the osirismd executable and a directory of files that are used to store logs, configurations, certificates and passwords, scan data, and more. This section looks at some of the major components that make up the Osiris directory.

Directory Structure

By default, all of the data related to the management console is stored under a single directory ( /usr/local/osiris on UNIX systems and %WindowsRoot%\osiris on Windows) (see Figure 6.6).


Figure 6.6: Directory Structure for the Osiris Management Console

Every host that is monitored by the console has its own directory under the hosts directory (see Figure 6.7).


Figure 6.7: Host Directories
Copyright Syngress Publishing, Inc. 2005 under license agreement with Books24x7

Products & Services
Console consolidation systems are modules that allow multiple operators to access, work and simultaneously monitor several mainframes and PC systems consoles. Learn more about Console Consolidation Systems
Console and consolet enclosures are freestanding structures with a sloped front or top for mounting electric or electronic control components. They protect sensitive equipment such as computer monitors in harsh, wet, dirty, or dusty environments. Search by Specification | Learn more about Console and Consolet Enclosures
Stretch forming equipment produces complex shapes by stretching a metal sheet, plate or extrusion over a form die. Learn more about Stretch Forming Equipment
Network monitoring software is used to monitor network traffic for user-defined parameters. Learn more about Network Monitoring Software
Intercoms are an electronic communications system generally composed of fixed microphone/speaker units connected to a central control device. Learn more about Intercoms

Product Announcements
Rena Systems, Inc. - Inkjet Address Envelope Printers & More
Inkjet Address Printers, Mail Piece Tabbing & Stamping Systems for all size companies from Entry-Level to Floor Model Production systems, RENA Systems has what you need. (read more)
BioCold Environmental, Inc. - Critical Storage
BioCold® offers peace of mind with its complete redundancy temperature systems. Valuable products, testing, or research often require the utmost in system reliability. This type of storage reliability... (read more)
BioCold Environmental, Inc. - Critical Storage - Redundant Systems
BioCold® offers peace of mind with its complete redundancy temperature systems. Valuable products, testing, or research often require the utmost in system reliability. This type of storage reliability... (read more)
SIE Computing Solutions, Inc. - ContolTower Serial I/O & Fabrics
SIE Computing Solutions, Inc. is the industry leader in Backplane design, offering multiple standard and custom solutions based on the following technologies: VPX, VXS, VME64, CompactPCI, AdvancedTCA,... (read more)
Moxa Inc. - RS-232/422/485 terminal server with LAN redundancy
Dual LAN redundancy involves two separate physical networks that connect a PC host to the terminal server. On the CN2600 terminal server, two networks can be connected through two built-in LAN ports. (read more)
Moxa Inc. - IEEE 802.11a/b/g wireless AP/bridge/client
The AWK-3121 can operate as a wireless access point, bridge, or wireless client, and supports IEEE 802.11 a/b/g communication, including the 5 GHz bandwidth. Built-in support for WPA2 and AES offers... (read more)
Psion Teklogix Inc. - Tek Speech
TekSpeech from Psion Teklogix is a speech recognition solution that is an end-to-end solution providing speech-directed interaction between the mobile worker and the host system. Every TekSpeech... (read more)
Dataforth Corporation - Enhanced ReDAQ™ Remote Data Acquisition Software
The enhanced ReDAQ™ software package available from Dataforth provides an integrated solution for test and measurement and data acquisition applications when combined with one or more SCM5B... (read more)

Topics of Interest
Command-Line Interface The Osiris command line is used for all interactions with the management console and indirectly with your monitored hosts. Although used briefly in the last section when... (Read More)
Administering Osiris One of the biggest pitfalls with software security solutions (including Osiris) is that adequate administration is often ignored or the system is misconfigured. After you have... (Read More)
Solutions Fast Track Configuring and Building Osiris Burn the Osiris source to read-only media, and verify the PGP signature before building installer packages. Establish dedicated... (Read More)
Introduction In Chapter 2, this book covered the installation of VMware ESX Server. This chapter goes into further detail regarding the directory structure, configuration files, boot process, and... (Read More)
Introduction Osiris and Samhain are two of the most widely deployed open source host integrity monitoring systems today. This chapter examines how each of these systems work and their respective... (Read More)