發表文章

目前顯示的是有「tpam」標籤的文章

有哪些TPAM的功能會使用WMI? 為何會用使用49154, 49155 port 連接受管目標主機?

圖片
最近有使用TPAM的客戶,在防火牆端發現TPAM appliance連接到受管目標主機,而連接埠號是 49154 and 49155,進而詢問這個現象的原因。以下對此狀況做一分析與說明。 49154 and 49155  是   Windows Server  內部定義的 RPC dynamic port ,當 TPAM 使用 TCP/135 和受管目標主機初始連接後,接下來會使用 RPC dynamic port 來做後續的連接。 WMI / DCOM from DPA/TPAM will need access to TCP/135 to initiate communication on the target. The subsequent conversation then continues on a random negotiated port. On Windows 2003/XP this would be in the range 1025 - 5000 on Windows 7/Windows 2008 and above : 49152 - 65535. 一般TPAM PPM (Privileged Password Management) 的功能,像是修改作業系統帳號密碼,會使用這些連接埠: Windows Active Dir: TCP/389, TCP/445 Windows, Windows Desktop TCP/445 而當使用下列功能的時候, TPAM 會使用 WMI/DCOM access  target ,沒有強制關閉的方式。 - Managing service account passwords ("Change password for Windows Service started by this account" ticked) - Managing scheduled task passwords ("Change password for Scheduled Tasks started by this account" ticked) - Restarting a service ("Automatically re...

How to, One Identity TPAM - 如何查看進行Account Discovery?

圖片
對於Windows、Unix、Linux和資料庫系統,可以在TPAM中配置 帳戶掃描(Account Discovery) 的功能。 帳戶掃描是在TPAM受管系統上發現帳戶的過程。 如果帳戶在遠端系統系統中被發現或被刪除,這些帳戶可以自動在TPAM中新增或被刪除。 TPAM管理員還可以選擇,在這些帳戶時被發現/刪除時,只發送電子郵件通知而不真的進行在TPAM中新增或刪除帳戶。 帳戶掃描使用account template在TPAM的系統上創建新帳戶。 容易讓我們混淆的是,TPAM系統中有一項功能是 自動掃描(Auto Discovery) 。兩者有什麼不同的地方呢? Auto Discovery是一個進程,先查詢LDAP,AD或數據庫,從TPAM外部容器獲取系統或用戶列表的過程。 此列表用於在TPAM中添加,更新或刪除 受管系統 或 用戶 。 Account Discovery - 用帳戶掃描Profile和functional account在現有TPAM受管系統上發現帳戶的過程。 它們由各自獨立的服務控制,目前不共享任何schedule或process information。 這兩個進程間接交互,因為Auto Discovery可以使用帶有Account Discovery Profile的template來進行新增系統。 帳號掃描 Account Discovery 的設定方式:    1. Create a system template. Select Systems, Accounts, & Collections | Systems | Add System Template from the menu.    2. Add an account to the system template. Select Accounts | Add Account from the menu. Filter for the system template you just created. Select the template from the System tab and click the Det...