OpManager Security Recommendations
The Security Recommendations tab serves as a central hub for configuring various security settings in OpManager. It provides options to enhance user access control, enforce secure communication, protect sensitive data, and apply additional security measures.
1. Secure User Access
- Enable Two-Factor Authentication: Adds an extra layer of security by requiring users to verify their identity using an OTP in addition to their password.
- Change default admin password: Recommended to change the default administrator password to a strong and unique one.
- User session timeout: Automatically logs out inactive users after a defined period to prevent unauthorized access. The security score will only be displayed to admin with access to all modules.
2. Secure Communication
- Disable HTTP in OpManager: By default, OpManager allows both HTTP and HTTPS access. To enforce secure access, users can disable HTTP and allow only HTTPS. Note that HTTPS will be enabled by default in Enterprise editions.
- Use a Third-Party SSL certificate: Supports third-party SSL certificates for encrypting communication and securing connections.
- Disable TLSv1 and TLSv1.1 Protocols: Ensures only modern, secure versions (TLS 1.2 and TLS 1.3) are used.
- Disable Weak Ciphers for HTTPS Port: Disables weak cipher suites to enforce strong encryption methods.
- Configure Mail server with SSL/TLS: Recommended to use SSL or TLS encryption for secure email communication.
3. Enforce Data Protection