SPS 6.2 SecurityChecklist
SPS 6.2 SecurityChecklist
Sessions 6.2
Security Checklist
Copyright 2019 One Identity LLC.
ALL RIGHTS RESERVED.
This guide contains proprietary information protected by copyright. The software described in this guide
is furnished under a software license or nondisclosure agreement. This software may be used or copied
only in accordance with the terms of the applicable agreement. No part of this guide may be reproduced
or transmitted in any form or by any means, electronic or mechanical, including photocopying and
recording for any purpose other than the purchaser’s personal use without the written permission of
One Identity LLC .
The information in this document is provided in connection with One Identity products. No license,
express or implied, by estoppel or otherwise, to any intellectual property right is granted by this
document or in connection with the sale of One Identity LLC products. EXCEPT AS SET FORTH IN THE
TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR THIS PRODUCT,
ONE IDENTITY ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR
STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-
INFRINGEMENT. IN NO EVENT SHALL ONE IDENTITY BE LIABLE FOR ANY DIRECT, INDIRECT,
CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT
LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF
INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF
ONE IDENTITY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. One Identity makes no
representations or warranties with respect to the accuracy or completeness of the contents of this
document and reserves the right to make changes to specifications and product descriptions at any
time without notice. One Identity does not make any commitment to update the information
contained in this document.
If you have any questions regarding your potential use of this material, contact:
One Identity LLC.
Attn: LEGAL Dept
4 Polaris Way
Aliso Viejo, CA 92656
Refer to our Web site (http://www.OneIdentity.com) for regional and international office information.
Patents
One Identity is proud of our advanced technology. Patents and pending patents may apply to this
product. For the most current information about applicable patents for this product, please visit our
website at http://www.OneIdentity.com/legal/patents.aspx.
Trademarks
One Identity and the One Identity logo are trademarks and registered trademarks of One Identity
LLC. in the U.S.A. and other countries. For a complete list of One Identity trademarks, please visit
our website at www.OneIdentity.com/legal. All other trademarks are the property of their
respective owners.
Legend
About us 7
Contacting us 7
Technical support resources 7
Encryption-related settings
l One Identity recommends using 2048-bit RSA keys (or stronger).
l Use strong passwords: at least 8 characters that include numbers, letters, special
characters, and capital letters. For local One Identity Safeguard for Privileged
Sessions (SPS) users, require the use of strong passwords (set AAA > Settings >
Minimal password strength to strong). For details, see "Setting password policies
for local users" in the Administration Guide.
l When exporting the configuration of SPS, or creating configuration backups, always
use encryption. Handle the exported data with care, as it contains sensitive
information, including credentials. For details on encrypting the configuration, see
"Encrypting configuration backups with GPG" in the Administration Guide.
l Use every keypair or certificate only for one purpose. Do not reuse cryptographic
keys or certificates (for example, do not use the certificate of the One Identity
Safeguard for Privileged Sessions (SPS) webserver to encrypt audit trails, or the
same keypair for signing and encrypting data).
l Do not use the CBC block cipher mode, or the diffie-hellman-group1-sha1 key
exchange algorithm. For details, see "Supported encryption algorithms" in the
Administration Guide.
l Always encrypt your audit trails to protect sensitive data. For details, see "Encrypting
audit trails" in the Administration Guide.
Appliance access
l Accessing the One Identity Safeguard for Privileged Sessions (SPS) host directly
using SSH is not recommended or supported, except for troubleshooting purposes. In
such case, the One Identity Support Team will give you exact instructions on what to
do to solve the problem.
For security reasons, disable SSH access to SPS when it is not needed. For details,
see "Enabling SSH access to the One Identity Safeguard for Privileged Sessions
(SPS) host" in the Administration Guide.
l Permit administrative access to SPS only from trusted networks. If possible,
monitored connections and administrative access to the SPS web interface should
originate from separate networks.
l Configure SPS to send an alert if a user fails to login to SPS. For details, see the
Login failed alert in "System related traps" in the Administration Guide.
l Configure Disk space fill-up prevention, and configure SPS to send an alert if the
free space on the disks of SPS is low. For details, see "Preventing disk space fill-up"
in the Administration Guide.
About us
One Identity solutions eliminate the complexities and time-consuming processes often
required to govern identities, manage privileged accounts and control access. Our solutions
enhance business agility while addressing your IAM challenges with on-premises, cloud and
hybrid environments.
Contacting us
For sales or other inquiries, visit https://www.oneidentity.com/company/contact-us.aspx
or call +1-800-306-9329.