Vulnerability Assessment Execution in Virtual Appliance - Identity Suite
search cancel

Vulnerability Assessment Execution in Virtual Appliance - Identity Suite

book

Article ID: 130712

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction

This article outlines the methods and limitations for performing vulnerability assessments on the Identity Suite Virtual Appliance. It identifies compatible user accounts and tool categories for system-level and network-level scanning.

Environment

Virtual Appliance 14.5

Cause

The Virtual Appliance is a pre-packaged environment that restricts direct root access for security reasons. Consequently, vulnerability assessment tools requiring root-level privileges cannot be executed locally on the appliance.

Resolution

To perform a vulnerability assessment on the Virtual Appliance, determine the requirements of the scanning tool and use one of the following methods:

Method 1: Local System Scanners

  1. Ensure the assessment tool does not require root privileges.
  2. Execute the tool using one of the following authorized system accounts:
    • config
    • dsa
    • imps
    • oracle

Method 2: External Network Scanners

  1. Utilize external tools that do not require local installation, such as SSL or HTTP scanners.
  2. Run these tools against the Virtual Appliance from a separate network-connected system, similar to assessments performed on standard servers.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.