CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-19
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default using masteradmin considered harmful

At the CPUG Conference 2007, I gave a talk on the Integrity server product and towards the end, chillyjim diplomatically reminded me that I was unwisely logging in as masteradmin. Since it was just a VMware test host and I *almost* never use masteradmin in production, I just shrugged it off.

After thinking about it though, it occurred to me that I'm guilty of setting a bad example. Even on a test system, I should exercise due care and strive to uphold best practices rather than sloth and carelessness. This is especially true when presenting material on the subject to some who might replicate such a mistake in a production environment without the knowledge that it's in poor form.

The proper practice is to create other admin users, preferably individually mapped logins, like alice, bob or jsmith. And with Integrity's role-based administration, it's rather easy to setup.

So please, if you find yourself logging in as masteradmin more than once in a long while, you'll definitely want to switch to user specific logins.

Robert


PS: A big thanks goes out to chillyjim, not just for alerting me to my mistake, but for doing it in such an adroit manner.

Last edited by RobertGraham; 2007-05-19 at 21:32. Reason: fixed bad grammar
Reply With Quote
  #2 (permalink)  
Old 2007-07-02
unclerichard unclerichard is offline
Junior Member
 
Join Date: 2007-05-11
Location: Bristol, UK
Posts: 19
Rep Power: 0
unclerichard has an average reputation (10+)
Default Re: using masteradmin considered harmful

On a different note, I use my own personal login most of the time but always use the masteradmin account to modify any policy changes - purely so that the end userbase cannot see a real name against the policies in the integrity Client. In the past, we have been inundated with calls when IA is suspected of preventing user access to sites.

Cruel - but it does cause end users to follow the prescribed support chain!

Unc
Reply With Quote
  #3 (permalink)  
Old 2007-07-02
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: using masteradmin considered harmful

Another important reason for two masteradmin's is in case a password is forgotten or locked out. This is especially ture with the embedded database.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:37.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0