12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>WatchGuard</strong> Management Server PassphrasesThe master encryption key is used to encrypt all other passphrases that are on the hard drive of theManagement Server. This prevents a person with access to the hard drive or its archived contents fromgetting the passphrases and using them to get access to other sensitive data on the hard drive.Select and secure the master encryption key carefully. Make sure that the master encryption key and theManagement Server passphrase are not the same.You use the master encryption key when you:• Migrate the Management Server data to a new system• Restore a lost or corrupt master key file• Change the master encryption keyThe master encryption key is not used frequently. We recommend that you write it down and lock it in asecure location.Management Server passphraseThe second passphrase that the Configuration Wizard prompts for is the Management Server passphrase.This passphrase is used frequently by the administrator. You use this passphrase to connect tothe Management Server in <strong>WatchGuard</strong> System Manager.Password and key filesThe Management Server passphrase and all the automatically created passphrases are kept in a passphrasefile. The passphrase data in this file is protected by the master encryption key. The masterencryption key is not kept on the hard drive. An encryption key is created from the master encryptionkey.The default locations for the password file and encryption key are:• C:\Documents and Settings\<strong>WatchGuard</strong>\wgauth\wgauth.ini• C:\Documents and Settings\<strong>WatchGuard</strong>\wgauth\wgauth.keyNote that these files are used by the Management Server software and must not be modified directly byan administrator.Microsoft SysKey utilityThe password file is protected by the master key. This key is protected by an encryption key, which isprotected by the Windows system key.Windows operating systems use a system key to protect the Security Accounts Management (SAM)database. This is a database of the Windows accounts and passwords on the computer. By default, thesystem key data is hidden in the registry. The system is protected, and the system key is created from theregistry during the startup procedure. If you want a more secure system, you can remove the system keydata from the registry so that this sensitive data is not on the system at all.You can use the SysKey utility to:• Move the system key to a floppy disk• Make the administrator type a password at start time• Move the system key from the floppy disk to the systemIf you move the startup key to a floppy disk, then that disk must be inserted in the drive for the systemto start. If you make the administrator type a startup password, the administrator must type in the passwordeach time the system starts.To configure SysKey options, click Start > Run, type syskey, and click OK.198 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!