Skip to main content

Cluster compliance categories

This table describes the cluster security compliance parameters that Unified Manager evaluates, the Lenovo recommendation, and whether the parameter affects the overall determination of the cluster being complaint or not complaint.

Having non-compliant SVMs on a cluster will affect the compliance value for the cluster. So in some cases you may need to fix a security issues with an SVM before your cluster security is seen as compliant.

Note that not every parameter listed below appears for all installations. For example, if you have no peered clusters, or if you have disabled AutoSupport on a cluster, then you will not see the Cluster Peering or AutoSupport HTTPS Transport items in the UI page.

ParameterDescriptionRecommendationAffects Cluster Compliance
Global FIPSIndicates if Global FIPS (Federal Information Processing Standard) 140-2 compliance mode is enabled or disabled. When FIPS is enabled, TLSv1 and SSLv3 are disabled, and only TLSv1.1 and TLSv1.2 are allowed.EnabledYes
TelnetIndicates if Telnet access to the system is enabled or disabled. Lenovo recommends Secure Shell (SSH) for secure remote access.DisabledYes
Insecure SSH SettingsIndicates if SSH uses insecure ciphers, for example ciphers beginning with *cbc.NoYes
Login BannerIndicates if the Login banner is enabled or disabled for users accessing the system.EnabledYes
Cluster PeeringIndicates if communication between peered clusters is encrypted or unencrypted. Encryption must be configured on both the source and destination clusters for this parameter to be considered compliant.EncryptedYes
Network Time ProtocolIndicates if the cluster has one or more configured NTP servers. For redundancy and best service Lenovo recommends that you associate at least three NTP servers with the cluster.ConfiguredYes
OCSPIndicates if there are applications in ONTAP that are not configured with OCSP (Online Certificate Status Protocol) and therefore communications are not encrypted. The non-compliant applications are listed.EnabledNo
Remote Audit LoggingIndicates if log forwarding (Syslog) is encrypted or not encrypted.EncryptedYes
AutoSupport HTTPS TransportIndicates if HTTPS is used as the default transport protocol for sending AutoSupport messages to Lenovo support.EnabledYes
Default Admin UserIndicates if the Default Admin User (built-in) is enabled or disabled. Lenovo recommends locking (disabling) any unneeded built-in accounts.DisabledYes
SAML UsersIndicates if SAML is configured. SAML enables you to configure multi-factor authentication (MFA) as a login method for single sign-on.No RecommendationsNo
Active Directory UsersIndicates if Active Directory is configured. Active Directory and LDAP are the preferred authentication mechanisms for users accessing clusters.No RecommendationsNo
LDAP UsersIndicates if LDAP is configured. Active Directory and LDAP are the preferred authentication mechanisms for users managing clusters over local users.No RecommendationsNo
Certificate UsersIndicates if a certificate user is configured to log into the cluster.No RecommendationsNo
Local UsersIndicates if local users are configured to log into the cluster.No RecommendationsNo