/build/static/layout/Breadcrumb_cap_w.png

Security of KACE SMA over the internet

Hello All,

We are planning to make our KACE SMA appliance accessible over the internet to manage mobile devices. I have a couple of questions related to the security of the KACE SMA.

Is there any form of authentication or cert involved during the agent provisioning/installation? Is it possible anyone who knows the URL of our KACE appliance can download the agent from the internet and enrol a random device into our KACE appliance?

Is a database of KACE appliance is encrypted? 

Is it possible to disable the management/admin portal to be accessible over the internet? I think KACE use port 443 to manage the devices and the same port number is used to access admin portal.

Any recommendations or best practices to make the appliance more secure over the internet? 

Thank you


2 Comments   [ + ] Show comments
  • Good question, we are in the process of getting this done so would like to know the answer to this also. - babagee 5 years ago
  • Hey there, this is an old thread but we have now added a security token associated with the msi to restrict connectivity to the appliance. these without a token or incorrect / expired token will join and go into quarantine, then you can delete or allow. - Ozhunna 2 years ago

Answers (3)

Answer Summary:
Posted by: Hobbsy 5 years ago
Red Belt
0

If your KACE box is externally facing, one best practice is much more Asset management related. When disposing of an Asset, in this case, a Device that has the agent installed, you must make sure that the agent is removed, or better still the device is completely wiped before disposing of. Otherwise you may find the device continues to check in to your SMA and consumes a license.

Posted by: Ozhunna 2 years ago
Orange Belt
0

Hey there, this is an old thread but we have now added a security token associated with the msi to restrict connectivity to the appliance. these without a token or incorrect / expired token will join and go into quarantine, then you can delete or allow. 

 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ