Security Policies

The security policy is defined by entries made in security policy tables. A Site Policy table is required for each major Control-M component in zone 2 and 3 (Control-M/EM, Control-M/Server, and Control-M/Agent). The entries in these Site Policy tables provide the basic framework for the Control-M site security policy. Additions and modifications to the Site Policy, if needed, are defined in optional Application Policy tables for various Control-M functions. Entries in these tables add to and supersede the entries in the Site Policy tables.

On UNIX hosts, the security policy tables are contained in PLC (file extension *.plc) files. On Windows hosts, these tables are contained in the Windows registry.

SSL communication policy is based on variable value pairs, called attributes, that are stored in Policy Tables. Each UNIX stanza (or Microsoft Windows registry key) contains appropriate attributes. Some attributes do not apply to certain functions, some do not apply to certain security levels, and some cannot be changed.

A security policy is implemented by assigning values to the attribute variables described in the Security policy table referred to in Security Policy Settings. Default policy values for each major Control-M component are specified in a component-specific site.plc file (UNIX) or site registry hive (Windows).

After a network communication connection is established, the profile for that connection is obtained from variables in the PLC files (UNIX) or registry (Windows), which are described in the following topics:

Changes to the key database, key database password, and security policy do not take effect until you recycle the relevant Control-M/EM, Control-M/Server, or Agent components.

Security Policy Settings

The following table describes the Control-M component security policy settings, which are located in UNIX PLC files and Windows registry, as described in UNIX Security Policies and Windows Security Policies. You must update these settings to configure the security policy.

Setting

Description

security_level

Defines one of the following security levels:

  • 1: Encryption only

  • 2: Encryption and presence of valid certificate on the server (with no server authentication)

  • 3: Server authentication

  • 4: Client and server authentication

For more information, see Security Levels.

bindir

Defines the full path to the sub-directory that contains the dynamically loaded security binary modules

C:\Program Files\BMC Software\Control-M Server\ctm_server\exe

bindir64

Defines the full path to the binary directory for a 64-bit host.

C:\Program Files\BMC Software\Control-M Server\ctm_server\exe

sksdir

Defines the full path to a security keystore read/write sub-directory where Control-M encrypted keys are stored.

C:\Program Files\BMC Software\Control-M Server\ctm_server\data\SSL\cert

securitydir

Defines the full path to a read-only sub-directory where PKCS #12 keystoresClosed A Public-Key Cryptography Standards (PKCS) #12 keystore is a password-protected, encrypted file that contains a private key, its matching SSL/TLS certificate, and optionally a certificate chain of intermediate and root Certificate Authority (CA) certificates. Control-M components use this keystore to authenticate each other and encrypt the data that they exchange over SSL/TLS, which protects workload data in transit and makes sure that each component connects only to trusted components. and PEM key files.

C:\Program Files\BMC Software\Control-M Server\ctm_server\data\SSL\cert

keyfile

Defines the pathname of the component keystore

C:\Program Files\BMC Software\Control-M Server\ctm_server\data\SSL\cert\ctmkeystore.p12

identity

Defines a key pair label in a key database.

Valid Values:

  • CADN

  • CODN

  • NSDN

  • AGDN

logdir

Defines the full path to a sub-directory that contains the log file.

C:\Program Files\BMC Software\Control-M Server\ctm_server\data\SSL\log

loglevel

Defines one or more of the following values, which must be separated by commas:

  • ERROR

  • WARNING

  • INFO

  • TRACE

logfile

Defines the log file filename.

gtw_ssl.log

provider_options

Determines the SSL protocol(s) and cipher(s) that will be used for each protocol.

provider_options=SSLProtocol=TLS1_2,TLSCipherSuite =<ciphers list>

All SHA256 ciphers can only be used with the TLS1_2 protocol.