Server Requirements
Multiple, Load-Balanced Servers
Hitachi ID Group Manager supports multiple, load-balanced servers.
Each server can host multiple Group Manager instances, each with its own users, target systems, features and policies.
Server Platform
Group Manager must be installed on a Windows 2008 or Windows 2008R2 server.
Installing on a Windows server allows Group Manager to leverage client software for most types of target systems, which is available only on the "Wintel" platform. In turn, this makes it possible for Group Manager to manage passwords and accounts on target systems without installing a server-side agent.
The Group Manager server must also be configured with a web server. Since the Group Manager application is implemented as CGI executables, any web server will work. The Group Manager installation program can detect and automatically configure IIS or Apache web servers, but other web servers can be configured manually.
Group Manager is a security application and should be locked down accordingly. Please refer to the Hitachi ID Systems document about hardening Group Manager servers to learn how to do this. In short, most of the native Windows services can and should be removed, leaving a very small attack surface, with exactly one inbound TCP/IP port (443):
- IIS is not required (Apache is a reasonable substitute).
- No ASP, JSP or PHP are used, so these engines should be disabled.
- .NET is not required on the web portal and in most cases can be disabled on IIS.
- No ODBC or DCOM are required inbound, so these services should at least be filtered.
- File sharing should be disabled.
- Remote registry services should be disabled.
- Inbound TCP/IP connections should be firewalled, allowing only port 443 and possibly terminal services (if required for some configuration tasks).
Server Configuration
(1) Each Group Manager server is configured as follows:
- Hardware requirements:
- An Intel or AMD X86 CPU. Multi-core CPUs are supported and leveraged.
- At least 4GB RAM -- 8GB or more is typical for a server.
- At least 100GB disk, preferably configured as RAID for reliability and preferably larger for retention of more historical and log data. More disk is always better, to increase log retention.
- At least one Gigabit Ethernet NIC.
A virtual machine with similar specifications and resources allocated may also be used.
- Operating system:
- Windows 2003 or Windows 2008 (or R2) Server with current service packs.
- 32-bit or 64-bit versions are both acceptable.
- The server should not normally be a domain controller.
- Installed and tested software on the server:
- TCP/IP networking, with a static IP address and DNS name.
- Web server (Apache/Windows or IIS or).
- Client software: web browser, Acrobat reader (to read the manual) native clients for the systems that Group Manager needs to interface with.
- SQL Server client or Oracle client to connect to the Group Manager database. Please note that the SQL or Oracle client must include 32-bit client libraries.
- If the Group Manager database is local (reduces hardware cost; not recommended on a VM), then SQL Server or Oracle Database.
- SSL server certificate, to support HTTPS connections to the web user interface and SOAP API.
In addition to a web server, Group Manager requires a database server. In most environments, the database server software (Microsoft SQL Server or Oracle Database Server) can be installed on the same hardware as the Group Manager software. This reduces hardware cost, eliminates network latency and reduces the security surface of the combined solution.
In large deployments, a separate database server may be required, so as to distribute the processing load between application and data components. In these cases, the database server is typically configured similarly to the application server and co-located with the application.
If Group Manager is installed on a virtual machine, the database should be installed separately, on hardware, with minimum packet latency and maximum bandwidth available between the two.
