Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
      • About the DevOps Program
      • DataMiner DevOps Support
  • Downloads
  • More
    • DataMiner Releases & Updates
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

Requirements for DMA to DMA authentication

Solved1.90K views29th June 2022Administrator best practices security
2
Jamie Stutz [SLC] [DevOps Member]1.18K 28th June 2022 0 Comments

We're in the process of hardening DMAs for one of our clients by removing local admin accounts to adhere to security policies set by InfoSec. In a separate Dojo post called, How to Disable Windows Administrator in Production DMS? this seems to be quite doable, but I have a question. Wouter said in the comments:

Hi Bruno, it is a misconception that agents communicate with each other using the Administrator account by default.

The default behavior is that the machines try to authenticate using their system/machine account. This usually works as machines are in the same domain.

Currently each DMA has a local account with the same UN/PW that has local admin rights. In the past I recall we attempted to use a domain account instead of a local admin when installing the DM software and ran into a lot of problems with communications between the DMAs. Unfortunately it's been a while and I don't remember the exact error, but it was something about unauthorized users. I do seem to think by rerunning the installers with the local admin account, it cleared things up.

Based on what I read in the article posted above, it seems we SHOULD NOT have had issues, so I'm trying to figure out what happened to make sure we can avoid that problem when we remove the local admin accounts. We'd like to avoid using connection strings, but I'm unsure what we need to do to make sure the "default behavior" is successful. Are there any requirements we can check, procedures to test or other suggestions prior to removing the local admin accounts just to make sure we don't break anything?

Thanks!

Jamie Stutz [SLC] [DevOps Member] Selected answer as best 29th June 2022

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
3
Gellynck Jens [SLC]2.71K Posted 29th June 2022 3 Comments

Hi Jamie,

First of all, I'm very happy you're hardening your DataMiner System!

The inter-DMA authentication will authenticate using the LocalSystem user, which will only work if the agents are joined to the same domain. If they are not in the same domain, you will have to set up connection strings.

Other than this requirement, I don't expect disabling the Administrator accounts to pose any problems, but I will try this in a testing environment and get back to you with my findings.

Gellynck Jens [SLC] Posted new comment 29th June 2022
Gellynck Jens [SLC] commented 29th June 2022

I’ve tested this (2 machines in the same domain), both have their local Administrator disabled and I was able to set up a DataMiner cluster. I had some issues with NATS but these were unrelated to the Local Administrator account being disabled. Other than this I don’t see any obvious issues

Jamie Stutz [SLC] [DevOps Member] commented 29th June 2022

Thanks Jens! All of the machines are on the same domain, so sounds like we’re good to go. Thanks for testing it out.

Gellynck Jens [SLC] commented 29th June 2022

Feel free to ping me if you would have issues

You are viewing 1 out of 1 answers, click here to view all answers.
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin