Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

IT Optimize discovery security issue

EcoStruxure IT forum

Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT
  • EcoStruxure IT forum
  • IT Optimize discovery security issue
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Cory_McDonald
Admiral Cory_McDonald Admiral
124
Jef
Admiral Jef Admiral
109
gsterling
Captain gsterling Captain
71
APC_Steve
Captain APC_Steve Captain
62
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Solved Go to Solution
Back to EcoStruxure IT forum
Solved
jzurera
Lt. Commander jzurera
Lt. Commander

Posted: ‎2021-07-28 04:21 AM

0 Likes
7
1670
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-28 04:21 AM

IT Optimize discovery security issue

Hi team,

 

we have a customer with IT Optimize deployed with IT Advisor and his security department has detected an issue in IT Optimize.

 

IT Optimize is trying to connect to a discovered server with the Windows IT Optimize local user, that we used to install IT Optimize in the server. Even when you have discovered the server with an specific user for this server depending on the protocol, IT Optimize is trying to connect with the local user in the server instead the user that we used for the discovery.

 

The customer has deleted the discovered server and also the discovery search, and IT Optimize is still trying to connect to this server.

 

The local user is itouser and the IP of the IT Optimize is 172.20.17.133 in this picture:ito security issue.png

Labels
  • Labels:
  • IT Advisor
  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic

Accepted Solutions
gsterling
Captain gsterling Captain
Captain

Posted: ‎2021-07-30 09:55 AM

0 Likes
1
1611
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-30 09:55 AM

Adding some details for your security team as well.

 

When WMI protocol is used with ITO, the connection is made from the WMI interface on the ITO server to the target server (the discovered server). The connection to the local WMI interface on the ITO server is made with the user specified during the ITO installation, this is the reason that user account must be a windows user with local admin rights and has to be allowed to run as a service. Once connected to the local ITO server, the user makes the remote connection via the WMI interface to the discovered server using the discovery credentials specified. So the credentials used for logon to a discovered server should be the credentials specified in the discovery, the user initiating the connection from the ITO server may show up as the user used to run the ITO services.

 

This might explain why your security team is seeing that user.

 

But, if the discovered server is deleted from ITO, we expect the polling of the discovered server to stop.

 

Regards

 

Greg Sterling

See Answer In Context

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Replies 7
gsterling
Captain gsterling Captain
Captain

Posted: ‎2021-07-28 04:26 AM

0 Likes
4
1666
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-28 04:26 AM

Hello Javier

 

If I may ask, what method did the customer use to delete the asset?

 

I assume they unassociated the server from the device in DCO or ITA, but then did they delete the asset from the unassociated items? If they did, the server should no longer appears in the inventory list on the ITO server (if you browse to https://<ito-server-ip>:8090/ and view the inventory page.

 

Regards

 

Greg Sterling

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

jzurera
Lt. Commander jzurera
Lt. Commander

Posted: ‎2021-07-28 04:39 AM

In response to gsterling
0 Likes
3
1664
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-28 04:39 AM

Hi Greg,

 

the server  xxxxx101 does not appear in the list of discovered servers:ito security issue 2.png

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

gsterling
Captain gsterling Captain
Captain

Posted: ‎2021-07-28 02:24 PM

In response to jzurera
0 Likes
1
1650
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-28 02:24 PM

I will try to test this on Thursday to see if I can replicate the behavior.

 

Which version of ITO are you using?

 

Regards

 

Greg Sterling

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

jzurera
Lt. Commander jzurera
Lt. Commander

Posted: ‎2021-07-29 08:14 AM

In response to gsterling
0 Likes
0
1644
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-29 08:14 AM

Hi Greg,

 

the IT Optimize version is: ITO Server Version 7.5.6.0.999

 

and IT Advisor 9.0.4

 

Regards

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

gsterling
Captain gsterling Captain
Captain

Posted: ‎2021-07-30 09:45 AM

In response to jzurera
0 Likes
0
1612
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-30 09:45 AM

Hello Javier

 

I attempted to duplicate the condition you are reporting and so far have been unable to. When I delete discovered servers from ITO they so far have stopped polling the previously discovered server.

 

The cache/list of servers ITO polls is refreshed when ITO is restarted, if you reboot your ITO server, do the logins the target server stop?

 

Regards

 

Greg Sterling

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

gsterling
Captain gsterling Captain
Captain

Posted: ‎2021-07-30 09:55 AM

0 Likes
1
1612
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-07-30 09:55 AM

Adding some details for your security team as well.

 

When WMI protocol is used with ITO, the connection is made from the WMI interface on the ITO server to the target server (the discovered server). The connection to the local WMI interface on the ITO server is made with the user specified during the ITO installation, this is the reason that user account must be a windows user with local admin rights and has to be allowed to run as a service. Once connected to the local ITO server, the user makes the remote connection via the WMI interface to the discovered server using the discovery credentials specified. So the credentials used for logon to a discovered server should be the credentials specified in the discovery, the user initiating the connection from the ITO server may show up as the user used to run the ITO services.

 

This might explain why your security team is seeing that user.

 

But, if the discovered server is deleted from ITO, we expect the polling of the discovered server to stop.

 

Regards

 

Greg Sterling

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

jzurera
Lt. Commander jzurera
Lt. Commander

Posted: ‎2021-08-19 03:46 AM

In response to gsterling
0 Likes
0
1503
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2021-08-19 03:46 AM

Hi Greg,

 

the customer confirms that the problem was solved 3 weeks ago. Thanks for your support.

 

Regards

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of