Chapter 1. Configuring the SGI Internet Server for E-commerce

The SGI Internet Server for e-commerce is a completely integrated solution based on the SGI thin-server platform, the Mercantec SoftCart e-commerce software, the SSL-enabled Apache 1.3.14 web server, and the software set known as the Internet Server Environment. The SGI Internet Server for e-commerce combines the convenience of an appliance with the flexibility, features, and full support of a commercial-grade virtual storefront and e-commerce system.

The SGI Internet Server for e-commerce offers the following:


Note: You should read through this document first before completing the steps in the guide provided with your SGI Internet Server for e-commerce.

This chapter covers the following:

What Do I Need to Do?

The following is an overview of the tasks required to use your SGI server.


Note: Steps 9 and 11 below, Bastille Linux and Linuxconf HTTP access, are optional but recommended.


  1. Review and sign Mercantec, Inc.'s license agreement. See “Mercantec SoftCart License Agreement”.

  2. Unpack the hardware. Check for damage and completeness.

  3. Read through this document and the hardware documentation provided to understand the requirements.

  4. Understand the vendor recommendations:

  5. Install the hardware according to the directions in the hardware documentation:

  6. Fill out the following worksheets:

  7. Power on the SGI server and log in as root.

  8. The system will boot to multiuser mode and Linuxconf will be automatically invoked. You will supply the information from Appendix B, “Network Connectivity Worksheet”. For more information, see Chapter 3, “Configuring the Network”.


    Note: You must enter all of the information for this step or the Bastille Linux step will fail.


  9. Use the Bastille Linux hardening script to lock down the SGI server. See Chapter 4, “SGI Server Lockdown Using Bastille Linux”. This step is optional but recommended.

  10. Reboot the SGI server.

  11. Enable Linuxconf HTTP access. See Chapter 5, “Enabling HTTP Access for Linuxconf Administration”. This step is optional but recommended for ease of use only if you restrict access to a private network port.

  12. Connect serial consoles if you did not already do this in step 4. See “Serial Console Access” in Chapter 2.

  13. Log on using the serial console and the new root password.

  14. Ensure that your SGI server is accessible on the preproduction network (but not yet in production).

  15. Point your browser to the Web administration graphical user interface (GUI) using the following URL, where hostname is the name of the SGI server:

    http://hostname/sgi-iserver/

    Use user iseadmin and password iseadmin. For more information, see Chapter 6, “Web Administration GUI”.

  16. Use the GUI to configure additional features, such as using Tripwire intrusion detection software. For information about these tasks, see the SGI Internet Server for E-commerce Administrator's Guide.

  17. Connect the SGI server into your production environment.

  18. Obtain an X.509 Digital Certificate from a Certificate Authority. See the SGI Internet Server for E-commerce Administrator's Guide.

Mercantec SoftCart License Agreement

To provision Mercantec SoftCart stores, you must review and sign Mercantec, Inc.'s Hosting and Distribution License Agreement. Fax the signed copy to Mercantec at 630-305-6065.

After Mercantec registers you into the system, Mercantec will provide a contract ID and activation code to start SoftCart.

If you have questions regarding the agreement or Mercantec SoftCart software, please contact Mercantec directly at 630-305-3200.

Vendor Recommendations

This section contains information about hardware that is specific to the SGI Internet Server for e-commerce:

Mercantec SoftCart Software

Included in this package is the Mercantec SoftCart e-commerce software, version 5.1.4 for Linux RedHat 6.2. Mercantec SoftCart is considered one of the most popular e-commerce solutions on the market today because of its reputation for ease of use, unparalleled security, proven reliability, open architecture, and worldwide adaptability. Out of the box, SoftCart provides merchants with an easy to use StoreBuilder Wizard that walks new merchants through the required steps of setting up a viable e-commerce storefront.

Mercantec's award-winning SoftCart line of e-commerce enabling software is targeted primarily at small- to medium-sized merchants that are hosted by service providers and have stores between 10 and 1,000,000 products.

Electronic copies of the following SoftCart manuals are provided as links from the Web administration GUI Documentation page:

  • Mercantec SoftCart User's Guide

  • Mercantec SoftCart Technical Reference Guide

  • Mercantec SoftCart Update Guide 5.1

  • Mercantec SoftCart CyberCash Integration Module User's Guide

  • Merchant Reports and Tools

  • Mercantec SoftCart QBLink Module User's Guide

  • Mercantec SoftCart Drop-Ship Module User's Guide

  • Mercantec SoftCart Template Guide for Web Designers

Security Policies

You must know the corporate security policy for systems and applications. If you do not have a policy, you should consider establishing one. See “Network Port Use Security Policy”.

You should establish a security policy that specifies how domain name service (DNS) names for secondary network interfaces are derived from the basic hostname. In particular, private network interfaces should be readily identified as such by a standard prefix or suffix.

The basic hostname should be associated with the public interface on which incoming requests are received. If you have multiple public interfaces, your network architecture may call for giving the default gateway interface a derived name.

Network Port Use Security Policy

To simplify the integration of new systems into your network architecture, you should do the following before plugging in any network cables:

  • Establish a security policy that defines how port names should be mapped to untrusted (public) and trusted (private) networks.

    Apply the policy consistently when cabling up all of your servers -- regardless of vendor -- to your network equipment (this equipment is not included in the SGI server). Doing so greatly reduces the risk of accidental misconfiguration, including the opening up of security holes in your production environment.

  • If you have only one interface, it will be named eth0. If your architecture calls for a private network, you should reserve the name eth1 for that private network, irrespective of its physical location. Ports eth0, eth2, and so on, may be used for public networks.

    For a front-end server, the outbound traffic will typically be to an untrusted network like the Internet; therefore, you should use port eth0 as your default gateway interface.

  • If you must use eth1 for a public interface, you should mark the exception clearly in the following places:

    • Affected name tag

    • /etc/motd file on that system

    • Diagrams of your production network operations center network architecture

    Alternatively, you can choose to purchase network adapters such that eth1 need not be used at all. If the port physically exists but there are security reasons why it should not be used on that system, the port should be covered up with tape (not included).


Note: An SGI server that has a connection to a public network, or communicates with systems or applications that run on a public network, should implement an IP filtering tool to increase security. Therefore, you should run the Bastille Linux script when prompted.

You may also wish to lockdown other systems at your site using Bastille Linux. You can copy the Bastille Linux software from the CD-ROM set or download the latest copy from the Bastille Web site. However, your license does not permit you to copy the entire package to a non SGI server.


Support

For SGI Linux support services, see http://support.sgi.com/linux.

General Product Feedback

For general feedback (not support), see:

http://www.sgi.com/cgi-bin/feedback/

For marketing information, see:

http://www.sgi.com/solutions/broadband/sgi_internet.html