How to configure Titan for enhanced security
This article describes the recommended steps to configure Titan family of products (Titan SFTP, Titan MFT, Titan DMZ, Titan Syslog, Titan ICAP, Titan Neo).
When Titan is installed onto a Window or Linux system by default the service runs under the Local System (Windows) or system(Linux) user context. We highly recommend changing this to a specific user that has only the needed privileges and access to specific data folders needed for Titan.
1. Create a new user in your operating system, i.e. "TITANUSER"
2. Give this user Modify permissions to the following folders:
Windows
- C:\ProgramData\SouthRiverTechnologies for files and subdirectories. This is where the admin database is stored
- C:\SrtData - this is where user data is stored by default, you can always configure this to be a UNC path or Azure file storage etc. But make sure the service has access to this folder where data is stored
- C:\SrtLogs - log files are stored here
- Whatever Database your server instance is using, i.e. SQL Server, MySQL, Postgres
Linux
- /var/southriver - this is where admin database and data directories are stored
- Access to the server instance database of choice
-