Where does TEM store its Trusted Manager authorization information?
For Trusted Manager assignments over Users and Groups, TEM securely stores five control files, TEMAdmin2.TDB, TEMGroup2.TDB, TEMMAP.CFG, GRPQUOTA.TDB, and TEMOPTIONS.INI in the TEMCFG directory. This directory is shared on the network and leverages NT’s native NTFS/Share security model. Only NT/2000 Administrators, TEM Enterprise Managers, and the TEM services should have administrative and access rights. No one else (including Trusted Managers) needs to have ANY access to this directory. For Trusted Manager assignments over computers, services, and shares, TEM uses a secure SQL database. Eventually, all Trusted Manager assignments and permissions will be stored and updated here. The TEM Robot service is a “substitute Domain Administrator” and proxies requests on behalf of the Trusted Managers using the TEM Client. This service may run on any NT/2000 machine in the Domain in which it is managing. It can run on multiple machines in the managed domain(s) for performance, fault tolerance,