<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting on security settings in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409104#M202235</link>
    <description>passwd -sa gets you some dat.&lt;BR /&gt;&lt;BR /&gt;I'm attaching a utility script that has lots of code snippets in it, most commented. There are lots of things you can change or merely report on with this script.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Wed, 27 Oct 2004 09:21:58 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-10-27T09:21:58Z</dc:date>
    <item>
      <title>Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409103#M202234</link>
      <description>Hi,&lt;BR /&gt;Does anyone know of a way to report on security settings (such as password expiration). We have many trusted systems. Auditing wants a listing of all of the security settings for each server. The only way that I can find to get this information is to do screen prints of SAM's security panels. &lt;BR /&gt;Thanks for any thoughts on this. &lt;BR /&gt;Karen</description>
      <pubDate>Wed, 27 Oct 2004 09:08:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409103#M202234</guid>
      <dc:creator>Karen Elrod</dc:creator>
      <dc:date>2004-10-27T09:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409104#M202235</link>
      <description>passwd -sa gets you some dat.&lt;BR /&gt;&lt;BR /&gt;I'm attaching a utility script that has lots of code snippets in it, most commented. There are lots of things you can change or merely report on with this script.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 27 Oct 2004 09:21:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409104#M202235</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-10-27T09:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409105#M202236</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Take a look at the 'logins' command.  If you give it the '-x' option it will display extended information, including password aging data.&lt;BR /&gt;&lt;BR /&gt;JP&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Oct 2004 09:24:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409105#M202236</guid>
      <dc:creator>John Poff</dc:creator>
      <dc:date>2004-10-27T09:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409106#M202237</link>
      <description>Did you look at the commands - getprpw, modprpw, getprdef and modprdef.&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/gerprpw "user_name" Will give you the details about a user and related settings for the user.&lt;BR /&gt;The default settings go under /tcp/auth/files/default&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Wed, 27 Oct 2004 09:30:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409106#M202237</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2004-10-27T09:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409107#M202238</link>
      <description>Another tool to look at is System Health Check.&lt;BR /&gt;&lt;BR /&gt;The Lite report is free as is the software:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=SHCBASE01" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=SHCBASE01&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Example of what it finds:&lt;BR /&gt;&lt;BR /&gt;Security&lt;BR /&gt; &lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt; &lt;BR /&gt;No. Priority # Found Problems Description &lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt; &lt;BR /&gt;1 H 6 User's home directory is writable by others. &lt;BR /&gt;2 H 1 World-writable directories allow other users than owner to modify/delete files. &lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt; &lt;BR /&gt;1 M 10 The cron daemon can be used by other users, besides root. &lt;BR /&gt;2 M 6 The at command can be used by other users, besides root. &lt;BR /&gt;3 M 1 The system parameter executable_stack differs from recommended. &lt;BR /&gt;4 M 1 The security defaults configuration file does not exist. &lt;BR /&gt;5 M 1 The number of concurrent sessions per user exceeds threshold. &lt;BR /&gt;6 M 1 On missing home directory, users are logged in to '/'. &lt;BR /&gt;7 M 1 Password history depth is below threshold. &lt;BR /&gt;8 M 1 su command usage is not restricted. &lt;BR /&gt;9 M 1 Password aging is not implemented. &lt;BR /&gt;10 M 8 .rhosts file detected in a user's home directory. &lt;BR /&gt;11 M 1 Bad logins pattern may indicate a security breach attempt. &lt;BR /&gt;12 M 1 Ownership manipulation command usage is not restricted. &lt;BR /&gt;13 M 7 .netrc files found. &lt;BR /&gt;14 M 4 External input may cause security problems on some directories. &lt;BR /&gt;15 M 2 PATH contains directories writable by others. &lt;BR /&gt;&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt; &lt;BR /&gt;1 L 1 Optional trusted system functionality is not enabled. &lt;BR /&gt;2 L 1 Internet services access is not restricted. &lt;BR /&gt;3 L 1 Connection logging is not enabled. &lt;BR /&gt;4 L 1 Root access not restricted. &lt;BR /&gt;5 L 1 The /etc/ftpd/ftpusers file does not exist. &lt;BR /&gt;6 L 1 Ftp configuration file does not exist. &lt;BR /&gt;7 L 11 Some enabled daemons/network services could present a security problem. &lt;BR /&gt;8 L 1 Running sendmail may present a security problem. &lt;BR /&gt;9 L 1 The system grants unrestricted community access via /etc/SnmpdAgent.d/snmpd.conf. &lt;BR /&gt;10 L 8 Network tunables differ from recommended. &lt;BR /&gt;11 L 49 Filesystem may allow SUID program execution. &lt;BR /&gt;12 L 1 Security Patch Check is not installed. &lt;BR /&gt;13 L 1 Bastille is not installed. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff</description>
      <pubDate>Wed, 27 Oct 2004 09:43:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409107#M202238</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2004-10-27T09:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409108#M202239</link>
      <description>getprpw is of use in this case. &lt;BR /&gt;&lt;BR /&gt;/usr/lbin/getprpw -m exptm,spwchg sys something like this shall be able to help you out..&lt;BR /&gt;&lt;BR /&gt;just go through the set of commands..&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Prashant</description>
      <pubDate>Wed, 27 Oct 2004 09:46:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409108#M202239</guid>
      <dc:creator>Prashant Zanwar_4</dc:creator>
      <dc:date>2004-10-27T09:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on security settings</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409109#M202240</link>
      <description>Thanks for all of the help. The information is just what I was looking for.&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Oct 2004 12:34:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/reporting-on-security-settings/m-p/3409109#M202240</guid>
      <dc:creator>Karen Elrod</dc:creator>
      <dc:date>2004-10-27T12:34:40Z</dc:date>
    </item>
  </channel>
</rss>

