<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security queries in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841715#M273418</link>
    <description>Tim,&lt;BR /&gt;it's probably down to what you get used to.&lt;BR /&gt;Even if the data is not critical, the machine would still give access to your network.&lt;BR /&gt;I would certainly go ahead with your suggested changes, even only to get the new systems to the standard required in your company.&lt;BR /&gt;May be worhtwhile running a few checks on the systems to ensure they were not compromised. Audit all the users and get them to chnage passwords etc..</description>
    <pubDate>Fri, 11 Aug 2006 03:55:13 GMT</pubDate>
    <dc:creator>Peter Godron</dc:creator>
    <dc:date>2006-08-11T03:55:13Z</dc:date>
    <item>
      <title>Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841712#M273415</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I have been asked to look at 2 HPUX 11 servers in a company we have taken over &amp;amp; have some queries.&lt;BR /&gt;&lt;BR /&gt;1. Neither system is set up as a trusted system with no password ageing etc. Passwords held in encrypted form in /etc/passwd. My own servers are trusted systems since day 1. Am I correct in recommending that they should be trusted.&lt;BR /&gt;&lt;BR /&gt;2. Root should only be able to login at console &amp;amp; not ftp - correct? All users are allowed ftp which I don't agree with. No secure ftp&lt;BR /&gt;There is no Web console.&lt;BR /&gt;&lt;BR /&gt;3. Ignite not being run - this should be run regularly &amp;amp; the files copied to the oposite server. This is what I do on my servers &amp;amp; need to know if this is correct.&lt;BR /&gt;&lt;BR /&gt;4. Finally, I run SysInfo on my servers once a week on the crontab &amp;amp; copy off the output. There is no SysInfo on these servers. Does this need to be downloaded &amp;amp; installed.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Tim&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Aug 2006 03:38:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841712#M273415</guid>
      <dc:creator>Tim O'Connell</dc:creator>
      <dc:date>2006-08-11T03:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841713#M273416</link>
      <description>All correct. go ahead and do that. You may also want to check that ignite versions are latest on these systems.</description>
      <pubDate>Fri, 11 Aug 2006 03:42:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841713#M273416</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2006-08-11T03:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841714#M273417</link>
      <description>Shalom Tim,&lt;BR /&gt;&lt;BR /&gt;So long as you are not using NIS going for trusted systems is a good idea.&lt;BR /&gt;&lt;BR /&gt;Ignite should be run on all systems once a week . If the system has a tape drive, I advocate make_tape_recovery, if not use make_net_recovery to a NFS shared mount point.&lt;BR /&gt;&lt;BR /&gt;I also recommend downloading and installing Bastille and PERL5 from &lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt; in order to make your system more secure.&lt;BR /&gt;&lt;BR /&gt;root should NEVER have ftp access. Its a major security flaw to permit it and because ftp sends paswords back and forth in clear text, its a great way to get your root password hacked.&lt;BR /&gt;&lt;BR /&gt;Secure Shell (software.hp.com) should be used in place of telnet.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 11 Aug 2006 03:52:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841714#M273417</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-08-11T03:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841715#M273418</link>
      <description>Tim,&lt;BR /&gt;it's probably down to what you get used to.&lt;BR /&gt;Even if the data is not critical, the machine would still give access to your network.&lt;BR /&gt;I would certainly go ahead with your suggested changes, even only to get the new systems to the standard required in your company.&lt;BR /&gt;May be worhtwhile running a few checks on the systems to ensure they were not compromised. Audit all the users and get them to chnage passwords etc..</description>
      <pubDate>Fri, 11 Aug 2006 03:55:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841715#M273418</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2006-08-11T03:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841716#M273419</link>
      <description>Hi Tim,&lt;BR /&gt;I agree with the earlier replies, but be a bit careful with question number 1.&lt;BR /&gt;If you are going to Trusted System mode and are running e.g Baan, you can cause quite a lot of trouble for users and admins since some applications do'nt "talk" with the OS/security system,</description>
      <pubDate>Fri, 11 Aug 2006 03:59:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841716#M273419</guid>
      <dc:creator>G Svedvall</dc:creator>
      <dc:date>2006-08-11T03:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841717#M273420</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;Thanks for all the replies. The system is only running Oracle so moving to a trusted system shouldn't be a problem.&lt;BR /&gt;&lt;BR /&gt;Where do I get SysInfo to install&lt;BR /&gt;&lt;BR /&gt;Many Thanks,&lt;BR /&gt;&lt;BR /&gt;Tim</description>
      <pubDate>Fri, 11 Aug 2006 04:11:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841717#M273420</guid>
      <dc:creator>Tim O'Connell</dc:creator>
      <dc:date>2006-08-11T04:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841718#M273421</link>
      <description>Hi Tim, &lt;BR /&gt;&lt;BR /&gt;Here it is : &lt;A href="http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sysinfo-3.3.1/" target="_blank"&gt;http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sysinfo-3.3.1/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Fri, 11 Aug 2006 04:19:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841718#M273421</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-08-11T04:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security queries</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841719#M273422</link>
      <description>Many thanks,&lt;BR /&gt;&lt;BR /&gt;Points assigned&lt;BR /&gt;&lt;BR /&gt;Tim</description>
      <pubDate>Fri, 11 Aug 2006 04:50:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-queries/m-p/3841719#M273422</guid>
      <dc:creator>Tim O'Connell</dc:creator>
      <dc:date>2006-08-11T04:50:25Z</dc:date>
    </item>
  </channel>
</rss>

