<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security hardening hpux 11.23 itanium in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425671#M354971</link>
    <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;No impact to changing ownership on soft links.&lt;BR /&gt;&lt;BR /&gt;Like to see that script.&lt;BR /&gt;&lt;BR /&gt;Try the swverify both ways, my way first then Dennis. If the results are not too verbose post them.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Tue, 26 May 2009 12:07:22 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2009-05-26T12:07:22Z</dc:date>
    <item>
      <title>Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425663#M354963</link>
      <description>their is an oracle process genlcntsh which creates a file called libclntsh.so.10.1. this file is critical to the linking process for  the oracle binaries. when i run the process as root it works, when i run it as oracle i get an error 'Failed to link libclntsh.so.10.1'..&lt;BR /&gt;oracle says this points in the direction of 'security hardening', evidently some module has the wrong read/write/access permission. &lt;BR /&gt;&lt;BR /&gt;i have a second server (backup server) where this linking process works as the user oracle.&lt;BR /&gt;&lt;BR /&gt;how does one go about comparing the access rights on the files between two servers ??</description>
      <pubDate>Mon, 25 May 2009 01:45:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425663#M354963</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-25T01:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425664#M354964</link>
      <description>&lt;!--!*#--&gt;"ls -l"?&lt;BR /&gt;"lsacl"?</description>
      <pubDate>Mon, 25 May 2009 04:14:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425664#M354964</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-05-25T04:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425665#M354965</link>
      <description>&amp;gt;how does one go about comparing the access rights on the files between two servers?&lt;BR /&gt;&lt;BR /&gt;You could use my scripts in the following thread and then compare the generated output script.&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1215123" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1215123&lt;/A&gt;</description>
      <pubDate>Mon, 25 May 2009 04:29:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425665#M354965</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-25T04:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425666#M354966</link>
      <description>swverify -F\* returns illegal option -- *  ??</description>
      <pubDate>Mon, 25 May 2009 16:16:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425666#M354966</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-25T16:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425667#M354967</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;swverify \* &lt;BR /&gt;&lt;BR /&gt;Not what you wrote.&lt;BR /&gt;&lt;BR /&gt;/sbin/init.d/swagentd -r&lt;BR /&gt;&lt;BR /&gt;Try again.&lt;BR /&gt;&lt;BR /&gt;Compare permissions of the libclntsh.so.10.1. library on the good system to the bad and make corrections and try again.&lt;BR /&gt;&lt;BR /&gt;Look at the oracle install logs for other issues.&lt;BR /&gt;&lt;BR /&gt;Check the environment of the install user on both systems for variations.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 25 May 2009 17:50:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425667#M354967</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-05-25T17:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425668#M354968</link>
      <description>&amp;gt;swverify -F\* returns illegal option -- *&lt;BR /&gt;&lt;BR /&gt;You need a space between -F and \*.&lt;BR /&gt;(You might want to leave out the -F first as SEP suggests.)</description>
      <pubDate>Mon, 25 May 2009 23:39:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425668#M354968</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-25T23:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425669#M354969</link>
      <description>dennis... i noticed your chown_script_B.ksh only deals with symbolic links (chown -h), whats the downside (if any) of changing the script to do all files in a particular directory</description>
      <pubDate>Tue, 26 May 2009 11:45:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425669#M354969</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-26T11:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425670#M354970</link>
      <description>what exactly does swverify -F \*   do ??</description>
      <pubDate>Tue, 26 May 2009 12:04:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425670#M354970</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-26T12:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425671#M354971</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;No impact to changing ownership on soft links.&lt;BR /&gt;&lt;BR /&gt;Like to see that script.&lt;BR /&gt;&lt;BR /&gt;Try the swverify both ways, my way first then Dennis. If the results are not too verbose post them.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 26 May 2009 12:07:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425671#M354971</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-05-26T12:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425672#M354972</link>
      <description>steven to see dennis's script go to:&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1215123" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1215123&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;what does the swverify -F \* verify the ownership and permissions against ???</description>
      <pubDate>Tue, 26 May 2009 12:12:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425672#M354972</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-26T12:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425673#M354973</link>
      <description>&amp;gt; when i run the process as root it works, when i run it as oracle i get an error 'Failed to link libclntsh.so.10.1'..&lt;BR /&gt;&lt;BR /&gt;If you ran this as root, it probably has created the library file(s) in the oracle directory tree that are owned by root. So if you run this process again as the oracle user, it will fail because it can not write over any files that are owned by root.&lt;BR /&gt;&lt;BR /&gt;Check the owner and permissions of &lt;BR /&gt;$ORACLE_HOME/lib/libclntsh*&lt;BR /&gt;$ORACLE_HOME/lib32/libclntsh*&lt;BR /&gt;or use a find command to find root owned files in the entire oracle installation directory.&lt;BR /&gt;&lt;BR /&gt;Check in the oracle directory tree for any files that are owned by root and have a date stamp from the time you ran this process as root. &lt;BR /&gt;&lt;BR /&gt;&amp;gt; i have a second server (backup server) where this linking process works as the user oracle &lt;BR /&gt;&lt;BR /&gt;If you did not run this process as root on this second server, my above claim makes even more sense. (Don't run it as root)</description>
      <pubDate>Tue, 26 May 2009 12:31:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425673#M354973</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2009-05-26T12:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425674#M354974</link>
      <description>Hi Donald:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; what does the swverify -F \* verify the ownership and permissions against ???&lt;BR /&gt;&lt;BR /&gt;It examines the IPD (Installed Product Database) or the contents of the '/var/adm/sw/products' directory.  Therein are 'INFO' files (deeper down) that specify the modes, ownership and mtime attributes associated with the installed files.  It is this information that 'swverify' uses to make its comparisons to the actual file attributes.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Tue, 26 May 2009 12:50:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425674#M354974</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2009-05-26T12:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425675#M354975</link>
      <description>&amp;gt;I noticed your chown_script_B.ksh only deals with symbolic links (chown -h), whats the downside (if any) of changing the script to do all files in a particular directory&lt;BR /&gt;&lt;BR /&gt;You don't run the generated script, you just compare the scripts.  It should do all of the files, including symlinks.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;what does the swverify -F \* verify the ownership and permissions against?&lt;BR /&gt;&lt;BR /&gt;The IPD.  Which probably be useless in problems with Oracle.  Note the -F will "fix" the permission issues.</description>
      <pubDate>Tue, 26 May 2009 15:21:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425675#M354975</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-26T15:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425676#M354976</link>
      <description>i ran this process:&lt;BR /&gt;&lt;BR /&gt;chown_script_A.sh /etc | chown_script_B.sh &amp;gt; chown.sh&lt;BR /&gt;&lt;BR /&gt;and the only entries in chown.sh are &lt;BR /&gt;&lt;BR /&gt;chown -h entries...i assumed from looking at &lt;BR /&gt;&lt;BR /&gt;chown_script_B.sh (print "chown -h") that it only picked up symbolic links ..</description>
      <pubDate>Tue, 26 May 2009 17:31:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425676#M354976</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-26T17:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425677#M354977</link>
      <description>&amp;gt;the only entries in chown.sh are&lt;BR /&gt;chown -h entries...&lt;BR /&gt;&lt;BR /&gt;Yes, you then do this on the other system and compare the chown.sh files.  You may have to sort these first:&lt;BR /&gt;chown_script_A.sh /etc | chown_script_B.sh | sort -k4,4 &amp;gt; chown.txt&lt;BR /&gt;&lt;BR /&gt;&amp;gt;I assumed from looking at chown_script_B.sh (print "chown -h") that it only picked up symbolic links&lt;BR /&gt;&lt;BR /&gt;No it gets every "file".  You also need to use:&lt;BR /&gt;chown_script_A.sh /etc | chmod_script_C.sh | sort -k3,3 &amp;gt; chmod.txt&lt;BR /&gt;&lt;BR /&gt;And then compare those.&lt;BR /&gt;In your case, you probably need to look at the oracle filesystem, not /etc.</description>
      <pubDate>Wed, 27 May 2009 08:20:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425677#M354977</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-27T08:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425678#M354978</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt; The script is OK.Follow Dennis Handly's procedure.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Sunny</description>
      <pubDate>Wed, 27 May 2009 08:27:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425678#M354978</guid>
      <dc:creator>Sunny123_1</dc:creator>
      <dc:date>2009-05-27T08:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425679#M354979</link>
      <description>i'm running this script:&lt;BR /&gt;./chown_script_A.ksh /u01/app/oracle/product/10.2.0.4 | ./chmod_apollo.ksh | sort -k4,4 &amp;gt;chmod_oracle_apollo.txt&lt;BR /&gt;&lt;BR /&gt;i must have the syntax wrong because it displays all the files it can't change because they don't exist but nothing is in chmod_oracle_apollo.txt  ???</description>
      <pubDate>Wed, 27 May 2009 15:18:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425679#M354979</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-27T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425680#M354980</link>
      <description>i just realized that all the files are being rejected as not found... if i run the chmod commands individually i don't get errors  ??</description>
      <pubDate>Wed, 27 May 2009 16:24:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425680#M354980</guid>
      <dc:creator>Donald Thaler</dc:creator>
      <dc:date>2009-05-27T16:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425681#M354981</link>
      <description>&amp;gt;I must have the syntax wrong because it displays all the files it can't change because they don't exist but nothing is in chmod_oracle_apollo.txt?&lt;BR /&gt;&amp;gt;if I run the chmod commands individually&lt;BR /&gt;&lt;BR /&gt;To make it clear, the scripts were originally  developed to copy the ownership and permissions from one machine to another.&lt;BR /&gt;&lt;BR /&gt;I'm hijacking the scripts to enable you to do a difference between files on two systems.  To do that, you compare the output file chmod_oracle_apollo.txt with one from the other system.&lt;BR /&gt;&lt;BR /&gt;Or you can toss those scripts and just compare this:&lt;BR /&gt;find $* -xdev -exec ll -d {} + | awk '{ print $9, $1, $3, $4 }' | sort&lt;BR /&gt;&lt;BR /&gt;&amp;gt;but nothing is in chmod_oracle_apollo.txt?&lt;BR /&gt;&lt;BR /&gt;If there is nothing in that file, then we need to debug the pipeline in stages.  Does "chown_script_A.sh /u01/app/oracle/product/10.2.0.4" produce anything?</description>
      <pubDate>Thu, 28 May 2009 06:11:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425681#M354981</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-28T06:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security hardening hpux 11.23 itanium</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425682#M354982</link>
      <description>The script might be altering the PATH causing the commands not to be found.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 28 May 2009 08:13:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-hardening-hpux-11-23-itanium/m-p/4425682#M354982</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-05-28T08:13:15Z</dc:date>
    </item>
  </channel>
</rss>

