<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disadvantages of Trusted Systems anymore ? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496825#M364366</link>
    <description>The replacement for TCSEC "orange book" security is Common Criteria Certification:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria" target="_blank"&gt;http://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HP-UX Certifications against this are here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20338.www2.hp.com/hpux11i/cache/532758-0-0-0-121.html" target="_blank"&gt;http://h20338.www2.hp.com/hpux11i/cache/532758-0-0-0-121.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Duncan&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 14 Sep 2009 11:13:32 GMT</pubDate>
    <dc:creator>Duncan Edmonstone</dc:creator>
    <dc:date>2009-09-14T11:13:32Z</dc:date>
    <item>
      <title>Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496820#M364361</link>
      <description>As far as I know following disadvantages of Trusted System, and I am trying to find vulnerable and incompatible issue before go to Trusted Systems for my customer:&lt;BR /&gt;&lt;BR /&gt;1-Incompatible with NIS&lt;BR /&gt;2-Incompatible with that need directly modify /etc/passwd&lt;BR /&gt;&lt;BR /&gt;is there any other issue that anybody experienced ,please let me know.&lt;BR /&gt;Regards.</description>
      <pubDate>Mon, 14 Sep 2009 10:27:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496820#M364361</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-09-14T10:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496821#M364362</link>
      <description>Hi Hakki:&lt;BR /&gt;&lt;BR /&gt;In my mind, the biggest disadvantage is that Trusted Systems are deprecated in 11.31 and will not be supported in a subsequent release.&lt;BR /&gt;&lt;BR /&gt;The '/etc/shadow' password implementation is more consistent with other UNIX/LINUX and is the foundation for a number of evolving security enhancements.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Mon, 14 Sep 2009 10:36:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496821#M364362</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2009-09-14T10:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496822#M364363</link>
      <description>So , can I say that Orange Book (it used to referencing to measure) is about to obsoleting now ?</description>
      <pubDate>Mon, 14 Sep 2009 10:58:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496822#M364363</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-09-14T10:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496823#M364364</link>
      <description>Agree with JRF - most of what needed Trusted Mode in 11.11 can be done in standard mode on 11.31. Even on 11.23 there are optional products to do most of this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=StdModSecExt" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=StdModSecExt&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Setting up new systems with Trusted Mode makes little sense now unless there is something very specific that only Trusted Mode can offer.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Duncan</description>
      <pubDate>Mon, 14 Sep 2009 11:00:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496823#M364364</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2009-09-14T11:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496824#M364365</link>
      <description>So it seems , if somebody like my customer use 11i v1, then it can be considered. But after that not important.</description>
      <pubDate>Mon, 14 Sep 2009 11:13:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496824#M364365</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-09-14T11:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496825#M364366</link>
      <description>The replacement for TCSEC "orange book" security is Common Criteria Certification:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria" target="_blank"&gt;http://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HP-UX Certifications against this are here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20338.www2.hp.com/hpux11i/cache/532758-0-0-0-121.html" target="_blank"&gt;http://h20338.www2.hp.com/hpux11i/cache/532758-0-0-0-121.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Duncan&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 14 Sep 2009 11:13:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496825#M364366</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2009-09-14T11:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496826#M364367</link>
      <description>And if passwords in /etc/passwd are all you are concerned about, even 11.11 can offer a shadow password file in standard mode:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=ShadowPassword" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=ShadowPassword&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Duncan</description>
      <pubDate>Mon, 14 Sep 2009 11:16:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496826#M364367</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2009-09-14T11:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496827#M364368</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;TCB is going away. Better prepare for it.&lt;BR /&gt;It is much better to use Shadow Passwords&lt;BR /&gt;(especially on HP-UX 11.31, which has lot&lt;BR /&gt;of additional features).&lt;BR /&gt;&lt;BR /&gt;One of the bad sides of TCB is that /tcb&lt;BR /&gt;directory structure is root-read only, and&lt;BR /&gt;there are numerous applications that cannot&lt;BR /&gt;get authenticated.&lt;BR /&gt;&lt;BR /&gt;On the other hand, the biggest disadvantage&lt;BR /&gt;of Shadow Passwords on is that it does not&lt;BR /&gt;support passwords longer than eight&lt;BR /&gt;characters.&lt;BR /&gt;&lt;BR /&gt;The new bundles for much longer Shadow &lt;BR /&gt;Password support on HP-UX 11.31 (up to 255 &lt;BR /&gt;characters) is in testing now.&lt;BR /&gt;&lt;BR /&gt;Some parts of HP-UX 11.31 0909 release&lt;BR /&gt;have already been made aware of longer&lt;BR /&gt;password support.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;VK2COT</description>
      <pubDate>Mon, 14 Sep 2009 20:28:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496827#M364368</guid>
      <dc:creator>VK2COT</dc:creator>
      <dc:date>2009-09-14T20:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496828#M364369</link>
      <description>&amp;gt; Setting up new systems with Trusted Mode makes little sense now&lt;BR /&gt;&amp;gt; unless there is something very specific that only Trusted Mode can offer.&lt;BR /&gt;&lt;BR /&gt;Trusted mode does indeed offer very specific protection that is *NOT* available with Shadow passwords on 11.31 servers.  Trusted Mode is the *ONLY* system that enforces password length, complexity, ageing, history, etc policies for the root user account.  &lt;BR /&gt;&lt;BR /&gt;With Shadow passwords the password length, complexity, ageing, history policies specified in the /etc/default/security file do *NOT* apply to the root user account - they only apply when a non-root user changes a password. As a result the root user can bypass these policies when changing the password for itself *AND* for other users - the root user can even set passwords to null!!&lt;BR /&gt;&lt;BR /&gt;Due to our security requirements we'll be sticking with Trusted Mode for the foreseeable future!!&lt;BR /&gt;&lt;BR /&gt;Kathy</description>
      <pubDate>Thu, 24 Sep 2009 00:30:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496828#M364369</guid>
      <dc:creator>KathyL1</dc:creator>
      <dc:date>2009-09-24T00:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496829#M364370</link>
      <description>&amp;gt; 1-Incompatible with NIS&lt;BR /&gt; &lt;BR /&gt;For good reason. NIS is an archaic password system that broadcasts the passwords all over the network. It was probably useful in the days before the Internet but no auditor would allow NIS in a secure environment. NIS+ is a better choice but not many OS's can use it. LDAP is the more common method for multi-platform authentication.&lt;BR /&gt; &lt;BR /&gt;&amp;gt; 2-Incompatible with that need directly modify /etc/passwd&lt;BR /&gt;  &lt;BR /&gt;Also a very good feature. No program should ever, ever be allowed to modify the passwd file that is not part of the OS.&lt;BR /&gt; &lt;BR /&gt;&amp;gt; One of the bad sides of TCB is that /tcb&lt;BR /&gt;directory structure is root-read only, and&lt;BR /&gt;there are numerous applications that cannot&lt;BR /&gt;get authenticated.&lt;BR /&gt; &lt;BR /&gt;Actually, I consider /tcb root-read only is a very great benefit. The numerous applications are dinosaurs that were written before industry standard PAM interfaces became available, or worse, these are new programs written by programmers that need to go back to changing tapes. &lt;BR /&gt; &lt;BR /&gt;Trusted is still a supported security method for all current versions of HP-UX and I'll be recommending it for 11.31 systems. Since 11.31 will be around for a few years, I'll be waiting for a replacement that actually improves on Trusted features.</description>
      <pubDate>Thu, 01 Oct 2009 01:22:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496829#M364370</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2009-10-01T01:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496830#M364371</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Shadow passwords, available on &lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt; are probably the way to go.&lt;BR /&gt;&lt;BR /&gt;I've noticed an underlying trend to be a little more Linux like and this would make HP-UX easier to work with with the larger, Linux crowd.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 01 Oct 2009 02:25:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496830#M364371</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-10-01T02:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Disadvantages of Trusted Systems anymore ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496831#M364372</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;While there is no doubt that TCB has excellent&lt;BR /&gt;features and works well, it is a fact that&lt;BR /&gt;HP, for better or worse, decided to retire&lt;BR /&gt;it in the future release.&lt;BR /&gt;&lt;BR /&gt;As an alternative, many enhancements to&lt;BR /&gt;Shadow passwords were added.&lt;BR /&gt;&lt;BR /&gt;Just recently, I tested the new bundles for &lt;BR /&gt;much longer Shadow Password support on HP-UX 11.31.&lt;BR /&gt;&lt;BR /&gt;There is also an enhancement request&lt;BR /&gt;QXCR1000970986 to apply password policies on&lt;BR /&gt;the root user.&lt;BR /&gt;&lt;BR /&gt;Overall, whether we liked TCB or not (personally, I was very fond of it),&lt;BR /&gt;we need to move on :)&lt;BR /&gt;&lt;BR /&gt;As far as "old" applications that had&lt;BR /&gt;problems with TCB due to permissions -&lt;BR /&gt;sadly, that is still the case. I have number&lt;BR /&gt;of customers who use weird applications&lt;BR /&gt;and TCB is making it very difficult.&lt;BR /&gt;Telling them to change the application design&lt;BR /&gt;did not help much because when a customer is,&lt;BR /&gt;say, a Fortune-500 company, they do not care&lt;BR /&gt;what the technical people say most of the&lt;BR /&gt;time. Quite a few companies typically&lt;BR /&gt;learn only when a disaster strikes and&lt;BR /&gt;the IT best practices are meaningless&lt;BR /&gt;in that case.&lt;BR /&gt;&lt;BR /&gt;If only shareholders knew what kind of companies they support sometimes!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;VK2COT</description>
      <pubDate>Thu, 01 Oct 2009 04:41:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disadvantages-of-trusted-systems-anymore/m-p/4496831#M364372</guid>
      <dc:creator>VK2COT</dc:creator>
      <dc:date>2009-10-01T04:41:18Z</dc:date>
    </item>
  </channel>
</rss>

