<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Level Associated with Traditional HPUX installation in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732545#M65783</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The easiest variation from vanilla HP-UX is of course the move to trusted system.&lt;BR /&gt;&lt;BR /&gt;But many more changes may be made to ensure a greater security.&lt;BR /&gt;&lt;BR /&gt;This document clearly highlights obvious changes.&lt;BR /&gt;&lt;A href="http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/building_a_bastion_host.pdf" target="_blank"&gt;http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/building_a_bastion_host.pdf&lt;/A&gt;&lt;BR /&gt;Excellent read!&lt;BR /&gt;&lt;BR /&gt;Glenn</description>
    <pubDate>Wed, 29 May 2002 12:14:25 GMT</pubDate>
    <dc:creator>Glenn L. Stewart</dc:creator>
    <dc:date>2002-05-29T12:14:25Z</dc:date>
    <item>
      <title>Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732538#M65776</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt; Can someone tell me what is the security level associated with Traditional HP UX installation? Is there any utility for assessing the security levels of HPUX systems?&lt;BR /&gt;With trusted system, the level is known as C2 level.Is there any level or standard like this for normal HPUX installation?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks and Regds,&lt;BR /&gt;&lt;BR /&gt;Abdul Salam</description>
      <pubDate>Tue, 28 May 2002 12:02:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732538#M65776</guid>
      <dc:creator>Abdul Salam H S_1</dc:creator>
      <dc:date>2002-05-28T12:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732539#M65777</link>
      <description>Standard UNIX is C1</description>
      <pubDate>Tue, 28 May 2002 12:10:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732539#M65777</guid>
      <dc:creator>Sebastian Galeski_1</dc:creator>
      <dc:date>2002-05-28T12:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732540#M65778</link>
      <description>I dont think there is any security level associated with a default HP-UX installation. Its basically not very secure at all.&lt;BR /&gt;&lt;BR /&gt;If you convert to a trusted system it does NOT make your server C2 security compliant. All youve done is adopt part of the C2 security requirements - only those for password control. A truly C2 compliant server would have encrypted network connections and lots of other goodies (ssh, nfs over ssh etc.)&lt;BR /&gt;</description>
      <pubDate>Tue, 28 May 2002 12:14:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732540#M65778</guid>
      <dc:creator>Stefan Farrelly</dc:creator>
      <dc:date>2002-05-28T12:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732541#M65779</link>
      <description>Most security experts would define a cold install of HP-UX as un-secure.  There are several missing features (like umask), almost every service is turned on by default and many directories and files have open permissions. These will not be fixed by converting to C2 (Trusted). You still need to shutdown the majority of network services and ideally install IDS/9000 (for 11.0 and higher). Also get a copy of the book "HP-UX 11i Security" by Chris Wong.</description>
      <pubDate>Tue, 28 May 2002 12:18:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732541#M65779</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2002-05-28T12:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732542#M65780</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Center for Internet Security has a level 1 (not TCSEC) security benchmark for HP-UX 10.20, 11.00 and 11.11:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisecurity.org/bench_HPUX.html" target="_blank"&gt;http://www.cisecurity.org/bench_HPUX.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;To comply with TCSEC Orange Book C2 security, you need to convert your server to trusted (TCB). &lt;BR /&gt;&lt;BR /&gt;To comply to TCSEC B-level security, you should be looking at HP's VirtualVault.&lt;BR /&gt;&lt;BR /&gt;"Virtualvault trusted Web server platform is built upon a trusted operating system that incorporates tough B-level Department of Defense Trusted Computer System Standards (TCSEC) features."&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.hp.com/security/products/virtualvault/papers/brief_4.0/" target="_blank"&gt;http://www.hp.com/security/products/virtualvault/papers/brief_4.0/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Tue, 28 May 2002 13:05:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732542#M65780</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2002-05-28T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732543#M65781</link>
      <description>Salam,&lt;BR /&gt;&lt;BR /&gt;actually as long as HP-UX stores the (encrypted) passwords visible for everybody in "/etc/passwd" it belongs to the TCSEC category "D" (="minimal security", read: none!)!&lt;BR /&gt;For that reason do so many other vendors make use of the not-public-readable "/etc/shadow" store for passwords...&lt;BR /&gt;&lt;BR /&gt;Just my $0.02,&lt;BR /&gt;Wodisch&lt;BR /&gt;</description>
      <pubDate>Tue, 28 May 2002 17:02:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732543#M65781</guid>
      <dc:creator>Wodisch</dc:creator>
      <dc:date>2002-05-28T17:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732544#M65782</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Standard HP-UX is not at TCSEC level D. It is at TCSEC level C1 because it complies with security features such as "Identification and Authentication" as well as "Discretionary Access Controls" etc. &lt;BR /&gt;&lt;BR /&gt;An example of an OS at TCSEC level D is MS-DOS i.e. it is an OS with no knowledge of "user identity" and "access control" etc.&lt;BR /&gt;&lt;BR /&gt;Btw, the following is an excellent whitepaper on the security differences between standard and trusted HP-UX:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/sec9906.pdf" target="_blank"&gt;http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/sec9906.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Some of the B1 special releases include HP-UX 10.09 and 10.16 etc.&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Tue, 28 May 2002 22:07:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732544#M65782</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2002-05-28T22:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Security Level Associated with Traditional HPUX installation</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732545#M65783</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The easiest variation from vanilla HP-UX is of course the move to trusted system.&lt;BR /&gt;&lt;BR /&gt;But many more changes may be made to ensure a greater security.&lt;BR /&gt;&lt;BR /&gt;This document clearly highlights obvious changes.&lt;BR /&gt;&lt;A href="http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/building_a_bastion_host.pdf" target="_blank"&gt;http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/building_a_bastion_host.pdf&lt;/A&gt;&lt;BR /&gt;Excellent read!&lt;BR /&gt;&lt;BR /&gt;Glenn</description>
      <pubDate>Wed, 29 May 2002 12:14:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-level-associated-with-traditional-hpux-installation/m-p/2732545#M65783</guid>
      <dc:creator>Glenn L. Stewart</dc:creator>
      <dc:date>2002-05-29T12:14:25Z</dc:date>
    </item>
  </channel>
</rss>

