<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Services in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934007#M739601</link>
    <description>Dear Gurus,&lt;BR /&gt;&lt;BR /&gt;I would like to ask how to disable the following services:&lt;BR /&gt;&lt;BR /&gt;Any form of dynamic routing (routed,gated)&lt;BR /&gt;NFS and related services (nfsd, biod, mountd, statd, lockd, automount, etc)&lt;BR /&gt;NIS (both client and server)&lt;BR /&gt;HTTP&lt;BR /&gt;Bootps&lt;BR /&gt;Booting services (tftpd, bootd, bootpd, dhcpd)&lt;BR /&gt;Dhcpd&lt;BR /&gt;rwhod&lt;BR /&gt;Fingerd&lt;BR /&gt;Uucp&lt;BR /&gt;Ntalk&lt;BR /&gt;Rexd&lt;BR /&gt;Rstatd&lt;BR /&gt;Ruserd&lt;BR /&gt;Rwalld&lt;BR /&gt;Sprayd&lt;BR /&gt;BSD “r” commands&lt;BR /&gt;&lt;BR /&gt;Also, how can enable inetd and ftp logging?&lt;BR /&gt;What about forwarding all syslog messages to centralized logging host?</description>
    <pubDate>Mon, 29 Jan 2007 00:39:47 GMT</pubDate>
    <dc:creator>Pando</dc:creator>
    <dc:date>2007-01-29T00:39:47Z</dc:date>
    <item>
      <title>Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934007#M739601</link>
      <description>Dear Gurus,&lt;BR /&gt;&lt;BR /&gt;I would like to ask how to disable the following services:&lt;BR /&gt;&lt;BR /&gt;Any form of dynamic routing (routed,gated)&lt;BR /&gt;NFS and related services (nfsd, biod, mountd, statd, lockd, automount, etc)&lt;BR /&gt;NIS (both client and server)&lt;BR /&gt;HTTP&lt;BR /&gt;Bootps&lt;BR /&gt;Booting services (tftpd, bootd, bootpd, dhcpd)&lt;BR /&gt;Dhcpd&lt;BR /&gt;rwhod&lt;BR /&gt;Fingerd&lt;BR /&gt;Uucp&lt;BR /&gt;Ntalk&lt;BR /&gt;Rexd&lt;BR /&gt;Rstatd&lt;BR /&gt;Ruserd&lt;BR /&gt;Rwalld&lt;BR /&gt;Sprayd&lt;BR /&gt;BSD “r” commands&lt;BR /&gt;&lt;BR /&gt;Also, how can enable inetd and ftp logging?&lt;BR /&gt;What about forwarding all syslog messages to centralized logging host?</description>
      <pubDate>Mon, 29 Jan 2007 00:39:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934007#M739601</guid>
      <dc:creator>Pando</dc:creator>
      <dc:date>2007-01-29T00:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934008#M739602</link>
      <description>hello pando.&lt;BR /&gt;Some of this services can be disabled by comenting them out in&lt;BR /&gt;&lt;BR /&gt;/etc/inetd.conf&lt;BR /&gt;also check /etc/services</description>
      <pubDate>Mon, 29 Jan 2007 00:50:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934008#M739602</guid>
      <dc:creator>Fabian Briseño</dc:creator>
      <dc:date>2007-01-29T00:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934009#M739603</link>
      <description>You need to turn on the system firewall&lt;BR /&gt;HP-UX IPFilter and open only those services&lt;BR /&gt;that you need. This will effectively close all other&lt;BR /&gt;services including the ones you listed above.&lt;BR /&gt;&lt;BR /&gt;- Biswajit&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Jan 2007 03:48:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934009#M739603</guid>
      <dc:creator>Biswajit Tripathy</dc:creator>
      <dc:date>2007-01-29T03:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934010#M739604</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;you can comment out proper lines in /etc/inetd.conf file&lt;BR /&gt;&lt;BR /&gt;after that type&lt;BR /&gt;&lt;BR /&gt;#inetd -c to re-read configuration&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;rgds&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Jan 2007 04:46:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934010#M739604</guid>
      <dc:creator>Yarek</dc:creator>
      <dc:date>2007-01-29T04:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934011#M739605</link>
      <description>Those services started by inetd are disabled by commenting their entries in /etc/inetd.conf and subsequentially sending a SIGHUP to inetd's PID, or executing "/usr/sbin/inetd -c",&lt;BR /&gt;as already has been posted by the others.&lt;BR /&gt;However, those services that run stand-alone&lt;BR /&gt;need to be brought down and disabled in their respective config files separately.&lt;BR /&gt;For instance if you don't require the NFS server you can "/sbin/init.d/nfs.server stop" and edit /etc/rc.config.d/nfsconf so that it won't be restarted on next runlevel change.&lt;BR /&gt;The procedure for the NFS client is similar.&lt;BR /&gt;With httpd it depends what kind of webserver you have currently running.&lt;BR /&gt;If it is the HP port of apache it usually is shut down by "/sbin/init.d/hpws_apache stop",&lt;BR /&gt;and prevented from restart by editing /etc/rc.cnfig.d/hpws_apacheconf.&lt;BR /&gt;But the names of init script as well es separate rc conf file, if present at all,&lt;BR /&gt;very much depend on the version.&lt;BR /&gt;Generally, I would consider disabling any service that your users don't need more apropiate than setting up a packet filter rule set.&lt;BR /&gt;Besides, you save resources and avoid any trouble with bugs, exploits, security updates  etc. these services may be susceptible to.&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Jan 2007 05:26:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934011#M739605</guid>
      <dc:creator>Ralph Grothe</dc:creator>
      <dc:date>2007-01-29T05:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934012#M739606</link>
      <description>Generally, the places to check for enabling/disabling a service are the /etc/inetd.conf file and the /etc/rc.config.d directory.&lt;BR /&gt;&lt;BR /&gt;/etc/rc.config.d/namesvrs:&lt;BR /&gt;- first check /etc/nsswitch.conf and ensure the server does not require NIS for anything&lt;BR /&gt;- set all NIS_*SERVER and NIS_*CLIENT variables to 0 to disable NIS functions.&lt;BR /&gt;&lt;BR /&gt;/etc/rc.config.d/nfsconf:&lt;BR /&gt;- set NFS_CLIENT, NFS_SERVER, AUTOMOUNT, START_MOUNTD and AUTOFS to 0 as appropriate to disable NFS-related services&lt;BR /&gt;&lt;BR /&gt;/etc/rc.config.d/netconf:&lt;BR /&gt;- set GATED to 0 to disable dynamic routing daemon&lt;BR /&gt;- set RARP to 0 to disable rarpd daemon (booting services)&lt;BR /&gt;- set RDPD to 0 to disable rdpd&lt;BR /&gt;&lt;BR /&gt;/etc/rc.config.d/netdaemons:&lt;BR /&gt;- set INETD_ARGS to "-l" to enable inetd logging&lt;BR /&gt;- set START_RBOOTD to 0 to disable rbootd&lt;BR /&gt;- set MROUTED to 0 to disable multicast routing&lt;BR /&gt;- set RWHOD to 0 to disable rwhod&lt;BR /&gt; &lt;BR /&gt;To disable ftpd, telnetd, tftpd, bootps, finger, r* commands, ntalk, uucp, rexd, rstatd, rusersd, rwalld and sprayd, comment them out of /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;To disable HTTP, you need to find out what HTTP server software you're using. If it's HP-packaged Apache, see /etc/rc.config.d/hpws_apacheconf. For any other kind of HTTP server, see the documentation of that server and/or the notes of the person who installed the server.&lt;BR /&gt;&lt;BR /&gt;Bootp and DHCP are so closely related that usually one server program handles both of them. The network port that bootp/DHCP server uses is called "bootps"; in HP-UX, the bootp/DHCP server binary is called "bootpd".&lt;BR /&gt;&lt;BR /&gt;To enable ftpd logging, add "-l" to ftpd command line in /etc/inetd.conf file.&lt;BR /&gt;&lt;BR /&gt;To forward all syslog messages to centralized logging host, see "man syslogd".&lt;BR /&gt;&lt;BR /&gt;After making these changes, you'll need to send a HUP signal to inetd and/or stop any running service daemons to make the changes effective immediately. A reboot might be recommended to ensure the new configuration is bootable, although it isn't strictly required.</description>
      <pubDate>Mon, 29 Jan 2007 06:46:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934012#M739606</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2007-01-29T06:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934013#M739607</link>
      <description>One additional plug:  You can use HP-UX Bastille to both stop inetd and other services, and set up your IPFilter firewall.</description>
      <pubDate>Tue, 30 Jan 2007 12:11:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934013#M739607</guid>
      <dc:creator>Robert Fritz</dc:creator>
      <dc:date>2007-01-30T12:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934014#M739608</link>
      <description>I recommend starting with HP-UX Bastille, available for free from HP's Software Depot (&lt;A href="https://www.hp.com/go/softwaredepot)" target="_blank"&gt;https://www.hp.com/go/softwaredepot)&lt;/A&gt;  It walks you through the process of disabling unnecessary services (including the inetd services and others mentioned above), explaining the tradeoffs for each item.&lt;BR /&gt;&lt;BR /&gt;It will also help you setup a basic ipfilter firewall if desired, and has options to turn on logging.  I think it covers everything you mentioned except centralized logging.&lt;BR /&gt;&lt;BR /&gt;Hope that helps.&lt;BR /&gt;&lt;BR /&gt;-Keith</description>
      <pubDate>Tue, 30 Jan 2007 15:09:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934014#M739608</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2007-01-30T15:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934015#M739609</link>
      <description>Hello Robert and Keith,&lt;BR /&gt;&lt;BR /&gt;I have downloaded HP-UX Bastille and when i about to install it using swinstall, i got an error.&lt;BR /&gt;The error was:&lt;BR /&gt;&lt;BR /&gt;The software item "B6849AA,r=B.02.01.03,a=HP-UX_B.11.00_32/64,v=HP"&lt;BR /&gt;is a bundle (or a product, subproduct or fileset contained within a               &lt;BR /&gt;bundle). This item was successfully marked, but difficulties were                 &lt;BR /&gt;encountered while marking some items that it depends on. The messages             &lt;BR /&gt;below show which software items encountered difficulties and exactly               &lt;BR /&gt;what these difficulties were:                                                      &lt;BR /&gt;The software                                                                      &lt;BR /&gt;"Bastille.BASTILLE,r=B.02.01.03,a=HP-UX_B.11.00_32/64,v=HP" was             &lt;BR /&gt;successfully marked, but it depends on the following software items             &lt;BR /&gt;which could not be found in the source. However, these items may             &lt;BR /&gt;already be in the target. This will be checked during the Analysis              &lt;BR /&gt;Phase: Perl5.PERL-RUN,r&amp;gt;=B.5.6.1.E | Perl5-32.PERL-RUN,r&amp;gt;=B.5.6.1.E               &lt;BR /&gt;Perl5-64.PERL-RUN,r&amp;gt;=B.5.6.1.E &lt;BR /&gt;&lt;BR /&gt;I have installed perl 5.8.8 in my HP-UX machine. Any idea on how to proceed?&lt;BR /&gt;Thanks!</description>
      <pubDate>Mon, 05 Feb 2007 22:39:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934015#M739609</guid>
      <dc:creator>Pando</dc:creator>
      <dc:date>2007-02-05T22:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934016#M739610</link>
      <description>Where did you get perl 5.8?  You need the official packaged one from software.hp.com to fulfull the corequisites.  (this version includes Tk for the Bastille GUI, and has been tested by HP)&lt;BR /&gt;&lt;BR /&gt;-Keith</description>
      <pubDate>Tue, 06 Feb 2007 11:10:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934016#M739610</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2007-02-06T11:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934017#M739611</link>
      <description>Hi Keith,&lt;BR /&gt;&lt;BR /&gt;I have downloaded Perl 5.8.8 from HP-UX Porting Center. Here's the website : &lt;A href="http://hpux.connect.org.uk/hppd/auto/" target="_blank"&gt;http://hpux.connect.org.uk/hppd/auto/&lt;/A&gt;</description>
      <pubDate>Thu, 08 Feb 2007 02:18:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934017#M739611</guid>
      <dc:creator>Pando</dc:creator>
      <dc:date>2007-02-08T02:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Network Services</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934018#M739612</link>
      <description>You'll need to get perl from HP's download site:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.hp.com/go/softwaredepot" target="_blank"&gt;https://www.hp.com/go/softwaredepot&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I don't know what modules are included in the porting archive's version, and it certainly won't satisfy the official corequisites of the HP-packaged Bastille.</description>
      <pubDate>Thu, 08 Feb 2007 12:05:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/network-services/m-p/3934018#M739612</guid>
      <dc:creator>Keith Buck</dc:creator>
      <dc:date>2007-02-08T12:05:42Z</dc:date>
    </item>
  </channel>
</rss>

