<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HP-SSH Explained paper in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070335#M751353</link>
    <description>Version 1 of my HP-SSH Explained paper is now available at:&lt;BR /&gt;&lt;A href="http://newfdawg.com/docs/HP-SSH_Explained.PDF" target="_blank"&gt;http://newfdawg.com/docs/HP-SSH_Explained.PDF&lt;/A&gt;&lt;BR /&gt;It is almost 3 MB.&lt;BR /&gt;This paper does not include installation &amp;amp; configuration, that can be found at:&lt;BR /&gt;&lt;A href="http://newfdawg.com/SHP-Articles.htm" target="_blank"&gt;http://newfdawg.com/SHP-Articles.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;- Chris</description>
    <pubDate>Fri, 12 Sep 2003 22:20:42 GMT</pubDate>
    <dc:creator>Chris Wong</dc:creator>
    <dc:date>2003-09-12T22:20:42Z</dc:date>
    <item>
      <title>HP-SSH Explained paper</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070335#M751353</link>
      <description>Version 1 of my HP-SSH Explained paper is now available at:&lt;BR /&gt;&lt;A href="http://newfdawg.com/docs/HP-SSH_Explained.PDF" target="_blank"&gt;http://newfdawg.com/docs/HP-SSH_Explained.PDF&lt;/A&gt;&lt;BR /&gt;It is almost 3 MB.&lt;BR /&gt;This paper does not include installation &amp;amp; configuration, that can be found at:&lt;BR /&gt;&lt;A href="http://newfdawg.com/SHP-Articles.htm" target="_blank"&gt;http://newfdawg.com/SHP-Articles.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;- Chris</description>
      <pubDate>Fri, 12 Sep 2003 22:20:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070335#M751353</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-09-12T22:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: HP-SSH Explained paper</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070336#M751354</link>
      <description>Get it here.&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=T1471AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;A good configuration paper is attached.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 12 Sep 2003 22:22:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070336#M751354</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-12T22:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: HP-SSH Explained paper</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070337#M751355</link>
      <description>Hi Chris,&lt;BR /&gt;&lt;BR /&gt;I think this is a great article to help any HP-UX administrator new to SSH to pick up fast on both basic features as well as explore advanced features.&lt;BR /&gt;&lt;BR /&gt;I read the download portion and realised that there was no mention of any checksums to be checked to authenticate the downloaded T1471AA. Subsequently performed a check on &lt;A href="http://www.software.hp.com" target="_blank"&gt;http://www.software.hp.com&lt;/A&gt; and true enough, there were no md5 checksums or gpg signatures for package verification of any of HP's packages. &lt;BR /&gt;&lt;BR /&gt;If we look at most opensource programs like apache, openssl or openssh, there are md5 checksums and gpg signatures to check against trojan'ed packages. &lt;BR /&gt;&lt;BR /&gt;The security threat is real because there had been past reports (by CERT/CC) of trojan'ed OpenSSH distributions (CA-2002-24) and Sendmail distributions (CA-2002-28).&lt;BR /&gt;&lt;BR /&gt;Without &lt;A href="http://www.software.hp.com" target="_blank"&gt;http://www.software.hp.com&lt;/A&gt; on SSL and without any authenticode (md5 or gpg), it is a potentially big security risk that someone could compromise the server itself, or an internal DNS server or poison the DNS cache while creating a spoof'ed website to entrap a user into installing a trojan'ed package.&lt;BR /&gt;&lt;BR /&gt;Have I missed any mitigating mechanisms implemented by HP? &lt;BR /&gt;&lt;BR /&gt;Thanks in advance. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Mon, 15 Sep 2003 01:13:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070337#M751355</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2003-09-15T01:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: HP-SSH Explained paper</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070338#M751356</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Great point.  I guess the answer is "you can install it from the application CD".  Let's see if someone from HP responds to this.  I believe the same situation applies to any HP-UX software downloaded from software.hp.com.&lt;BR /&gt;&lt;BR /&gt;- Chris&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Sep 2003 01:20:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ssh-explained-paper/m-p/3070338#M751356</guid>
      <dc:creator>Chris Wong</dc:creator>
      <dc:date>2003-09-15T01:20:34Z</dc:date>
    </item>
  </channel>
</rss>

