<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553746#M759042</link>
    <description>It depends by what you mean by C2.&lt;BR /&gt;&lt;BR /&gt;You can convert your system to 'trusted mode'.  This gives you some of the features necessary to meet the C2 spec (at least for non-networked systems), and can be done without a reinstall (you do it through SAM or /usr/lbin/tsconvert).  But.. a regular HP-UX system in trusted mode is not actually C2 (not evaluated as such), and some add-on software that handles passwords may have to be recompiled (such as SSH).&lt;BR /&gt;&lt;BR /&gt;The other choice is to use one of HP's trusted OS flavors (10.24 and 11.04), which requires a complete reinstall of the OS.</description>
    <pubDate>Tue, 17 Jul 2001 13:39:32 GMT</pubDate>
    <dc:creator>Chris Calabrese</dc:creator>
    <dc:date>2001-07-17T13:39:32Z</dc:date>
    <item>
      <title>Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553745#M759041</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;Could someone tell me if there is anything on the ITRC about C2 security for HPUX 11.00? I'm after the major and minor differences between standard security and C2 ie what settings are set in stone and what setting can be changed. I have been informed that it would acctually take a complete re-installation to go to C2 security, but this was probably untrue.&lt;BR /&gt;I ask this question as our auditors have advised us that our current password security is inadequate.</description>
      <pubDate>Tue, 17 Jul 2001 12:59:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553745#M759041</guid>
      <dc:creator>Systems Department</dc:creator>
      <dc:date>2001-07-17T12:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553746#M759042</link>
      <description>It depends by what you mean by C2.&lt;BR /&gt;&lt;BR /&gt;You can convert your system to 'trusted mode'.  This gives you some of the features necessary to meet the C2 spec (at least for non-networked systems), and can be done without a reinstall (you do it through SAM or /usr/lbin/tsconvert).  But.. a regular HP-UX system in trusted mode is not actually C2 (not evaluated as such), and some add-on software that handles passwords may have to be recompiled (such as SSH).&lt;BR /&gt;&lt;BR /&gt;The other choice is to use one of HP's trusted OS flavors (10.24 and 11.04), which requires a complete reinstall of the OS.</description>
      <pubDate>Tue, 17 Jul 2001 13:39:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553746#M759042</guid>
      <dc:creator>Chris Calabrese</dc:creator>
      <dc:date>2001-07-17T13:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553747#M759043</link>
      <description>Thanks for the reply Chris.&lt;BR /&gt;I don't think a re-installation would go down very well at all.&lt;BR /&gt;Could you point me in the direction of some documentation on the security differences between a standard system and a trusted system.&lt;BR /&gt;&lt;BR /&gt;Many thanks.</description>
      <pubDate>Tue, 17 Jul 2001 14:30:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553747#M759043</guid>
      <dc:creator>Systems Department</dc:creator>
      <dc:date>2001-07-17T14:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553748#M759044</link>
      <description>What is meant by C2 comes from DoD documents.&lt;BR /&gt;&lt;BR /&gt;Try this URL: &lt;A href="http://all.net/books/orange/" target="_blank"&gt;http://all.net/books/orange/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Keep in mind that the "Orange Book" refers ONLY to standalone systems.  Networked systems are supposed to conform to Red Book standards.</description>
      <pubDate>Tue, 17 Jul 2001 15:55:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553748#M759044</guid>
      <dc:creator>Paul R. Dittrich</dc:creator>
      <dc:date>2001-07-17T15:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553749#M759045</link>
      <description>Re. documents on 'trusted mode' - there's definitely a shortage of these.  The only thing I could find is &lt;A href="http://www.hp.com/products1/unix/operating/hpux11i/infolibrary/hpuxsecurity.pdf," target="_blank"&gt;http://www.hp.com/products1/unix/operating/hpux11i/infolibrary/hpuxsecurity.pdf,&lt;/A&gt; though you might also check out the man pages for prpwd(4), authcap(4), and default(4).&lt;BR /&gt;&lt;BR /&gt;Re. Orange Book vs. Red Book - if I remember correctly, the Red Book interprets the Orange Book for networked environments.  So the Orange Book does address networked environemnt, in theory.  But meanwhile niether of these are DoD standards any longer.  First they were merged into the TCSEC (see &lt;A href="http://www.radium.ncsc.mil/tpep/library/rainbow/)." target="_blank"&gt;http://www.radium.ncsc.mil/tpep/library/rainbow/).&lt;/A&gt;&lt;BR /&gt;Later they were superceded by the Common Criteria and the specific CC Protection Profiles (see &lt;A href="http://www.radium.ncsc.mil/tpep/library/protection_profiles/index.html)" target="_blank"&gt;http://www.radium.ncsc.mil/tpep/library/protection_profiles/index.html)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The Common Criteria Controled Access Protection Profile is roughly equivelant to the old C2 designation.</description>
      <pubDate>Tue, 17 Jul 2001 16:43:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553749#M759045</guid>
      <dc:creator>Chris Calabrese</dc:creator>
      <dc:date>2001-07-17T16:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553750#M759046</link>
      <description>For information about configuring HP-UX as "Trusted System":&lt;BR /&gt;&lt;A href="http://docs.hp.com/hpux/onlinedocs/B2355-90121/B2355-90121.html" target="_blank"&gt;http://docs.hp.com/hpux/onlinedocs/B2355-90121/B2355-90121.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/hpux/onlinedocs/B2355-90121/B2355-90121.html" target="_blank"&gt;http://docs.hp.com/hpux/onlinedocs/B2355-90121/B2355-90121.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;These apply to HP-UX 10.xx.  I'm not aware of 11.x equivalents.&lt;BR /&gt;&lt;BR /&gt;Note that the C2 security level is characterized by Discretionary Access Control, and is pretty well deprecated in today's software environment.  C2 relies on the presumptions that your authorized "superusers" are absolutely reliable (security clearances, etc.), and that there can be no unauthorized "superuser" access.  Because of the common code flaws leading to unauthorized "superuser" access (particularly on Internet-exposed systems), it's generally considered that a compartmentalized Mandatory Access Control environment is required for truly secure applications.  This corresponds to the DoD "B2" level above C2.  HP's Virtual Vault is a commercial implementation.  It works well, but is expensive to buy and support, compared to HP-UX.  See:&lt;BR /&gt;&lt;A href="http://www.docs.hp.com/hpux/pdf/B5413-90027.pdf" target="_blank"&gt;http://www.docs.hp.com/hpux/pdf/B5413-90027.pdf&lt;/A&gt;&lt;BR /&gt;and other  documents linked from:&lt;BR /&gt;&lt;A href="http://www.docs.hp.com/hpux/internet/" target="_blank"&gt;http://www.docs.hp.com/hpux/internet/&lt;/A&gt;</description>
      <pubDate>Wed, 18 Jul 2001 14:01:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553750#M759046</guid>
      <dc:creator>W.C. Epperson</dc:creator>
      <dc:date>2001-07-18T14:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553751#M759047</link>
      <description>Thank you all fro your replies.&lt;BR /&gt;I have one final question to ask. Now that I have set my system to a trusted system, I know I can set a maximum password length but is there any way of setting a minimum password length?&lt;BR /&gt;I ask this question as I have been told to set a minimum password length of 8 characters and the minimum password length currently is 6 characters.</description>
      <pubDate>Thu, 19 Jul 2001 09:07:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553751#M759047</guid>
      <dc:creator>Systems Department</dc:creator>
      <dc:date>2001-07-19T09:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553752#M759048</link>
      <description>Its okay, I've just spoted the post from Ray Bell regarding "passowrd length".&lt;BR /&gt;&lt;BR /&gt;Many thanks for all your help.</description>
      <pubDate>Thu, 19 Jul 2001 09:25:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security/m-p/2553752#M759048</guid>
      <dc:creator>Systems Department</dc:creator>
      <dc:date>2001-07-19T09:25:02Z</dc:date>
    </item>
  </channel>
</rss>

