<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: securing hpux box in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599640#M855476</link>
    <description>Sharif,&lt;BR /&gt;&lt;BR /&gt;There is C2-security available with HP-UX but not by default. You need to enable it. You can convert the system to trusted by running the command /usr/lbin/tsconvert. Then you can implement enhanced password restrictions, auditing etc., etc.,.&lt;BR /&gt;&lt;BR /&gt;Check this URL for more details.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/hpux/onlinedocs/B2355-90672/B2355-90672.html" target="_blank"&gt;http://docs.hp.com/hpux/onlinedocs/B2355-90672/B2355-90672.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;All the best,&lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
    <pubDate>Tue, 23 Oct 2001 12:58:16 GMT</pubDate>
    <dc:creator>Sridhar Bhaskarla</dc:creator>
    <dc:date>2001-10-23T12:58:16Z</dc:date>
    <item>
      <title>securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599637#M855473</link>
      <description>Hi guys ,&lt;BR /&gt;i have nclass servers with hpux 11 installed .&lt;BR /&gt;could any body of you tell me how can i secure my hpux box or is there any software which can help me in assesing my hpux box security.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sharif&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Oct 2001 12:49:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599637#M855473</guid>
      <dc:creator>sharif naser_1</dc:creator>
      <dc:date>2001-10-23T12:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599638#M855474</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;there's a whitepaper available titled "How to build a bastion server".  It's a very good basis to build a secure server.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;Thierry.</description>
      <pubDate>Tue, 23 Oct 2001 12:53:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599638#M855474</guid>
      <dc:creator>Thierry Poels_1</dc:creator>
      <dc:date>2001-10-23T12:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599639#M855475</link>
      <description>Hi Sharif,&lt;BR /&gt;&lt;BR /&gt;Take a look at thread below.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90742/B2355-90742_top.html&amp;amp;con=/hpux/onlinedocs/B2355-90742/00/00/60-con.html&amp;amp;toc=/hpux/onlinedocs/B2355-90742/00/00/60-toc.html&amp;amp;searchterms=security&amp;amp;queryid=20011023-065709" target="_blank"&gt;http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90742/B2355-90742_top.html&amp;amp;con=/hpux/onlinedocs/B2355-90742/00/00/60-con.html&amp;amp;toc=/hpux/onlinedocs/B2355-90742/00/00/60-toc.html&amp;amp;searchterms=security&amp;amp;queryid=20011023-065709&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here are the security software from hp.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.hp.com/security/home.html" target="_blank"&gt;http://www.hp.com/security/home.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Oct 2001 12:57:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599639#M855475</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2001-10-23T12:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599640#M855476</link>
      <description>Sharif,&lt;BR /&gt;&lt;BR /&gt;There is C2-security available with HP-UX but not by default. You need to enable it. You can convert the system to trusted by running the command /usr/lbin/tsconvert. Then you can implement enhanced password restrictions, auditing etc., etc.,.&lt;BR /&gt;&lt;BR /&gt;Check this URL for more details.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/hpux/onlinedocs/B2355-90672/B2355-90672.html" target="_blank"&gt;http://docs.hp.com/hpux/onlinedocs/B2355-90672/B2355-90672.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;All the best,&lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Tue, 23 Oct 2001 12:58:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599640#M855476</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-10-23T12:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599641#M855477</link>
      <description>Take a look at this document&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.hp.com/products1/unix/operating/hpux11i/alwayssecure.html" target="_blank"&gt;http://www.hp.com/products1/unix/operating/hpux11i/alwayssecure.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;rainer</description>
      <pubDate>Tue, 23 Oct 2001 13:00:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599641#M855477</guid>
      <dc:creator>Rainer von Bongartz</dc:creator>
      <dc:date>2001-10-23T13:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599642#M855478</link>
      <description>hi again,&lt;BR /&gt;&lt;BR /&gt;got address and exact title:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://people.hp.se/stevesk/bastion11.html" target="_blank"&gt;http://people.hp.se/stevesk/bastion11.html&lt;/A&gt;&lt;BR /&gt;"Building a Bastion Host Using HP-UX 11" by Kevin Steves&lt;BR /&gt;&lt;BR /&gt;good luck,&lt;BR /&gt;Thierry</description>
      <pubDate>Tue, 23 Oct 2001 13:02:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599642#M855478</guid>
      <dc:creator>Thierry Poels_1</dc:creator>
      <dc:date>2001-10-23T13:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599643#M855479</link>
      <description>That is a very broad subject. But even before I started reading I might:&lt;BR /&gt;...first protect myself from outside sources getting in. So have a firewall installed and configured (by someone who is familiar with this process if you are not).&lt;BR /&gt;The next thing I would do is configure my /var/adm/inetd.sec file to allow or deny only certain IP's or hosts to use certain protocols.&lt;BR /&gt;Make sure your root password is secure AND double check your /etc/passwd file to ensure nobody has a GUID=0 except root and who you know should.&lt;BR /&gt;If your concerned already you may have folks trying things then setup inetd to log info to your syslog, so you can monitor for this.  And keep an eye on your /var/adm/sulog file to see who's trying to crack the password.&lt;BR /&gt;...Now you still have a long way to go...so start reading and set up what security measures will work best for your shop.&lt;BR /&gt;&lt;BR /&gt;Just a thought,&lt;BR /&gt;Rit</description>
      <pubDate>Tue, 23 Oct 2001 13:06:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599643#M855479</guid>
      <dc:creator>Rita C Workman</dc:creator>
      <dc:date>2001-10-23T13:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599644#M855480</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Others have already suggested quite a few good white papers.&lt;BR /&gt;&lt;BR /&gt;There is another tool called armor (which is a script) which secures a hp box. Might want to check it out&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://armor.sourceforge.net/" target="_blank"&gt;http://armor.sourceforge.net/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here's a FAQ about armor&lt;BR /&gt;&lt;A href="http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/~checkout~/armor/armor/FAQ?rev=HEAD&amp;amp;content-type=text/plain" target="_blank"&gt;http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/~checkout~/armor/armor/FAQ?rev=HEAD&amp;amp;content-type=text/plain&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here's another thread where some of the folks here in the forum were planning to come up with another script.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,11866,0x42b8cf38d6bdd5118ff10090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,11866,0x42b8cf38d6bdd5118ff10090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-HTH&lt;BR /&gt;Ramesh</description>
      <pubDate>Tue, 23 Oct 2001 13:08:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599644#M855480</guid>
      <dc:creator>linuxfan</dc:creator>
      <dc:date>2001-10-23T13:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: securing hpux box</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599645#M855481</link>
      <description>Hi Nasir,&lt;BR /&gt;&lt;BR /&gt;   this is a wide topic.&lt;BR /&gt;For starters:&lt;BR /&gt;&lt;BR /&gt;1) You can convert your&lt;BR /&gt;system to a Trusted mode.&lt;BR /&gt;It can be done through&lt;BR /&gt;SAM or command line(tsconvert).  Trusted&lt;BR /&gt;system implements features&lt;BR /&gt;like auditing, shadowpassword&lt;BR /&gt;file in a trusted database.&lt;BR /&gt;Basically, it gives a&lt;BR /&gt;strict control over password&lt;BR /&gt;and auditing policies of the&lt;BR /&gt;system.&lt;BR /&gt;&lt;BR /&gt;2) the next step is the tuning of connection services.&lt;BR /&gt;Go into /etc/services&lt;BR /&gt;and /etc/inetd.conf and&lt;BR /&gt;disable any service which&lt;BR /&gt;you feel is not required.&lt;BR /&gt;But, be very sure and careful&lt;BR /&gt;before you disable any services.&lt;BR /&gt;&lt;BR /&gt;3)  Then, use SSH/SFTP&lt;BR /&gt;instead of  telnet/ftp .&lt;BR /&gt;telnet does not encrypt&lt;BR /&gt;passwords when it sends&lt;BR /&gt;it on the network. &lt;BR /&gt;SSH is a secure version&lt;BR /&gt;of connection to the system.&lt;BR /&gt;&lt;BR /&gt;  There are many more steps&lt;BR /&gt;to secure your system.&lt;BR /&gt;It depends on your requirements.  Not all the&lt;BR /&gt;systems are secured to &lt;BR /&gt;a detailed extent.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;raj</description>
      <pubDate>Tue, 23 Oct 2001 15:27:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hpux-box/m-p/2599645#M855481</guid>
      <dc:creator>Roger Baptiste</dc:creator>
      <dc:date>2001-10-23T15:27:45Z</dc:date>
    </item>
  </channel>
</rss>

