<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet Explorer Update MS04-025 and HP SIM in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349826#M4881</link>
    <description>Fix is posted.  See thread at &lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=666957" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=666957&lt;/A&gt;</description>
    <pubDate>Thu, 12 Aug 2004 11:44:21 GMT</pubDate>
    <dc:creator>David Claypool</dc:creator>
    <dc:date>2004-08-12T11:44:21Z</dc:date>
    <item>
      <title>Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349818#M4873</link>
      <description>Latest news:  changes to the code are required for HP SIM to cope with the changes in behavior that Microsoft made to IE with this patch.  The exact changes have been identified and are being incorporated into the source.  It will take several days for the teams to go through the changes and qualify on all of the OS variants that are supported.&lt;BR /&gt;&lt;BR /&gt;Bottom line:  don't expect anything to be posted this week.  &lt;BR /&gt;&lt;BR /&gt;While we are hopeful that everything will go correctly, by the time the tests are completed and the publishing process goes through, expect something probably the week of August 12.&lt;BR /&gt;&lt;BR /&gt;In the meantime if you choose to de-install the patch, be careful where you surf because there are known sites out there that will exploit the vulnerability.  The best recommendation is not to de-install the patch and in the meantime attempt to use Netscape or Mozilla.</description>
      <pubDate>Wed, 04 Aug 2004 17:49:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349818#M4873</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-04T17:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349819#M4874</link>
      <description>bump</description>
      <pubDate>Wed, 04 Aug 2004 17:51:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349819#M4874</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-04T17:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349820#M4875</link>
      <description>We are also experiencing the same problem with HP SIM 4.0 after loading MS04-025.  Will the fix also apply to 4.0 or just 4.1?</description>
      <pubDate>Thu, 05 Aug 2004 13:36:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349820#M4875</guid>
      <dc:creator>Glen Brill</dc:creator>
      <dc:date>2004-08-05T13:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349821#M4876</link>
      <description>Rest easy.  It will apply to both HP SIM versions.</description>
      <pubDate>Thu, 05 Aug 2004 13:41:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349821#M4876</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-05T13:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349822#M4877</link>
      <description>David please look at "&lt;A href="http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=629545" target="_blank"&gt;http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=629545&lt;/A&gt;". I see that You have direct access to SIM development group. Some group os users hope that You have also access to PMP development group.</description>
      <pubDate>Thu, 05 Aug 2004 13:48:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349822#M4877</guid>
      <dc:creator>Grzegorz Kedziora</dc:creator>
      <dc:date>2004-08-05T13:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349823#M4878</link>
      <description>A problem like you describe is not related to any known issue.  It would be best to take this up with Customer Services locally and have them escalate it to the third level support team so it can be duplicated.  This forum is not the way to escalate problems to development.</description>
      <pubDate>Fri, 06 Aug 2004 10:49:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349823#M4878</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-06T10:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349824#M4879</link>
      <description>Can a HP person check out this patch and post it...?&lt;BR /&gt;&lt;BR /&gt;Technical Support&lt;BR /&gt;Hot News - Patch Released &lt;BR /&gt;The Microsoft patch MS04-025 (KB867801) for Internet Explorer broke the&lt;BR /&gt;login to HP SIM 4.0, 4.0.1, and 4.1 when using IE.. &lt;BR /&gt;&lt;BR /&gt;[EDIT]&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt; Windows patches Here you will find a directory for HP SIM 4.0 and&lt;BR /&gt;4.1. The patch and directions are in each directory. Once installed, the&lt;BR /&gt;patch for HP SIM 4.0 does not provide a version string in the help-about&lt;BR /&gt;box, however the 4.1 patch does show the version of HP SIM as being&lt;BR /&gt;C.04.01.00.01. A file is placed in the main HP SIM directory named&lt;BR /&gt;sp1.txt which prevents the patch from being installed a second time.&lt;BR /&gt;&lt;BR /&gt;In this edition:&lt;BR /&gt;HP SIM fix for Microsoft patch MS04-025 (KB867801)&lt;BR /&gt;&lt;BR /&gt;OpenSSH 3.7p1 PAM authentication vulnerability&lt;BR /&gt;&lt;BR /&gt;HP SIM fix for Microsoft patch MS04-025 (KB867801) &lt;BR /&gt;Microsoft released a new IE Patch on 7/30/04 that disables the ability&lt;BR /&gt;to login to HP SIM when using Internet Explorer.  Read more about this&lt;BR /&gt;in HP SIM Newsletter #7&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;[EDIT]&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;The version string will show in HP SIM 4.1 as C.04.01.00.01. However,&lt;BR /&gt;this will not show in HP SIM 4.0. You will have to check for the&lt;BR /&gt;presence of the sp1.txt file in the main HP SIM directory to determine&lt;BR /&gt;if the patch had been installed.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;OpenSSH 3.7p1 PAM authentication vulnerability&lt;BR /&gt;Recently a critical security advisory was released regarding OpenSSH and&lt;BR /&gt;PAM.  This advisory is being presented in the event you receive queries&lt;BR /&gt;about how it applies to HP SIM.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;Although HP SIM uses OpenSSH, PAM is not enabled in the sshd_config file&lt;BR /&gt;(see below where "usePAM" is commented-out):&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;The setting is appropriate for any of the OSs on which HP SIM can be&lt;BR /&gt;installed.  To ensure PAM vulnerability is not present, ensure that PAM&lt;BR /&gt;is commented-out in the sshd_conf file on your CMS platform.&lt;BR /&gt;&lt;BR /&gt;Below is the actual advisory from &lt;A href="http://www.openssh.com/txt/sshpam.adv." target="_blank"&gt;http://www.openssh.com/txt/sshpam.adv.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Subject: Portable OpenSSH Security Advisory: sshpam.adv&lt;BR /&gt; &lt;BR /&gt;This document can be found at:  &lt;A href="http://www.openssh.com/txt/sshpam.adv" target="_blank"&gt;http://www.openssh.com/txt/sshpam.adv&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt;1. Versions affected:&lt;BR /&gt; &lt;BR /&gt;Portable OpenSSH versions 3.7p1 and 3.7.1p1 contain multiple&lt;BR /&gt;vulnerabilities in the new PAM code. At least one of these bugs is&lt;BR /&gt;remotely exploitable (under a non-standard configuration, with privsep&lt;BR /&gt;disabled).&lt;BR /&gt; &lt;BR /&gt;The OpenBSD releases of OpenSSH do not contain this code and are not&lt;BR /&gt;vulnerable. Older versions of portable OpenSSH are not vulnerable.&lt;BR /&gt; &lt;BR /&gt;2. Solution:&lt;BR /&gt; &lt;BR /&gt;Upgrade to Portable OpenSSH 3.7.1p2 or disable PAM support ("UsePam no"&lt;BR /&gt;in sshd_config). &lt;BR /&gt; &lt;BR /&gt;Due to complexity, inconsistencies in the specification and differences&lt;BR /&gt;between vendors' PAM implementations we recommend that PAM be left&lt;BR /&gt;disabled in sshd_config unless there is a need for its use. Sites only&lt;BR /&gt;using public key or simple password authentication usually have little&lt;BR /&gt;need to enable PAM support.&lt;BR /&gt; &lt;BR /&gt;As stated earlier, the problem discussed in the advisory does not affect&lt;BR /&gt;systems on which HP SIM is installed unless someone has modified the&lt;BR /&gt;sshd_conf file.</description>
      <pubDate>Mon, 09 Aug 2004 14:20:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349824#M4879</guid>
      <dc:creator>Larry Hedrick</dc:creator>
      <dc:date>2004-08-09T14:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349825#M4880</link>
      <description>The text above refers to an internal document.  Maybe I'm being paranoid, but I'm sorry to edit--internal hostnames with their FQDN just might be a hacker invitation.&lt;BR /&gt;&lt;BR /&gt;Although the note says "tested," this refers to rudimentary testing to validate its effectiveness.  Much more rigorous QA testing is happening now across all of the platforms.&lt;BR /&gt;&lt;BR /&gt;The good news is that things are looking good.  With a little luck the patch will be available soon.  We appreciate your patience.  I know the wait is excruciating, but we would hate to have a patch for a patch need to be released.</description>
      <pubDate>Mon, 09 Aug 2004 14:44:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349825#M4880</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-09T14:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Internet Explorer Update MS04-025 and HP SIM</title>
      <link>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349826#M4881</link>
      <description>Fix is posted.  See thread at &lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=666957" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=666957&lt;/A&gt;</description>
      <pubDate>Thu, 12 Aug 2004 11:44:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/internet-explorer-update-ms04-025-and-hp-sim/m-p/3349826#M4881</guid>
      <dc:creator>David Claypool</dc:creator>
      <dc:date>2004-08-12T11:44:21Z</dc:date>
    </item>
  </channel>
</rss>

