Operating System - HP-UX
1847211 Members
2406 Online
110263 Solutions
New Discussion

Bastille - Is It Safe to Install, I have ONLY 1 Machine

 
Basheer_2
Trusted Contributor

Bastille - Is It Safe to Install, I have ONLY 1 Machine

Hello ITRC
I have only 1 Machine - which is a prodn machine. HP-UX B.11.11 U ( L200)

1) Is it Safe to Install Bastille
2) Any known issues/problems with this

I dont have a test machine to install/test.

Thanks
Basheer
4 REPLIES 4
Pete Randall
Outstanding Contributor

Re: Bastille - Is It Safe to Install, I have ONLY 1 Machine

First, installing it won't do anything. Second, even when you run it, it won't change anything unless you tell it to.


Pete

Pete
Jeff Schussele
Honored Contributor

Re: Bastille - Is It Safe to Install, I have ONLY 1 Machine

Hi Basheer,

Well, as we frequently see - it depends.
As Pete points out it won't do anything that you don't agree to.
So you need to have an intimate knowledge of your environment.
For example if something/someone is using r commands like remsh or rcp & you let Bastille turn them off - well then you'll have trouble.
So know you system & how it's now being used.

Rgds,
Jeff

P.S. I'm all for turning off r commands. Everyone should be using SSH/SCP/SFTP by now anyway.
PERSEVERANCE -- Remember, whatever does not kill you only makes you stronger!
Biswajit Tripathy
Honored Contributor

Re: Bastille - Is It Safe to Install, I have ONLY 1 Machine

It's definitely a good idea to install AND configure
Bastille. This will also configure IPFilter firewall that
would cutdown the possible number of entry points
into your system.

Since you have only one machine, it's even more
urgent that you install these security tools and
block/disable all services that are vulnerable (like, as
others have suggested, r commands etc).

- Biswajit

:-)
Basheer_2
Trusted Contributor

Re: Bastille - Is It Safe to Install, I have ONLY 1 Machine

Thanks for all of your help
Basheer