- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Boot Authentication
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2009 10:20 AM
02-05-2009 10:20 AM
Boot Authentication
I have an observation from an external auditory telling me to fix the exposure of our system from being booted by anyone with access to the site...
So, can anybody (that sounds like Fredy Mercury, right?) tell me if I mis something?
-First we had converted to trusted system
-Second I write this two lines to the /etc/default/security file:
BOOT_AUTH=1
BOOT_USERS=root,jsantana
-Third, from uncleSAM at Auditing and Security==>System Security Policies==>General User Account Policies--I set the option--[X] Require Login Upon Boot to Single-User State
-Finally also with SAM at Accounts for Users and Groups==>Users--the user--Actions==>Modify Security Policies==>General User Account Policies--i selected--Authorize User to Boot to Single-User State: [ Yes ->]
Tks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2009 10:43 AM
02-05-2009 10:43 AM
Re: Boot Authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2009 08:20 PM
02-05-2009 08:20 PM
Re: Boot Authentication
Hummm, do you mean somewhere in the building using a network connection, or access to the computer room? Outside the computer room, there is no possible way to for a user to interact with the computer unless you have connected the GSP (or MP, etc) to an outside network. The console LAN must never be routed outside the computer room. Access to the console is a big security issue.
Inside the computer room, there is no security. Every machine is wide open. The bad guy can pull out power plugs, put hubs in series with network cables, use a Blackberry to trace traffic or to plug into a console port, physically bypass a firewall, steal backup tapes, use flash drives to collect data, add a keyboard flash drive to collect keystrokes, and on and on. In other words, computer room security is much more important than any individual computer setup.
So your protection is fine but with the bad guys in the computer room, most everything is no longer secure.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-06-2009 11:25 AM
02-06-2009 11:25 AM
Re: Boot Authentication
The only console is on the site with security access... but i have this auditing observation, so i need to configure the system to doesn't allow an unauthorized boot of the system.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2009 07:01 AM
02-11-2009 07:01 AM
Re: Boot Authentication
The issue is that the statement is nonsense. If the server is in a secure room and only approved individuals have access to that room, then you have met the requirement. The only thing you can control is access to single user mode. Basically you are done, and your auditor is clueless.