Operating System - HP-UX
1834000 Members
2163 Online
110063 Solutions
New Discussion

Re: Class C2 security setting on password aging

 
SOLVED
Go to solution
PARK FOH CHIN
Occasional Contributor

Class C2 security setting on password aging

Hi,
HP-UX trusted mode is compliant with DoD class C2 security.
However, the Orange Book (http://www.dynamoo.com/orange/) does not mention the password aging should be how many days.

Pls advise on where to check class C2 password aging should be how many days.

Thanks & regards
Chin
1-Jul-09 (Wed) @3:11pm
4 REPLIES 4
Ganesan R
Honored Contributor

Re: Class C2 security setting on password aging

Steven E. Protter
Exalted Contributor

Re: Class C2 security setting on password aging

Shalom,

The document in the first answer definitely says how to do the password aging. I took a look and can not find out how many days. My memory says 60 or 90 days.

Note Trusted system itself is in its final OS release with HP-UX. With the next OS release something different will need to be used.

This document mentions an acceptable alternative to trusted system but also seems to not mention HOW MANY days the password should last: http://www.auscert.org.au/render.html?it=5819

This document does mention the number of days.
http://niatec.info/pdf.aspx?id=113
30

>>
meet both the TCSEC's C2 requirements and the Information Technology ... culmination of many years of effort to address IT security issues within the ..... shall be 30 days.® b. After the password aging threshold has been reached, ...
<<

A little deep, but a fun question.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Andrew C Fieldsend
Respected Contributor
Solution

Re: Class C2 security setting on password aging

Also, of course, the orange book itself was retired in 2005, and replaced with the "Common Criteria" (ISO 15408, parts 1-3), which is freely available in PDF form from the ISO website.

(This might explain why trusted mode is deprecated.)
PARK FOH CHIN
Occasional Contributor

Re: Class C2 security setting on password aging

Good comments.