- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Cross platform security scoring tool
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-01-2007 08:19 AM
02-01-2007 08:19 AM
Cross platform security scoring tool
We've been using the CIS scoring tool on HP-UX, but, until December, they didn't have a version for Linux. After months of delays, they finally do, but it's implemented in Java and it ran like a snail on a trial run I did.
The Linux version of Bastille has the assessment feature available on the current release (3.0) that's supposed to provide a score of some sort. (Haven't tested this yet to see how it performs and what the assessment looks like.) I see that Bastille on software.hp.com is still the 2.0 version, which does not have the assessment feature. Anyone know what the status of getting this feature on HP-UX is?
Any other options you know of that I haven't managed to find?
Jeff Traigle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-01-2007 02:12 PM
02-01-2007 02:12 PM
Re: Cross platform security scoring tool
Anyway, one thing I like about the Bastille report is that it generates both HTML and text versions. The CIS scoring tool only generates an HTML report. With the current CIS scoring tool on HP-UX, we have a script that generates a somewhat parsed diff with the last report generated so our security group can see if a score changes for a system and pinpoint the configuration changes that caused it. I imagine this would be much messier to accomplish with HTML than with straight text.
So I'd still like to know if we can look forward to seeing the latest version of Bastille with the assessment feature in the near future for HP-UX... or other scoring tools that work well on both platforms that generate text reports.
Jeff Traigle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-02-2007 04:19 AM
02-02-2007 04:19 AM
Re: Cross platform security scoring tool
The HP-UX version of Bastille 3.0 is completed. Actually, we added some additional GUI/usability/reporting granularity enhancements and a SIM integration as well. I think you'll be pleased.
The s/w will be delivered with HP-UX 11.31, and will be available for 11.23 / 11.11 on the web soon. I'm not sure how long posting the bits will take, but I'd check back in a couple weeks, and then if they're not up, a couple weeks after that.
Hope that helps, and I'd be interested in what you think (I'll monitor this thread for additional posts).
I'm glad you're excited about 3.0, me too :-).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2007 08:06 AM
02-07-2007 08:06 AM
Re: Cross platform security scoring tool
It has me a bit perplexed, however. When I run "bastille --assessnobrowser", I get the report files, but there is no score provided as the Linux version provides. Am I missing something or did the scoring not get implemented in the HP-UX version?
Jeff Traigle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2007 08:29 AM
02-07-2007 08:29 AM
Re: Cross platform security scoring tool
CIS (and Bastille Linux) currently has a flat weighting, which is a bit odd considering that some configurations have much more security value than others.
Rather than have the default values in HP-UX Bastille display something we thought, frankly, didn't help users understand their security more than just listing the answers, and that our beta testers found confusing, we left that configurable. We have already heard of at least one case where an end-user site preferred their own weighting.
That said, we're gong to spend some time looking at what scoring file we could deliver that would add value.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2007 09:27 AM
02-07-2007 09:27 AM
Re: Cross platform security scoring tool
I've used the Bastille tool on Linux to harden some systems and evaulate them after I tinkered.
I like it and the functionality is worth waiting for on HP-UX (not long).
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-15-2007 06:48 AM
06-15-2007 06:48 AM
Re: Cross platform security scoring tool
Jeff Traigle