- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: HP-UX Bastille - lockdown/hardening tool
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 06:24 AM
тАО05-23-2002 06:24 AM
Most of the actions are completely automated and all actions are optional (so you don't over-secure your box to the point that it's unusable). It will even help you configure Security Patch Check. The tool is the same codebase as the popular Linux tool, but has a lot of added HP-UX specific functionality (and without Linux specific functionality)
A Beta version of this tool is available *right now* and the HP-UX Bastille Development team is very interested in your feedback before our release.
We're currently coordinating with the Linux Bastille team, and I'll post a stable URL when we have one. In the meantime, if you'd like to take it for a spin, just send email to
bastille-feedback@fc.hp.com
with "send me bastille" in the subject line.
We want to know:
1. is this tool useful (somewhat, very, not at all)
2. what does it do well?
3. what is it missing?
- critical functionality
- would be nice to see in the future
4. what do you think about HP participating in the open source process? Would you be willing to help?
You can either send feedback to the email address above or post it here. (I can only assign points if you post it here, of course)
Thanks!
the HP-UX Bastille Development team
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 06:34 AM
тАО05-23-2002 06:34 AM
Re: HP-UX Bastille - lockdown/hardening tool
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 06:40 AM
тАО05-23-2002 06:40 AM
Re: HP-UX Bastille - lockdown/hardening tool
mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 06:58 AM
тАО05-23-2002 06:58 AM
Re: HP-UX Bastille - lockdown/hardening tool
Which 3rd party tools have you looked at? How does Bastille compare for your needs?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 07:40 AM
тАО05-23-2002 07:40 AM
Re: HP-UX Bastille - lockdown/hardening tool
mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 07:49 AM
тАО05-23-2002 07:49 AM
Re: HP-UX Bastille - lockdown/hardening tool
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 07:51 AM
тАО05-23-2002 07:51 AM
Re: HP-UX Bastille - lockdown/hardening tool
Timely - thanks. I'll be cruising it around soon and let you know what I find.
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 07:59 AM
тАО05-23-2002 07:59 AM
Solution2. what does it do well? It explains the reason for the changes and the affects that changes make to your system very well.
3. what is it missing? The TODO list should include more information such as using IPF_9000, IDS, Trusted Computing Base info...
- critical functionality?
- would be nice to see in the future? Installation options for other security tools
4. what do you think about HP participating in the open source process? Would you be willing to help? I think it is very important that HP participates in the open source process. I would be willing to help althought I don't do a whole lot of programming so...
Great Start!
Craig
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 08:07 AM
тАО05-23-2002 08:07 AM
Re: HP-UX Bastille - lockdown/hardening tool
I think it is very important that HP participates in the open source process. I would be willing to help althought I don't do a whole lot of programming so...
Actually, the most important part is writing relevant, useful questions which explain the tradeoffs of each action. From there, the basic steps to implement that action are required, and then implementation and testing.
If you're really interested, you can help even if you're not a programmer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 08:32 AM
тАО05-23-2002 08:32 AM
Re: HP-UX Bastille - lockdown/hardening tool
This tool is useful. It had several suggestions for hardening that I had not thought of when I hardened our image.
It doesn't seem to be missing much. I really like how everything you enter in and everything it does is logged. It is really nice to have the output if you need it.
I think HP should participate in the open source process. This will help HPUX pick up things it needs faster. We would be willing to help.
We are a University. (Education.)
Hope it helps
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 08:49 AM
тАО05-23-2002 08:49 AM
Re: HP-UX Bastille - lockdown/hardening tool
I found it very useful.
2. what does it do well?
It explains the reasoning behind each of the hardening suggestions quite well.
3. what is it missing?
- critical functionality
none that I'm aware of
- would be nice to see in the future
none that I'm aware of
4. what do you think about HP participating in the open source process?
Great
Would you be willing to help?
If I could
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 09:09 AM
тАО05-23-2002 09:09 AM
Re: HP-UX Bastille - lockdown/hardening tool
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 09:25 AM
тАО05-23-2002 09:25 AM
Re: HP-UX Bastille - lockdown/hardening tool
As John noted, the .gz version of the file appears not to be zipped. At least gunzip certainly didn't think it was. However, swinstall was perfectly happy to install it with the .gz extension. Just minor nit-picking - not with the product but with the install instructions.
Thanks again,
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2002 01:06 PM
тАО05-23-2002 01:06 PM
Re: HP-UX Bastille - lockdown/hardening tool
Also, it would be nice if one decides to keep things like ftp open, that it asks if you want to set an ftp umask (i.e. ftp -l -u 002 for the entry for ftp.) That way, if they leave ftp open, the files are protected by whatever umask the user wants, just like you recommend for the regular umask.
Hope it helps
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 05:12 AM
тАО05-24-2002 05:12 AM
Re: HP-UX Bastille - lockdown/hardening tool
bastille was one of those tools i missed most on hpux. (with regard to security)
no need to say i find it very usefull.
4. what do you think about HP participating in the open source process? Would you be willing to help?
i think hp is doing great open source work. bastille is not the only project they are working on. but i see there is still lot of room for improvement on some other projects.
i would certainly like to help, isn't that what 'being open' is all about.
> We're currently coordinating with the Linux Bastille team, and I'll post a stable URL when we have one. In the meantime, if you'd like to take it for a spin, just send email to bastille-feedback@fc.hp.com
bastille linux 2.0-beta with HPUX support is available from the bastille site already:
http://www.bastille-linux.org/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 05:39 AM
тАО05-24-2002 05:39 AM
Re: HP-UX Bastille - lockdown/hardening tool
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 07:20 AM
тАО05-24-2002 07:20 AM
Re: HP-UX Bastille - lockdown/hardening tool
I'm hoping this will be a really useful tool.
I'm trying to install it and got error while installing it, for Perl_TK.
I do have Perl 5.6.1 installed on system.
How do I overcome this.
Thanks.
Prashatn.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 08:58 AM
тАО05-24-2002 08:58 AM
Re: HP-UX Bastille - lockdown/hardening tool
give us a URL to break into!
Later,
Bill
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 08:59 AM
тАО05-24-2002 08:59 AM
Re: HP-UX Bastille - lockdown/hardening tool
I have added information about inetd.sec/tcpwrappers (not yet in the Beta version) in the TODO list if the user wants the reminder about securing inetd services.
ftpd has a default umask of 027. This results in reasonably secure permissions to begin with. It's likely that if we added the option to change this, people might actually change it to be less secure.
Thanks for the input!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-24-2002 06:23 PM
тАО05-24-2002 06:23 PM
Re: HP-UX Bastille - lockdown/hardening tool
I have found the CIS Security benchmark for HP-UX a very decent and detailed resource for manual hardening of HP-UX (up to HP-UX 11i i.e. talks about disabling executable stack etc).
http://www.cisecurity.org/bench_HPUX.html
It could serve as one source of reference for additional hardenings that may be worth automating in HP-UX Bastille
Hope this helps. Regards.
Steven Sim Kok Leong
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-25-2002 02:06 AM
тАО05-25-2002 02:06 AM
Re: HP-UX Bastille - lockdown/hardening tool
-Santosh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-26-2002 08:12 PM
тАО05-26-2002 08:12 PM
Re: HP-UX Bastille - lockdown/hardening tool
You *need* to install the B.5.6.1.C version of perl from http://www.software.hp.com
The existing version 5.6.1 on it's own will not work. The version from the porting centre will not work either. The link to the perl depot software is in Keith's email which you would have received. I had the same problem and this is how it was solved.
Cheers
~Michael~
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2002 07:56 AM
тАО05-27-2002 07:56 AM
Re: HP-UX Bastille - lockdown/hardening tool
In response to Steven's comments: Yes, we have looked at the CIS benchmark for candidates for inclusion into Bastille. Using Bastille can raise your CIS score substantially. (try it and let us know what you find!) Hopefully we will be including more of these items in the future. Any indications as to which of those items would be most important to you would be helpful.
When deciding upon the most important things to do first, we looked at the HP-UX Bastion Host whitepaper, Bastille Linux, and several customers' hardening scripts/procedures. If any of you have a step in your hardening procedure that is still missing, let us know.
If you'd like to see it go into Bastille sooner, you can provide us with a well-written explanation of the trade-offs (like Bastille questions today) and/or a step-by-step procedure to automate it (run this command, append a line to this file, etc.) That way it will be ready to include in Bastille quickly and you will be helping HP to serve your needs better through the open source process.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-27-2002 10:58 AM
тАО05-27-2002 10:58 AM
Re: HP-UX Bastille - lockdown/hardening tool
first, thanks for your work on this!
Then, since I was not able to install it on a local system here (back from Qatar at 6:30am, 1 hour travel from the airport, first meeting at 10:00am = hav had no time, yet), a few questions:
- do you have (and maintain) a list of "least privileges" for directories/devices/files?
- do you describe only the basic operationg system, or even some (all?) of the OpenView tools (other HP products)?
- does it include all the details usually given by Bill Hassell on this topic?
- does it use "ssh" and "scp" (or "rsync" over "ssh") instead of "telnet" and "ftp"?
- will this be "recommended" or even be "supported" by HP?
Regards,
Wodisch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-28-2002 10:41 AM
тАО05-28-2002 10:41 AM
Re: HP-UX Bastille - lockdown/hardening tool
Since locking down a server is a time consuming process, something like this can only help. Sounds like the same thing they have for Sun Solaris (YASSP, etc).
Hopefully since this is a HP product it will be able to "handle" the full suite (or most of them anyway) of OpenView products.
HTH, Gino.