- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- HP-UX Bastille or TCB Trusted mode?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2006 04:34 AM
09-19-2006 04:34 AM
The question is: I can use Bastille or use Trusted-mode or use Bastille in Trusted mode? they are excluding?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2006 05:21 AM
09-19-2006 05:21 AM
SolutionTrusted computing on the other hand is a way of enabling more security features on your hpux server, making it easier to audit. I am not sure if a trusted server is mutually exclusive from a bastion server. But if you are talking about securing a server that many people log in and out every day, TCB (trusted computing) server is the way to go. If you are going to need a server to handle your company web site, facing internet everyday but interactive access will be few and far between, use bastion servers.
Hope this helps
UNIX because I majored in cryptology...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2006 09:44 AM
09-19-2006 09:44 AM
Re: HP-UX Bastille or TCB Trusted mode?
If you have to secure your system, download the security_patch_check script from software.hp.com. Run the program to get a listing of problems, fix them all, then convert to Trusted, and run Bastille. Now start testing to see if some application fails due to high security.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2006 10:49 AM
09-19-2006 10:49 AM
Re: HP-UX Bastille or TCB Trusted mode?
I recommend both approaches.
Note that Bastille makes your system more efficient because it stops vulnerable and little used daemons from running.
Bastille is not required to bring a system to trusted mode.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-20-2006 04:30 AM
09-20-2006 04:30 AM
Re: HP-UX Bastille or TCB Trusted mode?
I'm on the HP-UX Bastille team, and I'd like to add a couple clarifications, if I may. Bastille is a security-configuration engine. It allows you to either use the GUI to interactively and selectively configure your system to be more secure. Alternatively, HP ships some "canned" security profiles with 11.23, that you can select at installation time (see HP-UX Install and Update Guide for reference). One of the many things Bastille can do is enable Trusted Mode, which gives you access to some better account-security policy settings on 11.11 and early 11.23 releases. In later 11.23 OEUR's and in upcoming 11.31 (see 11.31 press release), most of the settings that required Trusted Mode... no longer do... and since Trusted Mode does have some (minor) PAM support issues, I'd recommend only using Trusted Mode on 11.11 and pre OEUR 0505 11.23.
All that said, if you use Bastille... it will just figure out your best settings / conversion options based on the policies you set :-).
Also note that security is not just for servers on the edge of your network. There are a growing number of studies that show the threat is on the inside as well, so lock-down is important throughout your enterprise. See interesting stats from McAfee as quoted from Bruce Schneier:
* One in five workers (21%) let family and friends use company laptops and PCs to access the Internet.
* More than half (51%) connect their own devices or gadgets to their work PC.
* A quarter of these do so every day.
* Around 60% admit to storing personal content on their work PC.
* One in ten confessed to downloading content at work they shouldn't.
* Two thirds (62%) admitted they have a very limited knowledge of IT Security.
* More than half (51%) had no idea how to update the anti-virus protection on their company PC.
* Five percent say they have accessed areas of their IT system they shouldn't have.
http://www.schneier.com/blog/archives/2005/12/insider_threat.html