- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: HP-UX Security Guidlines
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2002 12:09 PM
11-22-2002 12:09 PM
HP-UX Security Guidlines
IBM has a document entitled: Strengthening AIX Security: A System-Hardening Approach along with several other Redbooks
SUN has documents entitled Solaris Operating Environment Security & Solaris Operating Environment Network Settings for Security
These documents give specific recommendations for increasing security in the base OS.
The document HP-UX 11 Security at:
http://www.hp.com/products1/unix/operating/infolibrary/whitepapers/sec9906.pdf
only lists HP-UX security features, not specific instructions on how to implement them.
Thanks in advance,
Brian
<*(((>< er
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2002 12:17 PM
11-22-2002 12:17 PM
Re: HP-UX Security Guidlines
If you haven't seen this you might find it useful:
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6849AA
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2002 12:21 PM
11-22-2002 12:21 PM
Re: HP-UX Security Guidlines
http://www2.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&docId=200000063104650
It is in the TKB as document ID USECKBAN00000800
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-22-2002 12:21 PM
11-22-2002 12:21 PM
Re: HP-UX Security Guidlines
Totally concur with JRF.
Bastille is the way to go.
Not only will it point out the deficiencies & weak points, it can solve them as well.
And the real-time help & messages it gives are great.
Rgds,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-24-2002 03:06 PM
11-24-2002 03:06 PM
Re: HP-UX Security Guidlines
HP-UX Bastille is the initial set of recommendations from HP. We felt that a tool was more useful than a whitepaper, as it can be applied consistently across many machines. However, looking at the points that you have assigned, it appears that you prefer papers with a lot of manual procedures. Care to share why? If it's really important, perhaps we could look into publishing the Bastille recommendations on paper.
(Note: the Bastion Host whitepaper was one of many sources used in compiling the content for HP-UX Bastille.)
-Keith, HP-UX Bastille developer :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-24-2002 03:35 PM
11-24-2002 03:35 PM
Re: HP-UX Security Guidlines
I replaced our Virtual Vault OS's (an HP product that was just to difficult to work with) with bastion hosts, hosts that had all unnecessary services shutoff and sometimes removed. I used Kevin Steves bastion host paper as a starting point: http://people.hp.se/stevesk/bastion.html. I also got Kevin's permission to use parts of his document in my project plans, with of course the proper acknowledgements and links to the original documents.
We even apply that same knowledge to our sun servers.
live free or die
harry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-25-2002 04:57 AM
11-25-2002 04:57 AM
Re: HP-UX Security Guidlines
hmmm... how about, learning something more, than just watching a tool, do its job ?
Is this a good reason why someone would prefer a whitepaper than a ready-to-run tool (like SATAN, etc,etc...)
Greetings,
NikosK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-26-2002 09:06 PM
11-26-2002 09:06 PM
Re: HP-UX Security Guidlines
I do have a book on HP-UX Security that covers the basics on the UNIX OS and HP specific features. You can see the book TOC at my web-site. I also have some book updates and other papers at my site.
http://newfdawg.com/SecBook.htm
- Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2002 04:26 AM
11-27-2002 04:26 AM
Re: HP-UX Security Guidlines
James - The Bastille product looks like it can help securing my HP systems, but it doesn't aid in setting a starting point for my Security department to write a standard
Patrick - The Bastion white paper is the best reference I have seen so far, but it still falls short compared to IBM & Sun papers
Keith - Although the Bastille tool can be directly applied, it is not useful when writing a UNIX security standard. A white paper going in to detail as to what is being changed and why would be a GREAT companion to the tool.
Chris - I already own HP-UX 11i security and it is a wonderful reference. I was just hoping for a summary white paper from HP.
Thanks again for the responses.
If you have any other suggestions, please let me know,
Brian
<*(((>< er
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2002 08:15 AM
11-27-2002 08:15 AM
Re: HP-UX Security Guidlines
Here's another suggestion for you.
Center for Information Security i.e. http://www.cisecurity.org has clear and detailed level 1 security guidelines for HP-UX 10.20, HP-UX 11.00 and HP-UX 11i.
Hope this helps. Regards.
Steven Sim Kok Leong
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-27-2002 08:39 AM
11-27-2002 08:39 AM
Re: HP-UX Security Guidlines
Thanks for clarifying. As long as we're on the topic, I'm wondering:
What would be missing from this 'whitepaper' that you need if I just put all of the Bastille explanatory text into pdf format? It already explains what it is doing and why. It makes recommendations and allows the user to choose whether or not to apply it. This could be used by your policy board to say "Apply this Bastille config to all your systems."
These explanations are in human-readable form. The Bastille code is also opensource and relatively easy to follow if you're interested in the details of what is actually being done to the system. (I know, that statement doesn't go very far coming from a developer...but really, if you take an hour
or so and just look at the modules in /opt/sec_mgmt/lib/bastille, it is pretty straightforward to find implementation for a given question/action.)
I'll also mention the CIS whitepapers. They overlap significantly with Bastille, but they are in 'paper' form rather than as a tool. And, they're available for Solaris, HP-UX, Linux, and maybe AIX soon.
Thanks.
-Keith