1830885 Members
1722 Online
110017 Solutions
New Discussion

System Security

 
SOLVED
Go to solution
Larry Scheetz
Advisor

System Security

Admins, There use to be a Hp mailing list for security "support.mayfield.hp.com" I see that is not around no more. Is there a mailing list I can get on to get updates on all security issues and patch information for Hp's?
A Happy heart makes the face cheerful
5 REPLIES 5
Cheryl Griffin
Honored Contributor
Solution

Re: System Security

HP provides Security Bulletins which can be sent automatically to notify you of security issues on your system. Connect to the ITRC --> Maintenance & Support tab (at the left of screen) --> under Notifications --> Support Information Digests --> select the check box for Security Bulletins Digest. To see archived security digests, scroll to the bottom of the page and follow the link.

In addition you should get the security_patch_check utility from www.software.hp.com. security_patch_check is a tool which can be used to download the latest data about security patches and compare it to the software installed on the system. The tool reports which security patches are missing from a system based on the security patch matrix which is derived from Security bulletins. It reports the "best" patch to install if the "low water mark patch" or a superceding patch is not installed. Also, any recalled patches which are present on the system will be reported. It works through a firewall, with the help of a web-proxy or similar network device. security_patch_check tool is supported on 11.00, 11.04, 11i (11.11), and future releases of 11i.

Cheryl
"Downtime is a Crime."
Larry Scheetz
Advisor

Re: System Security

Also, is there any other good programs out there to check your systems security besides like satan?
A Happy heart makes the face cheerful
harry d brown jr
Honored Contributor

Re: System Security

The security bulletins digest has been split into multiple digests based on the operating system (HP-UX, MPE/iX, and HP Secure OS Software for Linux). You will continue to receive all security bulletin digests unless you choose to update your subscriptions.

To update your subscriptions, use your browser to access the IT Resource Center on the World Wide Web at:

http://www.itresourcecenter.hp.com/

Under the Maintenance and Support Menu, click on the "more..." link.

Then use the 'login' link at the left side of the screen to login using your IT Resource Center User ID and Password.

Under the notifications section (near the bottom of the page), select Support Information Digests.


live free or die
harry
Live Free or Die
Cheryl Griffin
Honored Contributor

Re: System Security

HP provides risk management consulting, see
http://www.hp.com/hps/tech/security/risk/

See also http://www.hp.com/products1/unix/operating/security/

And
http://www.docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90742/B2355-90742_top.html&con=/hpux/onlinedocs/B2355-90742/00/00/63-con.html&toc=/hpux/onlinedocs/B2355-90742/00/00/63-toc.html&searchterms=virus&queryid=20010830-035340

In addition, stay on top of security alerts by checking: http://www.cert.org/nav/index_main.html

Here is also a site I ran across that may have some good info. I have not run any of these but someone else may be able to comment on their usefulness
http://www.cisecurity.org/bench_HPUX.html

Cheryl
"Downtime is a Crime."
Jeff Schussele
Honored Contributor

Re: System Security

Hi Larry,

You should also take a look at a new HP Security product named Bastille.
This is a SW tool which queries your system & makes suggestion on how to harden it down and based upon operator response it will/won't actually make those changes.
Best thing is that it's free & supported.
Here's the URL:

http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=B6849AA

Rgds,
Jeff
PERSEVERANCE -- Remember, whatever does not kill you only makes you stronger!