HP
UX Security Products and Features Software
manual
Install
Symbols
Administrator keys
Configuring
Software distributor issues
File access policies
Quick setup examples
Commands
Bpbackup -f backuplist
# make clean
Page 1
HP-UX
Whitelisting A.01.00 Administrator Guide
HP-UX
11iv3
HP Part Number:
5992-5210
Published: September 2010
Edition: 1
Page 1
Page 2
Image 1
Page 1
Page 2
Contents
HP-UX Whitelisting A.01.00 Administrator Guide
Copyright 2010 Hewlett-Packard Development Company, L.P
Table of Contents
HP Serviceguard considerations
Glossary Index
List of Figures
List of Examples
Page
File access policies
Security features
File lock access controls
Capabilities
Identity-based access controls
4 api
Page
WLI architecture
Product overview
Application API
Commands
Applications
WLI metadata files
WLI database
3 .$WLISIGNATURE$
Page
Generating keys
Key usage
User keys
Administrator keys
Installation requirements
Installing, removing, and upgrading
Installing WLI
Removing WLI
Upgrading WLI
Page
Authorizing the recovery key
Configuring
Authorizing administrator keys
Backing up the WLI database
Signing DLKMs
Rebooting to restricted mode
Page
Signing an executable binary
Enhancing security with WLI
Creating a Flac policy
Enabling DLKMs to load during boot
Removing a file access policy
Creating an Ibac policy
Wlisign -a -k adminpriv /usr/sbin/kcmodule
# wlisign -a -k /home/admin1/adminpriv /usr/conf/mod/ciss
Loading unsigned DLKMs
# kcmodule ciss=unused
Page
Overview
Backup and restore considerations
WLI database files
Write protected
Policy protected and metadata files
Read/write protected files
Recommendations
Ibac policies
Flac policies
Metadata files
Page
Administration
HP Serviceguard considerations
WLI database
Policy protected files
Software distributor issues
Troubleshooting and known issues
WLI reinstallation
Lost WLI administrator key or passphrase
Su root # rm -r /etc/wli
Wlisyspolicy -s mode=maintenance -k adminkey
# tar -xf /tmp/wlikeydb.tar
# kcmodule wli=unused # shutdown -r
Contacting HP
Support and other resources
Related information
Websites
Typographic conventions
User input
Times
Page
Instructions
# make clean
# make all
# su wliusr1
Ibac add and delete program
Flac add and delete program
Ibac add and delete program
Page
Administration examples
Su root # wlisign -a -k adm1.pvt /usr/bin/tar
Wlicert -s -c wli.admin1 -o wmd -k adm1.pvt
Bdf mydir
Tar -vtf tartest.tar
Cat /tmp/.$WLIFSPARMS$
Wlisys -k adm1.pvt -s wmdstoretype=pseudo
Bprestore -f backuplist
Bpbackup -f backuplist
Configuring WLI
Quick setup examples
Authorizing an administrator key
Authorizing a user key
Flac policies
Testing a Flac policy
Creating a Flac policy
Enabling a Flac policy
Ibac policies
Removing an Ibac policy
Disabling an Ibac policy
ASM
Glossary
Page
Index
Symbols
Index
Related manuals
Manual
130 pages
58.55 Kb
Related pages
All Admin page
Administrere snarveier for Samsung SM-A310FZKANEE
HP Web Jetadmin Common Tasks Task Module for HP Web Jetadmin Software
Administrarea Aparatului for Xerox COPYCENTRE C20
DSS vs WebJet Admin for HP MFP Sending Software 4.9X
Migrating CMS System Administration Data to the New Server for Lucent Technologies Release 3 Version 8
Administration for Asus GigaX
Admin Configure Dsc serial serial ID rack for Cisco Systems Cisco IOS XR
Administrator Reset for StarTech.com SV1107IPEXT
Administration NetEngine IAD User Guide for Polycom 7000
Where can I find the
RF217ACRS manual
?
Top
Page
Image
Contents