HP
UX Security Products and Features Software
manual
Install
Symbols
Administrator keys
Configuring
Software distributor issues
File access policies
Quick setup examples
Commands
Bpbackup -f backuplist
# make clean
Page 61
61
Page 60
Page 62
Image 61
Page 60
Page 62
Contents
HP-UX Whitelisting A.01.00 Administrator Guide
Copyright 2010 Hewlett-Packard Development Company, L.P
Table of Contents
HP Serviceguard considerations
Glossary Index
List of Figures
List of Examples
Page
File access policies
Security features
File lock access controls
Capabilities
Identity-based access controls
4 api
Page
WLI architecture
Product overview
Application API
Commands
Applications
WLI metadata files
WLI database
3 .$WLISIGNATURE$
Page
Generating keys
Key usage
User keys
Administrator keys
Installation requirements
Installing, removing, and upgrading
Installing WLI
Removing WLI
Upgrading WLI
Page
Authorizing the recovery key
Configuring
Authorizing administrator keys
Backing up the WLI database
Signing DLKMs
Rebooting to restricted mode
Page
Signing an executable binary
Enhancing security with WLI
Creating a Flac policy
Enabling DLKMs to load during boot
Removing a file access policy
Creating an Ibac policy
Wlisign -a -k adminpriv /usr/sbin/kcmodule
# wlisign -a -k /home/admin1/adminpriv /usr/conf/mod/ciss
Loading unsigned DLKMs
# kcmodule ciss=unused
Page
Overview
Backup and restore considerations
WLI database files
Write protected
Policy protected and metadata files
Read/write protected files
Recommendations
Ibac policies
Flac policies
Metadata files
Page
Administration
HP Serviceguard considerations
WLI database
Policy protected files
Software distributor issues
Troubleshooting and known issues
WLI reinstallation
Lost WLI administrator key or passphrase
Su root # rm -r /etc/wli
Wlisyspolicy -s mode=maintenance -k adminkey
# tar -xf /tmp/wlikeydb.tar
# kcmodule wli=unused # shutdown -r
Contacting HP
Support and other resources
Related information
Websites
Typographic conventions
User input
Times
Page
Instructions
# make clean
# make all
# su wliusr1
Ibac add and delete program
Flac add and delete program
Ibac add and delete program
Page
Administration examples
Su root # wlisign -a -k adm1.pvt /usr/bin/tar
Wlicert -s -c wli.admin1 -o wmd -k adm1.pvt
Bdf mydir
Tar -vtf tartest.tar
Cat /tmp/.$WLIFSPARMS$
Wlisys -k adm1.pvt -s wmdstoretype=pseudo
Bprestore -f backuplist
Bpbackup -f backuplist
Configuring WLI
Quick setup examples
Authorizing an administrator key
Authorizing a user key
Flac policies
Testing a Flac policy
Creating a Flac policy
Enabling a Flac policy
Ibac policies
Removing an Ibac policy
Disabling an Ibac policy
ASM
Glossary
Page
Index
Symbols
Index
Related manuals
Manual
130 pages
58.55 Kb
Related pages
Troubleshooting ideas for WatchGuard Technologies Firebox X
Error message on Smart Hub for Samsung UN65F9000AF
Bolt Sizing Chart for Hoist Fitness HD-3600
Where to get additional information for HP 8300 8300
Installing the Speakers for Sonance THINLINETM
Parts List Model 75 Dust Collector for Powermatic 75
Language code list for Toshiba D-R2SC
Queue-to Main Split and Check-Backup Split for AT&T 555-230-520
How often should I replace the batteries in my ReliOn monitor?
Get replacement advice
Top
Page
Image
Contents