HP
UX Bastille Software
manual
HP-UX Bastille Version B.3.3 User Guide
Troubleshooting
Install
Password
AccountSecurity.SUDEFAULTPATH
Login
IPFilter.blockhpidsadmin
Configuring a system
MiscellaneousDaemons.xaccess
HPUX.screensavertimeout
Weight
Page 1
HP-UX
Bastille Version B.3.3 User Guide
HP Part Number:
5900-0871
Published: June 2010
Edition: 1
Page 1
Page 2
Image 1
Page 1
Page 2
Contents
HP-UX Bastille Version B.3.3 User Guide
Trademark Acknowledgments
Table of Contents
Index
HP-UX Bastille user interface Standard assessment report
List of Figures
Question modules Security levels
List of Tables
About this product
Features and benefits
Performance
Compatibility
Support
Installation requirements
Installing HP-UX Bastille
Installation
Page
Creating a security configuration profile
Using HP-UX Bastille
1shows the main screen of the HP-UX Bastille user interface
If the Path environment variable has not been updated, use
Assessing a system
Configuring a system
Accepted standard configurations are detected
Using scored reports
Configuration for the corresponding question is not
Is not always detected. HP-UX Bastille might not detect all
Scored assessment report
# bastille -r
Reverting
Locating files
Monitoring drift
For more information, see bastilledrift1M
Var/opt/secmgmt/bastille/log/Assessment/Drift.txt
Check for a TOREVERT.txt file
Removing HP-UX Bastille
If the file exists, complete the actions listed
Page
Diagnostic tips
Troubleshooting
Known issues and workarounds
General use tips
Errors related to individual configuration files
Problems opening, copying, or reading files
HP-UX Bastille configures a firewall using IPFilter
Cannot use X because $DISPLAY is not set
Contacting HP
Support and other resources
Related information
Typographic conventions
To complete a task
Or damage to hardware or software
Supplement important points of the main text
Page
Choosing security levels
Install-Time Security ITS using HP-UX Bastille
Enable kernel-based stack execute protection
Table A-3 Additional Sec20MngDMZ security settings1
Choosing security dependencies
Selecting security levels during installation
Configuring Sec20MngDMZ or Sec30DMZ security levels
Configuring HP-UX Bastille for use with Serviceguard
Configuring Sec10Host level
Page
Question modules
AccountSecurity.hidepasswords
AccountSecurity.guilogin
AccountSecurity.crontabsfile
AccountSecurity.cronuser
AccountSecurity.NOLOGIN
AccountSecurity.MINPASSWORDLENGTH
AccountSecurity.NUMBEROFLOGINSALLOWED
AccountSecurity.lockaccountnopasswd
AccountSecurity.PASSWORDHISTORYDEPTH
AccountSecurity.NUMBEROFLOGINSALLOWEDyn
AccountSecurity.PASSWORDHISTORYDEPTHyn
AccountSecurity.PASSWORDMAXDAYS
AccountSecurity.serialportlogin
AccountSecurity.passwordpolicies
AccountSecurity.singleuserpassword
AccountSecurity.restricthome
AccountSecurity.SUDEFAULTPATHyn
AccountSecurity.SUDEFAULTPATH
AccountSecurity.systemauditing
AccountSecurity.umask
AccountSecurity.unownedfiles
AccountSecurity.umaskyn
AccountSecurity.userdotfiles
AccountSecurity.userrcfiles
Apache.deactivatehpwsapache
Apache.chrootapache
DNS.chrootbind
FTP.ftpusers
FilePermissions.worldwriteable
HPUX.guibanner
HPUX.mailconfig
HPUX.ndd
HPUX.othertools
HPUX.restrictswacls
HPUX.screensavertimeout
HPUX.scanports
HPUX.stackexecute
IPFilter.blockcfservd
HPUX.tcpisn
IPFilter.blockDNSquery
IPFilter.blockhpidsagent
IPFilter.blockhpidsadmin
You are managing some remote Hids agents, answer no
Hids does not
IPFilter.blocknetrange
Default 192.168.1.0/255.255.255.0 Description
IPFilter.blockping
IPFilter.blockSecureShell
IPFilter.configureipfilter
IPFilter.blockwebadmin
IPFilter.blockwbem
Otherwise, answer no to this question
Page
MiscellaneousDaemons.configuressh
IPFilter.installipfilter
MiscellaneousDaemons.diagnosticslocalonly
MiscellaneousDaemons.disableptydaemon
MiscellaneousDaemons.disablebind
MiscellaneousDaemons.disablepwgrd
MiscellaneousDaemons.disablerbootd
MiscellaneousDaemons.disablesmbserver
MiscellaneousDaemons.disablesmbclient
MiscellaneousDaemons.nfscore
MiscellaneousDaemons.nobodysecurerpc
Otherbootserv
MiscellaneousDaemons.xaccess
MiscellaneousDaemons.sysloglocalonly
Patches.spccrontime
Patches.spccronrun
Patches.spcproxyyn
Patches.spcrun
Printing.printing
SecureInetd.deactivatebootp
SecureInetd.banners
SecureInetd.deactivatedttools
SecureInetd.deactivatebuiltin
SecureInetd.deactivatefinger
SecureInetd.deactivateftp
SecureInetd.deactivatektools
SecureInetd.deactivateident
SecureInetd.deactivatentalk
SecureInetd.deactivateprinter
SecureInetd.deactivaterquotad
SecureInetd.deactivaterecserv
SecureInetd.deactivatertools
SecureInetd.deactivateswat
SecureInetd.deactivatetime
SecureInetd.deactivatetftp
SecureInetd.deactivateuucp
SecureInetd.ftplogging
SecureInetd.inetdgeneral
SecureInetd.loginetd
SecureInetd.owner
Sendmail.sendmailcron
Sendmail.vrfyexpn
Sendmail.sendmaildaemon
Page
All.weight
Sample weight files
Sample weight file below aligns with the CIS standard
CIS.weight
CIS.weight
Page
CIS ID
CIS mapping to HP-UX Bastille
Apache.deactivatehpwsapache
AccountSecurity.lockaccountnopasswd
Page
Index
Related pages
Troubleshooting Suggestions for Bloomfield 8781A
Specifications for Nikon AF DC-NIKKOR
Indicator Light for Changhong Electric TM150F7E, TM201F7E
Figure 10. Flow Chart Mono Continuous Mode for Texas Instruments TLV1562
How to Use for Flymo EHT 530
Install the LP Cylinder LP Models only for Vermont Casting VCS501
Exploded View and Parts List Wheel KIT for Briggs & Stratton 030227
Language Code List for Sylvania DVL1000
What common issues are addressed in the
Craftsman 580.752 manual
?
Top
Page
Image
Contents