B Configuring HP-UX Bastille for use with Serviceguard
B.1 Configuring Sec20MngDMZ or Sec30DMZ security levels
Serviceguard uses dynamic ports. To enable operation, the
For more information about
http://docs.hp.com/en/netsys.html.
Before you open the Serviceguard port range, review the required
http://docs.hp.com/en/internet.html
When the Serviceguard security patch of 2004 is installed, Serviceguard requires identd. To enable identd:
1.Edit the
Should Bastille ensure inetd's ident service does not run on this system?
Change the answer from Y to N.
SecureInetd.deactivate_ident=N
2.Apply the configuration file changes.
•If you have not made any configuration changes to the system since the last time
a.Revert to the previous
#bastille -r
b.Apply the new
#bastille
•If the you have applied configuration changes to the system since the last time
a.Remove the # from the /etc/inetd.conf file line:
#auth stream tcp6 wait bin /usr/lbin/identd identd
b.Force inetd to read the configuration:
#inetd
B.2 Configuring Sec10Host level
If
SecureInetd.deactivate_ident=Y
Change the Y to N:
SecureInetd.deactivate_ident=N
If you are using the Serviceguard SNMP subagent, set:
MiscellaneousDaemons.snmpd=N
B.1 Configuring Sec20MngDMZ or Sec30DMZ security levels 31