Actions | Adds a summary description of HP security and services to the TODO.txt |
| file for user reference. |
HP_UX.restrict_swacls
Headline | Restrict remote access to swlist. |
Default | N |
Description | The swagentd daemon allows remote access to list and install software on |
| your system. This feature is convenient for remote administration. Security |
| Patch Check can use this to query remote machines. It can also be a security |
| risk because patch and other critical system information is available to anyone |
| inside that system's firewall. HP recommends that you disallow the swagentd |
| default, remote read access. |
Actions | If the swagentd daemon is running, use swacl to remove remote read access: |
| swacl |
| swacl |
| Otherwise, an item is created in the TODO.txt file to remind you to run |
| Bastille again when the daemon is up. |
HP_UX.scan_ports
Headline | Provide instructions in your TODO.txt file on how to run a port scan. |
Default | N |
Description | One of the final steps in lock down is to verify that only the services you need |
| are still running. Several tools do this, including netstat which is included |
| with |
| The lsof tool provides information about all the processes running on your |
| system. If there are processes running that you don't recognize, take this |
| opportunity to do some research and learn about them. |
| IMPORTANT: Manual action required to complete this configuration. See |
| the TODO.txt file for details. |
Actions | Provide instructions in your TODO.txt file on how to run a port scan. |
HP_UX.screensaver_timeout | |
Headline | Set the GUI |
Default | N |
Description | The GUI login |
| on the |
| minutes. Setting a short timeout ensures that extended absences don't leave |
| a console unnecessarily open. |
Actions | For all sys.resources files in /usr/dt/config/* directories, modify the |
| matching /etc/dt/config/*/sys.resources file by adding the following |
| lines: |
dtsession*saverTimeout: 10
dtsession*lockTimeout: 10
Create the matching /etc/dt/config/*/sys.resources files if not present.
HP_UX.stack_execute
Headline | Enable |
44 Question modules