HP UX Bastille Software manual CIS.weight, Sample weight file below aligns with the CIS standard

Page 64

MiscellaneousDaemons.disable_bind=1

MiscellaneousDaemons.disable_ptydaemon=1

MiscellaneousDaemons.disable_pwgrd=1

MiscellaneousDaemons.disable_rbootd=1

MiscellaneousDaemons.disable_smbclient=1

MiscellaneousDaemons.disable_smbserver=1

MiscellaneousDaemons.nfs_client=1

MiscellaneousDaemons.nfs_core=1

MiscellaneousDaemons.nfs_server=1

MiscellaneousDaemons.nis_client=1

MiscellaneousDaemons.nis_server=1

MiscellaneousDaemons.nisplus_client=1

MiscellaneousDaemons.nisplus_server=1

MiscellaneousDaemons.nobody_secure_rpc=1

MiscellaneousDaemons.other_boot_serv=1

MiscellaneousDaemons.snmpd=1

MiscellaneousDaemons.syslog_localonly=1

MiscellaneousDaemons.xaccess=1

Patches.spc_cron_run=1

Patches.spc_run=1

Printing.printing=1

SecureInetd.banners=1

SecureInetd.deactivate_bootp=1

SecureInetd.deactivate_builtin=1

SecureInetd.deactivate_dttools=1

SecureInetd.deactivate_finger=1

SecureInetd.deactivate_ftp=1

SecureInetd.deactivate_ident=1

SecureInetd.deactivate_ktools=1

SecureInetd.deactivate_ntalk=1

SecureInetd.deactivate_printer=1

SecureInetd.deactivate_recserv=1

SecureInetd.deactivate_rquotad=1

SecureInetd.deactivate_rtools=1

SecureInetd.deactivate_swat=1

SecureInetd.deactivate_telnet=1

SecureInetd.deactivate_tftp=1

SecureInetd.deactivate_time=1

SecureInetd.deactivate_uucp=1

SecureInetd.ftp_logging=1

SecureInetd.log_inetd=1

SecureInetd.owner=1

Sendmail.sendmailcron=1

Sendmail.sendmaildaemon=1

Sendmail.vrfyexpn=1

D.2 CIS.weight

The sample weight file below aligns with the CIS standard.

AccountSecurity.AUTH_MAXTRIES=1

AccountSecurity.MIN_PASSWORD_LENGTH=1

AccountSecurity.PASSWORD_HISTORY_DEPTH=1

AccountSecurity.PASSWORD_MAXDAYS=1

AccountSecurity.PASSWORD_MINDAYS=1

AccountSecurity.PASSWORD_WARNDAYS=1

AccountSecurity.atuser=1

AccountSecurity.block_system_accounts=1

AccountSecurity.create_securetty=1

AccountSecurity.crontabs_file=1

AccountSecurity.cronuser=1

AccountSecurity.gui_login=1

AccountSecurity.hidepasswords=1

AccountSecurity.lock_account_nopasswd=1

AccountSecurity.mesgn=1

64 Sample weight files

Image 64
Contents HP-UX Bastille Version B.3.3 User Guide Trademark Acknowledgments Table of Contents Index List of Figures HP-UX Bastille user interface Standard assessment reportList of Tables Question modules Security levelsFeatures and benefits About this productPerformance CompatibilitySupport Installation requirements Installing HP-UX BastilleInstallation Page Using HP-UX Bastille Creating a security configuration profileIf the Path environment variable has not been updated, use 1shows the main screen of the HP-UX Bastille user interfaceConfiguring a system Assessing a systemUsing scored reports Accepted standard configurations are detectedConfiguration for the corresponding question is not Is not always detected. HP-UX Bastille might not detect allScored assessment report Reverting # bastille -rLocating files Monitoring driftFor more information, see bastilledrift1M Var/opt/secmgmt/bastille/log/Assessment/Drift.txt Check for a TOREVERT.txt file Removing HP-UX BastilleIf the file exists, complete the actions listed Page Troubleshooting Diagnostic tipsKnown issues and workarounds General use tipsProblems opening, copying, or reading files Errors related to individual configuration filesHP-UX Bastille configures a firewall using IPFilter Cannot use X because $DISPLAY is not setContacting HP Support and other resourcesRelated information Typographic conventions To complete a task Or damage to hardware or softwareSupplement important points of the main text Page Install-Time Security ITS using HP-UX Bastille Choosing security levelsEnable kernel-based stack execute protection Table A-3 Additional Sec20MngDMZ security settings1 Selecting security levels during installation Choosing security dependenciesConfiguring Sec20MngDMZ or Sec30DMZ security levels Configuring HP-UX Bastille for use with ServiceguardConfiguring Sec10Host level Page Question modules AccountSecurity.guilogin AccountSecurity.hidepasswordsAccountSecurity.crontabsfile AccountSecurity.cronuserAccountSecurity.MINPASSWORDLENGTH AccountSecurity.NOLOGINAccountSecurity.NUMBEROFLOGINSALLOWED AccountSecurity.lockaccountnopasswdAccountSecurity.NUMBEROFLOGINSALLOWEDyn AccountSecurity.PASSWORDHISTORYDEPTHAccountSecurity.PASSWORDHISTORYDEPTHyn AccountSecurity.PASSWORDMAXDAYSAccountSecurity.passwordpolicies AccountSecurity.serialportloginAccountSecurity.singleuserpassword AccountSecurity.restricthomeAccountSecurity.SUDEFAULTPATH AccountSecurity.SUDEFAULTPATHynAccountSecurity.systemauditing AccountSecurity.umaskAccountSecurity.umaskyn AccountSecurity.unownedfilesAccountSecurity.userdotfiles AccountSecurity.userrcfilesApache.deactivatehpwsapache Apache.chrootapacheDNS.chrootbind FilePermissions.worldwriteable FTP.ftpusersHPUX.guibanner HPUX.mailconfigHPUX.ndd HPUX.othertools HPUX.screensavertimeout HPUX.restrictswaclsHPUX.scanports HPUX.stackexecuteIPFilter.blockcfservd HPUX.tcpisnIPFilter.blockDNSquery IPFilter.blockhpidsadmin IPFilter.blockhpidsagentYou are managing some remote Hids agents, answer no Hids does notDefault 192.168.1.0/255.255.255.0 Description IPFilter.blocknetrangeIPFilter.blockping IPFilter.blockSecureShellIPFilter.blockwebadmin IPFilter.configureipfilterIPFilter.blockwbem Otherwise, answer no to this questionPage MiscellaneousDaemons.configuressh IPFilter.installipfilterMiscellaneousDaemons.diagnosticslocalonly MiscellaneousDaemons.disablebind MiscellaneousDaemons.disableptydaemonMiscellaneousDaemons.disablepwgrd MiscellaneousDaemons.disablerbootdMiscellaneousDaemons.disablesmbclient MiscellaneousDaemons.disablesmbserverMiscellaneousDaemons.nfscore MiscellaneousDaemons.nobodysecurerpcOtherbootserv MiscellaneousDaemons.xaccessMiscellaneousDaemons.sysloglocalonly Patches.spccronrun Patches.spccrontimePatches.spcproxyyn Patches.spcrunPrinting.printing SecureInetd.deactivatebootpSecureInetd.banners SecureInetd.deactivatebuiltin SecureInetd.deactivatedttoolsSecureInetd.deactivatefinger SecureInetd.deactivateftpSecureInetd.deactivateident SecureInetd.deactivatektoolsSecureInetd.deactivatentalk SecureInetd.deactivateprinterSecureInetd.deactivaterecserv SecureInetd.deactivaterquotadSecureInetd.deactivatertools SecureInetd.deactivateswatSecureInetd.deactivatetftp SecureInetd.deactivatetimeSecureInetd.deactivateuucp SecureInetd.ftploggingSecureInetd.loginetd SecureInetd.inetdgeneralSecureInetd.owner Sendmail.sendmailcronSendmail.sendmaildaemon Sendmail.vrfyexpnPage Sample weight files All.weightCIS.weight Sample weight file below aligns with the CIS standardCIS.weight Page CIS mapping to HP-UX Bastille CIS IDApache.deactivatehpwsapache AccountSecurity.lockaccountnopasswd Page Index