HP
UX Bastille Software
manual
Troubleshooting
Install
Password
AccountSecurity.SUDEFAULTPATH
Login
IPFilter.blockhpidsadmin
Configuring a system
MiscellaneousDaemons.xaccess
HPUX.screensavertimeout
Weight
Page 70
70
Page 69
Page 71
Image 70
Page 69
Page 71
Contents
HP-UX Bastille Version B.3.3 User Guide
Trademark Acknowledgments
Table of Contents
Index
List of Figures
HP-UX Bastille user interface Standard assessment report
List of Tables
Question modules Security levels
Features and benefits
About this product
Performance
Compatibility
Support
Installation requirements
Installing HP-UX Bastille
Installation
Page
Using HP-UX Bastille
Creating a security configuration profile
If the Path environment variable has not been updated, use
1shows the main screen of the HP-UX Bastille user interface
Configuring a system
Assessing a system
Configuration for the corresponding question is not
Using scored reports
Accepted standard configurations are detected
Is not always detected. HP-UX Bastille might not detect all
Scored assessment report
Reverting
# bastille -r
Locating files
Monitoring drift
For more information, see bastilledrift1M
Var/opt/secmgmt/bastille/log/Assessment/Drift.txt
Check for a TOREVERT.txt file
Removing HP-UX Bastille
If the file exists, complete the actions listed
Page
Known issues and workarounds
Troubleshooting
Diagnostic tips
General use tips
HP-UX Bastille configures a firewall using IPFilter
Problems opening, copying, or reading files
Errors related to individual configuration files
Cannot use X because $DISPLAY is not set
Contacting HP
Support and other resources
Related information
Typographic conventions
To complete a task
Or damage to hardware or software
Supplement important points of the main text
Page
Install-Time Security ITS using HP-UX Bastille
Choosing security levels
Enable kernel-based stack execute protection
Table A-3 Additional Sec20MngDMZ security settings1
Selecting security levels during installation
Choosing security dependencies
Configuring Sec20MngDMZ or Sec30DMZ security levels
Configuring HP-UX Bastille for use with Serviceguard
Configuring Sec10Host level
Page
Question modules
AccountSecurity.crontabsfile
AccountSecurity.guilogin
AccountSecurity.hidepasswords
AccountSecurity.cronuser
AccountSecurity.NUMBEROFLOGINSALLOWED
AccountSecurity.MINPASSWORDLENGTH
AccountSecurity.NOLOGIN
AccountSecurity.lockaccountnopasswd
AccountSecurity.PASSWORDHISTORYDEPTHyn
AccountSecurity.NUMBEROFLOGINSALLOWEDyn
AccountSecurity.PASSWORDHISTORYDEPTH
AccountSecurity.PASSWORDMAXDAYS
AccountSecurity.singleuserpassword
AccountSecurity.passwordpolicies
AccountSecurity.serialportlogin
AccountSecurity.restricthome
AccountSecurity.systemauditing
AccountSecurity.SUDEFAULTPATH
AccountSecurity.SUDEFAULTPATHyn
AccountSecurity.umask
AccountSecurity.userdotfiles
AccountSecurity.umaskyn
AccountSecurity.unownedfiles
AccountSecurity.userrcfiles
Apache.deactivatehpwsapache
Apache.chrootapache
DNS.chrootbind
FilePermissions.worldwriteable
FTP.ftpusers
HPUX.guibanner
HPUX.mailconfig
HPUX.ndd
HPUX.othertools
HPUX.scanports
HPUX.screensavertimeout
HPUX.restrictswacls
HPUX.stackexecute
IPFilter.blockcfservd
HPUX.tcpisn
IPFilter.blockDNSquery
You are managing some remote Hids agents, answer no
IPFilter.blockhpidsadmin
IPFilter.blockhpidsagent
Hids does not
IPFilter.blockping
Default 192.168.1.0/255.255.255.0 Description
IPFilter.blocknetrange
IPFilter.blockSecureShell
IPFilter.blockwbem
IPFilter.blockwebadmin
IPFilter.configureipfilter
Otherwise, answer no to this question
Page
MiscellaneousDaemons.configuressh
IPFilter.installipfilter
MiscellaneousDaemons.diagnosticslocalonly
MiscellaneousDaemons.disablepwgrd
MiscellaneousDaemons.disablebind
MiscellaneousDaemons.disableptydaemon
MiscellaneousDaemons.disablerbootd
MiscellaneousDaemons.nfscore
MiscellaneousDaemons.disablesmbclient
MiscellaneousDaemons.disablesmbserver
MiscellaneousDaemons.nobodysecurerpc
Otherbootserv
MiscellaneousDaemons.xaccess
MiscellaneousDaemons.sysloglocalonly
Patches.spcproxyyn
Patches.spccronrun
Patches.spccrontime
Patches.spcrun
Printing.printing
SecureInetd.deactivatebootp
SecureInetd.banners
SecureInetd.deactivatefinger
SecureInetd.deactivatebuiltin
SecureInetd.deactivatedttools
SecureInetd.deactivateftp
SecureInetd.deactivatentalk
SecureInetd.deactivateident
SecureInetd.deactivatektools
SecureInetd.deactivateprinter
SecureInetd.deactivatertools
SecureInetd.deactivaterecserv
SecureInetd.deactivaterquotad
SecureInetd.deactivateswat
SecureInetd.deactivateuucp
SecureInetd.deactivatetftp
SecureInetd.deactivatetime
SecureInetd.ftplogging
SecureInetd.owner
SecureInetd.loginetd
SecureInetd.inetdgeneral
Sendmail.sendmailcron
Sendmail.sendmaildaemon
Sendmail.vrfyexpn
Page
Sample weight files
All.weight
CIS.weight
Sample weight file below aligns with the CIS standard
CIS.weight
Page
CIS mapping to HP-UX Bastille
CIS ID
Apache.deactivatehpwsapache
AccountSecurity.lockaccountnopasswd
Page
Index
Related pages
Figure E-3. IFT Troubleshooting Flowchart, #1 for Emerson B-106-300NH
Specifications for Nikon S2600
Programme sequence indicator lights for Miele G 6XX
Schematic Switch PC Board ALL Codes L11385-3 for Lincoln Electric SVM173-A
When searching the item for more detail, repeat steps 4 for Sanyo HDP-M3000
Installation for Tyan Computer Tyan S1857
Feed Rod Feed Rod Parts List for Grizzly G4003G
Language Code List for Magnavox MBP5220F
Install the Router for Juniper Networks M10
Refrigerator Features And Use for Haier HTQ21JAARSS
Initial Cleaning for AEG BP7714000
What is the risk of noise exposure with the DWMT70782L?
Noise Exposure Risks
Top
Page
Image
Contents