HP
UX 11i Role-based Access Control (RBAC) Software
manual
Troubleshooting
Install
Symbols
HP-UX Rbac Configuration Files
Access Control Basics
HP-UX Rbac Commands
Authorization
Features and Benefits
Using HP-UX Rbac
Page 12
12
Page 11
Page 13
Image 12
Page 11
Page 13
Contents
HP-UX 11i Security Containment Administrators Guide
Copyright 2007 Hewlett-Packard Development Company, L.P
Table of Contents
Fine-Grained Privileges
Index
Page
List of Figures
Page
List of Tables
Page
List of Examples
Page
About This Document
Intended Audience
New and Changed Information in This Edition
Publishing History
Typographic Conventions
HP-UX Release Name and Release Identifier
UserInput
Related Information
HP Encourages Your Comments
HP-UX 11i Releases
Page
Authorization
HP-UX 11i Security Containment Introduction
Conceptual Overview
Account Policy Management
Features and Benefits
Defined Terms
Isolation
Auditing
Features
Benefits
Installation
Installing HP-UX 11i Security Containment
Prerequisites and System Requirements
Verifying the HP-UX 11i Security Containment Installation
# swlist -d @ /tmp/securitycontainmentbundle.depot
# swverify SecurityExt
# swlist -a state -l fileset SecurityExt
Installing HP-UX Role-Based Access Control
Verifying the HP-UX Role-Based Access Control Installation
Installing HP-UX Standard Mode Security Extensions
# swverify Rbac
Uninstalling HP-UX 11i Security Containment
Uninstalling HP-UX Rbac
# swverify TrustedMigration
# swlist -a state -l fileset TrustedMigration
Uninstalling HP-UX Standard Mode Security Extensions
# swremove Rbac
# swremove TrustedMigration
Page
HP-UX Role-Based Access Control
HP-UX Rbac Versus Other Rbac Solutions
Overview
Access Control Basics
Simplifying Access Control with Roles
Example of Authorizations Per User
Example of Authorizations Per Role
HP-UX Rbac Components
HP-UX Rbac Access Control Policy Switch
HP-UX Rbac Configuration Files
HP-UX Rbac Commands
HP-UX Rbac Configuration Files
HP-UX Rbac Commands
HP-UX Rbac Manpages
HP-UX Rbac Architecture
HP-UX Rbac Manpages
HP-UX Rbac Example Usage and Operation
HP-UX Rbac Architecture
Planning Authorizations for the Roles
Planning the HP-UX Rbac Deployment
Planning the Roles
Planning Command Mappings
HP-UX Rbac Limitations and Restrictions
Configuring HP-UX Rbac
Configuring Roles
Creating Roles
Example Planning Results
Configuring Authorizations
Assigning Roles to Users
Assigning Roles to Groups
Configuring Additional Command Authorizations and Privileges
Is mainly intended for scripts
Example Roles Configuration in HP-UX Rbac B.11.23.02
Hierarchical Roles
Overview
Examples of Hierarchical Roles
Changes to the authadm Command for Hierarchical Roles
Example 3-1 The authadm Command Syntax
Example 3-2 Example of the authadm Command Usage
Hierarchical Roles Considerations
Configuring HP-UX Rbac with Fine-Grained Privileges
Configuring HP-UX Rbac with Compartments
Command
Matches the following /etc/rbac/cmdpriv entries
Configuring HP-UX Rbac to Generate Audit Trails
GID
Procedure for Auditing HP-UX Rbac Criteria
Using HP-UX Rbac
Following is the privrun command syntax
# privrun ipfstat
HP-UX Rbac in Serviceguard Clusters
Customizing privrun and privedit Using the Acps
Troubleshooting HP-UX Rbac
Rbacdbchk Database Syntax Tool
Privrun -v Information
Commands
Fine-Grained Privileges Commands
Fine-Grained Privileges
Fine-Grained Privileges Components
Available Privileges
Manpages
Fine-Grained Privileges Manpages
Available Privileges
Configuring Applications with Fine-Grained Privileges
Or launch policy
Privilege Model
Compound Privileges
# setfilexsec options filename
Fine-Grained Privileges in HP Serviceguard Clusters
Troubleshooting Fine-Grained Privileges
Security Implications of Fine-Grained Privileges
Privilege Escalation
# getprocxsec options pid
Compartments
Compartment Architecture
Compartment Architecture
Default Compartment Configuration
Planning the Compartment Structure
Modifying Compartment Configuration
Activating Compartments
# setrules -p
# cmpttune -e
Compartment Configuration Files
Compartment Components
Changing Compartment Rules
Changing Compartment Names
Compartment Commands
Compartment Configuration Files
Compartment Commands
Compartment Manpages
Compartment Rules and Syntax
Compartment Definition
File System Rules
IPC Rules
Permissionlist
Network Rules
IPC mechanism in the current compartment
Access
Miscellaneous Rules
Interface
Configuring Applications in Compartments
Troubleshooting Compartments
Example Rules File
Configured rules are loaded into the kernel
# vhardlinks
Compartments in HP Serviceguard Clusters
Do not configure standby LAN interfaces in a compartment
Standard Mode Security Extensions
Configuring Systemwide Attributes
Configuration Files
Security Attributes and the User Database
System Security Attributes
Commands
Attributes
Manpages
Configuring Attributes in the User Database
Troubleshooting the User Database
Auditing
Auditing Components
Audit Commands
Auditing Your System
Planning Your Auditing Implementation
Enabling Auditing
# audevent -P -F -e admin -e login -e moddac
AUDEVENTARGS1 = -P -F -e admin -e login -e moddac
Monitoring Audit Files
#audsys -n -c primaryauditfile -s
Guidelines for Administering Your Auditing System
Auditing Users
Performance Considerations
#audsys -f
Audevent command options
Auditing Events
Streamlining Audit Log Data
# /usr/sbin/userdbset -u user-nameAUDITFLAG=1
Audit Log Files
Self-auditing processes
Configuring Audit Log Files
Viewing Audit Logs
#/usr/sbin/audisp auditfile
Examples of Using the audisp Command
Page
Symbols
Index
Security attribute defining
Related manuals
Manual
10 pages
36.76 Kb
Related pages
Troubleshooting NMT for Cisco Systems OL-10426-01
Specifications for ViewSonic PJD6241
Error Messages and Indicators for Intel D102GGC2
Titta / Schema for Samsung UE19ES4005WXXE
How to watch the 3D image for Samsung UA40C7000WRXCS
Software Installation for Bushnell 18-0833
Parts List 720HD Heavy Duty Mortiser for Powermatic 720HD
Agilent E1445A Code List of Manufacturers for Agilent Technologies 75000 Series C
TROUBLESHOOTINGPAge header for Breville BRC600XL
¿Cuáles son los pasos para activar la función Ice Off en una nevera Samsung?
Infórmate aquí
Top
Page
Image
Contents