Figure 3-4 Assessment report score

The percentage of weight items secured properly is displayed at the end of the .txt report and in the header row of the .html report. For example, see Figure 3-4

Sample weight files that match the default configuration files are provided in /etc/opt/ sec_mgmt/bastille/configs/defaults. This directory also includes the template file all.weight which contains all possible HP-UX question items as selected. For sample files, see Appendix D (page 63).

3.4 Reverting

If you want to revert the system files to the state they were in before HP-UX Bastille was run, use the revert option:

#bastille -r

IMPORTANT: Before using the revert feature, read the revert-actions script to ensure changes do not disrupt your system. This file appears in /var/opt/sec_mgmt/bastille/ revert/revert-actions.

If changes were made to the system after HP-UX Bastille was run, either manually or by other programs, review those changes to verify they still work and have not broken the system or compromised its security. Certain firewall options and reverting the system can make a system less secure.

After running the revert option, look at the TOREVERT.txt file to ensure that the tasks needed to finalize the revert process are complete. The file is located in /var/opt/sec_mgmt/ bastille/TOREVERT.txt.

16 Using HP-UX Bastille