Manuals
/
HP
/
Computer Equipment
/
Software
HP
UX Security Products and Features Software
manual
Models:
UX Security Products and Features Software
1
58
62
62
Download
62 pages
27.73 Kb
55
56
57
58
59
60
61
62
<
>
Install
Symbols
Administrator keys
Configuring
Software distributor issues
File access policies
Quick setup examples
Commands
Bpbackup -f backuplist
# make clean
Page 58
Image 58
58
Page 57
Page 59
Page 58
Image 58
Page 57
Page 59
Contents
HP-UX Whitelisting A.01.00 Administrator Guide
Copyright 2010 Hewlett-Packard Development Company, L.P
Table of Contents
HP Serviceguard considerations
Glossary Index
List of Figures
List of Examples
Page
File access policies
Security features
File lock access controls
Identity-based access controls
Capabilities
4 api
Page
Product overview
WLI architecture
Commands
Application API
Applications
WLI database
WLI metadata files
3 .$WLISIGNATURE$
Page
Key usage
Generating keys
Administrator keys
User keys
Installation requirements
Installing, removing, and upgrading
Installing WLI
Removing WLI
Upgrading WLI
Page
Authorizing the recovery key
Configuring
Authorizing administrator keys
Signing DLKMs
Backing up the WLI database
Rebooting to restricted mode
Page
Signing an executable binary
Enhancing security with WLI
Creating a Flac policy
Enabling DLKMs to load during boot
Removing a file access policy
Creating an Ibac policy
Loading unsigned DLKMs
# wlisign -a -k /home/admin1/adminpriv /usr/conf/mod/ciss
Wlisign -a -k adminpriv /usr/sbin/kcmodule
# kcmodule ciss=unused
Page
Overview
Backup and restore considerations
WLI database files
Read/write protected files
Policy protected and metadata files
Write protected
Recommendations
Ibac policies
Flac policies
Metadata files
Page
Administration
HP Serviceguard considerations
WLI database
Policy protected files
WLI reinstallation
Troubleshooting and known issues
Software distributor issues
Lost WLI administrator key or passphrase
# tar -xf /tmp/wlikeydb.tar
Wlisyspolicy -s mode=maintenance -k adminkey
Su root # rm -r /etc/wli
# kcmodule wli=unused # shutdown -r
Contacting HP
Support and other resources
Related information
Websites
Typographic conventions
User input
Times
Page
# make all
# make clean
Instructions
# su wliusr1
Flac add and delete program
Ibac add and delete program
Ibac add and delete program
Page
Administration examples
Wlicert -s -c wli.admin1 -o wmd -k adm1.pvt
Su root # wlisign -a -k adm1.pvt /usr/bin/tar
Cat /tmp/.$WLIFSPARMS$
Tar -vtf tartest.tar
Bdf mydir
Wlisys -k adm1.pvt -s wmdstoretype=pseudo
Bpbackup -f backuplist
Bprestore -f backuplist
Authorizing an administrator key
Quick setup examples
Configuring WLI
Authorizing a user key
Creating a Flac policy
Testing a Flac policy
Flac policies
Enabling a Flac policy
Ibac policies
Disabling an Ibac policy
Removing an Ibac policy
Glossary
ASM
Page
Symbols
Index
Index
Top
Page
Image
Contents