Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX 11i Version 3 Release Notes: HP 9000 and HP Integrity Servers > Chapter 8 Security

Install-Time Security

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

Install-Time Security (ITS) version 1.0.4 adds a security step to the install/update process that allows you to run the Bastille security lockdown engine during system Installation with one of four configurations ranging from default security to DMZ.

ITS includes the following bundles:

  • Sec00Tools (recommended software bundle)

  • Sec10Host (optional software bundle)

  • Sec20MngDMZ (optional software bundle)

  • Sec30DMZ (optional software bundle)

Summary of Change

What’s New for Customers Migrating from HP-UX 11i v1 September 2005?

Install-Time Security is new with the HP-UX 11i v3 release for customers migrating from HP-UX 11i v1.

What’s New for Customers Migrating from HP-UX 11i v2 June 2006?

ITS 1.0.4 includes the following new functionality.

  • New questions/configuration

  • Diagnostic daemon configure to local-only use (not network)

  • Syslog local-only

Impact

You will benefit from new functionality:

  • New lockdown configuration items

  • New Ignite Integration (on security tab)

Compatibility

There are no differences between the Itanium®-based and PA-RISC implementation (they are the same). Some products depend on services, system settings, or network ports that Bastille secures. In those cases, products that depend on out-of-box settings that Bastille may change, document their dependency. Where practical, Bastille also documents these dependencies. HP-UX 11i v3 Installation and Update Guide, available at http://docs.hp.com/en/oshpux11iv3.html., discusses which particular Bastille settings are applied at each level.

Performance

ITS does not impact performance, but if the DMZ or MngDMZ levels are used, there may be a very small network performance slowdown due to the IPFilter packet filtering.

Documentation

Information can be found in the following documents:

Obsolescence

Not applicable.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2006-2007 Hewlett-Packard Development Company, L.P.