HP-UX 11i September 2001 Release Notes
HP-UX 11i Operating Environment Applications
HP-UX 11i Operating Environment (new at 11i original release)
Chapter 4
69
on a Microsoft Windows 2000 KDC, you will be asked for a new password but will not be
allowed to log in. This is a known problem in Windows 2000.
When changing passwords on a MIT KDC with a version prior to 1.1, up to 45 seconds
may elapse before the password is actually changed due to the selection mechanism of
the change password protocol.
Documentation
The following documentation is available:
• The newly created manpage for pam_kerberos is available at:
/usr/share/man/man5.Z/pam_krb5.5
• The whitepaper, Network Security Features of HP-UX 11i , is available on the web at:
http://www.unix.hp.com/operating/hpux11i/infolibrary/
• The PAM Kerberos Release Notes for HP-UX 11i is available at
http://docs.hp.com
Servicecontrol Manager (updated for September 2001)
Servicecontrol Manager allows you to manage groups of HP-UX systems from a central
server. This helps to reduce IT costs and makes it easier to manage multiple systems.
Update for
September 2001:
Servicecontrol Manager version A.02.03 provides the following new management and
security features:
• Integration with HP TopTools 5.5 is now included. TopTools is a web-based tool that
helps you to manage your computer assets, network devices, and HP printers, and
track your network resources and performance.
• When selecting nodes for managed clusters, you can now manage up to 999 nodes in
one cluster instead of the previous limit of 64.
• The Distributed Task Facility (DTF) now has a theoretical limit of 500 task
executions, instead of the previous limit of 10, and a theoretical limit of 1000 agent
connections, up from the previous limit of 16. Both limits may vary depending on
such factors as the machine’s kernel settings, memory capacity, tasks running, and
the number of threads the system is set up to allow.
• A Trusted User can now assign users’ roles on node groups as well as individual
nodes.
• New public/private key authentication between the Central Management Server and
the managed node.
• Digital signatures now provide tamper resistance between the CMS and the
managed nodes; however, digital signatures do not provide encryption.
• "On-the-wire" encryption with HP Praesidium IPSec/9000 cryptographic suites can
be configured.
• Servicecontrol Manager now provides an automated way to start, stop, and restart
daemons, instead of having to kill daemons manually.