Managing Systems and Workgroups: A Guide for HP-UX System Administrators
Administering a System: Managing System Security
HP-UX Bastille
Chapter 8 817
Predefined Configuration Files
Beginning with HP-UX 11i v2, Bastille includes three predefined
configuration files (see Table 8-5) that provide an increasing level of
lockdown. The files are delivered in /etc/opt/sec_mgmt/bastille
Table 8-5 Predefined Configuration Files
Configuration
File Name
Install-Time
Module
Description
HOST.config Sec10Host Host lockdown: no firewall; networking runs
normally, including Telnet and FTP. See Table 8-6
on page 817.
MANDMZ.config Sec20MngDMZ Managed DMZ lockdown: IPFilter firewall blocks
incoming connections except common, secured,
management protocols. See Table 8-7 on page 820.
DMZ.config Sec30DMZ DMZ lockdown: IPFilter blocks all incoming
connections except Secure Shell. See Table 8-8 on
page 821.
Table 8-6 HOST.config: Host-Based Security Settings
Category Actions
Logins and
Passwords
• Deny login unless home directory exists
• Deny nonroot logins if /etc/nologin file
exists
• Set a default path for su command
• Disable root logins from network tty
• Hide encrypted passwords
• Disallow ftpd system account logins
• Disable remote X (XDMCP) logins
File System,
Network, and
Kernel
• Modify ndd settings
ab
• Restrict remote access to swlist
• Set default umask
• Enable kernel-based stack execute
protection