HP-UX 11i Version 2 December 2005 Release Notes

Table Of Contents
Security
HP-UX Role-Based Access Control
Chapter 8
167
This product is available on the Software Pack (SPK) media for HP-UX 11i v2 December
2005. (For more information about SPK, see “Software Pack (Optional HP-UX 11i v2
Core Enhancements)” on page 27.).)
Summary of Change
The HP-UX 11i v2 (11.23) December 2005 is the first release to include the HP-UX
RBAC feature on the Software Pack media. The first release of HP-UX RBAC, version
11.23.01, was a Software Pack Web release and was released via HP’s Software Depot at
http://hp.com/go/softwaredepot.
The following is a list of the main differences between the previously released HP-UX
RBAC 11.23.01 and the HP-UX RBAC 11.23.02 included in the HP-UX 11i v2 (11.23)
December 2005 release.
HP-UX RBAC 11.23.02 includes:
integration and support for the Fine-Grained Privileges and Compartments
components of the HP-UX 11i Security Containment feature
1
privedit command that allows authorized users and groups to edit files they
normally would not be able to edit because of file permissions or Access Control Lists
enhanced auditing capabilities, including auditing based on HP-UX RBAC roles and
authorizations, and advanced filtering of audit records
ability to assign roles to groups
support for Access Control APIs
Impact
HP-UX RBAC B.11.23.02 allows customers to use HP-UX RBAC with components of the
HP-UX 11i Security Containment feature, specifically the Fine-Grained Privileges and
Compartments components. HP-UX RBAC B.11.23.02 also provides the opportunity for
customization by utilizing its APIs and includes several enhancements from the previous
HP-UX RBAC release.
Compatibility
There are no known compatibility issues.
Performance
There are no known performance issues.
Documentation
For further information, refer to the following:
•Manpages:
rbac (5)
1. HP-UX 11i Security Containment is available on the Web via the HP Software
Depot at http://hp.com/go/softwaredepot.