HP-UX 11i Version 2 June 2007 Release Notes

Security
Install-Time Security
Chapter 8
184
Performance
There are no known performance issues.
Documentation
Refer the sam (1M) and secweb (1M) manpages, and the product online help.
Obsolescence
Not applicable.
Install-Time Security
Install-Time Security (ITS) version 1.4.x adds a security step to the install/update
process that allows you to run the Bastille security lockdown engine during system
Installation with one of four configurations ranging from default security to DMZ.
ITS includes the following bundles:
Sec00Tools
Sec10Host
Sec20MngDMZ
Sec30DMZ
Summary of Change
ITS 1.4.x includes the following new functionality.
New questions/configuration
Diagnostic daemon configure to local-only use (not network)
Syslog local-only
Impact
You will benefit from new functionality:
New lockdown configuration items
New Ignite Integration (on security tab)
Compatibility
There are no differences between the Itanium-based and PA-RISC implementation
(they are the same). Some products depend on services, system settings, or network ports
that Bastille secures. In those cases, products that depend on out-of-box settings that