HP UX Bastille User Manual page 52

Version b.3.3
Table of Contents

Advertisement

Actions
MiscellaneousDaemons.disable_smbclient
Headline
Default
Description
Actions
MiscellaneousDaemons.disable_smbserver
Headline
Default
Description
Actions
MiscellaneousDaemons.nfs_core
Headline
Default
Description
Actions
MiscellaneousDaemons.nobody_secure_rpc
Headline
Default
Description
Actions
MiscellaneousDaemons.snmpd
Headline
Default
52
Question modules
If running, stop process rbootd.
Set START_RBOOTD=0 in /etc/rc.config.d/netdaemons.
Disable the HP-UX CIFS client.
Y
CIFS can be used to share files and other resources between computers. The
CIFS product suite integrates HP-UX with Microsoft Windows environments
by providing remote file sharing, printer access and authentication services
between HP-UX and Windows systems.
If running. stop process cifsclient.
Set RUN_CIFSCLIENT=0 in /etc/rc.config.d/cifsclient.
Disable the HP-UX CIFS (Samba) Server.
N
CIFS can be used to share files and other resources between computers. The
CIFS product suite integrates HP-UX with Microsoft Windows environments
by providing remote file sharing, printer access, and authentication services
between HP-UX and Windows systems.
If running, stop processes smbd and nmbd.
Set RUN_SAMBA=0 in /etc/rc.config.d/samba.
Disable the NFS and RPC infrastructure.
N
RPC is a traditional part of UNIX used in a variety of UNIX services, including
NIS, NFS, and others. If you are sure you are not using a service that is affected,
you may disable RPC. RPC has had security issues in the past and by default
does not support a strong authentication mechanism. If you disable the core
NFS infrastructure, HP-UX Bastille disables NIS, NIS+ and NFS.
Stop and disable NIS/NIS+ Server and Client.
Stop and disable NFS Server and Client.
Set NFS_CORE=0 in /etc/rc.config.d/nfsconf.
Disable the nobody user in the ONC Secure RPC
N
Secure RPC is a cryptographically authenticated means to communicate with
a system. By configuring keyserv to prevent the use of default keys for the
nobody user, other users are prevented from accessing the nobody user with
default credentials. This is a safer way to operate Secure RPC.
Add the -d flag to the KEYSERV_OPTIONS= parameter line in /etc/
rc.config.d/namesvrs.
Disable SNMPD.
N

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ux bastille b.3.3

Table of Contents