Securing HP NonStop Servers in an Open Systems World - TCP/IP, OSS and SQL

Securing HP NonStop Servers in an Open Systems World - TCP/IP, OSS and SQL

von: XYPRO Technology Corp

Elsevier Trade Monographs, 2006

ISBN: 9780080475578 , 1000 Seiten

Format: PDF, ePUB, OL

Kopierschutz: DRM

Windows PC,Mac OSX geeignet für alle DRM-fähigen eReader Apple iPad, Android Tablet PC's Apple iPod touch, iPhone und Android Smartphones Online-Lesen für: Windows PC,Mac OSX,Linux

Preis: 99,95 EUR

Mehr zum Inhalt

Securing HP NonStop Servers in an Open Systems World - TCP/IP, OSS and SQL


 

Front Cover

1

Securing HP NonStop™ Servers in an Open Systems World

4

Copyright Page

5

Contents

8

Foreward

44

Preface

46

Distinguished Contributors

50

Introduction

56

A Wider Perspective

58

Some New Terms

59

About This Handbook

60

Applying the Security

66

Chapter 1. Compliance Concepts

70

Representative Regulations

71

Analysis of Requirements in Common

80

Conclusions

88

Chapter 2. Changes to Safeguard Since G06.21

90

Safeguard Changes Included in Release G06.21

90

Safeguard Changes Included in Release G06.22

91

Safeguard Changes Included in Release G06.23

91

Safeguard Changes Included in Release G06.24

94

Explicit Nodes Example

95

Safeguard Changes Included in Release G06.25

97

Safeguard Changes Included in Release G06.26

102

Safeguard Changes Included in Release G06.27

103

Safeguard Changes Included in Release G06.28

106

Safeguard Changes Included in Release G06.29

106

Safeguard Subsystem Component Updates

114

Chapter 3. Securing Pathway Applications

120

Pathway Development

121

Pathway Run-Time Components

123

Chapter 4. TCP/IP

148

TCP/IP Security

148

TCP/IP Architecture

149

HP NonStop Server Implementation of TCP/IP

165

TCP/IP Applications

171

Firewalls and Routers

185

VPN

186

SSH Subsystem

186

Chapter 5. File Sharing Programs

226

Network File System (NFS) Subsystem

226

Samba

243

Chapter 6. NonStop SQL and Database Security

286

What is Database Security?

287

Compiling and Executing NonStop SQL Programs

309

Securing Client Queries from ODBC/MX and JDBC/MX

314

Securing Dynamic SQL Queries

318

NonStop SQL Interactions with other Utilities

323

Chapter 7. Open Database Connectivity (ODBC) SQL/MP

328

Security Configuration

336

Auditing in ODBC

341

Other ODBC Programs and Utilities

350

Chapter 8. System Management Tools

354

Tandem Service Management (TSM) Subsystem

354

Open System Management (OSM)

362

Distributed Systems Management/Software Configuration Manager

370

Chapter 9. The Guardian Gazette A–Z

384

ADDTOSCF Script

385

ADDTCPIP Script

385

ALTERIP Script

385

APPPRVD System Program

385

APPSRVR System Program

386

CIMON System Program

386

CONFIG System Configuration File

386

CTCPIP0 and CTCPIP1 Scripts

387

CEVSMX System Program

387

Distributed Systems Management/Software Configuration Manager (DSM/SCM)

387

ENOFT User Program

394

EVNTPRVD System Program

395

EVTMGR Program

395

FDIST System Program

396

FSCK System Utility

396

IAPRVD System Program

397

IAREPO File

397

IMPORT System Program

398

INIT0 and INIT1 Scripts

398

INITRD File

398

Integrity NonStop Compilers

398

LISTNER System Utility

402

LOGTCPIP Log File

403

LOGSCF Log Fill 8e

403

LOGTCP0 and LOGTCP1 Log File

403

LOGTCPIP Log File

404

MXANCHOR File Configuration File

404

MXAUDSRV System Program

404

MXCMP User Program

404

MXESP System Program

405

MXGNAMES System Program

405

MXOAS System Program

405

MXOCFG System Program

405

MXODSN Configuration File

405

MXOMSG File

406

MXOSRVR System Program

406

MXRTDSRV System Program

406

MXUDR System Program

406

MXUTP System Program

406

Network File System (NFS) Subsystem

407

NFS

417

NOS System Program

417

NOSCOM User Program

417

NOSUTIL System Program

417

NS System Program

417

OSMINI Configuration File

418

OSSFM System Program

418

Object Code Accelerator (OCA) User Program

418

OEVPRVD System Program

427

OSH User Program

427

Open System Management (OSM)

428

OSMCONF Configuration File

444

OSS File Manager (OSSFM)

444

OSS Monitor Process (OSSMON)

445

OSS Pipe Server (OSSPS)

454

OSSLS System Program

455

OSSMON System Program

455

OSSPS System Program

456

OSSTA System Program

456

OSSTTY System Utility

456

PCAUTHD System Program

458

PCLPRD System Program

458

PCNFSD System Program

458

PERSIST File

459

Persistence Manager (ZPM) System Program

459

PERSSUPP Configuration File

460

QIO Subsystem

460

RALPRVD System Program

461

RALPRVNP System Program

462

Remote Procedure Call (RPC) Subsystem

462

RPC

464

Safeguard Subsystem

465

SCS

467

SCSOBJ

467

SECPRVD

467

SNMP (Simple Network Management Protocol)

467

SNMPPAGT

470

SPDIST2

470

SQL Communication Subsystem (SCS)

471

SQL/MX

471

SRM

485

Storage-Pool Files

485

SUPPREPO

487

TACLPRVD

487

TDMNSM Placeholder File

487

TDMODBC Configuration File

487

Tandem Service Management (TSM) Subsystem

487

TCP/IP Subsystem

500

ZMXSTMPL Configuration File

509

TNS/E Link Editor (ELD) User Program

509

TNS/E Native Object File Tool (ENOFT) User Program

509

TSMERROR Log

509

TSMINI Configuration File

509

ZCT08153 File

509

ZCT08153 File

510

ZFB* Files

510

ZMPnnnnn Files

510

ZMSGQ System Program

510

ZNFSPTR User Program

510

ZNFSSCF System Program

511

ZNFSTEXT File

511

ZNFSTMPL Template File

511

ZNFSUSR and ZNFSUSR I Files

511

ZOSSFSET Configuration File

512

ZOSSPARM File Configuration File

512

ZOSSSERV Configuration File

512

ZPHIxxxx Files

512

ZPM System Program

512

ZRPCTMPL Template File

513

ZSPE System Program

513

ZTRC File

513

ZTRCn Files

513

ZZAAnnnn Files

513

ZZALnnnn Files

514

ZZDCnnnn Files

514

ZZNFSnnnn Files

514

ZZSNnnnn Files

514

ZZPSnnnnFiles

514

ZZSKnnnn Log Files

515

ZZSSnnnn Files

515

ZZUSERS and ZZUSERS2 Files

515

$ZCMOM Process

515

$ZLOG Process

515

$ZOEV Process

516

$ZOLHD Process

516

$ZOSM Process

516

$ZFMnn Process

516

$ZMSGQ Process

517

$ZPLS Process

517

$ZPM Process

517

$ZPMON Process

517

$ZPNS Process

517

$ZPPnn Process

517

$ZRD9 Process

518

$ZSPE Process

518

$ZTAnn Process

518

$ZTSM Process

518

$ZTSMS Process

518

Chapter 10. The Open System Services Subsystem

520

The OSS Environment

520

The OSS File System

526

Processes in OSS

550

Interactions With the Guardian Environment

555

User Authentication in OSS

557

OSS User Management

558

OSS Subsystem Components

570

Chapter 11. OSS Gazette a to z

580

OSS Commands

582

$HOME Directory

588

alias User Program

590

apropos User Program

592

ar User Program

593

at Subsystem

594

at.allow and at.deny Files

598

atjobs Job Queue Directory

599

atq User Program

599

atrm User Program

600

authorized_keys File

600

awk User Program

601

banner System Utility

602

basename User Program

602

batch User Program

603

bc User Program

605

Berkeley Internet Name Domain (BIND) Server

606

bg User Program

611

/bin Directory

612

BIND

613

c89 User Program

613

cal User Program

614

cancel User Program

615

cat User Program

615

cd User Program

617

charmap Configuration Files

618

chgrp User Program

618

chmod User Program

619

chown User Program

620

cksum User Program

621

clear User Program

622

cmp User Program

623

cobol User Program

624

command User Program

626

Command Aliases

626

Compilers in the OSS Environment

627

comm User Program

630

compress User Program

631

cp User Program

632

cpio User Program

633

cron Subsystem

634

cron.allow and cron.deny Files

642

cron log

642

crontab Job Queue Files

642

crontab User Program

643

csplit User Program

644

cut User Program

645

date User Program

646

dc User Program

646

dd User Program

647

df User Program

648

diff User Program

649

dircmp User Program

650

dirname User Program

650

dspcat User Program

651

dspmsg User Program

652

du User Program

653

echo User Program

654

ed User Program

655

egrep User Program

656

eld User Program

657

enoft User Program

657

env User Program

657

environment Files

658

/etc Directory

658

ex User Program

660

expand User Program

661

expr User Program

662

fc User Program

662

fg User Program

663

fgrep User Program

664

file User Program

665

find User Program

667

flex User Program

668

flex.skel File

669

fold User Program

670

ftp in OSS

671

gencat User Program

672

genxlt User Program

673

getconf User Program

673

getopts User Program

674

gname User Program

675

grep User Program

676

gtacl User Program

677

head User Program

678

hosts Configuration File

679

hosts.equiv Configuration File

679

iconv User Program

680

id User Program

681

id_dsa Files

682

id_rsa Files

682

identity Files

682

import User Program

683

inetd Subsystem

683

InstallSqlmx

697

ipcrm User Program

697

ipcs User Program

698

jobs User Program

699

join User Program

700

kill User Program

701

known_hosts File

702

ksh Command Interpreter

702

lex User Program

703

lex.backtrack File

704

lex.yy.c File

704

Library Files

704

line User Program

706

In User Program

707

locale Configuration File

708

locale Subsystem

709

logger User Program

713

logname User Program

714

Ip User Program

715

Ipstat User Program

715

Is User Program

716

magic File

717

make User Program

718

makefile Configuration Files

719

man User Program

721

merge_whatis System Utility

724

Message Text Files (.msg)

724

migrate

724

mkcatdefs User Program

724

mkdir User Program

726

mkfifo User Program

727

moduli Configuration File

728

more User Program

728

named User Program

729

named.conf Configuration File

729

mv User Program

730

mxci

731

mxcierrors.cat

731

mxcmp

731

mxCompileUserModule

731

mxexportddl

732

mxsqlc

732

mxsqlco

732

mxtool

732

nawk User Program

732

networks Configuration File

733

newgrp User Program

733

nice User Program

735

nl User Program

736

nld User Program

736

nm User Program

738

nmcobol User Program

739

noft User Program

740

nohup User Program

740

NSM/web Subsystem

741

nsupdate User Program

745

od User Program

745

pack User Program

746

passwd Configuration File

748

paste User Program

748

patch User Program

749

pathchk User Program

751

pax Utility

752

Pcleanup Utility

753

pinstall User Program

754

pname User Program

755

pr User Program

756

printf User Program

756

printcap Configuration File

757

/private Directory

760

prngd System Utility

761

.profile Configuration Files

761

program User Program

764

.proto Configuration File

765

queuedefs Configuration File

765

protocols Configuration File

765

ps User Program

765

pwd User Program

766

rc Configuration File

767

read User Program

767

Remote Name Daemon Control (rndc) User Program

768

resolv.conf Configuration File

768

rexecd

768

rhosts Configuration File

770

rm User Program

772

rmdir User Program

773

rndc User Program

774

rndc.conf Configuration File

774

rsh/rshd Subsystem

775

runcat User Program

778

runv User Program

779

Samba Subsystem

780

scp User Program

793

secrets Configuration File

793

sed User Program

794

services Configuration File

794

setmxdb

795

SFTP Subsystem

795

sh Command Interpreter

796

shadow Configuration File

797

share_info File

797

shift User Program

798

shosts Configuration File

798

sleep User Program

799

sort User Program

799

split User Program

800

SQL/MX Subsystem

801

SSH Subsystem

812

sshrc Configuration File

835

strings User Program

835

strip User Program

836

stty User Program

837

su User Program

838

sum User Program

841

syslog System Utility

841

tail User Program

843

tar Program

844

tee User Program

845

termcap Configuration File

846

test User Program

847

time User Program

848

times User Program

849

/tmp Directory

850

touch User Program

850

tr User Program

852

tty User Program

852

tty File

853

umask User Program

854

unalias User Program

856

uname User Program

856

uncompress User Program

856

unexpand User Program

857

unpack User Program

857

uniq User Program

857

/unsupported Directory

858

/usr/bin Directory

859

/usr/include Directory

860

/usr/local/bin Directory

861

/usr/local/Floss Directory

861

UTILSGE

863

uudecode

863

uuencode

864

vi User Program

865

vproc User Program

867

wait User Program

868

wall User Program

868

wc User Program

869

whatis User Program

870

who User Program

871

whoami User Program

872

xargs User Program

872

yacc User Program

873

zcat User Program

874

Appendix A. Understanding OSS Permission Strings and Octal Values

876

Appendix B. Table of File and Directory Permissions

883

Appendix C. Gathering the Audit Information

899

Guardian Wildcarding

900

OSS Commands

902

Gathering SQL/MP Information

939

Index

962