Jump to content

HP-UX 11i

Products & Services
Support & Drivers
Solutions
How to Buy

HP-UX 11i security overview

Layered security with in-depth protection of all your enterprise assets by protecting data, systems and identities.
Why HP-UX 11i v3?  See the savings and value vs. prior releases View the results Mission-critical UNIX® user preference 2009 Data Center Operating Environment
Content starts here
Vigilance: Introducing HP-UX 11i v3 Update 5

Featured case study

Campana Systems is an international leader in information solutions for the auto club and health care industries. Campana drives its market-leading solutions on HP Integrity servers and Intel® Itanium® processors running the HP-UX 11i v2 operating environment with the HP-UX Host Intrusion Detection System (HIDS) and the HP-UX Bastille. This approach promotes compliance with the Payment Card Industry (PCI) Data Security Standard for their auto club customers by providing security monitoring of cardholder data and by hardening the systems that contain cardholder data.

HP-UX 11i reduces risk from threats, simplifies identity management and is part of the compliance solution.

For the past 25 years HP has been building one of the most trustworthy and secure UNIX® operating systems on the market. Designed for the optimal protection against both external and internal threats, HP-UX 11i offers industry-leading breadth and depth of UNIX security features. Focused on feature integration aimed at proactively mitigating risk, reducing compliance cost and accelerating time to implementation, HP-UX security solutions significantly lower IT costs.

Security news and features

  • Enhanced Bastille offers 50% more system items that can be hardened to further reduce time and expertise required to secure your HP-UX 11i v2 and v3 systems, and to help you automate compliance with security benchmark standards.
    » Bastille: 50% more lockdown items covered
  • A new release of HP-UX IPSec (A.03.00) is now available. This version supports the latest set of IPsec RFCs, including RFC 4301, RFC 4306 (IKEv2), etc. and is compliant with the requirements specified in the US Government's DISR v2 (DoD Information Technology Standards Registry).
    » Learn more about HP-UX IPSec and the detailed list of supported RFCs
  • The HP-UX 11i v3 operating system has received common criteria certification at the EAL 4 assurance level against Controlled Access (CAPP) and Role-Based Access Control (RBACPP) Protection Profiles. Many enterprises and governments require this vendor-independent security certification to increase confidence in the product's security functionality, quality, and effectiveness.
    » Learn more about Common Criteria Certification for HP-UX 11i v3
  • HP-UX 11i encrypted volume and file system (EVFS) is an operating system service that fills the compliance need to store files in a way that they cannot be read by unauthorized parties who obtain physical access to storage. This is accomplished through the encryption of data on a per-volume basis.
    » Download EVFS software
    » Read more about EVFS
  • HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all HP-issued Security Bulletins and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically.
    » Download HP-UX Software Assistant

This set of fully integrated and complementary features is designed to provide layered security with in-depth protection of all your enterprise assets by protecting data, systems and identities.

Protecting data

HP-UX 11i offers data protection in many forms: protecting data in transit, in use and at rest. By using security features designed to protect data in its three forms, HP-UX 11i customers can minimize possible breaches not only in terms of data loss, but in customer trust as well. Several security features offer data protection capabilities to HP-UX customers:
  • Encrypted volume and file system
  • Trusted Computing Services
  • Security containment
  • Protected Systems Webserver
  • SSL
  • IPSec
  • Secure Shell
  • MD5sum
» Read more about the features that comprise this solution.

Protecting systems

One critical factor in enterprise security is system minimization and hardening. HP-UX 11i offers a set of security features designed to address known and unknown vulnerabilities by running only the services that are needed, thus minimizing a potential point of attack. The following security features have built-in mechanisms not only to minimize and harden the system, but also to detect and react to attack in real time:
  • Bastille
  • Host Intrusion Detection System
  • Secure Resource Partitions
  • IPFilter
  • Software Assistant (security bulletin currency)
  • Install-time Security
  • Boot Authentication
  • Standard Mode Security Extensions
  • Shadow Passwords
  • Strong Random Number Generator
» Read more about the features that comprise this solution.

 

 

Protecting identity

In modern day global enterprise companies, managing identity is not an easy task , especially as identity management requirements grow to include employees, contractors, partners and suppliers across many countries with various privacy protection laws and regulation. HP-UX 11i dramatically simplifies this critical task by integrating various identity management technologies which offer ease of use and adherence to compliance regulation:
  • Identity Management Integration
  • Select Access for IdMI
  • Role-based Access Control
  • AAA Server
  • Red Hat Directory Server for HP-UX
  • LDAP-UX Client
  • Kerberos Server
  • Kerberos Client Services
  • PAM Kerberos

HP also offers many additional security features available through open source software for HP-UX.

» Read more about the features that comprise this solution.

Why HP: Layered security with in-depth protection