Unix等保笔记
查看版本
身份鉴别
密码策略
AIX1 2 3 4 5 6 7 8 9 10
| /etc/security/user
maxage:8 minlen:8 minalpha:2 maxrepeats:3 mindiff:4 minother:2 histexpire: histsize:
|
HP-UX1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
| /etc/default/security
MIN_PASSWORD_LENGTH=8 PASSWORD_HISTORY_DEPTH=5 PASSWORD_MIN_UPPER_CASE_CHARS=1 PASSWORD_MIN_LOWER_CASE_CHARS=1 PASSWORD_MIN_DIGIT_CHARS=1 PASSWORD_MIN_SPECIAL_CHARS=1 PASSWORD_MAXDAYS=90 PASSWORD_MINDAYS=14
SAM-Auditing and Security-System Security Policies-password format policies SAM-Auditing and Security-System Security Policies-password format policies-Maximum Password Length SAM-Auditing and Security-System Security Policies-password Aging policies-password expiration time(days) SAM-Auditing and Security-System Security Policies-password Aging policies-password life time(days)
|
口令更换时间
1 2
| cat /etc/security/passwd perl -le 'print scalar localtime 1200982154'
|
登录失败
AIX1 2 3 4 5 6 7
| /etc/security/login.cfg logindisable:5 logininterval:60 loginreenable:30
/etc/security/user loginretries=5
|
HP-UX1 2 3 4 5 6
| /etc/default/security
AUTH_MAXTRIES
SAM-Auditing and Security-System Security Policies-General User Account policies-Unsunccessful Login Tries Allowed
|
远程协议
访问控制
umask
安全审计
审计进程
HP1
| SAM-Auditing and Security-Audited users
|
审计内容
AIX1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
| audit query /etc/syslog.conf
kern user mail daemon auth syslog uucp cron emerg alert crit err warning notice info debug
|
HP-UX1 2
| SAM-Auditing and Security-Audited Event /etc/syslog.conf
|
日志文件
AIX1 2 3 4 5
| /var/adm/message /var/adm/sulog /var/adm/wtmp /etc/utmp/security/faillogin /etc/security/lastlog
|
HP-UX1 2 3
| /var/.audit/audfile1 /var/.audit/audfile2 /var/adm/syslog/*.log
|
入侵防范
端口
1 2 3
| netstat -lntp netstat -lnup netstat -ano
|
服务
AIX1 2
| lssrc -a lssrc -a|grep active
|
组件
补丁
AIX1 2 3 4 5
| oslevel -r oslevel -q instfix -i | grep AIX_ML instfix -I | grep AIX_ML oslevel -r instfix -ivk IY07276
|
资源控制
地址限制
1 2 3
| /etc/hosts.allow /etc/hosts.deny /etc/ssh/sshd_config
|
HP-UX1 2
| cat /etc/securetty cat /var/adm/inetd.sec
|
超时锁定
1 2 3 4 5 6
| /etc/profile /etc/ssh/ssh_config
TMOUT=120 ConnectTimeout=120
|
HP-UX1
| System Security Policies-Terminal Security Policies-Login Timeout Value
|
系统资源
1 2 3 4 5 6 7 8 9
| /etc/security/limits.conf
|