sponsored by |
OSdata.com |
HP-UX is a UNIX-based operating system made by Hewlett-Packard that runs on HP PA RISC.
OSdata.com is used in more than 300 colleges and universities around the worldFind out how to get similar high web traffic and search engine placement. |
Intended purpose
server/mainframe: small to large scale servers; database servers; mainframes
desktop/workstation: workstations (for those with UNIX familiarity)
handheld: not appropriate
real time: not appropriate
Kind of OS: proprietary System V Release 4-based UNIXe121
Release Date: 1986w24 (see complete list of release dates at http://www.software.hp.com/HPUX-RDMP/history/slide1.htm, HP-UX Release History)
Current Version: 11iw85
Hardware Supported: HP PA-RISC (HP9000 workstations and serversw36), HP Focus (HP9000/500 family)e105, Motorola 680x0 (HP9000/300 family)e105
HP-UX started earlier than 1986 on their hp9000/500 family, with the HP Focus CPU, it was a multi CPU system, up to 7 CPUs in one box. Then came the HP9000/300 family, these where workstations, also running HP-UX. These where built on the Motorola 680X0 CPU. After that HP introduced the HP9000/400 family also called Apollo, since they merged with them. At this time the PA-RISC based HP-UX came along. The 300 and 400 family was supported up to HP-UX 9.10, this included some of the new things in HP-UX 10.X. Erkkie105
680x0 assembly language is discussed in the assembly language section.
Maximum Number of Processors: 128 for 11.10 and later; 32 for 11.00
Number of bits: 64w43 (64 or 32 bits for 11.00 or later; 32 bits for earlier than 11.00)
Digital UNIX continues to dominate the 64-bit arena, leaving HP-UX and IRIX to contest the second position, followed closely by AIX. Solaris and NT trail significantly behind. HP, having progressed about halfway through its hardware transition to 64-bits, also offering good backwards compatibility for 32-bit applications. D.H. Brown Associatesw43
Kernel:
POSIX: compatible
On-line file systems and volume management: HP-UX 11i provides simple and flexible file system and volume management tools that let you manage your environment dynamically expand your file system, create virtual volumes, and add new hardware components quickly. HP-UX 11i Manageabilityw86
Text Command Shell: UNIX shells
VUE has been replaced with CDE, which debuted with HP-UX 10.10. Starting with 10.20, CDE became the default windowing environment, though VUE was still provided as an option. As of 11.00, VUE is no longer part of HP-UX. The design of the CDE desktop incorporates and enhances many HP VUE features. Although the CDE desktop has a similar appearance to HP VUE, there are important differences. The differences include: comp.sys.hp.hpux FAQw75
- New and more customizable Front Panel
- Graphical MIME-enabled mail application
- Graphical Calendar
- Graphical Print Queue Manager
- New terminal emulator
- Action and datatype syntax changes
- ToolTalk messaging support
- Desktop application registration
Businesses and organizations with servers powered by HP-UX: HP (Hewlett Packard), Wal-Martw52
http://www.join.com JOIN DHCP/DDNS commercial integrated DHCP and DDNS servers from Join Systems for DHCP and BootP clients running on SunOS 4.x, Solaris 2.x SPARC and x86, Digital UNIX, HP-UX 10.x using Motif GUI, evaluation copies available online.
http://www.baynetworks.com/Products/nav/f_netid_3_0.html NetID commercial DHCP/DDNS server from Bay Networks that runs on Solaris, HP-UX, Windows NT 4.0, and Windows 95; links into Oracle and Sybase, with tools for managing IP addresses.
HP provides strong Internet support within HP-UX, bolstered by its good showing in advanced Internet protocol function and network security, while lagging behind in support for advanced NFS capability. HP-UX, along with AIX, has also established a lead in supporting NDS. Digital Equipment Corporation, AIX 4.3 Leaps To 64-Bits In Dead Heat With Digital UNIX 4.0w51
See also chart of internet features.
Safely leveraging internet opportunities
HP-UX 11i is a highly secure commercial UNIX operating system that provides the fortification your e-business needs to prevail against hacking and cyber attacks. Designed to enable this new era of Internet-based technologies and e-security, HP-UX 11i can meet your security requirements in the areas of policy, authorization and access control, identification and authentication, audit and alarms, and privacy and integrity.w87
» System security
» Network security
» Directory enabled computing
» Netscape Directory Server v6.2 for hp-ux
» HP-UX 11i additional security technologies
» HP-UX 11i system security features and benefits summary tableSystem security
Host Intrusion Detection System (HIDS)
Host Intrusion Detection System (HIDS) is a standard feature of HP-UX 11i security capabilities, making HP the only systems vendor to offer its own host intrusion detection product. HIDS enhances host-level security with near real-time automatic monitoring of each configured host for signs of potentially damaging intrusions.w87» HP-UX HIDS solutions brief (147KB, PDF)
» Download HIDSOther system security highlights include:
- Stack buffer overflow protectionuses a combination of highly efficient software and existing memory management hardware to protect against both known and unknown stack buffer overflow attacks. Eliminates need to modify a programs code to get stack buffer overflow protection, unlike other products that require time-consuming program modifications, recompilation, or relinking.w87
» Stack buffer overflow protection in HP-UX 11i white paper (104KB, PDF, 11/01)
- Security patch checkPerl script that performs analysis of file sets and patches installed on an HP-UX machine and generates a report of recommended security patches.w87
- HP-UX Bastilleis a security hardening/lockdown tool that enhances the security of an HP-UX Unix host. It accommodates the various degrees of hardening required of servers used for webs, applications and databases. By answering a series of security and usability questions, the server is tightened appropriately for its use. It configures daemons, system settings, and firewalls to be more secure. It turns off unneeded services such as pwgrd and printing, and it configures client software such as rcp and rlogin to be more secure. It also helps create chroot jails that help limit the vulnerability of common Internet services such as Web servers and DNS.w87
- HP-UX Install-Time Security
Install-time Security (ITS) is available to HP-UX 11i version 2 customers as an install option to lockdown systems during installation. ITS makes HP-UX more secure out-of-the-box when customers select higher security levels. There are four choices, including a maximum compatibility level which provides security tools, but doesnt apply a security level, because they represent tradeoffs between security, functionality, productivity, and usability.w87When the customer selects a level, Bastille will fit it to their system. Here are some examples of what ITS does:
- Run Security Patch Check and setup a cron job to help them become and stay current with security patches announced in security bulletins.w87
- Configure IPFilter at higher security levels to block incoming network connections. A new Bastille HP-UX11iv2 feature.w87
- Shutdown services with security tradeoffs. Enhanced in HP-UX 11iv2w87
- Allow, at customer option, select authenticated management network connections into the machine.w87
The security level choices for Install-time Security are:
- Tools Only Installs HP-UX Bastille, Security Patch Check, HP-UX Secure Shell, and HP-UX IPFilter for the customers later use either individually or by running Bastille interactively.w87
- Host, Performs roughly 50 host-based lockdown including turning off many services with security tradeoffs other than telnet and ftp, and many settings to their more secure state.w87
- DMZ applies the Host level then disables telnet and ftp. It then uses IPFilter to block all inbound network connections except Secure Shell. This level is suitable for deployment in a network De-Militarized Zone: a firewall-protected neutral zone typically between the Internet and an intranet. It does this by implementing the automatable portions of the General Configuration Policy section of the SANS consensus model Internet DMZ Equipment Policy.w87
- Managed DMZ. This level is the same as DMZ but allows select authenticated management protocols inbound.w87
Install-time Security is available in the foundation HP-UX 11i version 2.
- Certification HP-UX 11i is Hewlett-Packards UNIX®-based operating environment specifically targeted at Internet applications. HP-UX 11i delivers an end-to-end scalable, manageable, and secure infrastructure for developing, deploying, and brokering mission-critical e-services. HP-UX 11.11 is evaluated and certified to the Common Criteria evaluation assurance level EAL4, against the functional requirements in the Controlled Access Protection Profile (EAL4-CAPP). The target environment is for systems that may execute on a single HP 9000 Server or be connected to other HP 9000 Servers identically configured to form a local distributed system implementing a unified security policy. The details can be viewed at http://niap.nist.gov/cc-scheme/vpl_type.html.w87
HP also offers a version of HP-UX that is B1 certified.Network security
HP demonstrates its commitment to network security with HP-UX 11is rich set of standards-based and directory-enabled network security features that enable you to build your e-business without compromising corporate security:w87
» Network security features of HP-UX 11i white paper (560KB, PDF, 02/04)
- HP-UX kerberos serverprovides key distribution facilities to implement the Kerberos authentication protocol in network-distributed enterprises.
» HP-UX kerberos server white paper (627KB, PDF)
» HP-UX kerberos server product brief (105KB, PDF)
» Download this software- HP-UX ipsecprovides secure and private communication over the Internet and within the enterprise-without modifying existing applications.w87
- HP-UX ipfilteris a stateful firewall system that filters IP packets to control packet flow in or out of the system. It works as a security defense by minimizing the number of exposure points on a system.w87
» HP ipfilter solutions brief (64.3KB, PDF)
» Download this software- HP-UX AAA server provides authentication, authorization, and accounting services using the RADIUS protocol; enables service providers or enterprises to authenticate users and then account for time and billing use of network services. In addition to the features described in the product brief, release 6.1.x provides the following new features:w87
Support for the following major wireless-LAN authentication types: PEAP, TLS, TTLS, GTC, MSCHAP (in addition to already supported LEAP, MD5)w87
A GUI wireless LAN Advisor provides instructions to configure user based authentication and WEP/WPA key distribution in a wireless LAN environment. This Advisor is an HTML tutorial/help system that simplifies the process for securing WLANs with the AAA server.w87
Self-signed AAA server digital certificates created during installation. Users now deploy a secured TTLS and PEAP environment without a having to generate digital certificatesw87
DHCP Interface. The AAA server can now assign IP addresses generated by a DHCP server.w87
Support for Microsoft NT domain name syntax. Users can authenticate with either the standard network access identifier syntax (user@domain) or NT domain syntax (domain\user).w87
» HP-UX AAA server product brief (174KB, PDF)
» Designing a secure wireless LAN with the HP-UX AAA RADIUS server
(HP-UX 11.0, HP-UX 11i v1, HP-UX 11i v2) (4.9MB, PDF, 02/04)
» Introduction to diameter (HP-UX 11.0, HP-UX 11i v1) (PDF)
» Executive briefing: wireless network security (HP-UX 11.0, HP-UX 11i v1) (PDF)
» Download this software- HP-UX mobile AAA serverHP-UX mobile AAA server is a wireless data authenticator based on the emerging Diameter protocol. This advanced implementation provides authentication, authorization, and accounting (AAA) functions in 3GPP2 wireless data networks. It is the first Diameter implementation available, and is designed for next generation mobile operators and OEMs for use in 3G wireless test labs.w87
- HP-UX secure shellHP-UX Secure Shell is a powerful software-based approach to encrypted network security. It provides secured remote login. Data sent over the network is encrypted by SSH-1 or SSH-2 protocols and decrypted once it reaches its destination.w87
New Features in HP-UX Secure Shell A.03.50.000
- Privilege separation
- Enhanced ls support for sftp
- SSH protocol enhancements
Directory-enabled computing
As your enterprise extends outward to include partners, customers and suppliers for information sharing and increased collaboration, you need the protection to allow only the right people in. HP provides this added protection through directory-enabled computing. HP includes Netscape Directory Server for HP-UX with the HP-UX 11i operating environment.w87
In addition, LDAP Services are integrated through LDAP UX integration. LDAP is integrated with:w87
- Local OS login authorization as pam_authz
- Cluster management
- With sendmail
- With BIND 9.2.0
- With NIS
- With Network Quality of Service (QoS) management
- With Virtual Private Network (VPN) management
- AAA (RADIUS) Server
NIS+ Server is available as a directory server.w87
Netscape Directory Server V6.2 for hp-ux
Netscape Directory Server for hp-ux is an LDAP server that centralizes application settings, user profiles, group data, policies, and access control information into a network-based registry. Directory Server simplifies user management by eliminating data redundancy and automating data maintenance. It also improves security enabling administrators to store policies and access control information in the directory for a single authentication source across enterprise or extranet applications.w87
» Netscape Directory Server for hp-ux (104KB, PDF)
» Download this softwareNovell eDirectory for hp-ux
Novell® eDirectory is the foundation for the worlds largest identity management deployments-allowing businesses to manage identities and control access for employees, customers and partners. With Novell eDirectory, the industrys first and most advanced full-service directory, businesses lay the groundwork for complete secure identity management solutions and multi-platform network services. Now HP-UX customers can implement this popular directory on systems running the HP-UX operating system.w87
» Learn more at the Novell eDirectroy web site
» Download this softwareHP-UX 11i additional security technologies:
- HP-UX PAM Kerberos is implemented under the PAM (Pluggable Authentication Module) framework. PAM gives the system administrators the flexibility of choosing any authentication service available on the system to perform.w87
- LDAP-UX integration
LDAP-UX Integration for HP-UX is bundle consisting of two products, which provide access to the directory services of an LDAP directory server. These are NIS/LDAP Gateway and LDAP-UX Client Services.w87» Integrating HP-UX 11.x account management and authentication with Microsoft Windows 2000 (HP-UX 11.0, HP-UX 11i v1) (PDF)
» Integrating HP-UX account management and authentication with LDAP (PDF)
» Download this software
HP-UX 11i system security features and benefitsw87 HP-UX secure shell
- Encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other network-level attacks
- Provides a myriad of secure tunneling capabilities
- Protects a variety of authentication methods
- Secure remote logins
- Secure file transfer
- Secure remote commands execution
- Authenticate users using keys and agents
- Access control
- Port forwarding (tunneling)
HP-UX bastille
- Answer security questions
- Answer usability questions
- Lock-down appropriate to hp-ux server use
- Produce a profile script
- Use the script to harden many servers in the same category
Stack buffer overflow protection
- Uses a combination of highly efficient software and existing memory management hardware to protect against both known and unknown stack buffer overflow attacks. Eliminates need to modify a programs code to get stack buffer overflow protection, unlike other products that require time-consuming program modifications, recompilation or relinking
- Provides a trial mode that can be used to gain confidence that it will not interfere with legitimate applications
- Provides a zone bypass feature that allows application owners to mark their binaries as having a legitimate need to execute code located on their stack(s)
- Programs so marked are exempt from the HP-UX stack buffer overflow protection
Security_Patch_Check
- Perl script that performs analysis of file sets and patches installed on an HP-UX machine and generates a report of recommended security patches
Access Control List (ACL)
- Stores a series of entries that identify specific users or groups and their access privileges for a directory or file
- Specifies detailed access permissions for multiple users and groups
- Supports Journaled File System (JFS 3.3)
Generic Security Services Application Programming Interface (GSS API)
- Contains all the GSS APIs in RFC 2743 and is implemented as C programming language interfaces
- Provides security services for client/server applications independent of various underlying security mechanisms and communication protocols, including authentication, integrity and confidentiality services
- Enables application developers writing secure applications to write code only once, eliminating need to change it whenever the underlying security mechanism changes
Sendmail-8.9.3
- Uses the first sendmail release to include anti-spam rule sets, which give mail administrators significantly more power to reduce spam
Cryptographic algorithms
- HP implementation of RSA cryptographic algorithms for DES and Triple-DES uses advanced features in the enhanced assembly language for PA-RISC 2.0 that takes advantage of 64-bit registers
- Achieves almost twice the encryption speed of other leading software implementations
HP-UX 11i network security features and benefitsw87 HP-UX IPSec
- Provides secure and private communication over the Internet and within the enterprise-without modifying existing applications
- Incorporates Internet Key Exchange (IKE) as an automated protocol for dynamically negotiating the IPSec parameters. IKE provides dynamic secret key generation and exchange for IPSec and allows for scalability
- Interoperates with over 25 other IPSec implementations, including those of Cisco Systems and Microsoft®
HP-UX IPFilter
- A stateful inspection host-based firewall system that provides filtering of selected IP traffic and streaming UDP protocols into or out of the system
HP-UX Kerberos server
- Provides key distribution facilities to implement the Kerberos authentication protocol in network-distributed enterprises
- Provides strong authentication for client/server applications by using secret-key cryptography
- Enables encryption of all communications to assure privacy and data integrity
- Provides the foundation for secure single sign-on to applications and multi-platform resources
HP-UX AAA server
- Provides authentication, authorization and accounting services using the RADIUS protocol
- Enables service providers or enterprises to authenticate users and then account for time and billing use of network services
- Supports EAP (Extensible Authentication Protocol) for Wireless LAN Security
Pluggable Authentication Modules (PAM)
- Industry-standard authentication framework gives system administrators the flexibility to choose any authentication service available on the system
- Allows new authentication service modules to be plugged in and made available without modifying the applications
BIND9.2.0
- Provides data integrity and authentication to applications using cryptographic digital signature
- Prevents non-authorized access to DNS and prevents name-to-address mapping tampering over the wire
- Restricts DHCP updates to those authorized to perform them
- Guarantees the integrity of zone data using digital signatures
Other:
HP-UX 11.0 rates just behind Digital and IBM, complementing its effective 64-bit implementation with a Web-based version of its system management GUI, and competitive reliability and scalability features. D.H. Brown Associatesw42
Harnessing the demands of e-business. Designed for ease-of-use, power, multi-systems, and high availability, HP-UX 11i system management tools and products are designed to remove the complexity out of system administration. They provide extensive capabilities for allocating system resources among application loads. Hard and virtual (soft) partitions allow multiple instances of HP-UX 11i to exist within one server, enabling application-specific tuning. HP-UX 11i Manageabilityw86
(for your convenience, look for this symbol marking passages about HP-UX)
Please send recommendations on additional URLs to Milo.
HP: http://www.hp.com/products1/unix/operating/, HP-UXe121
HP: http://www.docs.hp.com/hpux/os/, HP-UXe52
HP: http://www.docs.hp.com/, on-line documentse52
(Frequently Asked Questions)
HP: http://www.docs.hp.com/hpux/content/osfaq.html, HP-UX FAQ
http://hpux.cs.utah.edu/hppd/FAQ/e11
http://www.faqs.org/faqs/hp/hpux-faq/preamble.html, comp.sys.hp.hpux FAQ
http://www.triolet.com/HPVend/hpvend.html, Hewlett-Packard Third-Party Vendor Listing
http://www.unixguide.net/unixguide.shtml UNIXguide.net (AIX, FreeBSD, HP-UX, LINUX, SOLARIS & Tru64); a guide for comparable commands and directories in several popular forms of UNIX.
http://home.earthlink.net/~bhami/rosetta.html Rosetta Stone for Unix; a guide for comparable commands and directories in several popular forms of UNIX (AIX, Darwin, DG-UX, FreeBSD, HP-UX, IRIX, Linux, NetBSD, OpenBSD, SCO OpenServer, Solaris, SunOS, Tru64, and ULTRIX).
HP-UX/Sun Interoperability Cookbook: a detailed comparison of commands, OS calls, data structures, directories, and other parts of Sun-OS and HP-UX, especially for those going from one OS to the other.
AIX/HP-UX Interoperability Guide, Version 2: a detailed comparison of commands, OS calls, data structures, directories, and other parts of AIX and HP-UX, especially for those going from one OS to the other.
SunOS to HP-UX 9.05 Porting Guide: a detailed comparison of commands, OS calls, data structures, directories, and other parts of Sun-OS and HP-UX, especially for those going from one OS to the other.
Stokelys HP-UX System Administrator FAQ links
http://www.linuxrx.com/WS_Linux/OS_comparison.html The Linux resource exchange Operating systems comparison LINUX, HPUX, Windows NT, BSDi, FreeBSD, IRIX, Digital UNIX, Solaris, Macintosh, OS/2, UnixWare, OpenServere83
http://www.unix-vs-nt.org/ John Kirchs article Microsoft Windows NT Server 4.0 versus UNIX
http://www.dhbrown.com/pdfs/osscorecard.html Operating System Scorecard D.H. Brown Associates
http://www.join.com JOIN DHCP/DDNS commercial integrated DHCP and DDNS servers from Join Systems for DHCP and BootP clients running on SunOS 4.x, Solaris 2.x SPARC and x86, Digital UNIX, HP-UX 10.x using Motif GUI, evaluation copies available online.
http://www.baynetworks.com/Products/nav/f_netid_3_0.html NetID commercial DHCP/DDNS server from Bay Networks that runs on Solaris, HP-UX, Windows NT 4.0, and Windows 95; links into Oracle and Sybase, with tools for managing IP addresses.
For more UNIX book listings, see also the general book listings on the UNIX web page.
If you want your book reviewed, please send a copy to: Milo, POB 1361, Tustin, CA 92781, USA.
Price listings are for courtesy purposes only and may be changed by the referenced businesses at any time without notice.
Five Steps to HP-UX/Book and Disk; by Onword Press Development Team, Jim Rice; OnWord Press; December 1993; ISBN 0934605246; paperback (with disk); 120 pages; $24.95
Learning the HP-UX Operating System (Hewlett-Packard Professional Books); by Martin Poniatowski; Prentice Hall Press; July 1996; ISBN 0132585340; paperback; $36.00
A Practical Guide to the Unix System; by Mark G. Sobell; Addison-Wesley Pub Co; October 1994; ISBN 0805375651; paperback; 800 pages; $37.95
HP-UX System Administration Handbook and Toolkit (Hewlett-Packard Professional Books); by Marty Poniatowski; Prentice Hall Computer Books; January 1998; ISBN 0139055711; paperback (with 2 CD-ROMs); 700 pages; $53.00
HP-UX 10.X System Administration: How To Book (Hewlett Packard Professional Books); by Marty Poniatowski; Prentice Hall Press; October 1995; ISBN 0131258737; paperback; $45.00
Essential System Administration: Help for Unix System Administrators (Nutshell Handbook); 2nd edition; by Aeleen Frisch; OReilly & Associates; December 1996; ISBN 1565921275; paperback; 788 pages; $27.96
The Complete Guide to Netware 4.11/Intranetware; 2nd edition; by James E. Gaskin; Sybex; December 1996; ISBN 078211931X; paperback; $47.99; includes information on getting NetWare working with Windows, Macintosh, UNIX, and OS/2
Building a Unix Internet Server; by George Eckel; New Riders Publishing; June 1995; ISBN 1562054945; paperback (with CD-ROM); 325 pages; $30.40
Advanced Programming in the Unix Environment (Addison-Wesley Professional Computing Series); by W. Richard Stevens; Addison-Wesley Pub Co; June 1992; ISBN 0201563177; hardcover; 744 pages; $63.95
If you want your book reviewed, please send a copy to: Milo, POB 1361, Tustin, CA 92781, USA.
If youre a UNIX user, all UNIX are pretty much the same. If youre a UNIX programmer, all UNIX are a little bit different. If youre a UNIX system admin, all UNIX are completely different! Thats comming from ULTRIX, AIX, HP-UX, Solaris, and Digital UNIX experiences. Might as well count linux, too. Bob Koehler, Hubble Space Telescope Payload Flight Software Team
OSdata.com is used in more than 300 colleges and universities around the world |
Tweets by @osdata |
A web site on dozens of operating systems simply cant be maintained by one person. This is a cooperative effort. If you spot an error in fact, grammar, syntax, or spelling, or a broken link, or have additional information, commentary, or constructive criticism, please e-mail Milo. If you have any extra copies of docs, manuals, or other materials that can assist in accuracy and completeness, please send them to Milo, PO Box 1361, Tustin, CA, USA, 92781.
If you have an extra or unwanted copy of any official manuals or documentation on this operating system, please send them to: Milo, POB 1361, Tustin, CA 92781, USA. I have the following items: NONE.
Note: I am looking for a fan of HP-UX who has the time to check this web site for completeness and accuracy regarding HP-UX. Just check through the site about once a week or so and report back with any information (including the URL of the web page you are reporting).
Click here for our privacy policy.
Click here to skip over the summaries of individual operating systems.
previous page | next page |
Digital UNIX (or DUNIX) |
||
HP-UX |
||
OpenVMS (or OVMS) |
||
This web site handcrafted on Macintosh computers using Tom Benders Tex-Edit Plus and served using FreeBSD .
UNIX used as a generic term unless specifically used as a trademark (such as in the phrase UNIX certified). UNIX is a registered trademark in the United States and other countries, licensed exclusively through X/Open Company Ltd.
Names and logos of various OSs are trademarks of their respective owners.
Copyright © 1998, 1999, 2000, 2001, 2002, 2004 Milo
Last Updated: March 25, 2004
Created: June 22, 1998
Click here to skip over the summaries of individual operating systems.
previous page | next page |