<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DISA releases official ESX Security Technical Implementation Guide</title>
	<atom:link href="http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/</link>
	<description>A home for all things TechnoGeeky</description>
	<lastBuildDate>Thu, 04 Feb 2010 07:43:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/comment-page-1/#comment-207</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Tue, 04 Nov 2008 20:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-207</guid>
		<description>Not sure I understand the question?</description>
		<content:encoded><![CDATA[<p>Not sure I understand the question?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Givens</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/comment-page-1/#comment-206</link>
		<dc:creator>Givens</dc:creator>
		<pubDate>Tue, 04 Nov 2008 20:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-206</guid>
		<description>What is this?
AS-08-548 Security Technical Implementation Guidance (STIG)</description>
		<content:encoded><![CDATA[<p>What is this?<br />
AS-08-548 Security Technical Implementation Guidance (STIG)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/comment-page-1/#comment-209</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Wed, 20 Aug 2008 22:41:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-209</guid>
		<description>So, the process I use is this.

1. Run the DISA provided SRR Unix script.
    Capture the open issues report.
2. Install LAUS rpm files off of ESX CD
    Make sure to chkconfig so the service starts at boot
    service start audit
3. We have another script (unpublished) that changes the banner info based on secret/top secret
4. Run ESX_SRRSecure.sh to lock things down.
5. Reboot
6. Re-run the Unix SRR script.
7. Capture the new open findings report and compare to the first file.

As an aside note we also have a corresponding document that goes along with the script to document all the original findings and how to manually fix them or document if they are false positives....</description>
		<content:encoded><![CDATA[<p>So, the process I use is this.</p>
<p>1. Run the DISA provided SRR Unix script.<br />
    Capture the open issues report.<br />
2. Install LAUS rpm files off of ESX CD<br />
    Make sure to chkconfig so the service starts at boot<br />
    service start audit<br />
3. We have another script (unpublished) that changes the banner info based on secret/top secret<br />
4. Run ESX_SRRSecure.sh to lock things down.<br />
5. Reboot<br />
6. Re-run the Unix SRR script.<br />
7. Capture the new open findings report and compare to the first file.</p>
<p>As an aside note we also have a corresponding document that goes along with the script to document all the original findings and how to manually fix them or document if they are false positives&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/comment-page-1/#comment-208</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 20 Aug 2008 01:39:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-208</guid>
		<description>So, which meant we need to run the ESX SRR script (what is the latest version -1.2?) then run the UNIX script and compare it, right?</description>
		<content:encoded><![CDATA[<p>So, which meant we need to run the ESX SRR script (what is the latest version -1.2?) then run the UNIX script and compare it, right?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
