<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for Phil's NewsPhlash</title>
	<atom:link href="http://www.intrasection.com/pjmorr/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.intrasection.com/pjmorr</link>
	<description>A home for all things TechnoGeeky</description>
	<pubDate>Mon, 01 Dec 2008 21:28:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>Comment on DISA releases official ESX Security Technical Implementation Guide by Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/#comment-432</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Tue, 04 Nov 2008 20:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-432</guid>
		<description>Not sure I understand the question?</description>
		<content:encoded><![CDATA[<p>Not sure I understand the question?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DISA releases official ESX Security Technical Implementation Guide by Givens</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/#comment-431</link>
		<dc:creator>Givens</dc:creator>
		<pubDate>Tue, 04 Nov 2008 20:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-431</guid>
		<description>What is this?
AS-08-548 Security Technical Implementation Guidance (STIG)</description>
		<content:encoded><![CDATA[<p>What is this?<br />
AS-08-548 Security Technical Implementation Guidance (STIG)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-391</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Thu, 21 Aug 2008 22:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-391</guid>
		<description>I think I answered this in the VMTN but in case I didnt (ive been on a bunch of planes lately)...
/var/log/ESX_SRRSecure.timestamp should have the output of the results.</description>
		<content:encoded><![CDATA[<p>I think I answered this in the VMTN but in case I didnt (ive been on a bunch of planes lately)&#8230;<br />
/var/log/ESX_SRRSecure.timestamp should have the output of the results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-388</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Thu, 21 Aug 2008 04:58:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-388</guid>
		<description>Thanks Philip. 

Also, for the ESX script, is there a way to output the result to a log file for later review. As I have noticed when I ran the script it has some errors but it went by too fast. Or, is there a way to pause the script at certain point to see what is going on? 

I am new to UNXIX and shell scripting. Thanks again for your help and much appreciated.

Cheers,</description>
		<content:encoded><![CDATA[<p>Thanks Philip. </p>
<p>Also, for the ESX script, is there a way to output the result to a log file for later review. As I have noticed when I ran the script it has some errors but it went by too fast. Or, is there a way to pause the script at certain point to see what is going on? </p>
<p>I am new to UNXIX and shell scripting. Thanks again for your help and much appreciated.</p>
<p>Cheers,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-387</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Wed, 20 Aug 2008 22:43:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-387</guid>
		<description>when you run the SRR it creates a folder that is the same as the FQDN of the server you ran it on.  IF you told the SRR to only report open findings you should find a file there that should be the name-of-the-server.open  It should have all the open findings in txt format.</description>
		<content:encoded><![CDATA[<p>when you run the SRR it creates a folder that is the same as the FQDN of the server you ran it on.  IF you told the SRR to only report open findings you should find a file there that should be the name-of-the-server.open  It should have all the open findings in txt format.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DISA releases official ESX Security Technical Implementation Guide by Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/#comment-386</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Wed, 20 Aug 2008 22:41:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-386</guid>
		<description>So, the process I use is this.

1. Run the DISA provided SRR Unix script.
    Capture the open issues report.
2. Install LAUS rpm files off of ESX CD
    Make sure to chkconfig so the service starts at boot
    service start audit
3. We have another script (unpublished) that changes the banner info based on secret/top secret
4. Run ESX_SRRSecure.sh to lock things down.
5. Reboot
6. Re-run the Unix SRR script.
7. Capture the new open findings report and compare to the first file.

As an aside note we also have a corresponding document that goes along with the script to document all the original findings and how to manually fix them or document if they are false positives....</description>
		<content:encoded><![CDATA[<p>So, the process I use is this.</p>
<p>1. Run the DISA provided SRR Unix script.<br />
    Capture the open issues report.<br />
2. Install LAUS rpm files off of ESX CD<br />
    Make sure to chkconfig so the service starts at boot<br />
    service start audit<br />
3. We have another script (unpublished) that changes the banner info based on secret/top secret<br />
4. Run ESX_SRRSecure.sh to lock things down.<br />
5. Reboot<br />
6. Re-run the Unix SRR script.<br />
7. Capture the new open findings report and compare to the first file.</p>
<p>As an aside note we also have a corresponding document that goes along with the script to document all the original findings and how to manually fix them or document if they are false positives&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DISA releases official ESX Security Technical Implementation Guide by BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/06/04/disa-releases-official-esx-security-technical-implementation-guide/#comment-384</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 20 Aug 2008 01:39:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/?p=1200#comment-384</guid>
		<description>So, which meant we need to run the ESX SRR script (what is the latest version -1.2?) then run the UNIX script and compare it, right?</description>
		<content:encoded><![CDATA[<p>So, which meant we need to run the ESX SRR script (what is the latest version -1.2?) then run the UNIX script and compare it, right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-383</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 20 Aug 2008 01:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-383</guid>
		<description>Thanks Philip.

As a note,the doc above mentioned that you run the SRR and allowed the ESX server rebooted. Then, re-run the SRR script again and compare the result. Where the results are save as?

TIA</description>
		<content:encoded><![CDATA[<p>Thanks Philip.</p>
<p>As a note,the doc above mentioned that you run the SRR and allowed the ESX server rebooted. Then, re-run the SRR script again and compare the result. Where the results are save as?</p>
<p>TIA</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by Philip Morrison</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-379</link>
		<dc:creator>Philip Morrison</dc:creator>
		<pubDate>Thu, 07 Aug 2008 00:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-379</guid>
		<description>There is a way to do this from the command line.
vimsh -n -e /hostsvc/maintenance_mode_exit

This was going to be in the script but we decided not to do so since it could impact production environments.</description>
		<content:encoded><![CDATA[<p>There is a way to do this from the command line.<br />
vimsh -n -e /hostsvc/maintenance_mode_exit</p>
<p>This was going to be in the script but we decided not to do so since it could impact production environments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Script to allow ESX to pass a DISA Security Readiness Review by BacMan</title>
		<link>http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-378</link>
		<dc:creator>BacMan</dc:creator>
		<pubDate>Wed, 06 Aug 2008 23:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.intrasection.com/pjmorr/2008/05/12/script-to-allow-esx-to-pass-a-disa-security-readiness-review/#comment-378</guid>
		<description>In ESX SRR prerequisites that the ESX server need to be in the "maintenance mode". Do you know how to do this from the console? 

I guessed I can use VC to put the ESX server in the maintenance mode. But, just want to know if I can do it from CLI.

Thanks.</description>
		<content:encoded><![CDATA[<p>In ESX SRR prerequisites that the ESX server need to be in the &#8220;maintenance mode&#8221;. Do you know how to do this from the console? </p>
<p>I guessed I can use VC to put the ESX server in the maintenance mode. But, just want to know if I can do it from CLI.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
