Jump to content WorldWide-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
HP.com Home
Solutions

HP-UX 11i security containment - secure virtualization

» 

HP-UX 11i

» Latest release
» Virtualization
» Security
» High availability
» Disaster tolerance
» Management
» Software development
» Internet & networking
» Open source software
» Packaging - OEs
» Utility pricing
» Products index

Leadership UNIX

» Lowest UNIX TCO
» Run it on blades
» Performance 
» ISVs’ v3 quotes
» The Real Story

Learn more:

» Information library
» Executive update
» Customer successes
» Knowledge-on-Demand technical Webcasts
» Transition from other environments

Related products

» Services
» HP-UX 11i storage
» HP Integrity servers
» HP 9000 servers
» Integrity solutions
» Try our software

Get what you need:

» Releases & media
» HP software from Software Depot
» HP-UX technical forum
» Technical documentation
» Training courses
» Events & user forums
» A local reseller
» Section map
The Real Story about HP-UX 11i
Content starts here
red lockers

Security containment combines compartments, fine-grained privileges and role-based access control.

News and features

- Security containment is field-proven: it is a customer-requested major update of the HP Virtualvault technology. Virtualvault is employed in 125 of the world's largest financial institutions, in over 50 countries, hosting over 60% of global electronic banking transactions. Billions of dollars per second flow through Virtualvault. Its proven protection forms the basis for this next generation, HP-UX 11i security containment.

- Security containment is being installed at over 100 major IT centers and undergoing evaluation at over 50 others, in more than 40 countries. Customers include the heavily-fortified Swiss banking sector and other major banks, government treasuries, segments of the healthcare industry, government defense departments, government agencies, telecommunications, water and power infrastructure markets worldwide.

Plan to deploy HP-UX 11i security containment into your adaptive enterprise

If your company's system security is your priority, you’ll value the incremental security and flexibility delivered by HP security containment.

»  Product details, specifications and links to software download and documentation

»  See what you can do with us that other UNIX vendors don't claim they can do!

If HP-UX 11i v2 system security is your priority, there's no reason not to turn your systems on to security containment and three huge reasons you should:

1. You need the incremental protection HP-UX 11i security containment delivers: 

»  Fault isolation at the partition level
»  Flexible multi-purpose compartments

2. There are no charges or hidden costs to deploy security containment. The software will be a no-charge download. Plus:
»  Deploying security containment should require no modifications to existing applications.
»  Security containment works with the rest of your workload and security products.

3. Security containment may save your company money.

That's improved HP-UX 11i TCO. Download security containment now for your partitioned HP-UX 11i systems! Let your HP rep know how he or she can help.

HP-UX 11i security containment

» Unique advantages
» Executive white paper
» QuickSpec
» Security containment download
» Press release

Related security links

» RBAC white paper
» Securing Virtual Partitions-RBAC
» Common Criteria Certification
» HP-UX 11i security home
» HP security home

Containment works with:

» Secure Resource Partitions
» Virtual Server Environment
» Workload Manager
» Global Workload Manager

Related links

» Come to HP-UX 11i
» Latest HP-UX 11i news
» HP-UX 11i business value
» VSE Suites for HP-UX 11i

Security containment in a preplanned packaged application

Protected Systems Web Server


fruits With HP-UX 11i Protected Systems Web Server (PS-Webserver) customers mitigate risk and benefit from a highly secure web server environment that uses security containment compartmented processing to isolate customer facing web processing from internal databases, files and applications. This preplanned system combines HP-UX 11i Apache-based Web Server with security containment and other built-in security features to reduce security risks, lower TCO through automated and integrated security features, and improve time to market for secure web serving.

The PS-Webserver is a secure Web services platform built on the HP-UX11iv2 operating system. The secure architecture and run-time environment isolate the Internet from backend servers and isolate the Web server from the intranet. If the Web server is compromised, the PS-Webserver mitigates damage to system and intranet resources by minimizing the system access and resource privileges an attacker can obtain.


»  Download the software
»  Read more
»  Product Administration Guide

HP-UX 11i security containment delivers incremental protection.

The security required for consolidation and virtualization projects

For over 100% improvement in typical system utilization, customers are turning to virtualization with the HP-UX 11i v2 Virtual Server Environment (VSE).

  • Security containment works within the HP-UX 11i v2 VSE to form secure resource partitions.

  • Using secure resource partitions, you can now isolate entire applications or individual processes within partitions.

  • Now you can secure your VSE partitions while reaping the benefits of improved utilization.

Flexible multi-purpose compartments

Security containment uses multiple airtight compartments to isolate your applications and data.

  • When configured in a compartment, applications (processes, binaries, data files and communication channels used) have restricted access to those resources outside its compartment.

  • This restriction is enforced by the HP-UX 11i v2 kernel and can not be overridden unless configured to do so. Because the application is isolated from other applications and system resources, if the application is compromised it will not be able to damage other parts of the system.

  • Administrative tasks can now be broken up into logical role groupings and delegated to users without having to grant all users all administrative capabilities.

  • Enhanced features of HP-UX 11i v2 make unauthorized system access even tougher than before by closing known points of attack as well as giving administrators the ability to tighten security policy enforcement. In the unlikely event of a security breach the audit trail provided by the HP-UX 11i v2 audit subsystem maintains excellent forensic data to track down the intruder.

Contain the software, contain the risk. It's just good business.

There are no charges or hidden costs to deploy security containment.

Deploy security containment without modifying existing applications.

By combining the new features of security containment with the enhanced features available in the standard operating system, HP-UX 11i v2 provides a highly secure, easy to maintain and backwards compatible environment to deploy business applications. Existing application software does not have to be modified to take advantage of these security feature: test your applications for any unusual requirements.

It works with existing operating environment security features.

HP-UX 11i is a highly secure commercial UNIX operating system that provides the fortification your business needs to prevail against hacking and cyber attacks. HP-UX 11i customers are rock-solid in the areas of policy, authorization and access control, identification and authentication, audit and alarms, and privacy and integrity.

Integrating security containment, HP takes security one step down - down to the level of granularity you need for today's partitioned workloads.

For more on the wide range of HP-UX 11i security capabilities click here.

Security containment drives costs down again for HP-UX 11i customers - who already have the best TCO available!

A leading IT financial analyst concludes that for enterprise UNIX installations, HP-UX 11i delivers the highest business value and lowest cost of ownership available today. Click here for the backup.

On application and database servers processing high-value transactions, unplanned downtime reductions may save millions of dollars a minute.

The security containment feature of HP-UX 11i v2 can lower TCO unplanned downtime due to server compromise is largely eliminated.

At HP, our engineers innovate to increase the value HP-UX 11i contributes to your business everyday. We're pleased to bring you security containment at no incremental cost to you.


»  Back to top

»  Archived HP-UX 11i hot topics


»  Download the latest Adobe Acrobat Reader
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2008 Hewlett-Packard Development Company, L.P.