Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
HP.com home
Education & Training  >  Find a course 

Enterprise Linux Security Administration

» 

Education & Training
US & Canada

» Contact Us
» Register for a class
» Education Centers
» HP RAIL
» Onsite & Dedicated Training
» What's new
» Find a course
» Big Data
» Business Analysis & Project Management
» Cloud
» Data Center
» HP ExpertOne Customer
» HP ExpertOne Partner
» HP Integrity
» Graphic Solutions
» ITSM / ITIL
» Linux
» Microsoft
» HP Networking
» HP NonStop
» HP OpenVMS
» HP Project Odyssey
» HP ProLiant
HP BladeSystem
» Security
» HP Storage
» HP Tru64
» HP-UX
» Virtualization
» HP VISPEL-Video Training
» VMware
» HP Education Consulting
» Certification
» HP Virtual Rooms
» eLearning
» HP Software Education
Content starts here
At a glance
View schedule & enroll Sorted by: location or date
Course number U8630S
Length 5 days
Delivery method Remotely assisted instructional learning ( RAIL)
Onsite dedicated training ( OST)
Price USD $3,000
CAD $3,300

Course overview

This highly technical course focuses on properly securing machines running the Linux operating systems. A broad range of general security techniques such as packet filtering, password policies, and file integrity checking are covered. Advanced security technologies such as Kerberos and SELinux are taught. Special attention is given to securing commonly deployed network services. At the end of the course, students have an excellent understanding of the potential security vulnerabilities -- know how to audit existing machines, and how to securely deploy new network services.


Prerequisites

This class covers advanced security topics and is intended for experienced systems administrators. Candidates should have current Linux or UNIX systems administration experience equivalent to the U8583/GL120 "Linux Fundamentals", H7091/GL250 "Enterprise Linux Systems Administration", and H7092/GL275 "Enterprise Linux Network Services".

Supported Distributions

  • Red Hat Enterprise Linux 6

Ways to save

Course outline

This course includes the following topics:

  • Security Concepts

    • Basic Security Principles
    • Default Install
    • Firewall
    • Minimization – Discovery
    • Service Discovery
    • Hardening
    • Security Concepts

  • Scanning, Probing, and Mapping Vulnerabilities

    • The Security Environment
    • Stealth Reconnaissance
    • The WHOIS database
    • Interrogating DNS
    • Discovering Hosts
    • Discovering Reachable Services
    • Reconnaissance with SNMP
    • Discovery of RPC Services
    • Enumerating NFS Shares
    • Nessus Insecurity Scanner
    • Configuring OpenVAS

  • Password Security and PAM

    • Unix Passwords
    • Password Aging
    • Auditing Passwords
    • PAM Overview
    • PAM Module Types
    • PAM Order of Processing
    • PAM Control Statements
    • PAM Modules
    • pam_unix
    • pam_cracklib.so
    • pam_env.so
    • pam_xauth.so
    • pam_tally2.so
    • pam_wheel.so
    • pam_limits.so
    • pam_nologin.so
    • pam_deny.so
    • pam_warn.so
    • pam_securetty.so
    • pam_time.so
    • pam_access.so
    • pam_listfile.so
    • pam_lastlog.so
    • pam_console.so

  • Secure Network Time Protocol (NTP)

    • The Importance of Time
    • Hardware and System Clock
    • Time Measurements
    • NTP Terms and Definitions
    • Synchronization Methods
    • NTP Evolution
    • Time Server Hierarchy
    • Operational Modes
    • NTP Clients
    • Configuring NTP Clients
    • Configuring NTP Servers
    • Securing NTP
    • NTP Packet Integrity
    • Useful NTP Commands

  • Kerberos Concepts and Components

    • Common Security Problems
    • Account Proliferation
    • The Kerberos Solution
    • Kerberos History
    • Kerberos Implementations
    • Kerberos Concepts
    • Kerberos Principals
    • Kerberos Safeguards
    • Kerberos Components
    • Authentication Process
    • Identification Types
    • Logging In
    • Gaining Privileges
    • Using Privileges
    • Kerberos Components and the KDC
    • Kerberized Services Review
    • Kerberized Clients
    • KDC Server Daemons
    • Configuration Files
    • Utilities Overview

  • Implementing Kerberos

    • Plan Topology and Implementation
    • Kerberos 5 Client Software
    • Kerberos 5 Server Software
    • Synchronize Clocks
    • Create Master KDC
    • Configuring the Master KDC
    • KDC Logging
    • Kerberos Realm Defaults
    • Specifying [realms]
    • Specifying [domain_realm]
    • Allow Administrative Access
    • Create KDC Databases
    • Create Administrators
    • Install Keys for Services
    • Start Services
    • Add Host Principals
    • Add Common Service Principals
    • Configure Slave KDCs
    • Create Principals for Slaves
    • Define Slaves as KDCs
    • Copy Configuration to Slaves
    • Install Principals on Slaves
    • Create Stash on Slaves
    • Start Slave Daemons
    • Client Configuration
    • Install krb5.conf on Clients
    • Client PAM Configuration
    • Install Client Host Keys

  • Administrating and Using Kerberos

    • Administrative Tasks
    • Key Tables
    • Managing Keytabs
    • Managing Principals
    • Viewing Principals
    • Adding, Deleting, and Modifying Principals
    • Principal Policy
    • Overall Goals for Users
    • Signing In to Kerberos
    • Ticket types
    • Viewing Tickets
    • Removing Tickets
    • Passwords
    • Changing Passwords
    • Giving Others Access
    • Using Kerberized Services
    • Kerberized FTP
    • Enabling Kerberized Services
    • OpenSSH and Kerberos

  • Securing The Filesystem

    • Filesystem Mount Options
    • NFS Properties
    • NFS Export Option
    • NFSv4 and GSSAPI Auth
    • Implementing NFSv4
    • Implementing Kerberos with NFS
    • GPG – GNU Privacy Guard
    • File Encryption with OpenSSL
    • File Encryption With encfs
    • Linux Unified Key Setup (LUKS)

  • AIDE

    • Filesystem Mount Options
    • NFS Properties
    • NFS Export Option
    • NFSv4 and GSSAPI Auth
    • Implementing NFSv4
    • Implementing Kerberos with NFS
    • GPG – GNU Privacy Guard
    • File Encryption with OpenSSL
    • File Encryption With encfs
    • Linux Unified Key Setup (LUKS)

  • Accountability with Kernel audited

    • Accountability and Auditing
    • Simple Session Auditing
    • Simple Process Accounting & Command History
    • Kernel-Level Auditing
    • Configuring the Audit Daemon
    • Controlling Kernel Audit System
    • Creating Audit Rules
    • Searching Audit Logs
    • Generating Audit Log Reports
    • Audit Log Analysis

  • SELinux

    • DAC vs. MAC
    • Shortcomings of Traditional Unix Security
    • SELinux Goals
    • SELinux Evolution
    • SELinux Modes
    • Gathering Information
    • SELinux Virtual Filesystem
    • SELinux Contexts
    • Managing Contexts
    • The SELinux Policy
    • Choosing an SELinux Policy
    • Policy Layout
    • Tuning and Adapting Policy
    • Booleans
    • Permissive Domains
    • Managing File Contexts
    • Managing Port Contexts
    • SELinux Policy Tools
    • Examining Policy
    • SELinux Troubleshooting
    • SELinux Troubleshooting Continued

  • Securing APACHE

    • Apache Overview
    • httpd.conf – Server Settings
    • Configuring CGI
    • Turning Off Unneeded Modules
    • Delegating Administration
    • Apache Access Controls (mod_access)
    • HTTP User Authentication
    • Standard Auth Modules
    • HTTP Digest Authentication
    • Authentication via SQL
    • Authentication via LDAP
    • Authentication via Kerberos
    • Scrubbing HTTP Headers
    • Metering HTTP Bandwidth

  • Securing PostgreSQL

    • PostgreSQL Overview
    • PostgreSQL Default Config
    • Configuring SSL
    • Client Authentication Basics
    • Advanced Authentication
    • Identity-based Authentication

  • [Appendix] Securing Email Systems

    • SMTP Implementations
    • Security Considerations
    • chrooting Postfix
    • Email with GSSAPI/Kerberos Auth

U8630S C.00



Privacy statement Using this site means you accept its terms Feedback to Education & Training
© 2013 Hewlett-Packard Development Company, L.P.