HP might
want to consider finishing SSH for MPE
SOX is
already having an impact that is leaking through the 3000s
security. Is it hopeless to think that HP wont finish up the
SSH security tool that could help thousands of HP 3000 shops? Donna
Garverick, whos on the OpenMPE board of directors, wishes it
werent so obvious that HP wont fix a hole in the
3000s Internet capability. If this were a different time,
Id be pushing HP real hard to fully support SSH on MPE,
she said. Thanks to Sarbanes-Oxley, a lot of us are running
into this. Clearly, weve got a security issue on MPE. SSH
has limited support on the 3000, but it hasnt made it into
HPs standard release of MPE/iX its a freeware
add-on.
Garverick said that FTP on the 3000 really doesnt fill
the security gap with its current feature set, either. The
topic has come up for FTP, she said. For us, the
preferred solution is to do secure FTP... but anonymous FTP is
(barely) acceptable. The problem with MPEs anonymous FTP is
that its really meant for pick-up only. (Ill put a file
somewhere in /FTPguest/ for you to come pick up.) However, if you put
a file into /FTPguest/, unless I am user.FTPguest (unlikely) or an SM
user (not), Ill not have access to this file. In a
multi-server, multi-OS environment, non-privileged production users
have to be able to get these files.
Garverick, who works with 3000s at Longs Drugs
California HQ, has opened a Service Request with HP requesting
site chmod support in FTP, which could serve as a
workaround for SSH. The number is SR/jagaf55353. If youre
in a similar situation, please call HP and let them know you want
site chmod support, she said.