Xerox 6180N DocuSP Common Controller System Guide - Page 59

User level changes, Solaris file permissions, Network and name service changes

Page 59 highlights

User level changes Security and Network Setup The following user-level changes are made: • all users for at, cron, and batch are disallowed • nuucp account is disabled • listen account is disabled • password entry locked for bin, sys, adm, uucp, nobody, • noaccess, nobody4, and anonymous • removal of + from the hosts.equiv file Solaris file permissions The fix-modes utility (from the Solaris Security Toolkit) adjusts group and world write permissions. It is run with the s option to secure file permissions for Solaris files that were created at install time only. Customer-generated files are not affected. NOTE: When this command is run, a file called /var/ sadm/ install/content.mods is left. Do not delete this file. It contains valuable information needed by fix modes to revert the changes to the system file permissions if the security setting is changed back to medium. Network and name service changes The following changes occur when security is invoked. Disabling secure name service databases The following databases are disabled when security is invoked: • passwd(4) • group(4) • exec_attr(4) • prof_attr(4) • ser_attr(4) System Guide 3-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Security and Network Setup
System Guide
3-9
User level changes
The following user-level changes are made:
all users for at, cron, and batch are disallowed
nuucp account is disabled
listen account is disabled
password entry locked for bin, sys, adm, uucp, nobody,
noaccess, nobody4, and anonymous
removal of + from the hosts.equiv file
Solaris file permissions
The fix-modes utility (from the Solaris Security Toolkit)
adjusts group and world write permissions. It is run with the -
s option to secure file permissions for Solaris files that were
created at install time only.
Customer-generated files are not
affected.
NOTE:
When this command is run, a file called /var/ sadm/
install/content.mods is left. Do not delete this file.
It contains
valuable information needed by fix modes to revert the
changes to the system file permissions if the security setting
is changed back to medium.
Network and name service changes
The following changes occur when security is invoked.
Disabling secure name service databases
The following databases are disabled when security is
invoked:
passwd(4)
group(4)
exec_attr(4)
prof_attr(4)
ser_attr(4)