Xerox 6180N Common Controller System Guide v 3.7 - Page 32

Solaris file permissions secured, Network and name service changes

Page 32 highlights

Security and Network Setup System Guide Solaris file permissions secured The fix-modes utility (from the Solaris Security Toolkit) adjusts group and world write permissions. It is run with the '-s' option to secure file permissions for Solaris files that were created at install time only. Customer-generated files will not be affected. NOTE: When this command is run, a file called /var/sadm/ install/content.mods is left. Do not delete this file. It contains valuable information needed by fix modes to revert the changes to the system file permissions if the security setting is changed back to medium. Network and name service changes Disabling secure name service databases The following databases are disabled when Security is invoked: • passwd(4) • group(4) • exec_attr(4) • prof_attr(4) • user_attr(4) Multicast routing disabled Multicast is used to send data to many systems at the same timewhile using one address. OS and host information hidden The ftp, telnet and sendmail banners are set to null so that users in cannot see the hostname and OS level. (Note that all of these services are prohibited with a 'high' security setting, but if they are re-enabled manually the hostname information will remain hidden.) Sendmail daemon secured Sendmail is forced to perform only outgoing mail. No incoming mail will be accepted. 4-8 Common Controller

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

Security and Network Setup
System Guide
4-8
Common Controller
Solaris file permissions secured
The fix-modes utility (from the Solaris Security Toolkit) adjusts
group and world write permissions. It is run with the '-s' option to
secure file permissions for Solaris files that were created at
install time only.
Customer-generated files will not be affected.
NOTE:
When this command is run, a file called /var/sadm/
install/content.mods is left. Do not delete this file.
It contains
valuable information needed by fix modes to revert the changes
to the system file permissions if the security setting is changed
back to medium.
Network and name service changes
Disabling secure name service databases
The following databases are disabled when Security is invoked:
passwd(4)
group(4)
exec_attr(4)
prof_attr(4)
user_attr(4)
Multicast routing disabled
Multicast is used to send data to many systems at the same
timewhile using one address.
OS and host information hidden
The ftp, telnet and sendmail banners are set to null so that users
in cannot see the hostname and OS level.
(Note that all of
these services are prohibited with a 'high' security setting, but if
they are re-enabled manually the hostname information will
remain hidden.)
Sendmail daemon secured
Sendmail is forced to perform only outgoing mail. No incoming
mail will be accepted.