Xerox 6180N Common Controller System Guide v 3.7 - Page 33

Network parameters secured, Executable stacks disabled, NFS port monitor restricted - network settings

Page 33 highlights

System Guide Security and Network Setup Network parameters secured Sun's nddconfig security tool is run. For additional information, view Sun's document, Solaris Operating Environment Network Settings for Security, at http://www.sun.com/solutions/blueprints/ 1200/network-updt1.pdf. Executable stacks disabled The system stack is made non-executable. This is done so security exploitation programs cannot take advantage of the Solaris OE kernel executable system stack and thereby attack the system NFS port monitor restricted The NFS server normally accepts requests from any port number. The NFS Server is altered to process only those requests from privileged ports. Note that with the high security setting, NFS is disabled; however if the service is re-enabled manually the port restriction will still apply. Remote CDE login disabled The Remote CDE login is disabled. DocuSP router capabilities disabled The DocuSP router capabilities is disabled (empty /etc/notrouter file created). Security warning banners Security warning banners are displayed when a user logs in or telnets into the DocuSP server. This message explains that only authorized users should be using the system and that any others face the possibility of being monitored by law enforcement officials. NOTE: DRW (DocuSP Remote Workflow) is not impacted by security settings. Common Controller 4-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

System Guide
Security and Network Setup
Common Controller
4-9
Network parameters secured
Sun's nddconfig security tool is run. For additional information,
view Sun's document, Solaris Operating Environment Network
1200/network-updt1.pdf.
Executable stacks disabled
The system stack is made non-executable.
This is done so
security exploitation programs cannot take advantage of the
Solaris OE kernel executable system stack and thereby attack
the system
NFS port monitor restricted
The NFS server normally accepts requests from any port
number. The NFS Server is altered to process only those
requests from privileged ports.
Note that with the high security
setting, NFS is disabled; however if the service is re-enabled
manually the port restriction will still apply.
Remote CDE login disabled
The Remote CDE login is disabled.
DocuSP router capabilities disabled
The DocuSP router capabilities is disabled (empty /etc/notrouter
file created).
Security warning banners
Security warning banners are displayed when a user logs in or
telnets into the DocuSP server. This message explains that only
authorized users should be using the system and that any others
face the possibility of being monitored by law enforcement
officials.
NOTE:
DRW (DocuSP Remote Workflow) is not impacted by
security settings.