1 2

System Auditing

1008 byte By Sandile at 2007-11-25 23:04:38
HiI'm hoping someone will be able to help me here.I'm running Solaris 10 i386 (Virtually - i.e using VMWare). I'm trying to enable and test System Auditing. My questions:- Do I need Trusted Solaris (TSOL) or does Solaris 10 come with TSOL modules enabled.- Will it be possible to run ...

Installing IPF on Trusted Solaris

752 byte By gallogjj at 2007-11-25 23:04:43
I am trying to install and get running the IPF package on Trusted Solaris. The packages (ipfx and ipf) seem to install fine and even run on boot however I can not run some of the support commands like ipfstatWhen I run ipfstat I get an error cannot open /dev/kmem. Reading throught he manuals I ...

label_encodings collors from C app

310 byte By Perry at 2007-11-25 23:04:44
Are there any C commands to get the collor that belongs to a label?I know I can parse the label_encodings file and figure it out but I was hoping that TSOL 8 would provide a command to get the collor for a label without me having to parse the label_encodings file.thanksPerry ...

Solaris 10 with Trusted Extensions

369 byte By at 2007-11-25 23:04:45
I just want to get some clarification since news report on this subject is not clear. I understand the whole concepts of the trusted extensions. Where I am cloudy will this still be strong enough to be able to continue multi-level processing? Will this version still have the labels encoding ...

tsolinfo acl entry

222 byte By at 2007-11-25 23:04:46
Hi,Can someone show an example of an acl entry for the tsolinfo file ?There is no example in the documentation and the setfacl format doesn't work as far as I can tell.Thanks.J.D.

Remote CDE Login Fails!

1259 byte By TheNewGuy at 2007-11-25 23:04:47
Gents:We have our TSOL servers configured much like guard servers...one NIC per Security Family with workstations on that specific LAN and at a specific maximum level.Only 127.0.0.1 lives in the TSOL family on any of our systems.That being said, here's our challenge:We still would like to be ...

Sun Fire V440 Server and TSol-8

123 byte By bigAl at 2007-11-25 23:04:50
Hi Guys,I am wondering if TSol-8 will install and run ok on the Sun Fire V440 Server?Any ideas?

Sun Fire V40z Server and TSol-8

115 byte By at 2007-11-25 23:04:51
Hi Guys,Anyone knows if TSol-8 would run ok the Sun Fire V40z server?ThanksbigAl

Can't display scheduled jobs

378 byte By johnpet at 2007-11-26 6:55:40
I'm using Trusted Solaris 8 7/03 and when I try to display the scheduled jobs via SMC I get the following error: "The management server cannot perform the operation requested. Verify that the CIMOM is running. The actual error reported was: RMIERROR". I didn't see any process running with a ...

Keytool Help

483 byte By lnordstrom at 2007-11-26 7:58:37
Hello, hopefully I am posting this in the correct forum. I am trying to use Keytool to install a certificate purchased through Entrust. I have installed in in IIS successfully, but when I get to the Import portion of the keytool, I get an error that states:"Keytool error: java.lang.Exception: ...

Permission denied error

233 byte By bbirger_ar at 2007-11-26 8:27:04
I have a problem on a SunFire V480 server running SunOS5.9. When I login as a user other than root to "vi" a file, I get the following error:Permission Denied. Any idea why?Thanks for your help.Amal

sshd_config Question

318 byte By dfrook at 2007-11-26 8:55:32
Does anybody know how to set a paramater in SSH so that if the connection have been idle (all channels) for a specified period of time thechild process is killed with SIGHUP, and connection is closed down. Does anybody know what value this is to set in the sshd_config file and what is the ...

Error messages

74 byte By aye_baba at 2007-11-26 9:07:43
How do I stop error messages from popping up on my terminal screen?

SSH hang up.

16158 byte By Jeff_C at 2007-11-26 9:46:59
Dear SSH experts,I was working for troubleshooting SSH for the whole afternoon. I have no idea what's wrong with my configuration.Whatever you input password or not,your login window hung up. Please refer to the following debug log:root@walden # /usr/lib/ssh/sshd -ddddebug1: sshd version ...

Trusted Device Driver

451 byte By mk1553b at 2007-11-26 10:10:44
We will be porting an existing Solaris 10 (serial) device driver to Trusted Solaris in the next few months. Can you point us to documentation that specifies what criteria is used for saying a driver is trusted ?For instance, are there changes to the DDI/DDK required to support trusted drivers, ...

IPsecinit.conf conruptted occutionally during Solaris Reboot

256 byte By may8000 at 2007-11-26 10:39:10
Hi, All:There is an issue bugs me for a long time: the ipsecinit.conf conruptted occutionally during Solaris reboot, then the maunal IPsec SAs are no longer validated, can anybody have ideas on how it happened?Thanks in advance!

Restricting access to USB ports on Solaris 8 and Sun Ray terminals

569 byte By cannonac at 2007-11-26 10:41:20
Hi All,I'm in the middle of setting up a workstation (Blade-100) connected to two Sun Ray 2 terminals for some analytical work (I know it isn't exactly the fastest system going, but it is all we have available until the new stuff comes in...). Due to the confidentiality and security ...

Open SSL Upgradation.

225 byte By reddy_chinni at 2007-11-26 11:23:14
Hi I want to upgrade Open SSL to 0.9.8d in all my Sun servers.Will there be any patch for doing that or i need to remove the previous installation and put a new one.Please advice me.prathap.

blocking an unsecured port in solaris 5.8

233 byte By Murugesht at 2007-11-26 12:01:29
Hello,Does any one give me the procedure how to block port (1521) at solaris 5.8 server so that no one can use it ? I do know there is a procedure existing for linux environment.thanks in advance,Murugesht

SST/JASS 4.2 "bug" reporting

1455 byte By kickslopa at 2007-11-26 13:32:40
1. In the Reference Manual:Using File Templates...This directory stores file templates that are copied to aJumpStart client during a hardening run.Not just Jumpstart clients as I can tell, but standalone runs as well.2. Messed up numeric list in docs:To Add a New Variable to the user.init ...

Sun Solaris telnet authentication bypass vulnerability

151 byte By bperttunena at 2007-11-26 18:13:22
What is Sun doing about the Solaris 10 telnet authentication bypass vulnerability whichwas mentioned here: http://www.kb.cert.org/vuls/id/881872

Possible bug in DST patches

1084 byte By fcbsecia at 2007-11-26 19:27:24
I am running Trusted Solaris 8 12/02 x86I have installed patches 125235-01 and 125237-01. It appears the spring forward time change works however the fall back time change does not seem to be losing an hour. I performed the following steps to test the time changes.Spring forward time change:1. ...

tsolxagent error

710 byte By hay1a at 2007-11-26 21:48:35
We are running Trusted Solaris 8 x86 HW 12/02 and are having trouble with one of our applications starting. The application is called in dtprofile to be started upon login and randomly it fails to open. We receive the errors listed below in /var/adm/messages. It seems completely random as I ...

Sun Alert and Security Discussion - What are the ports that are absolutely needed to be kept ope

585 byte By shiva@indiaa at 2007-11-26 23:10:41
HelloIn a desktop, standalone, not networked in a LAN, that does not even have a peer-to-peer computer in the local environment, but connected to the Internet for Browsing (The desktop is not a web server ) , e-mail and chat, what are the ports that are absolutely needed to be kept open ?How ...

Port number for rstatd

175 byte By leongyca at 2007-11-27 0:41:12
Hi,Correct me if I'm wrong that rstatd uses port number randomly evey time it started? Can it be configured to use a fixed port number?Thanks in advance.

Securely Removing individual files from a system

314 byte By tumminea at 2007-11-27 7:49:23
Is there any way to securely delete individual files from the Solaris OS so that the file is removed and overwritten. I have read on using the format utility to wipe whole disks, however I do not want to lose all data on that disk. In Linux the shred command deletes individual files and then ...

SSH version in ALOM 1.6.3

929 byte By gtaubea at 2007-11-27 11:33:34
We are using Nessus 3.0.5 build W313 with all standard plug-ins in order to verify the security of our system (Netra 210, Netra 440). This tool is complaining that the SSH version contained in ALOM 1.6.3 is older than 3.1.Here is the Nessus report:You are running a version of OpenSSH which is older ...