This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
netras [2007/08/27 20:13] 75.132.107.251 |
netras [2007/08/27 21:43] 75.132.107.251 |
||
---|---|---|---|
Line 100: | Line 100: | ||
This will further lock down services, set PermitRootLogin to "No" in SSH, harden the FTP server configuration, tighten permissions, configure log rotation, set up TCP wrappers, enforce password complexity rules, and generally do Useful Things to keep the system secure. JASS does a couple of overly-secure things, like restrict SSH logins to machines on the local domain, so in /etc/hosts.allow, we'll need to change the sshd line to read "all". | This will further lock down services, set PermitRootLogin to "No" in SSH, harden the FTP server configuration, tighten permissions, configure log rotation, set up TCP wrappers, enforce password complexity rules, and generally do Useful Things to keep the system secure. JASS does a couple of overly-secure things, like restrict SSH logins to machines on the local domain, so in /etc/hosts.allow, we'll need to change the sshd line to read "all". | ||
- | ==Enable Binary Auditing== | ||
- | Edit /etc/security/audit_control to read: | ||
- | |||
- | dir:/var/audit | ||
- | flags:lo,ap,ss,ua,am,pc | ||
- | minfree:20 | ||
- | naflags:lo,ap,ss,ua.am,pc | ||
- | |||
- | Then run: | ||
- | |||
- | /etc/security/bsmconv | ||
- | |||
- | and reboot. Binary logs (similar to pacct logs) will now be written to /var/audit and will be readable via praudit(1). | ||
- | |||
- | Once rebooted, run | ||
- | |||
- | auditconfig -setpolicy +argv | ||
- | |||
- | which will enable recording of process arguments. | ||
Line 149: | Line 130: | ||
archive_location nfs://192.168.1.30/jumpstart/sol10u3.flar | archive_location nfs://192.168.1.30/jumpstart/sol10u3.flar | ||
partitioning explicit | partitioning explicit | ||
- | filesys c0t1d0s0 6036 / | + | filesys rootdisk.s0 6036 / |
- | filesys c0t1d0s1 512 swap | + | filesys rootdisk.s1 512 swap |
- | filesys c0t1d0s3 2048 / | + | filesys rootdisk.s3 2048 /var |
Share the /jumpstart directory: | Share the /jumpstart directory: |