Search:
== Solaris 10 == * Fun beginners cribsheet with tips: http://www.pcnetcom.net/solaris.htm * Learning Solaris 10: http://www.learningsolaris.com/ * Good reading: http://http//www.opensolaris.org/os/blogs/ * Security Features burblingly enthusiastic review: http://www.securityfocus.com/infocus/1776 * Sun's rather dry FAQ: http://www.sun.com/software/solaris/faqs/security.xml * Hardening: * "Automating Solaris 10 File Integrity Checks," March 2005, by Glenn Brunettehttp://www.sun.com/blueprints/0305/819-2259.pdf * CIS tools (Sol 10 not supported as of Nov 9, 2005) http://www.cisecurity.org/bench_solaris.html * Possibly relevant ** Minimizing the Solaris Operating Environment for Security: Updated for Solaris 9 Operating Environment http://www.sun.com/blueprints/1102/816-5241.pdf ** Solaris Operating Environment Security: Updated for Solaris 9 Operating Environment http://www.sun.com/blueprints/1202/816-5242.pdf * Discussing / getting buy-in from management on priorities: http://www.sans.org/top20/ == Installation == * Solaris 8 Build Document http://www.sun.com/bigadmin/content/ submitted/Solaris_build_document.pdf * Sun's Secure Shell Tools kit /secureshell-tools.tar.Z/ == Hardening / Securing Solaris == * Sun /SST Solaris Security Toolkit [[jass]] * Titan hardening script http://www.fish.com/titan/ * Sun Blueprints, Security section: http://www.sun.com/blueprints/browsesubject.html * Solaris Hardening Recommendations http://www.sans.org/resources/hard_solaris.htm == Intrusion Detection == * /Intrusion Detection using Solaris' Basic Security Module/ http://www.securityfocus.com/printable/infocus/1211 * Catalog of system integrity checkers: http://www.softpanorama.org/Security/integrity_checkers.shtml == Other References == * http://www.adminschoice.com/docs/P_securing_solaris.htm: this document may be sufficient for an Audit 5900. * Catalog of Open Source Security Tools: http://www.softpanorama.org/Security/classic_sec_tools.shtml * Information Security Implementation for a Local Government http://www.group1ifw.com/whitepapers/information_security.htm * Solaris Tips & Tricks: http://sysunconfig.net/unixtips/solaris.html * Sun Security Resources: http://wwws.sun.com/software/security/resources.html * Other tools recommended by Sun: http://www.sun.com/blueprints/tools/ == Unfiled At The Moment == * The Centre for Internet Security has some papers that could possibly be useful: http://www.cisecurity.org/resources.html ** /Taking Control: Policy-based Vulnerability Management for the Real World/ ** /Auditing-In-Depth For Solaris/ ** /Configuration and Patch Verification on Solaris Systems/ ** Center for Internet Security /Solaris Benchmarks/ /http://www.cisecurity.org/bench_solaris.html " the Benchmark document contains detailed instructions for implementing the steps necessary for CIS Level-I security. CISscan ? a Host-based Scoring Tool ? scores the security of a system against the Benchmark and creates a variance report." * http://www.cert.org/security-improvement/implementations/i027.02.html The CERT's guide to installing and hardening Solaris 2.6
Summary:
This change is a minor edit.
To save this page you must answer this question:
What do you get when you remove the ARIS from Solaris?
Username: