Monday Jan 07, 2008

Glenn Brunette just published an excellent blog listing his 5 favorite Solaris security features.  Among the valuable quotes are:

  • Solaris has had its auditing facility in place since Solaris 2.3, but I can't even begin to count how often I talk with people who do not know that it exists.  (I frequently get this question)
  • Zones are IMHO one of the most significant security features in the Solaris 10 OS. Kernel and most user-land forms of root kits are essentially rendered non-effective when running your applications in a sparse-root non-global zone. (I even recommend to customer when only running one application on a box to run it in a local zone for enhanced security.)
  • For those wanting something a little more advanced, you can use RBAC to implement a two-person (or four-eyes) access control scenario.  (An excellent recommendation for security conscious DoD customers

He also points you to a number of learning resources on Solaris:

Why should you care?

You chose Solaris because of its stellar reputation for security.  Don't be "living in the 90s."  Take the time to learn the new features of Solaris 10 so that you can build and maintain a more robust and secure infrastructure for your organization.

If security is your main area of interest, join the OpenSolaris security community and participate.  Don't forget to get your free download of Solaris 10 or OpenSolaris for Sparc or X64 platforms.

Comments:

Solaris has been receiving EAL4 evaluations against the Controlled Access Protection Profile (CAPP) since the Solaris 2.5 days. With Solaris 8 we added the RBAC PP. To the best of my knowledge the Linux variants (RHAT 4 and Suse) have only recently (2006) received EAL 4 evaluations. We were the first to have a multi-level OS with TSOL 2.5 and some versions of SunOS 4. (aka Solaris 1.X) Several versions of Trusted Solaris (2.5. 2.6, 8) have received EAL4 evaluations including the LSPP. No Linux or MS Windows variant has ever received this evaluation yet.
http://www.watchrolexshop.com
http://www.gamegoldme.com
http://www.cheap-lotrogold.com
http://www.globalsale.me/Aion-gold-083.aspx
http://www.cheap-gamegold.org
http://www.gamegoldvip.org

Posted by lotro gold on June 25, 2009 at 01:02 AM EDT #

Post a Comment:
  • HTML Syntax: NOT allowed