資源描述:
《solaris安全設(shè)置方案》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在行業(yè)資料-天天文庫。
1、From:編號:To:版本號:1.1Cc:存檔路徑:Solari系統(tǒng)安全設(shè)置方案1、打patchpatch的下載地址是:http://sunsolve.sun.com/securitypatch在下載了相應(yīng)系統(tǒng)以及平臺的補丁包之后,可以按照下列步驟安裝:首先要進入單用戶方式:按STOP-A后,敲boot-s或者執(zhí)行init1命令然后執(zhí)行下列命令:#cd/var/tmp#unzip8_Recommended.tar.Z#cd8_Recommended#./install_cluster2、停掉不必要的服務(wù)cd/etc/rc2.dmkdirDISABLEmvS73nfs.clientK28nfs.
2、serverS15nfs.serverS74autofsS30sysid.netS71sysid.sysS72autoinstallDISABLEmvS93cacheos.finishS73cachefs.daemonS80PRESERVES85powerK07dmiS77dmiS47aspppS89bdconfigDISABLEmvS70uucpS80lpS76nscdS74xntpdK07snmpdxS88sendmailS47pppdS99sshdS71ldap.clientDISABLEcd/etc/rc3.dmkdirDISABLEmvS15nfs.serverS34dhcpS50a
3、pacheS76snmpdxS77dmiDISABLE3、安裝ssh3.4p1a、下載軟件包,解壓縮,按順序安裝軟件包zlib-1.1.3-sol8-sparc-local.gzperl-5.6.1-sol8-sparc-local.gzprngd-0.9.23-sol8-sparc-local.gzegd-0.8-sol8-sparc-local.gz12北京潤匯科技有限公司tcp_wrappers-7.6-sol8-sparc-local.gzopenssl-0.9.6c-sol8-sparc-local.gzb、啟動prngdcat/var/log/syslog/var/adm/mess
4、ages>/usr/local/etc/prngd/prngd-seedmkdir/var/spool/prngd/usr/local/bin/prngd/var/spool/prngd/pool/usr/local/bin/egc.pl/var/spool/prngd/poolget添加文件如下vi/etc/init.d/prngd#!/bin/shpid=`/usr/bin/ps-e
5、/usr/bin/grepprngd
6、/usr/bin/sed-e's/^*//'-e's/.*//'`case$1in'start')/usr/local/bin/prngd/var/spool/prngd
7、/pool;;'stop')if["${pid}"!=""]then/usr/bin/kill${pid}fi;;*)echo"usage:/etc/init.d/prngd{start
8、stop}";;esac修改權(quán)限chownroot/etc/init.d/prngdchgrpsys/etc/init.d/prngdchmod555/etc/init.d/prngdln-s/etc/init.d/prngd/etc/rc2.d/S98prngdc、安裝ssh和sshd修改/.profilecd/vi.profilePATH=/usr/local/sbin:/usr/local/bin:/u
9、sr/local/ssl/bin:/usr/sbin:/usr/bin:/usr/ccs/binexportPATH12北京潤匯科技有限公司運行環(huán)境變量../.profilecd/tools/openssh-3.4p1./configure--with-tcp-wrappersmakemakeinstalluseraddsshd編輯文件vi/etc/init.d/sshd#!/bin/shpid=`/usr/bin/ps-e
10、/usr/bin/grepsshd
11、/usr/bin/sed-e's/^*//'-e's/.*//'`case$1in'start')/usr/local/sbin/ss
12、hd;;'stop')if["${pid}"!=""]then/usr/bin/kill${pid}fi;;*)echo"usage:/etc/init.d/sshd{start
13、stop}";;esac修改權(quán)限chownroot/etc/init.d/sshdchgrpsys/etc/init.d/sshdchmod555/etc/init.d/sshdln-s/etc/init.d/sshd/