NOTE: All of these services are prohibited with a 'high' security setting, but if they are re-enabled manually the hostname information will remain hidden.

Sendmail daemon secured

Sendmail is forced to perform only outgoing mail. No incoming mail will be accepted.

Network parameters secured

Sun's nddconfig security tool is run. For additional information, view Sun's document, Solaris Operating Environment Network Settings for Security, at

http://www.sun.com/solutions/ blueprints/1200/network-updt1.pdf.

Executable stacks disabled

The system stack is made non-executable. This is done so security exploitation programs cannot take advantage of the Solaris OE kernel executable system stack and thereby attack the system.

NFS port monitor restricted

The NFS server normally accepts requests from any port number. The NFS Server is altered to process only those requests from privileged ports. Note that with the high security setting, NFS is disabled; however if the service is re-enabled manually, the port restriction will still apply.

Remote CDE login disabled

The Remote CDE login is disabled.

Xerox FreeFlow Print Server router capabilities disabled

The Xerox FreeFlow Print Server router capabilities is disabled (empty/etc/notrouter file created).

12

Security Guide

Page 16
Image 16
Xerox 701P46740 Sendmail daemon secured, Network parameters secured, Executable stacks disabled, Remote CDE login disabled