Re: Experiences using 'enhanced' Solaris features: BSM, extended ACLs, RBAC

From: Darren J Moffat (Darren.Moffat_at_Sun.COM)
Date: 03/23/05

  • Next message: Kapetanakis Giannis: "ipf and NIS"
    To: Drew Simonis <simonis@myself.com>
    Date: Wed, 23 Mar 2005 10:37:45 -0800
    
    

    On Sat, 2005-03-19 at 15:57, Drew Simonis wrote:
    > isolation. You really need to evaluate what events can be
    > recorded, and who would be the consumer of that data. I've

    Note that you can change the class definitions and define your
    own.

    See this Sun Blueprint, originally written for Solaris 8, but
    the concepts are still very relevant for Solaris 9 and 10.

    http://www.sun.com/blueprints/0201/audit_config.pdf

    > found it necessary to have a plan of what is to be done with
    > the data as a means to justify the collection, since the load
    > can be non-trivial, and the data geberated substantial. If you
    > just collect it because you can, then you are clearly doing half
    > of what can be done, and the cost probably outweighs the benefit.

    Or you are just doing it to give the disks something to do :-)

    With Solaris 10 you can also send summary data of the event classes
    to syslog, see audit_syslog(5) for more details.

    -- 
    Darren J Moffat
    

  • Next message: Kapetanakis Giannis: "ipf and NIS"

    Relevant Pages

    • Advice on porting app to Solaris 10
      ... The app consists of two processes, one to collect data, and one to process ... "consumer" side from being able to modify the collected data files. ... Since I don't have virtual consoles under Solaris, ...
      (SunManagers)
    • Re: user proces cloaking
      ... and I got that to work ok on Solaris 9 (with ... it does all sorts of totally unsupported stuff), ... In anything less than the isolation of zones, ...
      (comp.unix.solaris)
    • Re: A thread ID question
      ... The result on Solaris is different than that on Linux: ... Despite any other listing of product contents found ... herein, the consumer is advised that, in actuality, this product ...
      (comp.unix.programmer)