Sun Microsystems Logo
Products and Services
 
Support and Training
 
 

Previous Previous     Contents     Index     Next Next

Index

Numbers and Symbols

* (asterisk)
device_allocate file, (Index Term), (Index Term)
wildcard character in ASET, (Index Term)
\ (backslash)
device_allocate file, (Index Term)
ending in device_maps file, (Index Term)
. (dot), path variable entry, (Index Term)
= (equal sign), file permissions symbol, (Index Term)
- (minus sign)
audit flag prefix, (Index Term)
file permissions symbol, (Index Term)
+ (plus sign)
audit flag prefix, (Index Term)
file permissions symbol, (Index Term)
# (pound sign)
device_allocate file, (Index Term)
device_maps file, (Index Term)
? (question mark), in ASET tune files, (Index Term)
^+ audit flag prefix, (Index Term)
^- audit flag prefix, (Index Term)
~/.gkadmin file, description, (Index Term)
~/.k5login file, description, (Index Term)
$HOME/.ssh/known_hosts file
description, (Index Term), (Index Term)
3des-cbc encryption algorithm, ssh_config file, (Index Term)
3des encryption algorithm, sshd_config file, (Index Term)

A

aa audit flag, (Index Term)
absolute mode
changing file permissions, (Index Term), (Index Term)
description, (Index Term)
setting special permissions, (Index Term)
access
getting to server
with SEAM, (Index Term)
obtaining for a specific service, (Index Term)
restricting for KDC servers, (Index Term)
root access
displaying attempts on console, (Index Term)
monitoring su command use, (Index Term), (Index Term)
restricting, (Index Term), (Index Term)
security
ACLs, (Index Term), (Index Term), (Index Term)
controlling system usage, (Index Term)
file access restriction, (Index Term)
firewall setup, (Index Term), (Index Term)
login access restrictions, (Index Term), (Index Term)
login control, (Index Term)
monitoring system usage, (Index Term)
network control, (Index Term)
path variable setting, (Index Term)
physical security, (Index Term)
reporting problems, (Index Term)
root login tracking, (Index Term)
setuid programs, (Index Term)
sharing files, (Index Term)
system logins, (Index Term)
access control list
See ACL
Access Control Lists (ACLs), See ACL
ACL
adding entries, (Index Term)
changing entries, (Index Term)
checking entries, (Index Term)
commands, (Index Term)
default entries for directories, (Index Term), (Index Term)
deleting entries, (Index Term), (Index Term)
description, (Index Term), (Index Term)
directory entries, (Index Term), (Index Term)
displaying entries, (Index Term), (Index Term)
format of entries, (Index Term)
kadm5.acl file, (Index Term), (Index Term), (Index Term)
setting entries, (Index Term)
valid file entries, (Index Term)
acl token, format, (Index Term)
ad audit flag, (Index Term)
Add Administrative Role wizard
description, (Index Term), (Index Term)
Add Right dialog box, description, (Index Term)
Add User wizard, description, (Index Term)
adding
administration principals (SEAM), (Index Term)
allocatable devices (BSM), (Index Term)
custom roles (RBAC), (Index Term)
PAM module, (Index Term)
password encryption module, (Index Term)
rights profiles (RBAC), (Index Term)
roles (RBAC), (Index Term), (Index Term)
service principal to keytab file (SEAM), (Index Term)
the first role (RBAC), (Index Term)
the first user (RBAC), (Index Term)
admin_server section, krb5.conf file, (Index Term)
administering
auditing
audit class, (Index Term)
audit classes, (Index Term)
audit event, (Index Term)
audit files, (Index Term)
audit flags, (Index Term), (Index Term)
audit records, (Index Term)
audit trail overflow prevention, (Index Term)
auditreduce command, (Index Term)
cost control, (Index Term)
description, (Index Term)
efficiency, (Index Term)
kernel events, (Index Term)
process preselection mask, (Index Term)
reducing storage-space requirements, (Index Term)
user-level events, (Index Term)
SEAM
keytabs, (Index Term)
policies, (Index Term)
principals, (Index Term)
Secure Shell, (Index Term)
administrative (old) audit class, (Index Term)
administrative audit class, (Index Term)
aes128-cbc encryption algorithm, ssh_config file, (Index Term)
agent daemon, Secure Shell, (Index Term)
algorithms
configuration, (Index Term)
password encryption, (Index Term)
aliases file (ASET)
description, (Index Term)
example, (Index Term)
format, (Index Term)
specification, (Index Term)
all
audit class, (Index Term)
audit flag
caution for using, (Index Term)
described, (Index Term)
in user audit fields, (Index Term)
All rights profile
description, (Index Term), (Index Term)
allhard string, audit_warn script, (Index Term)
allocate command
authorizations required, (Index Term)
how the allocate mechanism works, (Index Term)
options, (Index Term)
using, (Index Term)
allocate error state, (Index Term), (Index Term)
AllowGroups keyword, sshd_config file, (Index Term)
AllowTCPForwarding keyword, sshd_config file, (Index Term)
AllowUsers keyword, sshd_config file, (Index Term)
allsoft string, audit_warn script, (Index Term)
always-audit flags
description, (Index Term), (Index Term)
process preselection mask, (Index Term)
am audit flag, (Index Term)
analysis
praudit command, (Index Term), (Index Term)
ap audit flag, (Index Term)
application audit class, (Index Term)
arbitrary token
format, (Index Term)
item size field, (Index Term)
print format field, (Index Term)
Archive tape drive clean script, (Index Term)
arg token, (Index Term)
arge audit policy
description, (Index Term)
exec_env token and, (Index Term)
argv audit policy
description, (Index Term)
exec_args token and, (Index Term)
as audit flag, (Index Term)
ASET
description, (Index Term)
environment variables, (Index Term)
error messages, (Index Term)
NFS servers and, (Index Term)
aset command
initiating ASET sessions, (Index Term)
-p option, (Index Term)
running ASET interactively, (Index Term)
running ASET periodically, (Index Term)
stop running ASET periodically, (Index Term)
aset.restore command, description, (Index Term)
ASETDIR variable (ASET), working directory specification, (Index Term)
asetenv file
description, (Index Term)
modifying, (Index Term)
running ASET periodically, (Index Term)
ASETSECLEVEL variable (ASET), setting security levels, (Index Term)
Assign Administrative Role dialog box, description, (Index Term)
Assign Rights to Role dialog box, description, (Index Term)
asterisk (*)
device_allocate file, (Index Term), (Index Term)
wildcard character, (Index Term)
at command, authorizations required, (Index Term)
atq command, authorizations required, (Index Term)
attr token, (Index Term)
audio_clean script, (Index Term)
audio devices, device-clean scripts, (Index Term)
AUDIO_DRAIN ioctl system call, (Index Term)
AUDIO_SETINFO ioctl system call, (Index Term)
AUDIOGETREG ioctl system call, (Index Term)
AUDIOSETREG ioctl system call, (Index Term)
audit administration audit class, (Index Term)
audit characteristics
overview, (Index Term)
process preselection mask, (Index Term)
audit class
description, (Index Term), (Index Term)
audit classes
description, (Index Term)
flags and definitions, (Index Term)
mapping events, (Index Term)
audit command
description, (Index Term)
-n option, (Index Term)
preselection mask for existing processes (-s option), (Index Term)
rereading audit files (-s option), (Index Term)
resetting directory pointer (-s option), (Index Term)
Audit Control, rights profile, (Index Term)
audit_control file
audit daemon rereading after editing, (Index Term)
audit_user file modification, (Index Term)
dir: line
described, (Index Term)
examples, (Index Term)
examples, (Index Term)
flags: line
described, (Index Term)
prefixes in, (Index Term)
process preselection mask, (Index Term)
minfree: line
audit_warn condition, (Index Term)
described, (Index Term)
naflags: line, (Index Term)
overview, (Index Term), (Index Term), (Index Term)
prefixes in flags line, (Index Term)
problem with contents, (Index Term)
audit daemon
audit_startup file, (Index Term)
audit trail creation, (Index Term), (Index Term)
audit_warn script
conditions invoking, (Index Term), (Index Term)
described, (Index Term), (Index Term)
execution of, (Index Term)
functions, (Index Term)
order audit files are opened, (Index Term)
rereading the audit_control file, (Index Term)
audit_data file, (Index Term)
audit directory, description, (Index Term)
audit event
audit_event file, (Index Term), (Index Term)
description, (Index Term), (Index Term), (Index Term)
kernel event, (Index Term)
mapping to classes, (Index Term)
user-level events, (Index Term)
audit_event file, (Index Term), (Index Term)
audit files
auditreduce command, (Index Term), (Index Term)
combining, (Index Term), (Index Term), (Index Term)
copying messages to single file, (Index Term)
displaying in entirety, (Index Term)
file token, (Index Term)
minimum free space for file systems, (Index Term)
names, (Index Term)
form, (Index Term)
still-active files, (Index Term)
time stamps, (Index Term)
nonactive files marked not_terminated, (Index Term)
order for opening, (Index Term)
printing, (Index Term)
reducing, (Index Term), (Index Term), (Index Term)
reducing storage-space requirements, (Index Term), (Index Term)
switching to new file, (Index Term)
time stamps, (Index Term)
audit flags, (Index Term)
audit_control file line, (Index Term)
audit_user file, (Index Term), (Index Term)
definitions, (Index Term)
description, (Index Term)
effect on public objects, (Index Term)
exceptions to machine-wide settings, (Index Term)
machine-wide, (Index Term), (Index Term), (Index Term)
overview, (Index Term), (Index Term)
prefixes, (Index Term)
process preselection mask, (Index Term)
syntax, (Index Term), (Index Term)
audit ID
mechanism, (Index Term)
overview, (Index Term)
audit messages, copying to single file, (Index Term)
audit policies
defaults, (Index Term)
description, (Index Term)
effects of, (Index Term)
audit policy, public, (Index Term)
audit records
audit directories full, (Index Term), (Index Term), (Index Term)
converting to readable format, (Index Term), (Index Term), (Index Term), (Index Term)
description, (Index Term)
displaying the format, (Index Term)
events that generate, (Index Term)
format or structure, (Index Term)
formatting example, (Index Term), (Index Term)
overview, (Index Term)
reducing audit files, (Index Term)
Audit Review, rights profile, (Index Term)
audit session ID, (Index Term)
audit_startup file, (Index Term)
audit threshold, (Index Term)
audit tokens
audit record format, (Index Term)
description, (Index Term), (Index Term)
format, (Index Term)
table of, (Index Term)
audit trail
analysis
praudit command, (Index Term), (Index Term)
analysis costs, (Index Term)
creating
audit daemon's role, (Index Term), (Index Term), (Index Term)
audit_data file, (Index Term)
overview, (Index Term)
description, (Index Term)
events included, (Index Term)
merging all files, (Index Term), (Index Term)
monitoring in real time, (Index Term)
no public objects, (Index Term)
overflow prevention, (Index Term)
overview, (Index Term)
audit_user file
exception to machine-wide audit flags, (Index Term)
prefixes for flags, (Index Term)
process preselection mask, (Index Term)
user audit fields, (Index Term), (Index Term)
audit_warn script, (Index Term)
audit daemon execution of, (Index Term)
conditions invoking, (Index Term), (Index Term)
description, (Index Term)
strings, (Index Term), (Index Term)
auditconfig command
audit flags as arguments, (Index Term), (Index Term)
description, (Index Term)
prefixes for flags, (Index Term)
auditd daemon
audit_startup file, (Index Term)
audit trail creation, (Index Term), (Index Term), (Index Term), (Index Term)
audit_warn script
conditions invoking, (Index Term), (Index Term)
described, (Index Term)
execution of, (Index Term)
functions, (Index Term)
order audit files are opened, (Index Term)
rereading the audit_control file, (Index Term)
auditing, rights profiles, (Index Term)
auditreduce command, (Index Term), (Index Term)
-c option, (Index Term)
cleaning not_terminated files, (Index Term)
-d option, (Index Term)
description, (Index Term), (Index Term)
examples, (Index Term)
-O option, (Index Term)
options, (Index Term)
time stamp use, (Index Term)
trailer tokens, and, (Index Term)
without options, (Index Term), (Index Term)
auditsvc() system call, audit_warn script and, (Index Term)
AUE_... names, description, (Index Term)
auth_attr database
description, (Index Term), (Index Term)
RBAC relationships, (Index Term)
AUTH_DH authentication, (Index Term)
AUTH_DH client-server session, (Index Term), (Index Term)
additional transaction, (Index Term)
client authenticates server, (Index Term)
contacting the server, (Index Term), (Index Term)
decrypting the conversation key, (Index Term)
generating public and secret keys, (Index Term)
generating the conversation key, (Index Term)
running keylogin, (Index Term)
storing information on the server, (Index Term), (Index Term)
verifier returned to client, (Index Term)
authentication
configuring cross-realm, (Index Term)
description, (Index Term)
DH, (Index Term), (Index Term)
network security, (Index Term), (Index Term)
overview of Kerberos, (Index Term)
root for NFS, (Index Term)
SEAM and, (Index Term)
Secure Shell
description, (Index Term)
hosts, (Index Term)
methods, (Index Term)
steps, (Index Term)
users, (Index Term)
terminology, (Index Term)
types, (Index Term)
authentication parameters, ssh_config file, (Index Term)
authenticator
in SEAM, (Index Term), (Index Term)
authorization
database
See auth_attr database
delegating, (Index Term)
description, (Index Term), (Index Term), (Index Term), (Index Term)
granularity, (Index Term)
naming convention, (Index Term)
network security, (Index Term), (Index Term)
SEAM and, (Index Term)
types, (Index Term)
authorized_keys file, description, (Index Term)
auths command, description, (Index Term)
authtok_check module, description, (Index Term)
authtok_get module, description, (Index Term)
authtok_store module, description, (Index Term)
Automated Security Enhancement Tool, See ASET
automatically enabling auditing, (Index Term)
automating principal creation, (Index Term)
Previous Previous     Contents     Index     Next Next