Index

Symbols

$MANPATH variable, 1
$PATH variable, 1
/etc/host.allow file, 1
/etc/ipf/ipf.conf file, 1
/etc/ssh/sshd_config file, 1

A

auditing
definition, 1
enabling BSM, 1
using BSM, 1
using Solaris Security Toolkit, 1
authorization
definition, 1
ldm subcommands, 1
levels, 1
read, 1
read and write, 1

B

Basic Security module (BSM), 1
auditing, 1
enabling, 1
BSM.See Basic Security module.
bsmconv(1M) command, 1

C

CLI.See command-line interface.
command-line interface (CLI), 1
commands
bsmconv(1M), 1
ldm(1M), 1
ssh(1M), 1
compliance
definition, 1
using Solaris Security Toolkit, 1
configuration
baseline for control domain, 1
factory-default, 1
mode, 1
selecting to boot, 1
storing on system controller, 1
control domain, 1
baseline configuration, 1
hardening, 1, 2, 3

D

daemons
drd, 1
ldmd, 1
vntsd, 1, 2
delayed reconfiguration (DR), 1
disable-rpc.fin script, 1
disable-sma.fin script, 1
disable-ssh-root-login.fin script, 1
domains
control, 1, 2, 3, 4
guest, 1
primary, 1
service, 1, 2
DR.See dynamic reconfiguration
drivers
customized, 1
ldm_control-secure.driver, 1, 2, 3
secure.driver, 1, 2
selecting alternate, 1
selecting none, 1
dynamic reconfiguration (DR), 1
dynamic reconfiguration daemon (drd), 1

E

enable-ipfilter.fin script, 1
enable-ldmd.fin script, 1
enable-ssh-root-login.fin script, 1

F

factory-default configuration, 1
files
/etc/host.allow, 1
/etc/ipf/ipf.conf, 1
/etc/ssh/sshd_config, 1
changed, 1
finish scripts
added, 1
disabled, 1

G

guest domain, 1

H

hardening
applying your own, 1
control domain, 1, 2
definition, 1
other than control domain, 1
hypervisor, 1

I

install-ldm script, 1, 2
install-ldm.fin script, 1

J

JASS.See Solaris Security Toolkit
JumpStart
minimal-ldm_control.profile, 1
minimizing, 1
JumpStart Architecture and Security Scripts (JASS).See Solaris Security Toolkit

L

LDC.See logical domain channel.
ldm subcommands
ls-dom, 1
rm-reconf, 1
user authorizations, 1
ldm(1M) command, 1
executing, 1
ldm(1M) man page, 1
accessing, 1
ldm_control-secure.driver, 1, 2, 3
ldmd.See Logical Domains Manager daemon
logical domain channel (LDC), 1
logical domains
definition, 1
roles, 1
Logical Domains Manager, 1, 2
Logical Domains Manager daemon (ldmd), 1
ls-dom subcommand, 1

M

minimizing
definition, 1
JumpStart support, 1
minimal-ldm_control.profile, 1
using Solaris Security Toolkit, 1

P

packages
SUNWjass, 1
SUNWldm, 1, 2
patches
Solaris Security Toolkit, 1
PCI Express (PCI-E) bus
splitting, 1
PCI-E.See PCI Express (PCI-E) bus.
physical devices, 1, 2
physical machine, 1
platforms
Sun Fire or SPARC Enterprise T1000 server, 1
Sun Fire or SPARC Enterprise T2000 server, 1
Sun UltraSPARC T1 processor, 1, 2
Sun UltraSPARC T2 processor, 1
primary domain, 1
profiles
minimal-ldm_control.profile, 1

R

RBAC.See Role-Based Access Control.
read
authorizing, 1
read and write
authorizing, 1
resources
See also virtual devices.
, 1
See also virtual devices.
definition, 1
rm-reconf subcommand, 1
Role-Based Access Control (RBAC), 1
roles
logical domains, 1

S

scripts
disable-rpc.fin, 1
disable-sma.fin, 1
disable-ssh-root-login.fin, 1
enable-ipfilter.fin, 1
enable-ldmd.fin, 1
enable-ssh-root-login.fin, 1
finish, added, 1
finish, disabled, 1
install-ldm, 1, 2
install-ldm.fin, 1
set-term-type.fin, 1
Solaris Security Toolkit, 1
Secure Shell (ssh)
use instead of Telnet, 1
secure.driver
changes from, 1
hardening other than control domain, 1
security
auditing, 1
authorization, 1
compliance, 1
hardening, 1
minimizing, 1
service domain, 1, 2
set-term-type.fin script, 1
Solaris Security Toolkit, 1
required patches, 1
Sun Fire or SPARC Enterprise T1000 server, 1
Sun Fire or SPARC Enterprise T2000 server, 1
Sun UltraSPARC T1 processor, 1, 2
Sun UltraSPARC T2 processor
preinstallation of software, 1
SUNWjass package, 1
SUNWldm package, 1, 2
system controller
monitoring and running physical machine, 1
storing configurations, 1

T

Telnet client
access to virtual consoles, 1
Telnet server
disabled, 1

V

variables
$MANPATH, 1
$PATH, 1
virtual devices, 1
I/O, 1
virtual console concentrator (vcc), 1
virtual CPU (vcpu), 1
virtual disk client (vdc), 1
virtual disk service (vds), 1
virtual network (vnet), 1
virtual switch (vsw), 1
virtual machine, 1
virtual network terminal server daemon (vntsd), 1, 2