System Administration Guide: Security Services
    
D
 
 -D option
  auditreduce command ( Index Term Link )
  ppriv command ( Index Term Link )
 
 d_passwd file
  creating ( Index Term Link )
  description ( Index Term Link )
  disabling dial-up logins temporarily ( Index Term Link )
 
 daemons
  auditd ( Index Term Link )
  kcfd ( Index Term Link )
  keyserv ( Index Term Link )
  nscd (name service cache daemon) ( Index Term Link ) ( Index Term Link )
  rpc.nispasswd ( Index Term Link )
  running with privileges ( Index Term Link )
  ssh-agent ( Index Term Link )
  sshd ( Index Term Link )
  table of Kerberos ( Index Term Link )
  vold ( Index Term Link )
 
 Data Encryption Standard, See DES encryption
 
 data forwarding, Solaris Secure Shell ( Index Term Link )
 
 databases
  audit_user ( Index Term Link )
  auth_attr ( Index Term Link )
  backing up and propagating KDC ( Index Term Link )
  creating KDC ( Index Term Link )
  cred for Secure RPC ( Index Term Link ) ( Index Term Link )
  exec_attr ( Index Term Link )
  KDC propagation ( Index Term Link )
  NFS secret keys ( Index Term Link )
  prof_attr ( Index Term Link )
  publickey for Secure RPC ( Index Term Link )
  RBAC ( Index Term Link )
  user_attr ( Index Term Link )
  with privilege information ( Index Term Link )
 
 dd command, generating secret keys ( Index Term Link )
 
 deallocate command
  allocate error state ( Index Term Link ) ( Index Term Link )
  authorizations for ( Index Term Link )
  authorizations required ( Index Term Link )
  description ( Index Term Link )
  device-clean scripts and ( Index Term Link )
  using ( Index Term Link )
 
 deallocating
  devices ( Index Term Link )
  forcibly ( Index Term Link )
  microphone ( Index Term Link )
 
 debugging, privileges ( Index Term Link )
 
 debugging sequence number ( Index Term Link )
 
 decrypt command
  description ( Index Term Link )
  syntax ( Index Term Link )
 
 decrypting
  conversation keys for Secure RPC ( Index Term Link )
  files ( Index Term Link )
  NFS secret keys ( Index Term Link )
  secret keys ( Index Term Link )
 
 default/login file, description ( Index Term Link )
 
 default_realm section
  krb5.conf file ( Index Term Link ) ( Index Term Link )
 
 defaultpriv keyword, user_attr database ( Index Term Link )
 
 defaults
  ACL entries for directories ( Index Term Link ) ( Index Term Link )
  praudit output format ( Index Term Link ) ( Index Term Link )
  privilege settings in policy.conf file ( Index Term Link )
  system-wide auditing ( Index Term Link )
  system-wide in policy.conf file ( Index Term Link )
  umask value ( Index Term Link )
 
 delegating, RBAC authorizations ( Index Term Link )
 
 delete_entry command, ktutil command ( Index Term Link )
 
 deleting
  ACL entries ( Index Term Link ) ( Index Term Link )
  archived audit files ( Index Term Link )
  audit files ( Index Term Link )
  host's service ( Index Term Link )
  not_terminated audit files ( Index Term Link )
  policies (Kerberos) ( Index Term Link )
  principal (Kerberos) ( Index Term Link )
  rights profiles ( Index Term Link )
 
 DenyGroups keyword, sshd_config file ( Index Term Link )
 
 DenyUsers keyword, sshd_config file ( Index Term Link )
 
 DES encryption
  kernel provider ( Index Term Link )
  Secure NFS ( Index Term Link )
 
 destroying, tickets with kdestroy ( Index Term Link )
 
 determining
  audit_control flags are correct ( Index Term Link )
  audit ID of a user ( Index Term Link )
  audit_user flags are correct ( Index Term Link )
  auditing is running ( Index Term Link )
  c2audit module is loaded ( Index Term Link )
  files with setuid permissions ( Index Term Link )
  if file has ACL ( Index Term Link )
  privileges on a process ( Index Term Link )
  privileges task map ( Index Term Link )
 
 /dev/arp device, getting IP MIB-II information ( Index Term Link )
 
 /dev/urandom device ( Index Term Link )
 
 devfsadm command, description ( Index Term Link )
 
 device_allocate file
  description ( Index Term Link )
  format ( Index Term Link )
  sample ( Index Term Link ) ( Index Term Link )
 
 device allocation
  adding devices ( Index Term Link )
  allocatable devices ( Index Term Link ) ( Index Term Link )
  allocate command ( Index Term Link )
  allocate error state ( Index Term Link )
  allocating devices ( Index Term Link )
  auditing ( Index Term Link )
  authorizations for commands ( Index Term Link )
  authorizing users to allocate ( Index Term Link )
  changing allocatable devices ( Index Term Link )
  commands ( Index Term Link )
  components of mechanism ( Index Term Link )
  configuration file ( Index Term Link )
  deallocate command ( Index Term Link )
   device-clean scripts and ( Index Term Link )
   using ( Index Term Link )
  deallocating devices ( Index Term Link )
  device_allocate file ( Index Term Link )
  device-clean scripts
   audio devices ( Index Term Link )
   CD-ROM drives ( Index Term Link )
   description ( Index Term Link )
   diskette drives ( Index Term Link )
   options ( Index Term Link )
   tape drives ( Index Term Link ) ( Index Term Link )
   writing new scripts ( Index Term Link )
  device_maps file ( Index Term Link )
  disabling ( Index Term Link )
  enabling ( Index Term Link ) ( Index Term Link )
  examples ( Index Term Link )
  forcibly allocating devices ( Index Term Link )
  forcibly deallocating devices ( Index Term Link )
  making device allocatable ( Index Term Link )
  managing devices ( Index Term Link )
  mounting devices ( Index Term Link )
  not requiring authorization ( Index Term Link )
  preventing ( Index Term Link )
  requiring authorization ( Index Term Link )
  task map ( Index Term Link )
  troubleshooting ( Index Term Link ) ( Index Term Link )
  troubleshooting permissions ( Index Term Link )
  unmounting allocated device ( Index Term Link )
  user procedures ( Index Term Link )
  using ( Index Term Link )
  using allocate command ( Index Term Link )
  viewing information ( Index Term Link )
 
 device-clean scripts
  and object reuse ( Index Term Link )
  audio devices ( Index Term Link )
  CD-ROM drives ( Index Term Link )
  description ( Index Term Link )
  diskette drives ( Index Term Link )
  options ( Index Term Link )
  tape drives ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  writing new scripts ( Index Term Link )
 
 device management, See device policy
 
 device_maps file
  description ( Index Term Link )
  format ( Index Term Link )
  sample entries ( Index Term Link )
 
 device policy
  add_drv command ( Index Term Link )
  auditing changes ( Index Term Link )
  changing ( Index Term Link )
  commands ( Index Term Link )
  configuring ( Index Term Link )
  kernel protection ( Index Term Link )
  managing devices ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  removing from device ( Index Term Link )
  task map ( Index Term Link )
  update_drv command ( Index Term Link ) ( Index Term Link )
  viewing ( Index Term Link )
 
 Device Security (RBAC), creating role ( Index Term Link )
 
 devices
  adding device policy ( Index Term Link )
  allocating for use ( Index Term Link )
  auditing allocation of ( Index Term Link )
  auditing policy changes ( Index Term Link )
  authorizing users to allocate ( Index Term Link )
  changing device policy ( Index Term Link )
  changing which are allocatable ( Index Term Link )
  deallocating a device ( Index Term Link )
  /dev/urandom device ( Index Term Link )
  device allocation
   See device allocation
  forcibly allocating ( Index Term Link )
  forcibly deallocating ( Index Term Link )
  getting IP MIB-II information ( Index Term Link )
  listing ( Index Term Link )
  listing device names ( Index Term Link )
  login access control ( Index Term Link )
  making allocatable ( Index Term Link )
  managing ( Index Term Link )
  managing allocation of ( Index Term Link )
  mounting allocated devices ( Index Term Link )
  not requiring authorization for use ( Index Term Link )
  policy commands ( Index Term Link )
  preventing use of all ( Index Term Link )
  preventing use of some ( Index Term Link )
  privilege model and ( Index Term Link )
  protecting by device allocation ( Index Term Link )
  protecting in the kernel ( Index Term Link )
  removing policy ( Index Term Link )
  security ( Index Term Link )
  superuser model and ( Index Term Link )
  unmounting allocated device ( Index Term Link )
  viewing allocation information ( Index Term Link )
  viewing device policy ( Index Term Link )
  zones and ( Index Term Link )
 
 dfstab file, sharing files ( Index Term Link )
 
 DH authentication
  configuring in NIS ( Index Term Link )
  configuring in NIS+ ( Index Term Link )
  description ( Index Term Link )
  for NIS+ client ( Index Term Link )
  for NIS client ( Index Term Link )
  mounting files with ( Index Term Link )
  sharing files with ( Index Term Link )
 
 DHCP Management (RBAC), creating role ( Index Term Link )
 
 dial-up passwords
  creating ( Index Term Link )
  disabling ( Index Term Link )
  disabling temporarily ( Index Term Link )
  /etc/d_passwd file ( Index Term Link )
  security ( Index Term Link )
 
 dialups file, creating ( Index Term Link )
 
 Diffie-Hellman authentication, See DH authentication
 
 digest command
  description ( Index Term Link )
  example ( Index Term Link )
  syntax ( Index Term Link )
 
 digestmd5.so.1 plug-in, SASL and ( Index Term Link )
 
 digests
  computing for file ( Index Term Link )
  of files ( Index Term Link ) ( Index Term Link )
 
 dir line, audit_control file ( Index Term Link )
 
 direct realms ( Index Term Link )
 
 directories
  See also files
  ACL entries ( Index Term Link ) ( Index Term Link )
  audit_control file definitions ( Index Term Link )
  audit directories full ( Index Term Link ) ( Index Term Link )
  auditd daemon pointer ( Index Term Link ) ( Index Term Link )
  displaying files and related information ( Index Term Link ) ( Index Term Link )
  mounting audit directories ( Index Term Link )
  permissions
   defaults ( Index Term Link )
   description ( Index Term Link )
  public directories ( Index Term Link )
 
 disabling
  abort sequence ( Index Term Link )
  audit policy ( Index Term Link )
  audit service ( Index Term Link )
  cryptographic mechanisms ( Index Term Link )
  device allocation ( Index Term Link )
  dial-up logins temporarily ( Index Term Link )
  dial-up passwords ( Index Term Link )
  executable stacks ( Index Term Link )
  executables that compromise security ( Index Term Link )
  hardware mechanisms ( Index Term Link )
  keyboard abort ( Index Term Link )
  keyboard shutdown ( Index Term Link )
  logging of executable stack messages ( Index Term Link )
  logins temporarily ( Index Term Link )
  programs from using executable stacks ( Index Term Link )
  remote root access ( Index Term Link )
  service on a host (Kerberos) ( Index Term Link )
  system abort sequence ( Index Term Link )
  user logins ( Index Term Link )
 
 disk partitioning, for binary audit files ( Index Term Link )
 
 disk-space requirements ( Index Term Link )
 
 diskette drives
  allocating ( Index Term Link )
  device-clean scripts ( Index Term Link )
 
 displaying
  ACL entries ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  allocatable devices ( Index Term Link )
  audit policies ( Index Term Link )
  audit queue parameter values ( Index Term Link )
  audit record formats ( Index Term Link )
  audit records ( Index Term Link )
  audit records in XML format ( Index Term Link )
  device policy ( Index Term Link )
  file information ( Index Term Link )
  files and related information ( Index Term Link )
  format of audit records ( Index Term Link )
  providers in the cryptographic framework ( Index Term Link )
  roles you can assume ( Index Term Link ) ( Index Term Link )
  root access attempts ( Index Term Link )
  selected audit records ( Index Term Link )
  su command attempts ( Index Term Link )
  sublist of principals (Kerberos) ( Index Term Link )
  user's login status ( Index Term Link ) ( Index Term Link )
  users with no passwords ( Index Term Link )
 
 dminfo command ( Index Term Link )
 
 DNS, Kerberos and ( Index Term Link )
 
 domain_realm section
  krb5.conf file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 dot (.)
  authorization name separator ( Index Term Link )
  displaying hidden files ( Index Term Link )
 
 double dollar sign ($$), parent shell process number ( Index Term Link )
 
 DSAAuthentication keyword, See PubkeyAuthentication keyword
 
 DTD for praudit command ( Index Term Link )
 
 duplicating, principals (Kerberos) ( Index Term Link )
 
 DynamicForward keyword, ssh_config file ( Index Term Link )