Trusted Solaris Installation and Configuration

How to Use the Examples

These are examples only. Do not use the IP addresses, names, and other details as they are written here.

Root NIS+ Master Installation Program Example

Dialog Box Title 

Answer 

Comment 

Select a language 

English 

Select a locale 

English 

Networked? 

Yes 

 

Host name 

toucan 

 

IP address 

129.159.110.1 

 

DHCP 

No 

You should choose DHCP only if this system does not have a permanent IP address and instead gets one from a DHCP server that you have already set up. 

Primary network interface 

le0 

You are not prompted for this unless the workstation has more than one network card. 

Name service 

None 

You will turn the machine into the name service master later. 

Subnet? 

Yes 

If your LAN is part of a larger network, say yes. 

Subnet mask 

255.255.255.0 

Check that the default is the appropriate mask for your site. 

Time zone 

Geographical, US Pacific 

A time zone map is provided on the WWW.

Date and Time 

 

The default provided is usually the correct clock time. 

The answers to the above questions are System ID Information (sysidinfo). When installing over a network, system information is automatically given to the installation program, reducing the installer's interaction with the program. 

Select Geographic Region 

North America 

Select the regions for which support should be installed. 

Install 

Install 

Upgrade is not supported for this release. 

System type 

Standalone 

 

Select Software 

Entire software group 

For a server, choose Developer or larger. 

 

Solaris 64-bit support 

Choose to enable 64-bit support or not. If you chose IPv6, above, you must choose 64. 

Customize? 

Yes | No 

Customizing a software group often results in software dependencies; system administration knowledge is required to fix dependencies. 

Select Disks 

c0t0d0, c0t1d0, c0t3d0, c0t5d0 

See "Root NIS+ Master Disk Partitioning Example" for the details of the example.

Preserve Data? 

Preserve | Continue 

Probably Continue. 

Auto Layout 

Continue 

Auto Layout displays the minimum disk amounts required per file system. 

File systems to auto-layout 

/, /usr, /var

See "Root NIS+ Master Disk Partitioning Example"

Customize File System and Disk Layout 

Customize 

Customizing requires advanced system administration skills. 

Customize Disks 

OK | Continue 

See "Root NIS+ Master Disk Partitioning Example"

Mount remote file systems 

No 

Mounting in Trusted Solaris is secure. Remote file systems are mounted after their security attributes are known to this machine. 

Begin installation 

Begin 

Read the disk layout and confirm its accuracy. 

Auto Reboot 

Auto | Manual 

 

The following prompts are on a plain screen, not in dialog boxes. 

Root password 

List it elsewhere

Workstation security requires a root password. 

Automatic power-saving shutdown 

y | n | ? 

To recover from power shutdown, press the power key at keyboard upper right. 

Confirm 

Yes | No 

 

The Web Launcher starts in Command Line Mode. 

Continue install: [1] Media | [2] Network | [3] Skip. 

The CD drawer opens. Remove the CD. 

Insert the CD for Solaris Software 2. 

Insert the second CD and press the Return key.

The screen may be overwritten with messages. Package installation is displayed in 25% increments: |-1%---25%---50%---75%---100%

Enter 1 to review the log, or 2 to end. 

Press the Return key.

The CD drawer opens. Remove the CD. Press the Return key to reboot the system.

Root NIS+ Master Disk Partitioning Example

Workstation Name: toucan

Disk 

Slice 

Mount point 

Size  

Disk 

Slice 

Mount point 

Size 

c0t0d0 

s0 

80 

c0t1d0 

s0 

/export/Answerbooks 

600 

 

s1 

swap 

180 

 

s1 

 

 

 

s2 

entire disk 

1034 

 

s2 

entire disk 

1570 

 

s3 

/var 

224 

 

s3 

 

 

 

s4 

 

 

 

s4 

 

 

 

s5 

 

 

 

s5 

 

 

 

s6 

/usr 

520 

 

s6 

 

410 

 

s7 

/export 

10 

 

s7 

/export/tools 

1380 

Disk 

Slice 

Mount point 

Size 

Disk 

Slice 

Mount point 

Size 

c0t3d0 

s0 

 

 

c0t5d0 

s0 

 

 

 

s1 

 

 

 

s1 

 

 

 

s2 

entire disk 

2028 

 

s2 

entire disk 

1980 

 

s3 

/etc/security/audit/toucan 

1014 

 

s3 

/swapfile 

600 

 

s4 

 

 

 

s4 

 

 

 

s5 

 

 

 

s5 

 

 

 

s6 

 

 

 

s6 

 

 

 

s7 

/etc/security/audit/toucan.1 

1014 

 

s7 

/opt 

1380 

Services Provided by Servers Example

Use 

Name 

IP address 

Shared File Systems 

Security Information 

NIS+ servers 

Root NIS+ master 

toucan 

129.159.110.1 

/etc/security/audit/toucan 

 

NIS+ replica 

willet 

129.159.110.3 

/etc/security/audit/willet 

nosuid, nodev, [high] 

 

 

 

/etc/security/audit/willet.1 

nosuid, nodev, [high] 

Network routers 

willet-118 le1 

129.159.118.25 

 

 

 

stilt-223 ie1 

129.159.223.20 

 

 

 

heron-119 le1 

129.159.119.26 

 

 

File Servers (Share file systems for mounting by end user workstations) 

for home directories 

nest 

129.159.118.2 

/export/home 

 

 

for AnswerBooks 

worker 

129.159.118.7 

/usr/all/books 

 

for CodeMgr 

ada 

129.159.110.5 

/opt/utils/cmgr 

 

for Man Pages 

ada 

129.159.110.5 

/opt/utils/man 

 

for Utilities 

ada 

129.159.118.5 

/opt/utils/ 

 

for Applications 

worker 

129.159.118.7 

/usr/all/apps 

 

Audit Servers (Share all audit file systems for mounting by audit administration server and user workstations) 

 

willet 

 

/etc/security/audit/willet.1 

nosuid, nodev, [high] 

 

egret 

 

.../egret.1,2,3,4 

nosuid, nodev, [high] 

 

stilt 

 

.../stilt.1,2,3 

nosuid, nodev, [high] 

 

tern 

 

.../tern.1,2,3,4 

nosuid, nodev, [high] 

Audit Administration Server (Shares no file systems; mounts all audit file systems) 

 

audacious 

129.159.110.7 

None 

nosuid, nodev, [high] 

Install Server (Shares file system that contains Trusted Solaris image) 

 

penguin 

 

 

 

Boot Server (One per NIS+ subdomain) 

 

penguin 

 

 

 

Mail Server (Share /var/mail file system) 

 

willet 

 

 

 

Print Servers  

 

cirrus 

 

 

 

 

cumulus 

 

 

 

 

 

 

 

 

Audit Server Installation Program Example


Note -

You will not be prompted for information that you have provided in NIS+ or in the boot_server:/etc/bootparams file (during a Custom JumpStart install).


Dialog Box Title 

Answer 

Comment 

Select a language 

English 

Select a locale 

English 

Networked? 

Yes 

 

Host name 

willett 

 

IP address 

129.159.110.3 

 

DHCP 

No 

You should choose DHCP only if this system does not have a permanent IP address and instead gets one from a DHCP server that you have already set up. 

Primary network interface 

le0 

You are not prompted for this unless the workstation has more than one network card. 

Name service 

NIS+ | NIS | None 

Choose the name service if the master is up and running. 

Subnet? 

Yes 

If your LAN is part of a larger network, say yes. 

Subnet mask 

255.255.255.0 

Check that the default is the appropriate mask for your site. 

Time zone 

Geographical, US Pacific 

A time zone map is provided on the WWW.

Date and Time 

 

The default provided is usually the correct clock time. 

The answers to the above questions are System ID Information (sysidinfo). When installing over a network, system information is automatically given to the installation program, reducing the installer's interaction with the program. 

Select Geographic Region 

North America 

Select the regions for which support should be installed. 

Install 

Install 

Upgrade is not supported for this release. 

System type 

Standalone 

 

Select Software 

Entire software group 

For a server, choose Developer or larger. 

 

Solaris 64-bit support 

Choose to enable 64-bit support or not. If you chose IPv6, above, you must choose 64. 

Customize? 

Yes | No 

Customizing a software group often results in software dependencies; system administration knowledge is required to fix dependencies. 

Select Disks 

c0t0d0, c0t1d0, c0t3d0, c0t5d0 

See "Audit Server Disk Partitioning Example" for the details of the example.

Preserve Data? 

Preserve | Continue 

Probably Continue. 

Auto Layout 

Continue 

Auto Layout displays the minimum disk amounts required per file system. 

File systems to auto-layout 

/, /usr, /var

See "Root NIS+ Master Disk Partitioning Example"

Customize File System and Disk Layout 

Customize 

Customizing requires advanced system administration skills. 

Customize Disks 

OK | Continue 

See "Audit Server Disk Partitioning Example" for the details of the example.

Mount remote file systems 

No 

Mounting in Trusted Solaris is secure. Remote file systems are mounted after their security attributes are known to this machine. 

Begin installation 

Begin 

Read the disk layout and confirm its accuracy. 

Auto Reboot 

Auto | Manual 

 

The following prompts are on a plain screen, not in dialog boxes. 

Root password 

List it elsewhere

Workstation security requires a root password. 

Automatic power-saving shutdown 

y | n | ? 

To recover from power shutdown, press the power key at keyboard upper right. 

Confirm 

Yes | No 

 

The Web Launcher starts in Command Line Mode. 

Continue install: [1] Media | [2] Network | [3] Skip. 

The CD drawer opens. Remove the CD. 

Insert the CD for Solaris Software 2. 

Insert the second CD and press the Return key.

The screen may be overwritten with messages. Package installation is displayed in 25% increments: |-1%---25%---50%---75%---100%

Enter 1 to review the log, or 2 to end. 

Press the Return key.

The CD drawer opens. Remove the CD. Press the Return key to reboot the system.

Audit Server Disk Partitioning Example


Note -

This workstation will be configured as a NIS+ client of the NIS+ root master.


Workstation Name: willet

Disk 

Slice 

Mount point 

Size  

Disk 

Slice 

Mount point 

Size 

c0t0d0 

s0 

75 

c0t1d0 

s0 

 

 

 

s1 

swap 

160 

 

s1 

 

 

 

s2 

entire disk 

1034 

 

s2 

entire disk 

1980 

 

s3 

 

 

 

s3 

/etc/security/audit/willet.1 

990 

 

s4 

/var 

200 

 

s4 

 

 

 

s5 

 

 

 

s5 

 

 

 

s6 

/usr 

350 

 

s6 

 

 

 

s7 

/export/home 

250 

 

s7 

/etc/security/audit/willet.2 

990 

Disk 

Slice 

Mount point 

Size 

Disk 

Slice 

Mount point 

Size 

c0t3d0 

s0 

 

 

c0t5d0 

s0 

 

 

 

s1 

 

 

 

s1 

 

 

 

s2 

entire disk 

1980 

 

s2 

entire disk 

1980 

 

s3 

/etc/security/audit/willet.3 

990 

 

s3 

/etc/security/audit/willet 

990 

 

s4 

 

 

 

s4 

 

 

 

s5 

 

 

 

s5 

 

 

 

s6 

 

 

 

s6 

 

 

 

s7 

/etc/security/audit/willet.4 

990 

 

s7 

/etc/security/audit/willet.5 

990 

Audit Server Configuration Worksheet

System Administrator Information 

Security Officer Information 

Name 

willet 

root password 

 

IP address 

129.159.110.3 

PROM mode 

full 

Ethernet address 

8:0:20:4c:7e:2f 

PROM password 

 

Sun architecture 

sun4m 

 

 

Network interfaces 

le0 

 

 

Network router 

willet-118 le1 (129.159.118.25) 

 

 

Mount Points (For local file systems) 

Security Attributes 

 

 

 

 

/usr 

 

 

 

/var 

 

 

 

/export/home 

 

nosuid 

for NIS+ utils 

/opt/nis/ 

 

 

Mount Points (For remote file systems) 

 

 

for Sol AnswerBks 

/usr/AB/Sol8.1/ 

 

 

for TS AnswerBks 

/usr/AB/TS8/ 

 

 

for ManPages 

/usr/share/man 

 

 

for CodeMgr 

/opt/prog/Code 

 

 

for Utilities 

/opt/dist/Util 

 

 

for Applications 

/opt/dist/App 

 

 

Audit Mount Points  

 

 

Primary  

/etc/security/audit/tern.1 

nosuid, nodev, [high] 

Secondary  

/etc/security/audit/egret.1 

nosuid, nodev, [high] 

Local 

/etc/security/audit/willet 

nosuid, nodev, [high] 

Audit File Systems  

 

 

Primary  

tern:/etc/security/audit/tern.1/files 

 

Secondary  

egret:/etc/security/audit/egret.1/files 

 

Local 

/etc/security/audit/willet/files 

 

Mail Server  

toucan 

Attached Devices 

CDROM (sd6) 

only usable by those whose profile includes the device_allocate command and the solaris.device.allocate authorization

 

tape drive (st4) 

Remote Printers  

cirrus 

 

 

cumulus 

Administrator printer [admin_high] only