System Administration Guide: Security Services
 -A option, auditreduce command ( Index Term Link )
 absolute mode
  changing file permissions ( Index Term Link ) ( Index Term Link )
  changing special file permissions ( Index Term Link )
  description ( Index Term Link )
  setting special permissions ( Index Term Link )
  control lists
   See ACL
  getting to server
   with Kerberos ( Index Term Link )
  granting to your account ( Index Term Link ) ( Index Term Link )
  login authentication with Solaris Secure Shell ( Index Term Link )
  obtaining for a specific service ( Index Term Link )
  restricting for
   devices ( Index Term Link ) ( Index Term Link )
   system hardware ( Index Term Link )
  restricting for KDC servers ( Index Term Link )
  root access
   displaying attempts on console ( Index Term Link )
   monitoring su command attempts ( Index Term Link ) ( Index Term Link )
   preventing login (RBAC) ( Index Term Link )
   restricting ( Index Term Link ) ( Index Term Link )
  Secure RPC authentication ( Index Term Link )
   ACLs ( Index Term Link ) ( Index Term Link )
   controlling system usage ( Index Term Link )
   devices ( Index Term Link )
   file access restriction ( Index Term Link )
   firewall setup ( Index Term Link ) ( Index Term Link )
   login access restrictions ( Index Term Link ) ( Index Term Link )
   login authentication ( Index Term Link )
   login control ( Index Term Link )
   monitoring system usage ( Index Term Link ) ( Index Term Link )
   network control ( Index Term Link )
   NFS client-server ( Index Term Link )
   PATH variable setting ( Index Term Link )
   peripheral devices ( Index Term Link )
   physical security ( Index Term Link )
   remote systems ( Index Term Link )
   reporting problems ( Index Term Link )
   root login tracking ( Index Term Link )
   saving failed logins ( Index Term Link )
   setuid programs ( Index Term Link )
   system hardware ( Index Term Link )
  sharing files ( Index Term Link )
  system logins ( Index Term Link )
 access control list
  See ACL
 Access Control Lists (ACLs), See ACL
  changing entries ( Index Term Link )
  checking entries ( Index Term Link ) ( Index Term Link )
  commands ( Index Term Link )
  copying ACL entries ( Index Term Link )
  default entries for directories ( Index Term Link ) ( Index Term Link )
  deleting entries ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  directory entries ( Index Term Link ) ( Index Term Link )
  displaying entries ( Index Term Link ) ( Index Term Link )
  format of entries ( Index Term Link )
  kadm5.acl file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  modifying entries ( Index Term Link )
  restrictions on copying entries ( Index Term Link )
  setting entries ( Index Term Link )
  setting on a file ( Index Term Link )
  task map ( Index Term Link )
  user procedures ( Index Term Link )
  valid file entries ( Index Term Link )
 acl audit token, format ( Index Term Link )
 add_drv command, description ( Index Term Link )
  ACL entries ( Index Term Link )
  administration principals (Kerberos) ( Index Term Link ) ( Index Term Link )
  allocatable device ( Index Term Link )
  attributes to a rights profile ( Index Term Link )
  audit classes ( Index Term Link ) ( Index Term Link )
  audit directories ( Index Term Link )
  auditing of roles ( Index Term Link )
  auditing of zones ( Index Term Link )
  cryptomgt role ( Index Term Link )
  custom roles (RBAC) ( Index Term Link )
  customized role ( Index Term Link )
  DH authentication to mounted file systems ( Index Term Link )
  dial-up passwords ( Index Term Link )
  hardware provider mechanisms and features ( Index Term Link )
  keys for DH authentication ( Index Term Link )
  library plugin ( Index Term Link )
  local user ( Index Term Link )
  new rights profile ( Index Term Link )
  Operator role ( Index Term Link )
  PAM modules ( Index Term Link )
  password encryption module ( Index Term Link )
  plugins to cryptographic framework ( Index Term Link )
  plugins to KMF ( Index Term Link )
  privileges directly to user or role ( Index Term Link )
  privileges to command ( Index Term Link )
  RBAC properties to legacy applications ( Index Term Link )
  rights profiles with Solaris Management Console ( Index Term Link )
   for particular profiles ( Index Term Link )
   from command line ( Index Term Link )
   to a user ( Index Term Link )
   with limited scope ( Index Term Link )
  security attributes to legacy applications ( Index Term Link )
  security-related role ( Index Term Link )
  security-related roles ( Index Term Link )
  security to devices ( Index Term Link ) ( Index Term Link )
  security to system hardware ( Index Term Link )
  service principal to keytab file (Kerberos) ( Index Term Link )
  software provider ( Index Term Link )
  System Administrator role ( Index Term Link )
  temporary audit policy ( Index Term Link )
  user-level software provider ( Index Term Link )
 admin_server section
  krb5.conf file ( Index Term Link ) ( Index Term Link )
  ACLs ( Index Term Link )
   audit classes ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit events ( Index Term Link )
   audit files ( Index Term Link )
   audit records ( Index Term Link )
   audit trail overflow prevention ( Index Term Link )
   auditreduce command ( Index Term Link )
   cost control ( Index Term Link )
   description ( Index Term Link )
   efficiency ( Index Term Link )
   process preselection mask ( Index Term Link )
   reducing storage-space requirements ( Index Term Link )
   task map ( Index Term Link )
   in zones ( Index Term Link ) ( Index Term Link )
  auditing in zones ( Index Term Link )
  cryptographic framework ( Index Term Link )
  cryptographic framework and zones ( Index Term Link )
  cryptographic framework task map ( Index Term Link )
  device allocation ( Index Term Link )
  device policy ( Index Term Link )
  dial-up logins ( Index Term Link )
  file permissions ( Index Term Link ) ( Index Term Link )
   keytabs ( Index Term Link )
   policies ( Index Term Link )
   principals ( Index Term Link )
  metaslot ( Index Term Link )
  NFS client-server file security ( Index Term Link )
  password algorithms ( Index Term Link )
  privileges ( Index Term Link )
  properties of a role ( Index Term Link )
  RBAC properties ( Index Term Link )
  remote logins with Solaris Secure Shell ( Index Term Link )
  rights profiles ( Index Term Link )
  role password ( Index Term Link )
  roles ( Index Term Link )
  roles to replace superuser ( Index Term Link )
  Secure RPC task map ( Index Term Link )
  Solaris Secure Shell
   clients ( Index Term Link )
   overview ( Index Term Link )
   servers ( Index Term Link )
   task map ( Index Term Link )
  without privileges ( Index Term Link )
 administrative (old) audit class ( Index Term Link )
 administrative audit class ( Index Term Link )
 AES kernel provider ( Index Term Link )
 aes128-cbc encryption algorithm, ssh_config file ( Index Term Link )
 aes128-ctr encryption algorithm, ssh_config file ( Index Term Link )
 agent daemon, Solaris Secure Shell ( Index Term Link )
 ahlt audit policy
  description ( Index Term Link )
  setting ( Index Term Link )
  definition in cryptographic framework ( Index Term Link )
  listing in the cryptographic framework ( Index Term Link )
   configuration ( Index Term Link )
  password encryption ( Index Term Link )
 all, in user audit fields ( Index Term Link )
 All (RBAC), rights profile ( Index Term Link )
 all audit class
  caution for using ( Index Term Link )
  description ( Index Term Link )
 allhard string, audit_warn script ( Index Term Link )
 allocate command
  allocate error state ( Index Term Link )
  authorizations for ( Index Term Link )
  authorizations required ( Index Term Link )
  description ( Index Term Link )
  tape drive ( Index Term Link )
  user authorization ( Index Term Link )
  using ( Index Term Link )
 allocate error state ( Index Term Link )
 allocating devices
  by users ( Index Term Link )
  forcibly ( Index Term Link )
  task map ( Index Term Link )
  troubleshooting ( Index Term Link )
 AllowGroups keyword, sshd_config file ( Index Term Link )
 AllowTcpForwarding keyword
  changing ( Index Term Link )
  sshd_config file ( Index Term Link )
 AllowUsers keyword, sshd_config file ( Index Term Link )
 allsoft string, audit_warn script ( Index Term Link )
 ALTSHELL in Solaris Secure Shell ( Index Term Link )
 always-audit classes
  audit_user database ( Index Term Link )
  process preselection mask ( Index Term Link )
 analysis, praudit command ( Index Term Link )
 antivirus software, See virus scanning
 appending arrow (>>), preventing appending ( Index Term Link )
 application audit class ( Index Term Link )
 application server, configuring ( Index Term Link )
 arcfour encryption algorithm, ssh_config file ( Index Term Link )
 ARCFOUR kernel provider ( Index Term Link )
 Archive tape drive device-clean script ( Index Term Link )
 archiving, audit files ( Index Term Link )
 arg audit token, format ( Index Term Link )
 arge audit policy
  and exec_env token ( Index Term Link )
  description ( Index Term Link )
 arge policy, setting ( Index Term Link )
 argv audit policy
  and exec_args token ( Index Term Link )
  description ( Index Term Link )
 argv policy, setting ( Index Term Link )
  privileges to commands in a rights profile ( Index Term Link )
  privileges to commands in a script ( Index Term Link )
  privileges to user or role ( Index Term Link )
  role to a user ( Index Term Link ) ( Index Term Link )
  role to a user locally ( Index Term Link )
 assuming role
  how to ( Index Term Link )
  in a terminal window ( Index Term Link )
  in Solaris Management Console ( Index Term Link )
  Primary Administrator ( Index Term Link )
  root ( Index Term Link )
  System Administrator ( Index Term Link )
 asterisk (*)
  checking for in RBAC authorizations ( Index Term Link )
  device_allocate file ( Index Term Link ) ( Index Term Link )
  wildcard character
   in RBAC authorizations ( Index Term Link ) ( Index Term Link )
 at command, authorizations required ( Index Term Link )
 at sign (@), device_allocate file ( Index Term Link )
 atq command, authorizations required ( Index Term Link )
 attribute audit token ( Index Term Link )
 attributes, keyword in BART ( Index Term Link )
 audio devices, security ( Index Term Link )
 audit administration audit class ( Index Term Link )
 audit characteristics
  audit ID ( Index Term Link )
  process preselection mask ( Index Term Link )
  processes ( Index Term Link )
  session ID ( Index Term Link )
  terminal ID ( Index Term Link )
  user process preselection mask ( Index Term Link )
 audit_class file
  adding a class ( Index Term Link )
  description ( Index Term Link )
  troubleshooting ( Index Term Link )
 audit class preselection, effect on public objects ( Index Term Link )
 audit classes
  adding ( Index Term Link )
  definitions ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  entries in audit_control file ( Index Term Link )
  exceptions in audit_user database ( Index Term Link )
  exceptions to system-wide settings ( Index Term Link )
  mapping events ( Index Term Link )
  modifying default ( Index Term Link )
  overview ( Index Term Link )
  prefixes ( Index Term Link )
  preselecting ( Index Term Link )
  preselection ( Index Term Link )
  process preselection mask ( Index Term Link )
  setting system-wide ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
  system-wide ( Index Term Link )
 audit command
  description ( Index Term Link )
  preselection mask for existing processes (-s option) ( Index Term Link )
  rereading audit files (-s option) ( Index Term Link )
  resetting directory pointer (-n option) ( Index Term Link )
  updating audit service ( Index Term Link )
  verifying syntax of audit_control file (-v option) ( Index Term Link )
 audit configuration file, See audit_control file
 audit_control file
  audit daemon rereading after editing ( Index Term Link )
  changing kernel mask for nonattributable events ( Index Term Link )
  configuring ( Index Term Link )
  description ( Index Term Link )
  entries ( Index Term Link )
  entries and zones ( Index Term Link )
  examples ( Index Term Link )
  exceptions to flags in audit_user database ( Index Term Link )
  flags line
   process preselection mask ( Index Term Link )
  minfree warning ( Index Term Link )
  plugin line ( Index Term Link )
  prefixes in flags line ( Index Term Link )
  syntax problem ( Index Term Link )
  system-wide audit ( Index Term Link )
  verifying classes ( Index Term Link )
  verifying syntax ( Index Term Link )
 Audit Control rights profile ( Index Term Link )
 audit daemon, See auditd daemon
 audit directory
  description ( Index Term Link )
  partitioning for ( Index Term Link )
  sample structure ( Index Term Link )
 audit_event file
  changing class membership ( Index Term Link )
  description ( Index Term Link )
  removing events safely ( Index Term Link )
 audit event-to-class mappings, auditd daemon's role ( Index Term Link )
 audit events
  audit_event file ( Index Term Link )
  changing class membership ( Index Term Link )
  description ( Index Term Link )
  mapping to classes ( Index Term Link )
  selecting from audit trail ( Index Term Link )
  selecting from audit trail in zones ( Index Term Link )
  summary ( Index Term Link )
  viewing from binary files ( Index Term Link )
 audit files
  auditreduce command ( Index Term Link )
  combining ( Index Term Link ) ( Index Term Link )
  configuring ( Index Term Link )
  copying messages to single file ( Index Term Link )
  limiting size of ( Index Term Link )
  managing ( Index Term Link )
  minimum free space for file systems ( Index Term Link )
  names ( Index Term Link ) ( Index Term Link )
  order for opening ( Index Term Link )
  partitioning disk for ( Index Term Link )
  printing ( Index Term Link )
  reducing ( Index Term Link ) ( Index Term Link )
  reducing storage-space requirements ( Index Term Link ) ( Index Term Link )
  switching to new file ( Index Term Link )
  time stamps ( Index Term Link ) ( Index Term Link )
 audit ID
  mechanism ( Index Term Link )
  overview ( Index Term Link )
 audit logs
  See also audit files
  comparing binary and textual ( Index Term Link )
  configuring textual audit logs ( Index Term Link )
  in text ( Index Term Link )
  modes ( Index Term Link )
 audit messages, copying to single file ( Index Term Link )
 audit.notice entry, syslog.conf file ( Index Term Link )
 audit plugins, summary ( Index Term Link )
 audit policy
  audit tokens from ( Index Term Link )
  auditd daemon's role ( Index Term Link )
  defaults ( Index Term Link )
  description ( Index Term Link )
  effects of ( Index Term Link )
  public ( Index Term Link )
  setting ( Index Term Link )
  setting ahlt ( Index Term Link )
  setting arge ( Index Term Link )
  setting argv ( Index Term Link )
  setting in global zone ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  setting perzone ( Index Term Link )
  that does not affect tokens ( Index Term Link )
  tokens added by ( Index Term Link )
 audit preselection mask
  modifying for existing users ( Index Term Link )
  modifying for individual users ( Index Term Link )
 audit queue control parameters, auditd daemon's role ( Index Term Link )
 audit records
  audit directories full ( Index Term Link ) ( Index Term Link )
  converting to readable format ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  displaying ( Index Term Link )
  displaying formats of
   procedure ( Index Term Link )
   summary ( Index Term Link )
  displaying formats of a program ( Index Term Link )
  displaying formats of an audit class ( Index Term Link )
  displaying in XML format ( Index Term Link )
  events that generate ( Index Term Link )
  format ( Index Term Link )
  formatting example ( Index Term Link )
  merging ( Index Term Link )
  overview ( Index Term Link )
  reducing audit files ( Index Term Link )
  sequence of tokens ( Index Term Link )
  syslog.conf file ( Index Term Link )
  /var/adm/auditlog file ( Index Term Link )
 Audit Review rights profile ( Index Term Link )
 audit session ID ( Index Term Link )
 audit threshold ( Index Term Link )
 audit tokens
  See also individual audit token names
  added by audit policy ( Index Term Link )
  audit record format ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  format ( Index Term Link )
  list of ( Index Term Link )
 audit trail
  analysis costs ( Index Term Link )
  analysis with praudit command ( Index Term Link )
  cleaning up not terminated files ( Index Term Link )
   auditd daemon's role ( Index Term Link )
  description ( Index Term Link )
  effect of audit policy on ( Index Term Link )
  events included ( Index Term Link )
  merging all files ( Index Term Link )
  monitoring in real time ( Index Term Link )
  no public objects ( Index Term Link )
  overview ( Index Term Link )
  preventing overflow ( Index Term Link )
  selecting events from ( Index Term Link )
  viewing events from ( Index Term Link )
  viewing events from different zones ( Index Term Link )
 audit_user database
  exception to system-wide audit classes ( Index Term Link )
  prefixes for classes ( Index Term Link )
  process preselection mask ( Index Term Link )
  specifying user exceptions ( Index Term Link )
  user audit fields ( Index Term Link )
 audit_user file, verifying classes ( Index Term Link )
 audit_warn script
  auditd daemon execution of ( Index Term Link )
  conditions invoking ( Index Term Link )
  configuring ( Index Term Link )
  description ( Index Term Link )
  strings ( Index Term Link )
 auditconfig command
  audit classes as arguments ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  prefixes for classes ( Index Term Link )
 auditconfig command, setting audit policy ( Index Term Link )
 auditconfig command
  setting audit policy temporarily ( Index Term Link )
 auditd daemon
  audit trail creation ( Index Term Link ) ( Index Term Link )
  audit_warn script
   description ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link )
  configuration functions ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link ) ( Index Term Link )
  plugins loaded by ( Index Term Link )
  rereading information for the kernel ( Index Term Link )
  rereading the audit_control file ( Index Term Link ) ( Index Term Link )
 auditd service
  configuring policy ( Index Term Link )
  configuring queue parameters ( Index Term Link )
 auditd service, enable on the command line ( Index Term Link )
 auditd service
  for auditing ( Index Term Link )
  all commands by users ( Index Term Link )
  changes in device policy ( Index Term Link )
  configuring identically for all zones ( Index Term Link )
  configuring in global zone ( Index Term Link ) ( Index Term Link )
  configuring per-zone ( Index Term Link )
  configuring queue parameters ( Index Term Link )
  device allocation ( Index Term Link )
  disabling ( Index Term Link )
  enabling ( Index Term Link )
  finding changes to specific files ( Index Term Link )
  logins ( Index Term Link )
  planning ( Index Term Link )
  planning in zones ( Index Term Link ) ( Index Term Link )
  preselection definition ( Index Term Link )
  privileges and ( Index Term Link )
  rights profiles for ( Index Term Link )
  roles ( Index Term Link )
  setting -setqctrl options ( Index Term Link )
  setting queue parameters ( Index Term Link )
  sftp file transfers ( Index Term Link )
  troubleshooting ( Index Term Link )
  troubleshooting praudit command ( Index Term Link )
  updating information ( Index Term Link )
  zones and ( Index Term Link ) ( Index Term Link )
 auditlog file, text audit records ( Index Term Link )
 auditrecord command
  [] (square brackets) in output ( Index Term Link )
  description ( Index Term Link )
  displaying audit record formats ( Index Term Link )
  example ( Index Term Link )
  listing all formats ( Index Term Link )
  listing formats of class ( Index Term Link )
  listing formats of program ( Index Term Link )
  optional tokens ([]) ( Index Term Link )
 auditreduce command ( Index Term Link )
  -c option ( Index Term Link )
  -O option ( Index Term Link )
  cleaning up audit files ( Index Term Link )
  description ( Index Term Link )
  examples ( Index Term Link )
  filtering options ( Index Term Link )
  merging audit records ( Index Term Link )
  options ( Index Term Link )
  selecting audit records ( Index Term Link )
  timestamp use ( Index Term Link )
  trailer tokens, and ( Index Term Link )
  using lowercase options ( Index Term Link )
  using uppercase options ( Index Term Link )
  without options ( Index Term Link )
 auth_attr database
  description ( Index Term Link )
  summary ( Index Term Link )
 AUTH_DES authentication, See AUTH_DH authentication
 AUTH_DH authentication, and NFS ( Index Term Link )
  AUTH_DH client-server session ( Index Term Link )
  configuring cross-realm ( Index Term Link )
  description ( Index Term Link )
  DH authentication ( Index Term Link )
  disabling with -X option ( Index Term Link )
  Kerberos and ( Index Term Link )
  name services ( Index Term Link )
  network security ( Index Term Link )
  NFS-mounted files ( Index Term Link ) ( Index Term Link )
  overview of Kerberos ( Index Term Link )
  Secure RPC ( Index Term Link )
  Solaris Secure Shell
   methods ( Index Term Link )
   process ( Index Term Link )
  terminology ( Index Term Link )
  types ( Index Term Link )
  use with NFS ( Index Term Link )
 authentication methods
  GSS-API credentials in Solaris Secure Shell ( Index Term Link )
  host-based in Solaris Secure Shell ( Index Term Link ) ( Index Term Link )
  keyboard-interactive in Solaris Secure Shell ( Index Term Link )
  password in Solaris Secure Shell ( Index Term Link )
  public keys in Solaris Secure Shell ( Index Term Link )
  Solaris Secure Shell ( Index Term Link )
  in Kerberos ( Index Term Link ) ( Index Term Link )
 authlog file, saving failed login attempts ( Index Term Link )
  Kerberos and ( Index Term Link )
  types ( Index Term Link )
 authorizations (RBAC)
  checking for wildcards ( Index Term Link )
  checking in privileged application ( Index Term Link )
  commands that require authorizations ( Index Term Link )
  database ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  delegating ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  for allocating device ( Index Term Link )
  for device allocation ( Index Term Link )
  granularity ( Index Term Link )
  naming convention ( Index Term Link )
  not requiring for device allocation ( Index Term Link )
  solaris.device.allocate ( Index Term Link ) ( Index Term Link )
  solaris.device.revoke ( Index Term Link )
 authorized_keys file, description ( Index Term Link )
 AuthorizedKeysFile keyword, sshd_config file ( Index Term Link )
 auths command, description ( Index Term Link )
 AUTHS_GRANTED keyword, policy.conf file ( Index Term Link )
 auto_transition option, SASL and ( Index Term Link )
 automatic login
  disabling ( Index Term Link )
  enabling ( Index Term Link )
 automatically configuring
   master KDC server ( Index Term Link )
   slave KDC server ( Index Term Link )
 automating principal creation ( Index Term Link )
 auxprop_login option, SASL and ( Index Term Link )