System Administration Guide: Security Services
    
S
 
 -s
  audit command ( Index Term Link )
  praudit command ( Index Term Link )
 
 -S option of st_clean script ( Index Term Link )
 
 sac service name, PAM ( Index Term Link )
 
 sample module, description ( Index Term Link )
 
 saving
  failed login attempts ( Index Term Link ) ( Index Term Link )
 
 scheduling ASET execution (PERIODIC_SCHEDULE) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 scope, description ( Index Term Link )
 
 scp command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  using ( Index Term Link )
 
 script
  securing ( Index Term Link )
  testing for authorizations ( Index Term Link )
 
 SCSI devices, st_clean script ( Index Term Link )
 
 SEAM
  administering ( Index Term Link )
  Administration Tool ( Index Term Link )
  and Kerberos V5 ( Index Term Link ) ( Index Term Link )
  commands ( Index Term Link )
  components of ( Index Term Link )
  configuration decisions ( Index Term Link )
  configuring KDC servers ( Index Term Link )
  daemons ( Index Term Link )
  files ( Index Term Link )
  gaining access to server ( Index Term Link )
  online help ( Index Term Link )
  overview ( Index Term Link )
  overview of authentication ( Index Term Link )
  password management ( Index Term Link )
  planning for ( Index Term Link )
  reference ( Index Term Link )
  terminology ( Index Term Link )
  using ( Index Term Link )
 
 SEAM Administration Tool ( Index Term Link )
  and limited administration privileges ( Index Term Link )
  and list privileges ( Index Term Link )
  and X Window system ( Index Term Link )
  command-line equivalents ( Index Term Link )
  context-sensitive help ( Index Term Link )
  creating a new principal ( Index Term Link )
  creating new policy ( Index Term Link ) ( Index Term Link )
  default values ( Index Term Link )
  deleting a principal ( Index Term Link )
  deleting policies ( Index Term Link )
  displaying sublist of principals ( Index Term Link )
  duplicating a principal ( Index Term Link )
  files modified by ( Index Term Link )
  Filter Pattern field ( Index Term Link )
  gkadmin command ( Index Term Link )
  gkadmin command vs. kadmin ( Index Term Link ) ( Index Term Link )
  .gkadmin file ( Index Term Link )
  help (print) ( Index Term Link )
  Help button ( Index Term Link )
  Help Contents ( Index Term Link )
  how affected by privileges ( Index Term Link )
  kadmin command vs. gkadmin ( Index Term Link ) ( Index Term Link )
  login window ( Index Term Link )
  modifying a principal ( Index Term Link )
  modifying policies ( Index Term Link )
  online help ( Index Term Link )
  panel descriptions ( Index Term Link )
  privileges ( Index Term Link )
  setting up principal defaults ( Index Term Link )
  starting ( Index Term Link )
  table of panels ( Index Term Link )
  viewing a principal's attributes ( Index Term Link )
  viewing list of policies ( Index Term Link )
  viewing list of principals ( Index Term Link )
  viewing policy attributes ( Index Term Link )
  vs. kadmin command ( Index Term Link )
 
 searching
  files with setuid permissions ( Index Term Link ) ( Index Term Link )
 
 secondary audit directory ( Index Term Link )
 
 secret key
  changing ( Index Term Link )
  database ( Index Term Link )
  decrypting ( Index Term Link )
  generating ( Index Term Link )
 
 secure access ( Index Term Link )
 
 secure NIS+, adding a user ( Index Term Link )
 
 Secure RPC ( Index Term Link )
  implementation of ( Index Term Link )
 
 Secure RPC authentication ( Index Term Link )
 
 Secure Shell
  administering ( Index Term Link )
  authentication ( Index Term Link )
  authentication steps ( Index Term Link )
  configuring ( Index Term Link )
  configuring clients ( Index Term Link )
  connecting outside firewall
   from command line ( Index Term Link )
   from configuration file ( Index Term Link )
  copying files ( Index Term Link )
  creating keys ( Index Term Link )
  description ( Index Term Link )
  forwarding mail ( Index Term Link )
  important files ( Index Term Link )
  local port forwarding ( Index Term Link ) ( Index Term Link )
  logging in ( Index Term Link )
  naming identity files ( Index Term Link )
  port forwarding ( Index Term Link )
  protocol versions ( Index Term Link )
  public key ( Index Term Link )
  remote port forwarding ( Index Term Link )
  transferring files ( Index Term Link )
  typical session ( Index Term Link )
  user task map ( Index Term Link )
  using without password ( Index Term Link )
 
 securing legacy applications, description ( Index Term Link )
 
 securing scripts, description ( Index Term Link )
 
 security
  auditing and ( Index Term Link )
  DH authentication
   AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  KERB authentication ( Index Term Link )
 
 security mode, setting up environment with multiple ( Index Term Link )
 
 security service
  in SEAM ( Index Term Link )
  integrity ( Index Term Link )
  privacy ( Index Term Link )
 
 seq audit policy
  description ( Index Term Link )
  seq token and ( Index Term Link )
 
 seq policy, seq token and ( Index Term Link )
 
 seq token
  format ( Index Term Link )
  seq policy and ( Index Term Link )
 
 server authentication parameters, sshd_config file ( Index Term Link )
 
 ServerKeyBits keyword, sshd_config file ( Index Term Link )
 
 servers
  and realms ( Index Term Link )
  AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  configuring for Secure Shell ( Index Term Link )
  definition in SEAM ( Index Term Link )
  gaining access with SEAM ( Index Term Link )
  obtaining credential for ( Index Term Link )
 
 service
  definition in SEAM ( Index Term Link )
  disabling on a host ( Index Term Link )
  obtaining access for specific service ( Index Term Link )
 
 service key ( Index Term Link )
  definition in SEAM ( Index Term Link )
 
 service names, PAM ( Index Term Link )
 
 service principal
  adding to keytab file ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  planning for names ( Index Term Link )
  removing from keytab file ( Index Term Link )
 
 session ID ( Index Term Link )
 
 session key
  definition in SEAM ( Index Term Link )
  SEAM authentication and ( Index Term Link )
 
 -setclass option, auditconfig command ( Index Term Link )
 
 -setcond option, auditconfig command ( Index Term Link )
 
 setenv command
  ASET security level specification ( Index Term Link )
  ASET working directory specification ( Index Term Link )
 
 setfacl command
  adding ACL entries ( Index Term Link )
  deleting ACL entries ( Index Term Link )
  description ( Index Term Link )
  examples ( Index Term Link ) ( Index Term Link )
  modifying ACL entries ( Index Term Link )
  setting ACL entries ( Index Term Link ) ( Index Term Link )
  syntax ( Index Term Link )
 
 setgid permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 -setpmask option of auditconfig comman, auditconfig command ( Index Term Link )
 
 -setpolicy option, auditconfig command ( Index Term Link )
 
 -setsmask option, auditconfig command ( Index Term Link )
 
 setting IDs on commands
  description ( Index Term Link )
  task description ( Index Term Link )
 
 setting up principal defaults ( Index Term Link )
 
 setuid permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  finding files with permissions set ( Index Term Link ) ( Index Term Link )
  security risks ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 setuid programs ( Index Term Link )
 
 -setumask option, auditconfig command ( Index Term Link )
 
 sftp command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  using ( Index Term Link )
 
 sh command ( Index Term Link )
  dial-up passwords ( Index Term Link )
  privileged version ( Index Term Link )
 
 share command, restricting root access ( Index Term Link )
 
 sharing files (network security) ( Index Term Link )
 
 shell, privileged versions ( Index Term Link )
 
 shell commands
  /etc/d_passwd file entries ( Index Term Link ) ( Index Term Link )
 
 shell programs
  ASET security level specification ( Index Term Link )
  ASET working directory specification ( Index Term Link )
 
 short praudit output format ( Index Term Link )
 
 shosts.equiv file, description ( Index Term Link )
 
 .shosts file, description ( Index Term Link )
 
 signal received during auditing shutdown ( Index Term Link )
 
 single-sign-on system, SEAM and ( Index Term Link )
 
 size
  reducing audit files ( Index Term Link )
   auditreduce command ( Index Term Link )
   auditreduce command ( Index Term Link )
  reducing storage-space requirements for audit files ( Index Term Link )
 
 slave_datatrans file ( Index Term Link )
  description ( Index Term Link )
 
 slave KDCs
  adding names to cron job ( Index Term Link )
  configuring ( Index Term Link )
  definition ( Index Term Link )
  master KDC and ( Index Term Link )
  or master ( Index Term Link )
  planning for ( Index Term Link )
  swapping with master KDC ( Index Term Link )
 
 smartcard module, description ( Index Term Link )
 
 smattrpop command, description ( Index Term Link )
 
 SMC
  See Solaris Management Console
 
 smexec command, description ( Index Term Link )
 
 smmultiuser command, description ( Index Term Link )
 
 smprofile command, description ( Index Term Link )
 
 smrole command, description ( Index Term Link )
 
 smuser command, description ( Index Term Link )
 
 socket token ( Index Term Link )
 
 soft limit
  audit_warn condition ( Index Term Link )
  minfree: line description ( Index Term Link )
 
 soft string with audit_warn script ( Index Term Link )
 
 Solaris Management Console
  role assumption ( Index Term Link )
  running the user tools ( Index Term Link )
 
 sr_clean script, description ( Index Term Link )
 
 ssh-add command
  description ( Index Term Link )
  example ( Index Term Link ) ( Index Term Link )
 
 ssh-agent command
  description ( Index Term Link )
  from command line ( Index Term Link )
  in scripts ( Index Term Link )
 
 ssh command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  -L option ( Index Term Link )
  -o option ( Index Term Link )
  permitting access ( Index Term Link )
  port forwarding ( Index Term Link )
  -R option ( Index Term Link )
  using ( Index Term Link )
 
 ssh_config file
  client authentication parameters ( Index Term Link )
  configuring Secure Shell ( Index Term Link )
  connection parameters ( Index Term Link )
  host-specific parameters ( Index Term Link )
  keywords
   See specific keyword
  known host file parameters ( Index Term Link )
 
 ssh_host_key file, description ( Index Term Link )
 
 ssh_host_key.pub file, description ( Index Term Link )
 
 ssh-keygen command
  description ( Index Term Link )
  using ( Index Term Link )
 
 ssh_known_hosts file
  configuring Secure Shell ( Index Term Link )
  description ( Index Term Link )
 
 ssh service name, PAM ( Index Term Link )
 
 sshd command
  configuring for forwarding ( Index Term Link )
  description ( Index Term Link )
  session controls ( Index Term Link )
 
 sshd_config file
  description ( Index Term Link )
  forwarding parameters ( Index Term Link )
  ports parameters ( Index Term Link )
  server connection parameters ( Index Term Link )
  session control parameters ( Index Term Link )
 
 sshd.pid file, description ( Index Term Link )
 
 sshrc file, description ( Index Term Link )
 
 st_clean script, description ( Index Term Link )
 
 st_clean script for tape drives ( Index Term Link )
 
 stacking, in PAM ( Index Term Link )
 
 standard cleanup ( Index Term Link )
 
 starting
  ASET
   initiating sessions from shell ( Index Term Link )
   running interactively ( Index Term Link )
  KDC daemon ( Index Term Link )
 
 stash file
  creating ( Index Term Link )
  definition ( Index Term Link )
 
 sticky bit permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 stopping, dial-up logins temporarily ( Index Term Link )
 
 storage, audit records and ( Index Term Link )
 
 storage costs, BSM and ( Index Term Link )
 
 storage overflow prevention, audit trail ( Index Term Link )
 
 StrictHostKeyChecking keyword, ssh_config file ( Index Term Link )
 
 StrictModes keyword, sshd_config file ( Index Term Link )
 
 su command
  displaying use on console ( Index Term Link ) ( Index Term Link )
  in role assumption ( Index Term Link )
  monitoring use ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 su file, monitoring su command ( Index Term Link )
 
 su service name, PAM ( Index Term Link )
 
 subject token, format ( Index Term Link )
 
 Subsystem keyword, sshd_config file ( Index Term Link )
 
 success
  audit flag prefix ( Index Term Link ) ( Index Term Link )
  turning off audit flags for ( Index Term Link )
 
 sufficient control flag, PAM ( Index Term Link )
 
 sulog file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 superuser
  eliminating superuser in RBAC ( Index Term Link )
  model versus RBAC ( Index Term Link )
 
 suser, security policy ( Index Term Link )
 
 swapping master and slave KDCs ( Index Term Link )
 
 symbolic links
  file permissions ( Index Term Link )
  latest directory (ASET) ( Index Term Link )
 
 symbolic mode
  changing file permissions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
 
 synchronizing clocks ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 sysconf.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 SyslogFacility keyword, sshd_config file ( Index Term Link )
 
 System Administrator
  rights profile ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  role ( Index Term Link )
 
 system calls
  arg token ( Index Term Link )
  auditsvc() fails ( Index Term Link )
  auditsvc() fails ( Index Term Link )
  close ( Index Term Link )
  event numbers ( Index Term Link )
  exec_args token ( Index Term Link )
  exec_env token ( Index Term Link )
  ioctl ( Index Term Link ) ( Index Term Link )
  return token ( Index Term Link )
 
 system security
  dial-up passwords ( Index Term Link ) ( Index Term Link )
   disabling dial-up logins temporarily ( Index Term Link )
   /etc/d_passwd file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   /etc/dialups file ( Index Term Link )
  displaying
   user's login status ( Index Term Link ) ( Index Term Link )
   users with no passwords ( Index Term Link )
  introduction ( Index Term Link )
  login access restrictions ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  passwords ( Index Term Link )
  restricted shell ( Index Term Link ) ( Index Term Link )
  restricting root login to console ( Index Term Link ) ( Index Term Link )
  root access restrictions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  saving failed login attempts ( Index Term Link ) ( Index Term Link )
  special logins ( Index Term Link ) ( Index Term Link )
  su command monitoring ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 System V IPC
  ipc audit class ( Index Term Link )
  ipc_perm token ( Index Term Link )
  ipc token ( Index Term Link ) ( Index Term Link )