System Administration Guide: Security Services
    
A
 
 absolute mode
  changing file permissions ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  setting special permissions ( Index Term Link )
 
 access
  getting to server
   with SEAM ( Index Term Link )
  obtaining for a specific service ( Index Term Link )
  restricting for KDC servers ( Index Term Link )
  root access
   displaying attempts on console ( Index Term Link ) ( Index Term Link )
   monitoring su command use ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   restricting ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  security
   ACLs ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   file access restriction ( Index Term Link )
   firewall setup ( Index Term Link ) ( Index Term Link )
   login access restrictions ( Index Term Link ) ( Index Term Link )
   login control ( Index Term Link )
   monitoring system usage ( Index Term Link )
   network control ( Index Term Link )
   path variable setting ( Index Term Link )
   physical site security ( Index Term Link )
   reporting problems ( Index Term Link )
   root access restrictions ( Index Term Link )
   root login tracking ( Index Term Link )
   setuid programs ( Index Term Link )
  sharing files ( Index Term Link )
  system logins ( Index Term Link ) ( Index Term Link )
 
 access control list
  See ACL
 
 Access Control Lists (ACLs)
  See ACL
 
 ACL
  adding entries ( Index Term Link )
  changing entries ( Index Term Link )
  checking entries ( Index Term Link )
  commands ( Index Term Link )
  default entries for directories ( Index Term Link ) ( Index Term Link )
  deleting entries ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  directory entries ( Index Term Link ) ( Index Term Link )
  displaying entries ( Index Term Link ) ( Index Term Link )
  format of entries ( Index Term Link )
  kadm5.acl file ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  setting entries ( Index Term Link ) ( Index Term Link )
  valid file entries ( Index Term Link )
 
 acl token, format ( Index Term Link )
 
 ad audit flag ( Index Term Link )
 
 Add Administrative Role wizard
  description ( Index Term Link ) ( Index Term Link )
 
 Add Right dialog box, description ( Index Term Link )
 
 Add User wizard, description ( Index Term Link )
 
 adding
  administration principals (SEAM) ( Index Term Link )
  allocatable devices (BSM) ( Index Term Link )
  custom roles (RBAC) ( Index Term Link )
  PAM module ( Index Term Link )
  rights profiles (RBAC) ( Index Term Link )
  roles (RBAC) ( Index Term Link ) ( Index Term Link )
  service principal to keytab file (SEAM) ( Index Term Link )
  the first role (RBAC) ( Index Term Link )
  the first user (RBAC) ( Index Term Link )
 
 admin_server section, krb5.conf file ( Index Term Link )
 
 administering
  BSM
   audit class ( Index Term Link )
   audit classes ( Index Term Link )
   audit event ( Index Term Link )
   audit files ( Index Term Link )
   audit flags ( Index Term Link ) ( Index Term Link )
   audit records ( Index Term Link )
   audit trail overflow prevention ( Index Term Link )
   auditreduce command ( Index Term Link )
   cost control ( Index Term Link )
   description ( Index Term Link )
   efficiency ( Index Term Link )
   kernel events ( Index Term Link )
   process preselection mask ( Index Term Link )
   reducing storage-space requirements ( Index Term Link )
   user-level events ( Index Term Link )
  SEAM
   keytabs ( Index Term Link )
   policies ( Index Term Link )
   principals ( Index Term Link )
  Secure Shell ( Index Term Link )
 
 administrative audit class ( Index Term Link )
 
 aes128–cbc encryption algorithm, ssh_config file ( Index Term Link )
 
 agent daemon, Secure Shell ( Index Term Link )
 
 aliases file (ASET)
  description ( Index Term Link )
  example ( Index Term Link )
  format ( Index Term Link )
  specification ( Index Term Link )
 
 all
  audit class ( Index Term Link )
  audit flag
   caution for using ( Index Term Link )
   described ( Index Term Link )
  in user audit fields ( Index Term Link )
 
 All rights profile
  description ( Index Term Link ) ( Index Term Link )
 
 allhard string, audit_warn script ( Index Term Link )
 
 allocate command
  authorizations required ( Index Term Link )
  how the allocate mechanism works ( Index Term Link )
  options ( Index Term Link )
  using ( Index Term Link )
 
 allocate error state ( Index Term Link ) ( Index Term Link )
 
 AllowGroups keyword, sshd_config file ( Index Term Link )
 
 AllowTCPForwarding keyword, sshd_config file ( Index Term Link )
 
 AllowUsers keyword, sshd_config file ( Index Term Link )
 
 allsoft string, audit_warn script ( Index Term Link )
 
 always-audit flags
  description ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 analysis
  praudit command ( Index Term Link ) ( Index Term Link )
 
 ap audit flag ( Index Term Link )
 
 application audit class ( Index Term Link )
 
 arbitrary token
  format ( Index Term Link )
  item size field ( Index Term Link )
  print format field ( Index Term Link )
 
 Archive tape drive clean script ( Index Term Link )
 
 arg token ( Index Term Link )
 
 arge audit policy
  description ( Index Term Link )
  exec_env token and ( Index Term Link )
 
 argv audit policy
  description ( Index Term Link )
  exec_args token and ( Index Term Link )
 
 ASET
  description ( Index Term Link )
  environment variables ( Index Term Link )
  error messages ( Index Term Link )
  NFS servers and ( Index Term Link )
 
 aset command
  initiating ASET sessions ( Index Term Link )
  -p option ( Index Term Link )
  running ASET interactively ( Index Term Link )
  running ASET periodically ( Index Term Link )
  stop running ASET periodically ( Index Term Link )
 
 aset.restore command, description ( Index Term Link )
 
 ASETDIR variable (ASET), working directory specification ( Index Term Link )
 
 asetenv file
  description ( Index Term Link )
  modifying ( Index Term Link )
  running ASET periodically ( Index Term Link )
 
 ASETSECLEVEL variable (ASET), setting security levels ( Index Term Link )
 
 Assign Administrative Role dialog box, description ( Index Term Link )
 
 Assign Rights to Role dialog box, description ( Index Term Link )
 
 asterisk (*)
  device_allocate file ( Index Term Link ) ( Index Term Link )
  wildcard character ( Index Term Link )
 
 at command, authorizations required ( Index Term Link )
 
 atq command, authorizations required ( Index Term Link )
 
 attr token ( Index Term Link )
 
 audio_clean script ( Index Term Link )
 
 audio devices, device-clean scripts ( Index Term Link )
 
 AUDIO_DRAIN ioctl system call ( Index Term Link )
 
 AUDIO_SETINFO ioctl system call ( Index Term Link )
 
 AUDIOGETREG ioctl system call ( Index Term Link )
 
 AUDIOSETREG ioctl system call ( Index Term Link )
 
 audit characteristics
  overview ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 audit class
  description ( Index Term Link ) ( Index Term Link )
 
 audit classes
  auditconfig command options ( Index Term Link )
  description ( Index Term Link )
  flags and definitions ( Index Term Link ) ( Index Term Link )
  mapping events ( Index Term Link )
 
 audit command
  -n option ( Index Term Link )
  preselection mask for existing processes (-s option) ( Index Term Link )
  rereading audit files (-s option) ( Index Term Link )
  resetting directory pointer (-s option) ( Index Term Link )
 
 audit_control file
  audit daemon rereading after editing ( Index Term Link )
  audit_user file modification ( Index Term Link )
  dir: line
   described ( Index Term Link )
   examples ( Index Term Link )
  examples ( Index Term Link )
  flags: line
   described ( Index Term Link )
   prefixes in ( Index Term Link ) ( Index Term Link )
   process preselection mask ( Index Term Link )
  minfree: line
   audit_warn condition ( Index Term Link )
   described ( Index Term Link )
  naflags: line ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  prefixes in flags line ( Index Term Link ) ( Index Term Link )
  problem with contents ( Index Term Link )
 
 audit daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
 
 audit_data file ( Index Term Link )
 
 audit directory, description ( Index Term Link )
 
 audit event
  audit_event file ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  kernel event ( Index Term Link )
  mapping to classes ( Index Term Link )
  user-level events ( Index Term Link )
 
 audit_event file ( Index Term Link ) ( Index Term Link )
 
 audit events
  kernel events
   auditconfig command options ( Index Term Link )
   auditconfig command options ( Index Term Link )
  user-level events
   auditconfig command options ( Index Term Link )
 
 audit files
  auditreduce command ( Index Term Link ) ( Index Term Link )
  combining ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  copying messages to single file ( Index Term Link )
  displaying in entirety ( Index Term Link )
  file token ( Index Term Link )
  minimum free space for file systems ( Index Term Link )
  names ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   form ( Index Term Link )
   still-active files ( Index Term Link )
  nonactive files marked not_terminated ( Index Term Link )
  order for opening ( Index Term Link )
  printing ( Index Term Link )
  reducing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  reducing storage-space requirements ( Index Term Link ) ( Index Term Link )
  switching to new file ( Index Term Link )
  time stamps ( Index Term Link )
 
 audit flags ( Index Term Link )
  audit_control file line ( Index Term Link )
  audit_user file ( Index Term Link ) ( Index Term Link )
  auditconfig command options ( Index Term Link )
  definitions ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  machine-wide ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  prefixes ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 audit ID ( Index Term Link )
  overview ( Index Term Link )
 
 audit messages, copying to single file ( Index Term Link )
 
 audit policies
  auditconfig options ( Index Term Link )
  default ( Index Term Link )
  description ( Index Term Link )
  list of ( Index Term Link )
 
 audit records
  audit directories full ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  converting to readable format ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  events that generate ( Index Term Link )
  format or structure ( Index Term Link )
  overview ( Index Term Link )
  reducing audit files ( Index Term Link )
 
 audit session ID ( Index Term Link )
 
 audit_startup file ( Index Term Link )
 
 audit threshold ( Index Term Link )
 
 audit tokens
  audit record format ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  format ( Index Term Link )
  table of ( Index Term Link )
 
 audit trail
  analysis
   praudit command ( Index Term Link ) ( Index Term Link )
  analysis costs ( Index Term Link )
  creating
   audit daemon's role ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit_data file ( Index Term Link )
   overview ( Index Term Link )
  description ( Index Term Link )
  events included ( Index Term Link )
  merging all files ( Index Term Link ) ( Index Term Link )
  monitoring in real time ( Index Term Link )
  overflow prevention ( Index Term Link )
  overview ( Index Term Link )
 
 audit_user file
  prefixes for flags ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
  user audit fields ( Index Term Link ) ( Index Term Link )
 
 audit_warn script ( Index Term Link )
  audit daemon execution of ( Index Term Link )
  conditions invoking ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  strings ( Index Term Link ) ( Index Term Link )
 
 auditconfig command
  audit flags as arguments ( Index Term Link ) ( Index Term Link )
  options ( Index Term Link ) ( Index Term Link )
  prefixes for flags ( Index Term Link ) ( Index Term Link )
 
 auditd daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link )
   execution of ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
 
 auditreduce command ( Index Term Link ) ( Index Term Link )
  -c option ( Index Term Link )
  cleaning not_terminated files ( Index Term Link )
  -d option ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  examples ( Index Term Link )
  -O option ( Index Term Link )
  options ( Index Term Link )
  time stamp use ( Index Term Link )
  without options ( Index Term Link ) ( Index Term Link )
 
 auditsvc() system call
  audit_warn script and ( Index Term Link )
  trailer token and ( Index Term Link )
 
 AUE_... names, description ( Index Term Link )
 
 auth_attr database
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 AUTH_DH authentication ( Index Term Link )
 
 AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  additional transaction ( Index Term Link )
  client authenticates server ( Index Term Link )
  contacting the server ( Index Term Link ) ( Index Term Link )
  decrypting the conversation key ( Index Term Link )
  generating public and secret keys ( Index Term Link )
  generating the conversation key ( Index Term Link )
  running keylogin ( Index Term Link )
  storing information on the server ( Index Term Link ) ( Index Term Link )
  verifier returned to client ( Index Term Link )
 
 authentication
  configuring cross-realm ( Index Term Link )
  description ( Index Term Link )
  DH ( Index Term Link ) ( Index Term Link )
  network security ( Index Term Link ) ( Index Term Link )
  overview of Kerberos ( Index Term Link )
  root for NFS ( Index Term Link )
  SEAM and ( Index Term Link )
  Secure Shell
   description ( Index Term Link )
   hosts ( Index Term Link )
   methods ( Index Term Link )
   steps ( Index Term Link )
   users ( Index Term Link )
  terminology ( Index Term Link )
  types ( Index Term Link )
 
 authentication parameters, ssh_config file ( Index Term Link )
 
 authenticator
  in SEAM ( Index Term Link ) ( Index Term Link )
 
 authorization
  database
   See auth_attr database
  delegating ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  granularity ( Index Term Link )
  naming convention ( Index Term Link )
  network security ( Index Term Link ) ( Index Term Link )
  SEAM and ( Index Term Link )
  types ( Index Term Link )
 
 authorized_keys file, description ( Index Term Link )
 
 auths command, description ( Index Term Link )
 
 authtok_check module, description ( Index Term Link )
 
 authtok_get module, description ( Index Term Link )
 
 authtok_store module, description ( Index Term Link )
 
 Automated Security Enhancement Tool
  See ASET
 
 automatically enabling auditing ( Index Term Link )
 
 automating principal creation ( Index Term Link )