System Administration Guide: Security Services
    
Numbers and Symbols
 
 * (asterisk)
  device_allocate file ( Index Term Link ) ( Index Term Link )
  wildcard character in ASET ( Index Term Link )
 
 \ (backslash)
  device_allocate file ( Index Term Link )
  ending in device_maps file ( Index Term Link )
 
 . (dot), path variable entry ( Index Term Link )
 
 = (equal sign), file permissions symbol ( Index Term Link )
 
 - (minus sign)
  audit flag prefix ( Index Term Link )
  file permissions symbol ( Index Term Link )
 
 + (plus sign)
  audit flag prefix ( Index Term Link )
  file permissions symbol ( Index Term Link )
 
 # (pound sign)
  device_allocate file ( Index Term Link )
  device_maps file ( Index Term Link )
 
 ? (question mark), in ASET tune files ( Index Term Link )
 
 ^+ audit flag prefix ( Index Term Link )
 
 ^- audit flag prefix ( Index Term Link )
 
 ~/.gkadmin file, description ( Index Term Link )
 
 ~/.k5login file, description ( Index Term Link )
 
 3des-cbc encryption algorithm, ssh_config file ( Index Term Link )
 
 3des encryption algorithm, sshd_config file ( Index Term Link )
 
 $HOME/.ssh/known_hosts file
  description ( Index Term Link ) ( Index Term Link )
    
A
 
 aa audit flag ( Index Term Link )
 
 absolute mode
  changing file permissions ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  setting special permissions ( Index Term Link )
 
 access
  getting to server
   with SEAM ( Index Term Link )
  obtaining for a specific service ( Index Term Link )
  restricting for KDC servers ( Index Term Link )
  root access
   displaying attempts on console ( Index Term Link )
   monitoring su command use ( Index Term Link ) ( Index Term Link )
   restricting ( Index Term Link ) ( Index Term Link )
  security
   ACLs ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   controlling system usage ( Index Term Link )
   file access restriction ( Index Term Link )
   firewall setup ( Index Term Link ) ( Index Term Link )
   login access restrictions ( Index Term Link ) ( Index Term Link )
   login control ( Index Term Link )
   monitoring system usage ( Index Term Link )
   network control ( Index Term Link )
   path variable setting ( Index Term Link )
   physical security ( Index Term Link )
   reporting problems ( Index Term Link )
   root login tracking ( Index Term Link )
   setuid programs ( Index Term Link )
  sharing files ( Index Term Link )
  system logins ( Index Term Link )
 
 access control list
  See ACL
 
 Access Control Lists (ACLs)
  See ACL
 
 ACL
  adding entries ( Index Term Link )
  changing entries ( Index Term Link )
  checking entries ( Index Term Link )
  commands ( Index Term Link )
  default entries for directories ( Index Term Link ) ( Index Term Link )
  deleting entries ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  directory entries ( Index Term Link ) ( Index Term Link )
  displaying entries ( Index Term Link ) ( Index Term Link )
  format of entries ( Index Term Link )
  kadm5.acl file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  setting entries ( Index Term Link )
  valid file entries ( Index Term Link )
 
 acl token, format ( Index Term Link )
 
 ad audit flag ( Index Term Link )
 
 Add Administrative Role wizard
  description ( Index Term Link ) ( Index Term Link )
 
 Add Right dialog box, description ( Index Term Link )
 
 Add User wizard, description ( Index Term Link )
 
 adding
  administration principals (SEAM) ( Index Term Link )
  allocatable devices (BSM) ( Index Term Link )
  custom roles (RBAC) ( Index Term Link )
  PAM module ( Index Term Link )
  password encryption module ( Index Term Link )
  rights profiles (RBAC) ( Index Term Link )
  roles (RBAC) ( Index Term Link ) ( Index Term Link )
  service principal to keytab file (SEAM) ( Index Term Link )
  the first role (RBAC) ( Index Term Link )
  the first user (RBAC) ( Index Term Link )
 
 admin_server section, krb5.conf file ( Index Term Link )
 
 administering
  auditing
   audit class ( Index Term Link )
   audit classes ( Index Term Link )
   audit event ( Index Term Link )
   audit files ( Index Term Link )
   audit flags ( Index Term Link ) ( Index Term Link )
   audit records ( Index Term Link )
   audit trail overflow prevention ( Index Term Link )
   auditreduce command ( Index Term Link )
   cost control ( Index Term Link )
   description ( Index Term Link )
   efficiency ( Index Term Link )
   kernel events ( Index Term Link )
   process preselection mask ( Index Term Link )
   reducing storage-space requirements ( Index Term Link )
   user-level events ( Index Term Link )
  SEAM
   keytabs ( Index Term Link )
   policies ( Index Term Link )
   principals ( Index Term Link )
  Secure Shell ( Index Term Link )
 
 administrative (old) audit class ( Index Term Link )
 
 administrative audit class ( Index Term Link )
 
 aes128–cbc encryption algorithm, ssh_config file ( Index Term Link )
 
 agent daemon, Secure Shell ( Index Term Link )
 
 algorithms
  configuration ( Index Term Link )
  password encryption ( Index Term Link )
 
 aliases file (ASET)
  description ( Index Term Link )
  example ( Index Term Link )
  format ( Index Term Link )
  specification ( Index Term Link )
 
 all
  audit class ( Index Term Link )
  audit flag
   caution for using ( Index Term Link )
   described ( Index Term Link )
  in user audit fields ( Index Term Link )
 
 All rights profile
  description ( Index Term Link ) ( Index Term Link )
 
 allhard string, audit_warn script ( Index Term Link )
 
 allocate command
  authorizations required ( Index Term Link )
  how the allocate mechanism works ( Index Term Link )
  options ( Index Term Link )
  using ( Index Term Link )
 
 allocate error state ( Index Term Link ) ( Index Term Link )
 
 AllowGroups keyword, sshd_config file ( Index Term Link )
 
 AllowTCPForwarding keyword, sshd_config file ( Index Term Link )
 
 AllowUsers keyword, sshd_config file ( Index Term Link )
 
 allsoft string, audit_warn script ( Index Term Link )
 
 always-audit flags
  description ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 am audit flag ( Index Term Link )
 
 analysis
  praudit command ( Index Term Link ) ( Index Term Link )
 
 ap audit flag ( Index Term Link )
 
 application audit class ( Index Term Link )
 
 arbitrary token
  format ( Index Term Link )
  item size field ( Index Term Link )
  print format field ( Index Term Link )
 
 Archive tape drive clean script ( Index Term Link )
 
 arg token ( Index Term Link )
 
 arge audit policy
  description ( Index Term Link )
  exec_env token and ( Index Term Link )
 
 argv audit policy
  description ( Index Term Link )
  exec_args token and ( Index Term Link )
 
 as audit flag ( Index Term Link )
 
 ASET
  description ( Index Term Link )
  environment variables ( Index Term Link )
  error messages ( Index Term Link )
  NFS servers and ( Index Term Link )
 
 aset command
  initiating ASET sessions ( Index Term Link )
  -p option ( Index Term Link )
  running ASET interactively ( Index Term Link )
  running ASET periodically ( Index Term Link )
  stop running ASET periodically ( Index Term Link )
 
 aset.restore command, description ( Index Term Link )
 
 ASETDIR variable (ASET), working directory specification ( Index Term Link )
 
 asetenv file
  description ( Index Term Link )
  modifying ( Index Term Link )
  running ASET periodically ( Index Term Link )
 
 ASETSECLEVEL variable (ASET), setting security levels ( Index Term Link )
 
 Assign Administrative Role dialog box, description ( Index Term Link )
 
 Assign Rights to Role dialog box, description ( Index Term Link )
 
 asterisk (*)
  device_allocate file ( Index Term Link ) ( Index Term Link )
  wildcard character ( Index Term Link )
 
 at command, authorizations required ( Index Term Link )
 
 atq command, authorizations required ( Index Term Link )
 
 attr token ( Index Term Link )
 
 audio_clean script ( Index Term Link )
 
 audio devices, device-clean scripts ( Index Term Link )
 
 AUDIO_DRAIN ioctl system call ( Index Term Link )
 
 AUDIO_SETINFO ioctl system call ( Index Term Link )
 
 AUDIOGETREG ioctl system call ( Index Term Link )
 
 AUDIOSETREG ioctl system call ( Index Term Link )
 
 audit administration audit class ( Index Term Link )
 
 audit characteristics
  overview ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 audit class
  description ( Index Term Link ) ( Index Term Link )
 
 audit classes
  description ( Index Term Link )
  flags and definitions ( Index Term Link )
  mapping events ( Index Term Link )
 
 audit command
  description ( Index Term Link )
  -n option ( Index Term Link )
  preselection mask for existing processes (-s option) ( Index Term Link )
  rereading audit files (-s option) ( Index Term Link )
  resetting directory pointer (-s option) ( Index Term Link )
 
 Audit Control, rights profile ( Index Term Link )
 
 audit_control file
  audit daemon rereading after editing ( Index Term Link )
  audit_user file modification ( Index Term Link )
  dir: line
   described ( Index Term Link )
   examples ( Index Term Link )
  examples ( Index Term Link )
  flags: line
   described ( Index Term Link )
   prefixes in ( Index Term Link )
   process preselection mask ( Index Term Link )
  minfree: line
   audit_warn condition ( Index Term Link )
   described ( Index Term Link )
  naflags: line ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  prefixes in flags line ( Index Term Link )
  problem with contents ( Index Term Link )
 
 audit daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
 
 audit_data file ( Index Term Link )
 
 audit directory, description ( Index Term Link )
 
 audit event
  audit_event file ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  kernel event ( Index Term Link )
  mapping to classes ( Index Term Link )
  user-level events ( Index Term Link )
 
 audit_event file ( Index Term Link ) ( Index Term Link )
 
 audit files
  auditreduce command ( Index Term Link ) ( Index Term Link )
  combining ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  copying messages to single file ( Index Term Link )
  displaying in entirety ( Index Term Link )
  file token ( Index Term Link )
  minimum free space for file systems ( Index Term Link )
  names ( Index Term Link )
   form ( Index Term Link )
   still-active files ( Index Term Link )
   time stamps ( Index Term Link )
  nonactive files marked not_terminated ( Index Term Link )
  order for opening ( Index Term Link )
  printing ( Index Term Link )
  reducing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  reducing storage-space requirements ( Index Term Link ) ( Index Term Link )
  switching to new file ( Index Term Link )
  time stamps ( Index Term Link )
 
 audit flags ( Index Term Link )
  audit_control file line ( Index Term Link )
  audit_user file ( Index Term Link ) ( Index Term Link )
  definitions ( Index Term Link )
  description ( Index Term Link )
  effect on public objects ( Index Term Link )
  exceptions to machine-wide settings ( Index Term Link )
  machine-wide ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  prefixes ( Index Term Link )
  process preselection mask ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 audit ID
  mechanism ( Index Term Link )
  overview ( Index Term Link )
 
 audit messages, copying to single file ( Index Term Link )
 
 audit policies
  defaults ( Index Term Link )
  description ( Index Term Link )
  effects of ( Index Term Link )
 
 audit policy, public ( Index Term Link )
 
 audit records
  audit directories full ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  converting to readable format ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  displaying the format ( Index Term Link )
  events that generate ( Index Term Link )
  format or structure ( Index Term Link )
  formatting example ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  reducing audit files ( Index Term Link )
 
 Audit Review, rights profile ( Index Term Link )
 
 audit session ID ( Index Term Link )
 
 audit_startup file ( Index Term Link )
 
 audit threshold ( Index Term Link )
 
 audit tokens
  audit record format ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  format ( Index Term Link )
  table of ( Index Term Link )
 
 audit trail
  analysis
   praudit command ( Index Term Link ) ( Index Term Link )
  analysis costs ( Index Term Link )
  creating
   audit daemon's role ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit_data file ( Index Term Link )
   overview ( Index Term Link )
  description ( Index Term Link )
  events included ( Index Term Link )
  merging all files ( Index Term Link ) ( Index Term Link )
  monitoring in real time ( Index Term Link )
  no public objects ( Index Term Link )
  overflow prevention ( Index Term Link )
  overview ( Index Term Link )
 
 audit_user file
  exception to machine-wide audit flags ( Index Term Link )
  prefixes for flags ( Index Term Link )
  process preselection mask ( Index Term Link )
  user audit fields ( Index Term Link ) ( Index Term Link )
 
 audit_warn script ( Index Term Link )
  audit daemon execution of ( Index Term Link )
  conditions invoking ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  strings ( Index Term Link ) ( Index Term Link )
 
 auditconfig command
  audit flags as arguments ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  prefixes for flags ( Index Term Link )
 
 auditd daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link )
   execution of ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
 
 auditing, rights profiles ( Index Term Link )
 
 auditreduce command ( Index Term Link ) ( Index Term Link )
  -c option ( Index Term Link )
  cleaning not_terminated files ( Index Term Link )
  -d option ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  examples ( Index Term Link )
  -O option ( Index Term Link )
  options ( Index Term Link )
  time stamp use ( Index Term Link )
  trailer tokens, and ( Index Term Link )
  without options ( Index Term Link ) ( Index Term Link )
 
 auditsvc() system call, audit_warn script and ( Index Term Link )
 
 AUE_... names, description ( Index Term Link )
 
 auth_attr database
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 AUTH_DH authentication ( Index Term Link )
 
 AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  additional transaction ( Index Term Link )
  client authenticates server ( Index Term Link )
  contacting the server ( Index Term Link ) ( Index Term Link )
  decrypting the conversation key ( Index Term Link )
  generating public and secret keys ( Index Term Link )
  generating the conversation key ( Index Term Link )
  running keylogin ( Index Term Link )
  storing information on the server ( Index Term Link ) ( Index Term Link )
  verifier returned to client ( Index Term Link )
 
 authentication
  configuring cross-realm ( Index Term Link )
  description ( Index Term Link )
  DH ( Index Term Link ) ( Index Term Link )
  network security ( Index Term Link ) ( Index Term Link )
  overview of Kerberos ( Index Term Link )
  root for NFS ( Index Term Link )
  SEAM and ( Index Term Link )
  Secure Shell
   description ( Index Term Link )
   hosts ( Index Term Link )
   methods ( Index Term Link )
   steps ( Index Term Link )
   users ( Index Term Link )
  terminology ( Index Term Link )
  types ( Index Term Link )
 
 authentication parameters, ssh_config file ( Index Term Link )
 
 authenticator
  in SEAM ( Index Term Link ) ( Index Term Link )
 
 authorization
  database
   See auth_attr database
  delegating ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  granularity ( Index Term Link )
  naming convention ( Index Term Link )
  network security ( Index Term Link ) ( Index Term Link )
  SEAM and ( Index Term Link )
  types ( Index Term Link )
 
 authorized_keys file, description ( Index Term Link )
 
 auths command, description ( Index Term Link )
 
 authtok_check module, description ( Index Term Link )
 
 authtok_get module, description ( Index Term Link )
 
 authtok_store module, description ( Index Term Link )
 
 Automated Security Enhancement Tool
  See ASET
 
 automatically enabling auditing ( Index Term Link )
 
 automating principal creation ( Index Term Link )
    
B
 
 backing up the Kerberos database ( Index Term Link )
 
 backslash (\), device_allocate file ( Index Term Link )
 
 backup
  Kerberos database ( Index Term Link )
  slave KDCs ( Index Term Link )
 
 Basic Solaris User rights profile
  description ( Index Term Link ) ( Index Term Link )
 
 Batchmode keyword, ssh_config file ( Index Term Link )
 
 binding control flag, PAM ( Index Term Link )
 
 blowfish-cbc encryption algorithm, ssh_config file ( Index Term Link )
 
 blowfish encryption algorithm
  policy.conf file ( Index Term Link )
  ssh_config file ( Index Term Link )
 
 Bourne shell
  ASET working directory specification ( Index Term Link )
  privileged version ( Index Term Link )
 
 bsmconv script, devicemaps file creation ( Index Term Link )
 
 bsmrecord command
  display audit record formats ( Index Term Link )
  example ( Index Term Link ) ( Index Term Link )
    
C
 
 -c option, auditreduce command ( Index Term Link )
 
 C shell
  ASET working directory specification ( Index Term Link )
  privileged version ( Index Term Link )
 
 cache, credential ( Index Term Link )
 
 caret (^) in audit flag prefixes ( Index Term Link )
 
 CD-ROM drives
  device-clean scripts ( Index Term Link ) ( Index Term Link )
 
 cd subcommand, sftp command ( Index Term Link )
 
 changepw principal ( Index Term Link )
 
 changing
  (command line) user properties ( Index Term Link )
  rights profiles (command line) ( Index Term Link )
  role properties (command line) ( Index Term Link )
  your password with kpasswd ( Index Term Link )
  your password with passwd ( Index Term Link )
 
 CheckHostIP keyword, ssh_config file ( Index Term Link )
 
 chgrp command
  description ( Index Term Link )
  syntax ( Index Term Link )
 
 chgrp subcommand, sftp command ( Index Term Link )
 
 chkey command ( Index Term Link ) ( Index Term Link )
 
 chmod command
  changing special permissions ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  syntax ( Index Term Link )
 
 chmod subcommand, sftp command ( Index Term Link )
 
 choosing, your password ( Index Term Link )
 
 chown command
  description ( Index Term Link )
  syntax ( Index Term Link )
 
 Cipher keyword, ssh_config file ( Index Term Link )
 
 Ciphers keyword
  ssh_config file ( Index Term Link )
  sshd_config file ( Index Term Link )
 
 cklist.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 CKLISTPATH_level variable (ASET), setting the directories to be checked ( Index Term Link )
 
 cl audit flag ( Index Term Link )
 
 class
  description ( Index Term Link ) ( Index Term Link )
 
 classes, flags and definitions ( Index Term Link )
 
 cleaning, not_terminated files ( Index Term Link )
 
 client
  AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  definition in SEAM ( Index Term Link )
 
 client names, planning for in SEAM ( Index Term Link )
 
 clients (SEAM), configuring ( Index Term Link )
 
 clock skew
  SEAM and ( Index Term Link ) ( Index Term Link )
 
 clock synchronizing
  SEAM and ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 cnt audit policy, description ( Index Term Link )
 
 combining audit files ( Index Term Link )
  auditreduce command ( Index Term Link ) ( Index Term Link )
 
 command-line equivalents of SEAM Administration Tool ( Index Term Link )
 
 commands
  device-allocation commands ( Index Term Link )
  table of SEAM ( Index Term Link )
 
 comments
  device_allocate file ( Index Term Link )
  device_maps file ( Index Term Link )
 
 common key
  calculation ( Index Term Link )
  DH authentication and ( Index Term Link )
 
 Compression keyword, ssh_config file ( Index Term Link )
 
 CompressionLevel keyword, ssh_config file ( Index Term Link )
 
 Computer Emergency Response Team/Coordination Center (CERT/CC) ( Index Term Link ) ( Index Term Link )
 
 computer security
  See system security
 
 configuration decisions
  SEAM
   client and service principal names ( Index Term Link )
   clock synchronization ( Index Term Link )
   database propagation ( Index Term Link )
   mapping hostnames onto realms ( Index Term Link )
   number of realms ( Index Term Link )
   ports ( Index Term Link )
   realm hierarchy ( Index Term Link )
   realm names ( Index Term Link )
   realms ( Index Term Link )
   slave KDCs ( Index Term Link )
 
 configuration file
  audit_control file ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_startup script for audit policy ( Index Term Link )
  PAM ( Index Term Link ) ( Index Term Link )
  password encryption algorithm ( Index Term Link )
  policy.conf file ( Index Term Link )
 
 configuring
  ASET ( Index Term Link ) ( Index Term Link )
  audit trail overflow prevention ( Index Term Link )
  auditconfig command ( Index Term Link )
  RBAC
   task map ( Index Term Link )
  SEAM
   adding administration principals ( Index Term Link )
   clients ( Index Term Link )
   cross-realm authentication ( Index Term Link )
   master KDC server ( Index Term Link )
   NFS servers ( Index Term Link )
   overview ( Index Term Link )
   slave KDC server ( Index Term Link )
   task map ( Index Term Link )
  Secure Shell ( Index Term Link )
 
 ConnectionAttempts keyword, ssh_config file ( Index Term Link )
 
 console
  displaying su command use on ( Index Term Link )
  root access restriction to ( Index Term Link )
 
 context-sensitive help ( Index Term Link )
 
 control flags, PAM ( Index Term Link )
 
 controlling, system usage ( Index Term Link )
 
 conversation key
  decrypting ( Index Term Link )
  generating ( Index Term Link )
 
 converting
  audit records to readable format ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 copying audit messages to single file ( Index Term Link )
 
 cost control, auditing and ( Index Term Link )
 
 creating
  credential table ( Index Term Link )
  /etc/d_passwd file ( Index Term Link )
  keytab file ( Index Term Link )
  new policy ( Index Term Link )
  new policy (SEAM) ( Index Term Link )
  new principal (SEAM) ( Index Term Link )
  Secure Shell keys ( Index Term Link )
  stash file ( Index Term Link )
  tickets with kinit ( Index Term Link )
 
 creating the audit trail ( Index Term Link )
  audit daemon's role ( Index Term Link )
  audit_data file ( Index Term Link )
  auditd daemon ( Index Term Link )
  overview ( Index Term Link )
 
 cred database ( Index Term Link ) ( Index Term Link )
  DH authentication and ( Index Term Link )
 
 cred table
  information stored by server ( Index Term Link ) ( Index Term Link )
 
 credential
  cache ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  obtaining for a server ( Index Term Link )
  obtaining for a TGS ( Index Term Link )
  or tickets ( Index Term Link )
 
 credential cache ( Index Term Link )
 
 credential table, adding single entry to ( Index Term Link )
 
 cron command, backing up using ( Index Term Link )
 
 cron service name, PAM ( Index Term Link )
 
 crontab files, authorizations required ( Index Term Link )
 
 crontab files
  running ASET periodically ( Index Term Link )
  stop running ASET periodically ( Index Term Link )
 
 cross-realm authentication, configuring ( Index Term Link )
 
 crypt command, file security ( Index Term Link )
 
 crypt_sunmd5 encryption algorithm ( Index Term Link )
 
 csh command
  dial-up passwords ( Index Term Link )
  privileged version ( Index Term Link )
 
 .cshrc file, path variable entry ( Index Term Link )
    
D
 
 -d option
  auditreduce command ( Index Term Link )
  praudit command ( Index Term Link )
 
 d_passwd file
  creating ( Index Term Link )
  description ( Index Term Link )
  disabling dial-up logins temporarily ( Index Term Link )
  /etc/passwd file and ( Index Term Link )
 
 daemon
  keyserv ( Index Term Link )
  krb5kdc ( Index Term Link )
 
 daemons, table of SEAM ( Index Term Link )
 
 Data Encryption Standard
  See DES
 
 data forwarding, Secure Shell ( Index Term Link )
 
 database
  backing up and propagating KDC ( Index Term Link ) ( Index Term Link )
  creating KDC ( Index Term Link )
  KDC propagation ( Index Term Link )
 
 deallocate command
  allocate error state ( Index Term Link )
  authorizations required ( Index Term Link )
  description ( Index Term Link )
  device-clean scripts and ( Index Term Link )
  using ( Index Term Link )
 
 debugging sequence number ( Index Term Link )
 
 decrypting
  conversation key ( Index Term Link )
  secret key ( Index Term Link )
 
 default_realm section, krb5.conf file ( Index Term Link )
 
 defaults
  ACL entries for directories ( Index Term Link ) ( Index Term Link )
  audit_startup file ( Index Term Link )
  machine-wide ( Index Term Link )
  praudit output format ( Index Term Link ) ( Index Term Link )
 
 delete_entry command ( Index Term Link )
 
 deleting
  ACL entries ( Index Term Link ) ( Index Term Link )
  host's service ( Index Term Link )
  policies (SEAM) ( Index Term Link )
  principal (SEAM) ( Index Term Link )
 
 DenyGroups keyword, sshd_config file ( Index Term Link )
 
 DenyUsers keyword, sshd_config file ( Index Term Link )
 
 DES encryption ( Index Term Link )
 
 destroying, tickets with kdestroy ( Index Term Link )
 
 device_allocate file
  format ( Index Term Link )
  overview ( Index Term Link )
 
 device allocation ( Index Term Link )
  adding devices ( Index Term Link )
  allocatable devices ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  allocate command
   how the allocate mechanism works ( Index Term Link )
   options ( Index Term Link )
   using ( Index Term Link )
  allocate error state ( Index Term Link ) ( Index Term Link )
  allocating a device ( Index Term Link )
  commands ( Index Term Link ) ( Index Term Link )
  components of the allocation mechanism ( Index Term Link )
  deallocate command
   allocate error state ( Index Term Link )
  deallocate command
   allocate error state ( Index Term Link )
  deallocate command
   described ( Index Term Link )
  deallocate command
   device-clean scripts and ( Index Term Link )
  deallocate command
   using ( Index Term Link )
  description ( Index Term Link )
  device_allocate file ( Index Term Link )
  device-clean scripts
   audio devices ( Index Term Link )
   CD-ROM drives ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link )
   diskette drives ( Index Term Link ) ( Index Term Link )
   options ( Index Term Link )
   tape drives ( Index Term Link ) ( Index Term Link )
   writing new scripts ( Index Term Link )
  device_maps file ( Index Term Link )
  device_maps file ( Index Term Link )
  list_devices command ( Index Term Link )
  lock file setup ( Index Term Link )
  managing devices ( Index Term Link )
  reallocating ( Index Term Link )
  using device allocations ( Index Term Link )
 
 device-clean scripts
  audio devices ( Index Term Link )
  CD-ROM drives ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  diskette drives ( Index Term Link ) ( Index Term Link )
  options ( Index Term Link )
  tape drives ( Index Term Link ) ( Index Term Link )
  writing new scripts ( Index Term Link )
 
 device_maps file
  format ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
 
 devices
  device allocation
   See device allocation
  lock files ( Index Term Link )
  managing ( Index Term Link )
  system device access control ( Index Term Link )
 
 dfstab file
  kerberos option ( Index Term Link )
  sharing files ( Index Term Link )
 
 DH authentication ( Index Term Link )
  AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  mounting files ( Index Term Link )
  sharing files ( Index Term Link )
 
 DH security
  for an NIS+ client ( Index Term Link )
  for an NIS client ( Index Term Link )
 
 dhkeys module, description ( Index Term Link )
 
 dial_auth module, description ( Index Term Link )
 
 dial-up passwords
  disabling ( Index Term Link )
  disabling dial-up logins temporarily ( Index Term Link )
  /etc/d_passwd file ( Index Term Link )
  security ( Index Term Link )
 
 dialups file, creating ( Index Term Link )
 
 Diffie-Hellman, role in authentication ( Index Term Link )
 
 dir: line
  audit_control file ( Index Term Link ) ( Index Term Link )
 
 direct realms ( Index Term Link )
 
 directories
  audit_control file definitions ( Index Term Link )
  audit daemon pointer ( Index Term Link ) ( Index Term Link )
  audit directories full ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  mounting audit directories ( Index Term Link )
 
 directory
  ACL entries ( Index Term Link ) ( Index Term Link )
  ASET files ( Index Term Link )
   checklist task (CKLISTPATH) setting ( Index Term Link ) ( Index Term Link )
   master files ( Index Term Link )
   reports ( Index Term Link )
   working directory ( Index Term Link ) ( Index Term Link )
  displaying files and related information ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  permissions
   defaults ( Index Term Link )
   description ( Index Term Link )
  public directories ( Index Term Link )
 
 disabling
  abort sequence ( Index Term Link )
  dial-up logins temporarily ( Index Term Link )
  keyboard shutdown ( Index Term Link )
  service on a host (SEAM) ( Index Term Link )
  user logins ( Index Term Link )
 
 disk-space requirements ( Index Term Link )
 
 diskette drives
  device-clean scripts ( Index Term Link ) ( Index Term Link )
 
 displaying
  ACL entries ( Index Term Link ) ( Index Term Link )
  ASET task status ( Index Term Link ) ( Index Term Link )
  audit log in entirety ( Index Term Link )
  files and related information ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  root access attempts on console ( Index Term Link )
  su command use on console ( Index Term Link )
  sublist of principals (SEAM) ( Index Term Link )
  user's login status ( Index Term Link ) ( Index Term Link )
 
 dminfo command ( Index Term Link )
 
 DNS ( Index Term Link )
  SEAM and ( Index Term Link )
 
 domain_realm section
  krb5.conf file ( Index Term Link ) ( Index Term Link )
 
 dot (.), path variable entry ( Index Term Link )
 
 DSAAuthentication keyword, sshd_config file ( Index Term Link )
 
 DTD for praudit command ( Index Term Link )
 
 dtlogin service name, PAM ( Index Term Link )
 
 .dtprofile script, use in Secure Shell ( Index Term Link )
 
 dtsession service name, PAM ( Index Term Link )
 
 duplicating, principal (SEAM) ( Index Term Link )
    
E
 
 ebusy string, audit_warn script ( Index Term Link )
 
 editing rights profiles, task description ( Index Term Link )
 
 eeprom command ( Index Term Link ) ( Index Term Link )
 
 eeprom.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 efficiency, auditing and ( Index Term Link )
 
 eject command, BSM device cleanup and ( Index Term Link )
 
 encrypting
  capturing encrypted passwords ( Index Term Link )
  files ( Index Term Link )
  passwords ( Index Term Link )
 
 encryption ( Index Term Link )
  password algorithms ( Index Term Link )
  privacy service ( Index Term Link )
  specifying algorithms in policy.conf ( Index Term Link )
  specifying algorithms in ssh_config ( Index Term Link )
  specifying algorithms in sshd_config ( Index Term Link )
 
 ending, signal received during auditing shutdown ( Index Term Link )
 
 env.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 environment file, description ( Index Term Link )
 
 environment file (ASET)
  description ( Index Term Link )
  modifying ( Index Term Link )
  running ASET periodically ( Index Term Link )
 
 environment variables
  ASET
   ASETDIR ( Index Term Link )
   ASETSECLEVEL ( Index Term Link )
   CKLISTPATH_level ( Index Term Link ) ( Index Term Link )
   PERIODIC_SCHEDULE ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   summary table ( Index Term Link )
   TASKS ( Index Term Link ) ( Index Term Link )
   UID_ALIASES ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   YPCHECK ( Index Term Link ) ( Index Term Link )
 
 equals sign (=), file permissions symbol ( Index Term Link )
 
 error message, with kpasswd ( Index Term Link )
 
 errors
  allocate error state ( Index Term Link ) ( Index Term Link )
  audit directories full ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  internal errors ( Index Term Link )
 
 EscapeChar keyword, ssh_config file ( Index Term Link )
 
 /etc/d_passwd file ( Index Term Link )
  creating ( Index Term Link )
  disabling dial-up logins temporarily ( Index Term Link )
  /etc/passwd file and ( Index Term Link )
 
 /etc/default/kbd file ( Index Term Link )
 
 /etc/default/login file, restricting root access to console ( Index Term Link )
 
 /etc/default/su file
  displaying su command use on console ( Index Term Link )
  monitoring su command ( Index Term Link )
 
 /etc/dfs/dfstab file
  kerberos option ( Index Term Link )
  sharing files ( Index Term Link )
 
 /etc/dialups file, creating ( Index Term Link )
 
 /etc/group file, ASET checks ( Index Term Link )
 
 /etc/hosts.equiv file, description ( Index Term Link )
 
 /etc/init.d/kdc file, description ( Index Term Link )
 
 /etc/init.d/kdc.master file, description ( Index Term Link )
 
 /etc/krb5/kadm5.acl file, description ( Index Term Link )
 
 /etc/krb5/kadm5.keytab file, description ( Index Term Link )
 
 /etc/krb5/kdc.conf file, description ( Index Term Link )
 
 /etc/krb5/kpropd.acl file, description ( Index Term Link )
 
 /etc/krb5/krb5.conf file, description ( Index Term Link )
 
 /etc/krb5/krb5.keytab file, description ( Index Term Link )
 
 /etc/krb5/warn.conf file, description ( Index Term Link )
 
 /etc/logindevperm file, description ( Index Term Link )
 
 /etc/nologin file ( Index Term Link )
  description ( Index Term Link )
 
 /etc/nsswitch.conf file, login access restrictions ( Index Term Link )
 
 /etc/pam.conf
  description ( Index Term Link ) ( Index Term Link )
  syntax ( Index Term Link )
 
 /etc/pam.conf file, SEAM and ( Index Term Link )
 
 /etc/passwd file
  ASET checks ( Index Term Link )
  /etc/d_passwd file and ( Index Term Link )
 
 /etc/publickey file, DH authentication and ( Index Term Link )
 
 /etc/security/audit/bsmconv script, device_maps file creation ( Index Term Link )
 
 /etc/security/audit_data file ( Index Term Link )
 
 /etc/security/audit_event file ( Index Term Link )
  audit events and ( Index Term Link )
 
 /etc/security/audit_startup file ( Index Term Link )
 
 /etc/security/audit_warn script ( Index Term Link ) ( Index Term Link )
 
 /etc/security/dev lock files ( Index Term Link )
 
 /etc/security/policy.conf file, algorithms configuration ( Index Term Link )
 
 /etc/ssh_host_key.pub file, description ( Index Term Link )
 
 /etc/ssh/shosts.equiv file, description ( Index Term Link )
 
 /etc/ssh/ssh_config file
  client authentication parameters ( Index Term Link )
  configuring Secure Shell ( Index Term Link )
  host-specific parameters ( Index Term Link )
 
 /etc/ssh/ssh_host_key file, description ( Index Term Link )
 
 /etc/ssh/ssh_known_hosts file
  configuring Secure Shell ( Index Term Link )
  controlling distribution ( Index Term Link )
  description ( Index Term Link )
 
 /etc/ssh/sshd_config file, description ( Index Term Link )
 
 /etc/ssh/sshrc file, description ( Index Term Link )
 
 /etc/syslog.conf file, PAM ( Index Term Link )
 
 event, description ( Index Term Link )
 
 event modifier field flags (header token) ( Index Term Link )
 
 events, audit, See audit events ( Index Term Link )
 
 ex audit flag ( Index Term Link )
 
 exec_args token
  argv policy and ( Index Term Link )
  format ( Index Term Link )
 
 exec_attr database
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 exec audit class ( Index Term Link )
 
 exec_env token, format ( Index Term Link )
 
 executable stacks ( Index Term Link )
 
 execute permissions, symbolic mode ( Index Term Link )
 
 execution attributes, description ( Index Term Link )
 
 execution log (ASET) ( Index Term Link ) ( Index Term Link )
 
 exit subcommand, sftp command ( Index Term Link )
 
 exit token, format ( Index Term Link )
    
F
 
 -F option
  allocate command ( Index Term Link )
  deallocate command ( Index Term Link )
  st_clean script ( Index Term Link )
 
 fa audit flag ( Index Term Link )
 
 failed login attempts ( Index Term Link )
 
 failure
  audit flag prefix ( Index Term Link ) ( Index Term Link )
  turning off audit flags for ( Index Term Link ) ( Index Term Link )
 
 FallBackToRsh keyword, ssh_config file ( Index Term Link )
 
 fc audit flag ( Index Term Link )
 
 fd audit flag ( Index Term Link )
 
 fd_clean script, description ( Index Term Link )
 
 file_attr_acc audit class ( Index Term Link )
 
 file_attr_mod audit class ( Index Term Link )
 
 file_close audit class ( Index Term Link )
 
 file_creation audit class ( Index Term Link )
 
 file_deletion audit class ( Index Term Link )
 
 file_read audit class ( Index Term Link )
 
 file token, format ( Index Term Link )
 
 file vnode token ( Index Term Link )
 
 file_write audit class ( Index Term Link )
 
 files
  copying with Secure Shell ( Index Term Link )
  device allocation lock ( Index Term Link )
  kdc.conf ( Index Term Link )
  table of SEAM ( Index Term Link )
  transferring with Secure Shell ( Index Term Link )
 
 files and file systems
  ACL entries
   adding or modifying ( Index Term Link )
   checking ( Index Term Link )
   deleting ( Index Term Link ) ( Index Term Link )
   displaying ( Index Term Link ) ( Index Term Link )
   setting ( Index Term Link )
   valid entries ( Index Term Link )
  ASET checks ( Index Term Link ) ( Index Term Link )
  ownership
   changing ( Index Term Link )
   setgid permission and ( Index Term Link )
   setuid permission and ( Index Term Link )
  permissions
   absolute mode ( Index Term Link ) ( Index Term Link )
   changing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   defaults ( Index Term Link )
   description ( Index Term Link )
   setgid ( Index Term Link ) ( Index Term Link )
   setuid ( Index Term Link )
   sticky bit ( Index Term Link )
   symbolic mode ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   umask setting ( Index Term Link )
  security ( Index Term Link ) ( Index Term Link )
   access restriction ( Index Term Link )
   ACL ( Index Term Link )
   changing ownership ( Index Term Link ) ( Index Term Link )
   changing permissions ( Index Term Link ) ( Index Term Link )
   directory permissions ( Index Term Link )
   displaying file information ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   encryption ( Index Term Link )
   file permissions ( Index Term Link )
   file types ( Index Term Link )
   special file permissions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   umask default ( Index Term Link )
   user classes ( Index Term Link )
  sharing files ( Index Term Link )
 
 find command
  finding files with setuid permissions ( Index Term Link ) ( Index Term Link )
 
 firewall.rpt file ( Index Term Link )
  description ( Index Term Link )
 
 firewall systems
  ASET setup ( Index Term Link ) ( Index Term Link )
  outside connections with Secure Shell
   from command line ( Index Term Link )
   from configuration file ( Index Term Link )
  packet smashing ( Index Term Link )
  security ( Index Term Link )
  SunScreen ( Index Term Link )
  trusted host ( Index Term Link )
 
 flags
  audit
   See audit flags
  audit_control file line ( Index Term Link )
  audit_user file ( Index Term Link ) ( Index Term Link )
  definitions ( Index Term Link )
  machine-wide ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  prefixes ( Index Term Link )
  process preselection mask ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 flags: line in audit_control file
  description ( Index Term Link )
  prefixes in ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 fm audit flag ( Index Term Link )
 
 forced cleanup ( Index Term Link )
 
 format of audit records
  bsmrecord command ( Index Term Link ) ( Index Term Link )
 
 forwardable tickets
  definition ( Index Term Link )
  description ( Index Term Link )
  example ( Index Term Link )
 
 forwarding, specifying in ssh_config ( Index Term Link )
 
 ForwardX11 keyword, Secure Shell port forwarding ( Index Term Link )
 
 FQDN (Fully Qualified Domain Name), in SEAM ( Index Term Link )
 
 fr audit flag ( Index Term Link )
 
 ftp command, authentication ( Index Term Link )
 
 ftp service name, PAM ( Index Term Link )
 
 fw audit flag ( Index Term Link )
    
G
 
 GatewayPorts keyword
  ssh_config file ( Index Term Link )
  sshd_config file ( Index Term Link )
 
 gateways
  See firewall systems
 
 Generic Security Service API
  See GSS-API
 
 get subcommand, sftp command ( Index Term Link )
 
 getfacl command
  description ( Index Term Link )
  displaying ACL entries ( Index Term Link )
  examples ( Index Term Link )
  verifying ACLs set on files ( Index Term Link )
 
 getting
  access to a specific service ( Index Term Link )
  credential for a server ( Index Term Link )
  credential for a TGS ( Index Term Link )
 
 gkadmin command
  See also SEAM Administration Tool
  description ( Index Term Link )
 
 .gkadmin file ( Index Term Link )
  description ( Index Term Link )
 
 GlobalKnownHostsFile keyword, ssh_config file ( Index Term Link )
 
 group ACL entries
  default entries for directories ( Index Term Link )
  description ( Index Term Link )
  setting ( Index Term Link )
 
 group audit policy
  description ( Index Term Link )
  groups token and ( Index Term Link )
 
 group identifier numbers (GIDs), special logins and ( Index Term Link )
 
 group policy
  group token ( Index Term Link )
  group token and ( Index Term Link )
  newgroups token ( Index Term Link )
  newgroups token and ( Index Term Link )
 
 group token ( Index Term Link )
  format ( Index Term Link )
 
 groups, changing file ownership ( Index Term Link )
 
 GSS-API
  SEAM and ( Index Term Link ) ( Index Term Link )
 
 gsscred command, description ( Index Term Link )
 
 gsscred table, using ( Index Term Link )
    
H
 
 -h option, bsmrecord command ( Index Term Link )
 
 hard-disk-space requirements, auditing and ( Index Term Link )
 
 hard string with audit_warn script ( Index Term Link )
 
 hardware
  protecting ( Index Term Link ) ( Index Term Link )
 
 header token
  description ( Index Term Link )
  event-modifier field flags ( Index Term Link )
  format ( Index Term Link )
  order in audit record ( Index Term Link )
 
 help
  context-sensitive ( Index Term Link )
  Help Contents ( Index Term Link )
  SEAM Administration Tool ( Index Term Link )
  URL for online ( Index Term Link )
 
 Help button, SEAM Administration Tool ( Index Term Link )
 
 hierarchical realms
  configuring ( Index Term Link )
  in SEAM ( Index Term Link ) ( Index Term Link )
 
 high ASET security level ( Index Term Link )
 
 host
  authentication in Secure Shell ( Index Term Link )
  disabling service on ( Index Term Link )
 
 Host keyword, ssh_config file ( Index Term Link )
 
 host names, mapping onto realms ( Index Term Link )
 
 host principal
  and DNS ( Index Term Link )
  creating ( Index Term Link )
 
 HostDSAKey keyword, sshd_config file ( Index Term Link )
 
 HostKey keyword, sshd_config file ( Index Term Link )
 
 Hostname keyword, ssh_config file ( Index Term Link )
 
 hosts, trusted host ( Index Term Link )
 
 hosts.equiv file, description ( Index Term Link )
    
I
 
 -I option
  deallocate command ( Index Term Link )
  st_clean script ( Index Term Link )
 
 identity file (Secure Shell), naming convention ( Index Term Link )
 
 IdentityFile keyword, ssh_config file ( Index Term Link )
 
 IDs
  audit ( Index Term Link )
   overview ( Index Term Link )
  audit session ( Index Term Link )
  mapping UNIX to Kerberos principals ( Index Term Link )
  terminal ( Index Term Link )
 
 in_addr token, format ( Index Term Link )
 
 init service name, PAM ( Index Term Link )
 
 initial ticket, definition ( Index Term Link )
 
 instance, in principals names ( Index Term Link )
 
 integrity
  SEAM and ( Index Term Link )
  security service ( Index Term Link )
 
 interactively running ASET ( Index Term Link )
 
 Internet firewall setup ( Index Term Link )
 
 Internet-related tokens
  in_addr token ( Index Term Link )
  ip token ( Index Term Link )
  iport token ( Index Term Link )
  socket token ( Index Term Link )
 
 invalid ticket, definition ( Index Term Link )
 
 io audit flag ( Index Term Link )
 
 ioctl audit class ( Index Term Link )
 
 ioctl() system calls ( Index Term Link )
 
 ioctl system calls ( Index Term Link )
 
 IP address, Secure Shell checking ( Index Term Link )
 
 ip audit flag ( Index Term Link )
 
 ip token, format ( Index Term Link )
 
 ipc audit class ( Index Term Link )
 
 ipc_perm token, format ( Index Term Link )
 
 ipc token ( Index Term Link )
  format ( Index Term Link )
 
 ipc type field values (ipc token) ( Index Term Link )
 
 iport token, format ( Index Term Link )
 
 item size field, arbitrary token ( Index Term Link )
    
K
 
 .k5.REALM file, description ( Index Term Link )
 
 .k5login file, description ( Index Term Link )
 
 kadm5.acl file
  description ( Index Term Link )
  format of entries ( Index Term Link )
  master KDC entry ( Index Term Link ) ( Index Term Link )
  new principals and ( Index Term Link ) ( Index Term Link )
 
 kadm5.keytab file ( Index Term Link )
  description ( Index Term Link )
 
 kadmin command ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  ktadd command ( Index Term Link )
  ktremove command ( Index Term Link )
  removing principals from keytab with ( Index Term Link )
 
 kadmin.local command ( Index Term Link ) ( Index Term Link )
  adding administration principals ( Index Term Link )
  description ( Index Term Link )
 
 kadmin.log file, description ( Index Term Link )
 
 kadmind daemon
  master KDC and ( Index Term Link )
  SEAM and ( Index Term Link )
 
 kadmind principal ( Index Term Link )
 
 kdb5_util command ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
 
 KDC
  adding entries to propagation file ( Index Term Link )
  adding slave names to cron job ( Index Term Link )
  backing up and propagating ( Index Term Link )
  configuring master ( Index Term Link )
  configuring server ( Index Term Link )
  configuring slave ( Index Term Link )
  copying administration files from slave to master ( Index Term Link )
  creating database ( Index Term Link )
  creating host principal ( Index Term Link )
  creating root principal ( Index Term Link ) ( Index Term Link )
  database propagation ( Index Term Link )
  master
   definition ( Index Term Link )
  planning ( Index Term Link )
  ports ( Index Term Link )
  propagating database with kprop_util ( Index Term Link )
  restricting access to servers ( Index Term Link )
  slave ( Index Term Link )
   definition ( Index Term Link )
  slave or master ( Index Term Link ) ( Index Term Link )
  starting daemon ( Index Term Link )
  swapping master and slave ( Index Term Link )
  synchronizing clocks ( Index Term Link ) ( Index Term Link )
 
 kdc.conf file
  description ( Index Term Link )
  ticket lifetime and ( Index Term Link )
 
 kdc file, description ( Index Term Link )
 
 kdc.log file, description ( Index Term Link )
 
 kdc.master file, description ( Index Term Link )
 
 kdestroy command
  description ( Index Term Link )
  example ( Index Term Link )
 
 KeepAlive keyword
  ssh_config file ( Index Term Link )
  sshd_config file ( Index Term Link )
 
 KERB authentication, dfstab file option ( Index Term Link )
 
 Kerberos
  and Kerberos V5 ( Index Term Link )
  and SEAM ( Index Term Link ) ( Index Term Link )
  dfstab file option ( Index Term Link )
  terminology ( Index Term Link )
 
 Kerberos (KERB) authentication ( Index Term Link )
 
 kernel events, auditing and ( Index Term Link )
 
 key
  creating for an NIS user ( Index Term Link )
  creating for Secure Shell ( Index Term Link )
  description ( Index Term Link )
  private ( Index Term Link )
  service ( Index Term Link )
  service key ( Index Term Link )
  session ( Index Term Link ) ( Index Term Link )
 
 Key Distribution Center
  See KDC
 
 KEYBOARD_ABORT system variable ( Index Term Link )
 
 keylogin command ( Index Term Link ) ( Index Term Link )
  running ( Index Term Link )
 
 KeyRegenerationInterval keyword, sshd_config file ( Index Term Link )
 
 keyserv daemon
  starting ( Index Term Link )
  verifying ( Index Term Link )
 
 keytab file
  adding master KDC's host principal to ( Index Term Link )
  adding service principal to ( Index Term Link ) ( Index Term Link )
  administering ( Index Term Link )
  administering with ktutil command ( Index Term Link )
  creating ( Index Term Link )
  disabling a host's service with delete_entry command ( Index Term Link )
  read into keytab buffer with with read_kt command ( Index Term Link )
  read into keytab with read_kt command ( Index Term Link )
  removing principals with ktremove command ( Index Term Link )
  removing service principal from ( Index Term Link )
  viewing contents with ktutil command ( Index Term Link ) ( Index Term Link )
  viewing keylist buffer with list command ( Index Term Link ) ( Index Term Link )
 
 kinds of tickets ( Index Term Link )
 
 kinit command
  description ( Index Term Link )
  example ( Index Term Link )
  -F option ( Index Term Link )
  ticket lifetime ( Index Term Link )
 
 klist command
  description ( Index Term Link )
  example ( Index Term Link )
  -f option ( Index Term Link )
 
 known_hosts file
  configuring Secure Shell ( Index Term Link )
  controlling distribution ( Index Term Link )
  description ( Index Term Link )
  role in authentication ( Index Term Link )
 
 Korn shell
  ASET working directory specification ( Index Term Link )
  privileged version ( Index Term Link )
 
 kpasswd command
  and passwd command ( Index Term Link )
  description ( Index Term Link )
  error message ( Index Term Link )
  example ( Index Term Link )
 
 kprop command, description ( Index Term Link )
 
 kprop_script script ( Index Term Link )
 
 kpropd.acl file ( Index Term Link )
  description ( Index Term Link )
 
 kpropd daemon, SEAM and ( Index Term Link )
 
 krb5.conf file
  description ( Index Term Link )
  domain_realm section ( Index Term Link )
  editing ( Index Term Link )
  ports definition ( Index Term Link )
 
 krb5.keytab file, description ( Index Term Link )
 
 krb5 module, description ( Index Term Link )
 
 krb5cc_uid file, description ( Index Term Link )
 
 krb5kdc daemon ( Index Term Link )
  master KDC and ( Index Term Link )
  SEAM and ( Index Term Link )
 
 ksh command ( Index Term Link )
  privileged version ( Index Term Link )
 
 ktadd command ( Index Term Link ) ( Index Term Link )
  syntax ( Index Term Link )
 
 ktremove command ( Index Term Link )
 
 ktutil command ( Index Term Link )
  delete_entry command ( Index Term Link )
  description ( Index Term Link )
  list command ( Index Term Link ) ( Index Term Link )
  read_kt command ( Index Term Link ) ( Index Term Link )
  viewing list of principals ( Index Term Link ) ( Index Term Link )
    
L
 
 -l option, praudit command ( Index Term Link )
 
 -L option
  ssh command ( Index Term Link ) ( Index Term Link )
 
 lcd subcommand, sftp command ( Index Term Link )
 
 LDAP
  passwords ( Index Term Link ) ( Index Term Link )
 
 ldap module, description ( Index Term Link )
 
 legacy application, securing ( Index Term Link )
 
 lifetime of ticket, in SEAM ( Index Term Link )
 
 list command ( Index Term Link ) ( Index Term Link )
 
 list_devices command ( Index Term Link )
  authorizations required ( Index Term Link )
 
 list privileges in SEAM Administration Tool ( Index Term Link )
 
 ListenAddress keyword, sshd_config file ( Index Term Link )
 
 lo audit flag ( Index Term Link )
 
 LocalForward keyword, ssh_config file ( Index Term Link )
 
 lock files
  how the allocate mechanism works ( Index Term Link )
  setting up ( Index Term Link )
 
 log files
  ASET execution log ( Index Term Link ) ( Index Term Link )
  monitoring su command ( Index Term Link )
 
 logging in
  displaying user's login status ( Index Term Link ) ( Index Term Link )
  root login
   account ( Index Term Link )
   restricting to console ( Index Term Link )
   tracking ( Index Term Link )
  security
   access restrictions ( Index Term Link ) ( Index Term Link )
   saving failed attempts ( Index Term Link )
   system access control ( Index Term Link )
   system device access control ( Index Term Link )
   tracking root login ( Index Term Link )
  system logins ( Index Term Link )
 
 .login file, path variable entry ( Index Term Link )
 
 login file, restricting root access to console ( Index Term Link )
 
 login_logout audit class ( Index Term Link )
 
 login service name, PAM ( Index Term Link )
 
 logindevperm file, description ( Index Term Link )
 
 LoginGraceTime keyword, sshd_config file ( Index Term Link )
 
 loginlog file, saving failed login attempts ( Index Term Link )
 
 logins command
  displaying user's login status ( Index Term Link ) ( Index Term Link )
  displaying users with no passwords ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 LogLevel keyword
  ssh_config file ( Index Term Link )
  sshd_config file ( Index Term Link )
 
 low ASET security level ( Index Term Link )
 
 ls subcommand, sftp command ( Index Term Link )
    
M
 
 machine security
  See system security
 
 mail, using with Secure Shell ( Index Term Link )
 
 makedbm command, description ( Index Term Link )
 
 managing
  passwords with SEAM ( Index Term Link )
  RBAC information ( Index Term Link )
 
 managing devices ( Index Term Link )
 
 mapping
  hostnames onto realms (SEAM) ( Index Term Link )
  UIDs to Kerberos principals ( Index Term Link )
 
 mappings, events to classes (auditing) ( Index Term Link )
 
 mask, process preselection
  description ( Index Term Link )
  machine-wide ( Index Term Link )
 
 mask ACL entries
  default entries for directories ( Index Term Link )
  description ( Index Term Link )
  setting ( Index Term Link )
 
 master files
  ASET ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 master KDC
  configuring ( Index Term Link )
  definition ( Index Term Link )
  slave KDCs and ( Index Term Link ) ( Index Term Link )
  swapping with slave KDC ( Index Term Link )
 
 max_life value, description ( Index Term Link )
 
 max_renewable_life value, description ( Index Term Link )
 
 MaxStartups keyword, sshd_config file ( Index Term Link )
 
 MD5 encryption algorithm, policy.conf file ( Index Term Link )
 
 medium ASET security level ( Index Term Link )
 
 minfree: line in audit_control file
  audit_warn condition ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
 
 minus (-) audit flag prefix ( Index Term Link )
 
 minus sign (-), file permissions symbol ( Index Term Link )
 
 mkdir subcommand, sftp command ( Index Term Link )
 
 modifying
  policies (SEAM) ( Index Term Link )
  principal (SEAM) ( Index Term Link )
  principal's password ( Index Term Link )
  roles (RBAC) ( Index Term Link )
  users (RBAC) ( Index Term Link )
 
 module types, PAM ( Index Term Link )
 
 modules
  PAM ( Index Term Link )
  password encryption ( Index Term Link )
 
 monitoring
  audit trail in real time ( Index Term Link )
  su command use ( Index Term Link ) ( Index Term Link )
  system usage ( Index Term Link )
 
 mounting, NFS file systems ( Index Term Link )
 
 mounting audit directories ( Index Term Link )
 
 mt command, BSM device cleanup and ( Index Term Link )
    
N
 
 -n option, audit command ( Index Term Link )
 
 na audit flag ( Index Term Link )
 
 naflags: line in audit_control file ( Index Term Link )
 
 name service scope, description ( Index Term Link )
 
 names
  audit classes ( Index Term Link )
  audit files
   closed files ( Index Term Link )
   form ( Index Term Link )
   still-active files ( Index Term Link )
   time stamps ( Index Term Link )
   use ( Index Term Link )
  audit flags ( Index Term Link )
  audit IDs ( Index Term Link )
  device names
   device_allocate file ( Index Term Link )
   device_maps file ( Index Term Link )
  IDs
   audit ( Index Term Link )
   audit session ( Index Term Link )
   terminal ( Index Term Link )
  kernel events ( Index Term Link )
  user-level events ( Index Term Link )
 
 naming convention, Secure Shell identity file ( Index Term Link )
 
 ncsd command, description ( Index Term Link )
 
 network audit class ( Index Term Link )
 
 network security
  authentication ( Index Term Link ) ( Index Term Link )
  authorization ( Index Term Link ) ( Index Term Link )
  firewall systems ( Index Term Link )
   need for ( Index Term Link )
   packet smashing ( Index Term Link )
   trusted host ( Index Term Link )
  issues ( Index Term Link )
  overview ( Index Term Link )
  reporting problems ( Index Term Link )
  restricting root access ( Index Term Link )
 
 Network Time Protocol
  See NTP
 
 never-audit flags ( Index Term Link )
  description ( Index Term Link )
 
 newgroups token
  format ( Index Term Link )
  group policy ( Index Term Link )
 
 newkey command
  creating keys for an NIS user ( Index Term Link )
  generating keys ( Index Term Link )
 
 NFS, mounting systems ( Index Term Link )
 
 NFS servers
  ASET and ( Index Term Link )
  configuring for SEAM ( Index Term Link )
 
 NFS system ( Index Term Link )
 
 NIS
  passwords ( Index Term Link ) ( Index Term Link )
 
 NIS+
  ASET checks ( Index Term Link )
  authentication ( Index Term Link )
  authorization ( Index Term Link )
  cred database ( Index Term Link )
  passwords ( Index Term Link ) ( Index Term Link )
  publickey database ( Index Term Link )
 
 nisaddcred command ( Index Term Link )
  generating keys ( Index Term Link )
 
 no audit flag ( Index Term Link )
 
 no_class audit class ( Index Term Link )
 
 nobody user ( Index Term Link )
 
 noexec_user_stack_log variable ( Index Term Link )
 
 noexec_user_stack variable ( Index Term Link )
 
 nologin file, description ( Index Term Link )
 
 non_attrib audit class ( Index Term Link )
 
 non-hierarchical realms, in SEAM ( Index Term Link )
 
 nonattributable flags in audit_control file ( Index Term Link )
 
 not_terminated files, cleaning ( Index Term Link )
 
 nt audit flag ( Index Term Link )
 
 NTP ( Index Term Link ) ( Index Term Link )
  SEAM and ( Index Term Link )
 
 null audit class ( Index Term Link )
 
 NumberOfPasswordPrompts keyword, ssh_config file ( Index Term Link )
    
O
 
 O option, auditreduce command ( Index Term Link )
 
 object-reuse requirement ( Index Term Link )
  device-clean scripts
   audio devices ( Index Term Link )
   CD-ROM drives ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link )
   diskette drives ( Index Term Link ) ( Index Term Link )
   tape drives ( Index Term Link ) ( Index Term Link )
   writing new scripts ( Index Term Link )
  in BSM ( Index Term Link )
 
 obtaining
  access to a specific service ( Index Term Link )
  credential for a server ( Index Term Link )
  credential for a TGS ( Index Term Link )
  forwardable tickets ( Index Term Link )
  tickets with kinit ( Index Term Link )
 
 online help
  context-sensitive ( Index Term Link )
  Help Contents ( Index Term Link )
  SEAM Administration Tool ( Index Term Link )
  URL for ( Index Term Link )
 
 opaque token, format ( Index Term Link )
 
 Operator rights profile
  description ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 Operator role, description ( Index Term Link )
 
 option control flag, PAM ( Index Term Link )
 
 ot audit flag ( Index Term Link )
 
 other ACL entries
  default entries for directories ( Index Term Link )
  description ( Index Term Link )
  setting ( Index Term Link )
 
 other audit class ( Index Term Link )
 
 overflow prevention, audit trail ( Index Term Link )
 
 ovsec_adm.xxxxx file, description ( Index Term Link )
 
 ownership of files
  ACLs and ( Index Term Link ) ( Index Term Link )
  changing ( Index Term Link ) ( Index Term Link )
  changing group ownership ( Index Term Link )
    
P
 
 -p option, bsmrecord command ( Index Term Link )
 
 packet transfers
  firewall security ( Index Term Link )
  packet smashing ( Index Term Link )
 
 PAM
  add a module ( Index Term Link )
  configuration file ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  control flags ( Index Term Link )
  /etc/syslog.conf file ( Index Term Link )
  module types ( Index Term Link )
  modules ( Index Term Link )
  overview ( Index Term Link )
  password mapping ( Index Term Link )
  planning ( Index Term Link )
  SEAM and ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  service names ( Index Term Link )
  try_first_pass ( Index Term Link )
 
 pam_*.so.1 files, description ( Index Term Link )
 
 pam.conf file
  description ( Index Term Link )
  SEAM and ( Index Term Link )
 
 pam_roles command, description ( Index Term Link )
 
 panels, table of SEAM Administration Tool ( Index Term Link )
 
 passphrase, example ( Index Term Link )
 
 passwd command
  and kpasswd command ( Index Term Link )
  try_first_pass ( Index Term Link )
 
 passwd file
  ASET checks ( Index Term Link )
  /etc/d_passwd file and ( Index Term Link )
 
 passwd service name, PAM ( Index Term Link )
 
 password mapping, in PAM ( Index Term Link )
 
 PasswordAuthentication keyword, sshd_config file ( Index Term Link )
 
 passwords
  and policies ( Index Term Link )
  capturing encrypted passwords ( Index Term Link )
  changing with kpasswd command ( Index Term Link )
  changing with passwd command ( Index Term Link )
  dial-up passwords
   disabling dial-up logins temporarily ( Index Term Link )
   /etc/d_passwd file ( Index Term Link )
  displaying users with no passwords ( Index Term Link )
  eliminating in Secure Shell use ( Index Term Link ) ( Index Term Link )
  encryption algorithms ( Index Term Link )
  LDAP ( Index Term Link ) ( Index Term Link )
  local ( Index Term Link )
  login security ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  management ( Index Term Link )
  modifying a principal's password ( Index Term Link )
  NIS ( Index Term Link ) ( Index Term Link )
  NIS+ ( Index Term Link ) ( Index Term Link )
  PROM security mode ( Index Term Link ) ( Index Term Link )
  secret-key decryption ( Index Term Link )
  Secure Shell ( Index Term Link )
  specifying encryption algorithm ( Index Term Link )
  suggestions on choosing ( Index Term Link )
  system logins ( Index Term Link ) ( Index Term Link )
  UNIX and Kerberos ( Index Term Link )
 
 path audit policy, description ( Index Term Link )
 
 PATH system variable ( Index Term Link )
 
 path token ( Index Term Link )
 
 path variable, setting ( Index Term Link )
 
 pc audit flag ( Index Term Link )
 
 PERIODIC_SCHEDULE variable (ASET)
  scheduling ASET ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 permissions
  ACLs and ( Index Term Link ) ( Index Term Link )
  ASET handling of ( Index Term Link ) ( Index Term Link )
  changing file permissions
   absolute mode ( Index Term Link ) ( Index Term Link )
   chmod command ( Index Term Link )
   symbolic mode ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  defaults ( Index Term Link )
  directory permissions ( Index Term Link )
  file permissions
   absolute mode ( Index Term Link ) ( Index Term Link )
   changing ( Index Term Link ) ( Index Term Link )
   description ( Index Term Link )
   special permissions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   symbolic mode ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  setgid permissions
   absolute mode ( Index Term Link ) ( Index Term Link )
   description ( Index Term Link ) ( Index Term Link )
   symbolic mode ( Index Term Link )
  setuid permissions
   absolute mode ( Index Term Link ) ( Index Term Link )
   description ( Index Term Link )
   finding files with permissions set ( Index Term Link ) ( Index Term Link )
   security risks ( Index Term Link )
   symbolic mode ( Index Term Link )
  special file permissions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  sticky bit ( Index Term Link )
  tune files (ASET) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  umask settings ( Index Term Link )
  user classes and ( Index Term Link )
 
 PermitEmptyPasswords keyword, sshd_config file ( Index Term Link )
 
 PermitRootLogin keyword, sshd_config file ( Index Term Link )
 
 pfcsh command, description ( Index Term Link )
 
 pfexec command, description ( Index Term Link )
 
 pfksh command, description ( Index Term Link )
 
 pfsh command, description ( Index Term Link )
 
 physical security ( Index Term Link )
 
 planning
  PAM ( Index Term Link )
  RBAC ( Index Term Link )
  SEAM
   client and service principal names ( Index Term Link )
   clock synchronization ( Index Term Link )
   configuration decisions ( Index Term Link )
   database propagation ( Index Term Link )
   number of realms ( Index Term Link )
   ports ( Index Term Link )
   realm hierarchy ( Index Term Link )
   realm names ( Index Term Link )
   realms ( Index Term Link )
   slave KDCs ( Index Term Link )
 
 pluggable authentication module
  See PAM
 
 plus (+) audit flag prefix ( Index Term Link )
 
 plus sign (+), file permissions symbol ( Index Term Link )
 
 pm audit flag ( Index Term Link )
 
 policies
  administering ( Index Term Link ) ( Index Term Link )
  and passwords ( Index Term Link )
  creating (SEAM ( Index Term Link )
  creating new (SEAM) ( Index Term Link )
  deleting ( Index Term Link )
  modifying ( Index Term Link )
  SEAM Administration Tool panels for ( Index Term Link )
  specifying password algorithm ( Index Term Link )
  task map for administering ( Index Term Link )
  viewing attributes ( Index Term Link )
  viewing list of ( Index Term Link )
 
 policy.conf database
  Basic Solaris User rights profile ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 port
  for KDC and admin services ( Index Term Link )
  KDC administration daemon ( Index Term Link )
 
 port forwarding
  configuring ssh_config ( Index Term Link )
  Secure Shell ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 Port keyword, sshd_config file ( Index Term Link )
 
 postdatable ticket, definition ( Index Term Link )
 
 postdated ticket, description ( Index Term Link )
 
 postsigterm string, audit_warn script ( Index Term Link )
 
 pound sign (#)
  device_allocate file ( Index Term Link )
  device_maps file ( Index Term Link )
 
 ppp service name, PAM ( Index Term Link )
 
 praudit command
  converting audit records to readable format ( Index Term Link ) ( Index Term Link )
  DTD for -x option ( Index Term Link )
  output formats ( Index Term Link ) ( Index Term Link )
  piping auditreduce output to ( Index Term Link )
  using ( Index Term Link ) ( Index Term Link )
 
 prefixes in audit flags ( Index Term Link )
 
 preselection mask
  description ( Index Term Link )
  machine-wide ( Index Term Link )
 
 preselection mask (auditing), reducing storage costs ( Index Term Link )
 
 primary, in principals names ( Index Term Link )
 
 Primary Administrator
  rights profile ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  role ( Index Term Link )
 
 primary audit directory ( Index Term Link )
 
 principal
  adding administration ( Index Term Link )
  adding service principal to keytab ( Index Term Link ) ( Index Term Link )
  administering ( Index Term Link ) ( Index Term Link )
  automating creation of ( Index Term Link )
  creating host ( Index Term Link )
  creating root ( Index Term Link ) ( Index Term Link )
  deleting ( Index Term Link )
  duplicating ( Index Term Link )
  in SEAM ( Index Term Link )
  modifying ( Index Term Link )
  principal name ( Index Term Link )
  removing from keytab file ( Index Term Link )
  removing service principal from keytab ( Index Term Link )
  root ( Index Term Link )
  SEAM Administration Tool panels for ( Index Term Link )
  service principal ( Index Term Link )
  setting up defaults ( Index Term Link )
  task map for administering ( Index Term Link )
  user ID comparison ( Index Term Link )
  user principal ( Index Term Link )
  viewing attributes ( Index Term Link )
  viewing list of ( Index Term Link )
  viewing sublist of principals ( Index Term Link )
 
 principal.db file, description ( Index Term Link )
 
 principal.kadm5 file, description ( Index Term Link )
 
 principal.kadm5.lock file, description ( Index Term Link )
 
 principal.ok file, description ( Index Term Link )
 
 principals, creating ( Index Term Link )
 
 print format field, arbitrary token ( Index Term Link )
 
 Printer Management rights profile
  description ( Index Term Link ) ( Index Term Link )
 
 printing, audit log ( Index Term Link )
 
 privacy
  SEAM and ( Index Term Link )
  security service ( Index Term Link )
 
 private key ( Index Term Link )
  definition in SEAM ( Index Term Link )
  description ( Index Term Link )
  naming convention ( Index Term Link )
 
 privilege ( Index Term Link )
  effects on SEAM Administration Tool ( Index Term Link )
 
 privileged application
  authorization checking ( Index Term Link )
  description ( Index Term Link )
  ID checking ( Index Term Link )
 
 process audit characteristics
  audit ID ( Index Term Link )
  audit session ID ( Index Term Link )
  process preselection mask ( Index Term Link )
  terminal ID ( Index Term Link )
 
 process audit class ( Index Term Link )
 
 process modify audit class ( Index Term Link )
 
 process preselection mask, description ( Index Term Link )
 
 process start audit class ( Index Term Link )
 
 process token, format ( Index Term Link )
 
 processing time costs, auditing and ( Index Term Link )
 
 prof_attr database
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 profile
  See rights profile
 
 .profile file, path variable entry ( Index Term Link )
 
 profile shell, description ( Index Term Link )
 
 profiles command, description ( Index Term Link )
 
 program, testing for authorizations ( Index Term Link )
 
 projects module, description ( Index Term Link )
 
 PROM security mode ( Index Term Link )
 
 propagation
  KDC database ( Index Term Link )
  Kerberos database ( Index Term Link )
 
 propagation file, adding entries to ( Index Term Link )
 
 Protocol keyword, sshd_config file ( Index Term Link )
 
 proxiable ticket, definition ( Index Term Link )
 
 proxy ticket, definition ( Index Term Link )
 
 ProxyCommand keyword, ssh_config file ( Index Term Link )
 
 ps audit flag ( Index Term Link )
 
 pseudo-tty, use in Secure Shell ( Index Term Link )
 
 public audit policy
  description ( Index Term Link )
  read-only events ( Index Term Link )
 
 public directories ( Index Term Link )
 
 public key
  description ( Index Term Link )
  DH authentication and ( Index Term Link )
  known hosts file ( Index Term Link )
  naming convention ( Index Term Link )
  Secure Shell ( Index Term Link )
 
 public-key cryptography
  AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  changing public and secret keys ( Index Term Link )
  common key
   calculation ( Index Term Link )
  database of public keys ( Index Term Link )
  generating keys
   conversation key ( Index Term Link )
   public and secret keys ( Index Term Link )
  secret key
   changing ( Index Term Link )
   database ( Index Term Link )
   decrypting ( Index Term Link )
   generating ( Index Term Link )
 
 public objects, auditing ( Index Term Link )
 
 publickey map, DH authentication and ( Index Term Link )
 
 put subcommand
  sftp command ( Index Term Link ) ( Index Term Link )
    
Q
 
 question mark (?) wildcard character, in ASET tune files ( Index Term Link )
 
 quit subcommand, sftp command ( Index Term Link )
    
R
 
 -R option
  ssh command ( Index Term Link ) ( Index Term Link )
 
 -r praudit output format ( Index Term Link )
 
 raw praudit output format ( Index Term Link )
 
 RBAC
  administration commands ( Index Term Link )
  audit profiles ( Index Term Link )
  authorization database ( Index Term Link )
  basic concept ( Index Term Link )
  database relationships ( Index Term Link )
  elements ( Index Term Link )
  name services ( Index Term Link )
  rights profile database ( Index Term Link )
  tasks ( Index Term Link )
   adding custom roles ( Index Term Link )
   adding first role ( Index Term Link )
   adding first user ( Index Term Link )
   adding rights profile example ( Index Term Link )
   adding roles ( Index Term Link )
   adding roles from command line ( Index Term Link )
   changing rights profiles from command line ( Index Term Link )
   changing roles from command line ( Index Term Link )
   changing user properties from command line ( Index Term Link )
   checking scripts or programs for authorizations ( Index Term Link )
   configuration ( Index Term Link )
   editing rights profiles ( Index Term Link )
   information management task map ( Index Term Link )
   modifying roles ( Index Term Link )
   modifying users ( Index Term Link )
   planning ( Index Term Link )
   running the user tools ( Index Term Link )
   securing legacy applications ( Index Term Link )
   securing scripts ( Index Term Link )
   setting IDs on commands ( Index Term Link )
   using privileged applications ( Index Term Link )
 
 rc file, description ( Index Term Link )
 
 rcp command, authentication ( Index Term Link )
 
 read into keytab buffer with read_kt command ( Index Term Link )
 
 read into keytab with read_kt command ( Index Term Link )
 
 read_kt command ( Index Term Link ) ( Index Term Link )
 
 read permissions, symbolic mode ( Index Term Link )
 
 readable audit record format
  converting audit records to ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 reallocating devices ( Index Term Link )
 
 realms
  and servers ( Index Term Link )
  configuration decisions ( Index Term Link )
  configuring cross-realm authentication ( Index Term Link )
  contents of ( Index Term Link )
  direct ( Index Term Link )
  hierarchical ( Index Term Link )
  hierarchical or non-hierarchical ( Index Term Link )
  hierarchy ( Index Term Link )
  in principal names ( Index Term Link )
  in principals names ( Index Term Link )
  mapping hostnames onto ( Index Term Link )
  names ( Index Term Link )
  number of ( Index Term Link )
 
 reducing
  audit files ( Index Term Link )
  storage-space requirements for audit files ( Index Term Link )
 
 reducing audit files
  auditreduce command ( Index Term Link ) ( Index Term Link )
 
 remote logins
  authentication ( Index Term Link )
  authorization ( Index Term Link )
  security and ( Index Term Link )
 
 remote systems
  logging in
   authentication ( Index Term Link )
   authorization ( Index Term Link )
 
 removing
  principals with ktremove command ( Index Term Link )
  service principal from keytab file ( Index Term Link )
 
 renewable ticket, definition ( Index Term Link )
 
 replayed transactions ( Index Term Link )
 
 reports
  ASET ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 reports directory (ASET) ( Index Term Link )
 
 required control flag, PAM ( Index Term Link )
 
 requisite control flag, PAM ( Index Term Link )
 
 restoring, ASET ( Index Term Link )
 
 restricted shell (rsh) ( Index Term Link )
 
 restricting access for KDC servers ( Index Term Link )
 
 return token, format ( Index Term Link )
 
 rewoffl option
  mt command
   BSM device cleanup and ( Index Term Link )
 
 rexd service name, PAM ( Index Term Link )
 
 .rhosts file
  description ( Index Term Link )
  role in authentication ( Index Term Link )
 
 rhosts module, description ( Index Term Link )
 
 RhostsAuthentication keyword, sshd_config file ( Index Term Link )
 
 RhostsRSAAuthentication keyword, sshd_config file ( Index Term Link )
 
 right
  See rights profile
 
 rights profile
  See also individual profiles
  Audit Control ( Index Term Link )
  Audit Review ( Index Term Link )
  changing rights profiles from command line ( Index Term Link )
  creation example ( Index Term Link )
  database
   See prof_attr database and exec_attr database
  description ( Index Term Link ) ( Index Term Link )
  editing ( Index Term Link )
  major rights profiles description ( Index Term Link )
 
 Rights tool, description ( Index Term Link )
 
 rlogin command, authentication ( Index Term Link )
 
 rlogin service name, PAM ( Index Term Link )
 
 role
  adding custom roles ( Index Term Link )
  adding first role ( Index Term Link ) ( Index Term Link )
  adding roles ( Index Term Link )
  adding roles from command line ( Index Term Link )
  assuming ( Index Term Link )
  assumption example ( Index Term Link )
  changing roles from command line ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  making root a role ( Index Term Link )
  modifying roles ( Index Term Link )
  properties
   summarized ( Index Term Link )
  recommended role rights profiles ( Index Term Link )
  recommended roles ( Index Term Link )
  use in RBAC ( Index Term Link )
 
 role-based access control
  See RBAC
 
 Role Properties dialog box, description ( Index Term Link )
 
 roleadd command, description ( Index Term Link )
 
 roledel command, description ( Index Term Link )
 
 rolemod command, description ( Index Term Link )
 
 roles command, description ( Index Term Link )
 
 roles module, description ( Index Term Link )
 
 root
  adding principal to host's keytab ( Index Term Link )
  authentication for NFS ( Index Term Link )
  eliminating root in RBAC ( Index Term Link )
 
 root access
  displaying attempts on console ( Index Term Link )
  monitoring su command use ( Index Term Link ) ( Index Term Link )
  restricting ( Index Term Link ) ( Index Term Link )
 
 root login
  account
   description ( Index Term Link )
  restricting to console ( Index Term Link )
  tracking ( Index Term Link )
 
 root principal
  creating ( Index Term Link ) ( Index Term Link )
 
 root role, creating ( Index Term Link )
 
 RPCSEC_GSS API, SEAM and ( Index Term Link )
 
 RSAAuthentication keyword, sshd_config file ( Index Term Link )
 
 rsh command (restricted shell) ( Index Term Link )
 
 rsh service name, PAM ( Index Term Link )
 
 running the User tool, task description ( Index Term Link )
    
S
 
 -s option
  audit command ( Index Term Link )
  praudit command ( Index Term Link )
 
 -S option of st_clean script ( Index Term Link )
 
 sac service name, PAM ( Index Term Link )
 
 sample module, description ( Index Term Link )
 
 saving, failed login attempts ( Index Term Link )
 
 scheduling ASET execution (PERIODIC_SCHEDULE) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 scope, description ( Index Term Link )
 
 scp command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  using ( Index Term Link )
 
 script
  securing ( Index Term Link )
  testing for authorizations ( Index Term Link )
 
 SCSI devices, st_clean script ( Index Term Link )
 
 SEAM
  administering ( Index Term Link )
  Administration Tool ( Index Term Link )
  and Kerberos V5 ( Index Term Link ) ( Index Term Link )
  commands ( Index Term Link )
  components of ( Index Term Link )
  configuration decisions ( Index Term Link )
  configuring KDC servers ( Index Term Link )
  daemons ( Index Term Link )
  files ( Index Term Link )
  gaining access to server ( Index Term Link )
  online help ( Index Term Link )
  overview ( Index Term Link )
  overview of authentication ( Index Term Link )
  password management ( Index Term Link )
  planning for ( Index Term Link )
  reference ( Index Term Link )
  remote applications ( Index Term Link )
  terminology ( Index Term Link )
  using ( Index Term Link )
 
 SEAM Administration Tool ( Index Term Link )
  and limited administration privileges ( Index Term Link )
  and list privileges ( Index Term Link )
  and X Window system ( Index Term Link )
  command-line equivalents ( Index Term Link )
  context-sensitive help ( Index Term Link )
  creating a new principal ( Index Term Link )
  creating new policy ( Index Term Link ) ( Index Term Link )
  default values ( Index Term Link )
  deleting a principal ( Index Term Link )
  deleting policies ( Index Term Link )
  displaying sublist of principals ( Index Term Link )
  duplicating a principal ( Index Term Link )
  files modified by ( Index Term Link )
  Filter Pattern field ( Index Term Link )
  gkadmin command ( Index Term Link )
  gkadmin command vs. kadmin ( Index Term Link ) ( Index Term Link )
  .gkadmin file ( Index Term Link )
  help (print) ( Index Term Link )
  Help button ( Index Term Link )
  Help Contents ( Index Term Link )
  how affected by privileges ( Index Term Link )
  kadmin command vs. gkadmin ( Index Term Link ) ( Index Term Link )
  login window ( Index Term Link )
  modifying a principal ( Index Term Link )
  modifying policies ( Index Term Link )
  online help ( Index Term Link )
  panel descriptions ( Index Term Link )
  privileges ( Index Term Link )
  setting up principal defaults ( Index Term Link )
  starting ( Index Term Link )
  table of panels ( Index Term Link )
  viewing a principal's attributes ( Index Term Link )
  viewing list of policies ( Index Term Link )
  viewing list of principals ( Index Term Link )
  viewing policy attributes ( Index Term Link )
  vs. kadmin command ( Index Term Link )
 
 searching
  files with setuid permissions ( Index Term Link ) ( Index Term Link )
 
 secondary audit directory ( Index Term Link )
 
 secret key
  changing ( Index Term Link )
  database ( Index Term Link )
  decrypting ( Index Term Link )
  generating ( Index Term Link )
 
 secure access ( Index Term Link )
 
 secure NIS+, adding a user ( Index Term Link )
 
 Secure RPC ( Index Term Link )
  implementation of ( Index Term Link )
 
 Secure RPC authentication ( Index Term Link )
 
 Secure Shell
  administering ( Index Term Link )
  authentication ( Index Term Link )
  authentication steps ( Index Term Link )
  configuring ( Index Term Link )
  configuring clients ( Index Term Link )
  connecting outside firewall
   from command line ( Index Term Link )
   from configuration file ( Index Term Link )
  copying files ( Index Term Link )
  creating keys ( Index Term Link )
  description ( Index Term Link )
  forwarding mail ( Index Term Link )
  important files ( Index Term Link )
  local port forwarding ( Index Term Link ) ( Index Term Link )
  logging in ( Index Term Link )
  naming identity files ( Index Term Link )
  no UDP ( Index Term Link )
  port forwarding ( Index Term Link )
  protocol versions ( Index Term Link )
  public key ( Index Term Link )
  remote port forwarding ( Index Term Link )
  TCP, and ( Index Term Link )
  transferring files ( Index Term Link )
  typical session ( Index Term Link )
  user task map ( Index Term Link )
  using without password ( Index Term Link )
 
 securing
  against denial of service ( Index Term Link )
  against Trojan horse ( Index Term Link )
  hardware ( Index Term Link )
  PROM ( Index Term Link )
  system
   task map ( Index Term Link )
 
 securing legacy applications, description ( Index Term Link )
 
 securing scripts, description ( Index Term Link )
 
 security
  auditing and ( Index Term Link )
  DH authentication
   AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  KERB authentication ( Index Term Link )
  password encryption ( Index Term Link )
 
 security commands
  eeprom command ( Index Term Link ) ( Index Term Link )
 
 security mode, setting up environment with multiple ( Index Term Link )
 
 security service
  in SEAM ( Index Term Link )
  integrity ( Index Term Link )
  privacy ( Index Term Link )
 
 seq audit policy
  description ( Index Term Link )
  seq token and ( Index Term Link )
 
 seq policy, seq token and ( Index Term Link )
 
 seq token
  format ( Index Term Link )
  seq policy and ( Index Term Link )
 
 server authentication parameters, sshd_config file ( Index Term Link )
 
 ServerKeyBits keyword, sshd_config file ( Index Term Link )
 
 servers
  and realms ( Index Term Link )
  AUTH_DH client-server session ( Index Term Link ) ( Index Term Link )
  configuring for Secure Shell ( Index Term Link )
  definition in SEAM ( Index Term Link )
  gaining access with SEAM ( Index Term Link )
  obtaining credential for ( Index Term Link )
 
 service
  definition in SEAM ( Index Term Link )
  disabling on a host ( Index Term Link )
  obtaining access for specific service ( Index Term Link )
 
 service key ( Index Term Link )
  definition in SEAM ( Index Term Link )
 
 service names, PAM ( Index Term Link )
 
 service principal
  adding to keytab file ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  planning for names ( Index Term Link )
  removing from keytab file ( Index Term Link )
 
 session ID ( Index Term Link )
 
 session key
  definition in SEAM ( Index Term Link )
  SEAM authentication and ( Index Term Link )
 
 setenv command
  ASET security level specification ( Index Term Link )
  ASET working directory specification ( Index Term Link )
 
 setfacl command
  adding ACL entries ( Index Term Link )
  deleting ACL entries ( Index Term Link )
  description ( Index Term Link )
  examples ( Index Term Link )
  modifying ACL entries ( Index Term Link )
  setting ACL entries ( Index Term Link )
  syntax ( Index Term Link )
 
 setgid permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link ) ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 setting IDs on commands
  description ( Index Term Link )
  task description ( Index Term Link )
 
 setting up principal defaults ( Index Term Link )
 
 setuid permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  finding files with permissions set ( Index Term Link ) ( Index Term Link )
  security risks ( Index Term Link ) ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 sftp command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  using ( Index Term Link )
 
 sh command ( Index Term Link )
  privileged version ( Index Term Link )
 
 share command, restricting root access ( Index Term Link )
 
 sharing files (network security) ( Index Term Link )
 
 shell, privileged versions ( Index Term Link )
 
 shell commands, /etc/d_passwd file entries ( Index Term Link )
 
 shell programs
  ASET security level specification ( Index Term Link )
  ASET working directory specification ( Index Term Link )
 
 short praudit output format ( Index Term Link )
 
 shosts.equiv file, description ( Index Term Link )
 
 .shosts file, description ( Index Term Link )
 
 signal received during auditing shutdown ( Index Term Link )
 
 single-sign-on system, SEAM and ( Index Term Link )
 
 size
  reducing audit files ( Index Term Link )
   auditreduce command ( Index Term Link )
   auditreduce command ( Index Term Link )
  reducing storage-space requirements for audit files ( Index Term Link )
 
 slave_datatrans file ( Index Term Link )
  description ( Index Term Link )
 
 slave KDCs
  adding names to cron job ( Index Term Link )
  configuring ( Index Term Link )
  definition ( Index Term Link )
  master KDC and ( Index Term Link )
  or master ( Index Term Link )
  planning for ( Index Term Link )
  swapping with master KDC ( Index Term Link )
 
 smartcard documentation ( Index Term Link )
 
 smartcard module, description ( Index Term Link )
 
 smattrpop command, description ( Index Term Link )
 
 SMC
  See Solaris Management Console
 
 smexec command, description ( Index Term Link )
 
 smmultiuser command, description ( Index Term Link )
 
 smprofile command, description ( Index Term Link )
 
 smrole command, description ( Index Term Link )
 
 smuser command, description ( Index Term Link )
 
 socket token ( Index Term Link )
 
 soft limit
  audit_warn condition ( Index Term Link )
  minfree: line description ( Index Term Link )
 
 soft string with audit_warn script ( Index Term Link )
 
 Solaris Management Console
  role assumption ( Index Term Link )
  running the user tools ( Index Term Link )
 
 sr_clean script, description ( Index Term Link )
 
 ss audit flag ( Index Term Link )
 
 ssh-add command
  description ( Index Term Link )
  example ( Index Term Link ) ( Index Term Link )
 
 ssh-agent command
  description ( Index Term Link )
  from command line ( Index Term Link )
  in scripts ( Index Term Link )
 
 ssh command
  authentication steps ( Index Term Link )
  description ( Index Term Link )
  -L option ( Index Term Link )
  -o option ( Index Term Link )
  permitting access ( Index Term Link )
  port forwarding ( Index Term Link )
  -R option ( Index Term Link )
  using ( Index Term Link )
 
 ssh_config file
  client authentication parameters ( Index Term Link )
  configuring Secure Shell ( Index Term Link )
  connection parameters ( Index Term Link )
  host-specific parameters ( Index Term Link )
  keywords
   See specific keyword
  known host file parameters ( Index Term Link )
 
 ssh_host_key file, description ( Index Term Link )
 
 ssh_host_key.pub file, description ( Index Term Link )
 
 ssh-keygen command
  description ( Index Term Link )
  using ( Index Term Link )
 
 ssh_known_hosts file
  configuring Secure Shell ( Index Term Link )
  description ( Index Term Link )
 
 ssh service name, PAM ( Index Term Link )
 
 sshd command
  configuring for forwarding ( Index Term Link )
  description ( Index Term Link )
  session controls ( Index Term Link )
 
 sshd_config file
  description ( Index Term Link )
  forwarding parameters ( Index Term Link )
  ports parameters ( Index Term Link )
  server connection parameters ( Index Term Link )
  session control parameters ( Index Term Link )
 
 sshd.pid file, description ( Index Term Link )
 
 sshrc file, description ( Index Term Link )
 
 st_clean script, description ( Index Term Link )
 
 st_clean script for tape drives ( Index Term Link )
 
 standard cleanup ( Index Term Link )
 
 starting
  ASET
   initiating sessions from shell ( Index Term Link )
   running interactively ( Index Term Link )
  KDC daemon ( Index Term Link )
 
 stash file
  creating ( Index Term Link )
  definition ( Index Term Link )
 
 sticky bit permissions
  absolute mode ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
  symbolic mode ( Index Term Link )
 
 stopping, dial-up logins temporarily ( Index Term Link )
 
 storage, audit records and ( Index Term Link )
 
 storage costs, auditing and ( Index Term Link )
 
 storage overflow prevention, audit trail ( Index Term Link )
 
 StrictHostKeyChecking keyword, ssh_config file ( Index Term Link )
 
 StrictModes keyword, sshd_config file ( Index Term Link )
 
 su command
  displaying use on console ( Index Term Link )
  in role assumption ( Index Term Link )
  monitoring use ( Index Term Link )
 
 su file, monitoring su command ( Index Term Link )
 
 su service name, PAM ( Index Term Link )
 
 subject token, format ( Index Term Link )
 
 Subsystem keyword, sshd_config file ( Index Term Link )
 
 success
  audit flag prefix ( Index Term Link ) ( Index Term Link )
  turning off audit flags for ( Index Term Link )
 
 sufficient control flag, PAM ( Index Term Link )
 
 sulog file ( Index Term Link )
 
 superuser
  eliminating superuser in RBAC ( Index Term Link )
  model versus RBAC ( Index Term Link )
 
 suser, security policy ( Index Term Link )
 
 swapping master and slave KDCs ( Index Term Link )
 
 symbolic links
  file permissions ( Index Term Link )
  latest directory (ASET) ( Index Term Link )
 
 symbolic mode
  changing file permissions ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
 
 synchronizing clocks ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 sysconf.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 SyslogFacility keyword, sshd_config file ( Index Term Link )
 
 System Administrator
  rights profile ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  role ( Index Term Link )
 
 system calls
  arg token ( Index Term Link )
  auditsvc() fails ( Index Term Link )
  close ( Index Term Link )
  event numbers ( Index Term Link )
  exec_args token ( Index Term Link )
  exec_env token ( Index Term Link )
  ioctl ( Index Term Link ) ( Index Term Link )
  return token ( Index Term Link )
 
 system security
  dial-up login restrictions ( Index Term Link )
  dial-up passwords
   disabling dial-up logins temporarily ( Index Term Link )
   /etc/d_passwd file ( Index Term Link )
  displaying
   user's login status ( Index Term Link ) ( Index Term Link )
   users with no passwords ( Index Term Link )
  firewall systems ( Index Term Link )
  hardware protection ( Index Term Link ) ( Index Term Link )
  introduction ( Index Term Link )
  login access restrictions ( Index Term Link ) ( Index Term Link )
  machine access ( Index Term Link )
  overview ( Index Term Link )
  password encryption ( Index Term Link )
  passwords ( Index Term Link )
  restricted shell ( Index Term Link ) ( Index Term Link )
  restricting root login to console ( Index Term Link )
  role-based access control ( Index Term Link )
  root access restrictions ( Index Term Link ) ( Index Term Link )
  saving failed login attempts ( Index Term Link )
  special logins ( Index Term Link )
  su command monitoring ( Index Term Link ) ( Index Term Link )
 
 system state audit class ( Index Term Link )
 
 System V IPC
  ipc audit class ( Index Term Link )
  ipc_perm token ( Index Term Link )
  ipc token ( Index Term Link ) ( Index Term Link )
 
 system-wide administration audit class ( Index Term Link )
 
 systems
  security
   ACL ( Index Term Link )
    
T
 
 tables, gsscred ( Index Term Link )
 
 tail command, auditing and ( Index Term Link )
 
 tape drives
  device-clean scripts ( Index Term Link )
  st_clean script ( Index Term Link )
 
 task map
  administering policies ( Index Term Link )
  administering principals ( Index Term Link )
  Secure Shell ( Index Term Link )
 
 TASKS variable (ASET)
  configuring ASET ( Index Term Link ) ( Index Term Link )
 
 taskstat command (ASET) ( Index Term Link ) ( Index Term Link )
 
 TCP, Secure Shell, and ( Index Term Link )
 
 TCP address ( Index Term Link )
 
 TCP/IP
  specifying in sshd_config ( Index Term Link )
  use in Secure Shell ( Index Term Link )
 
 telnet service name, PAM ( Index Term Link )
 
 temporary file cannot be used ( Index Term Link )
 
 terminal ID ( Index Term Link )
 
 terminating, signal received during auditing shutdown ( Index Term Link )
 
 terminology
  authentication-specific ( Index Term Link )
  Kerberos-specific ( Index Term Link )
  SEAM ( Index Term Link )
 
 text token ( Index Term Link )
 
 TGS, getting credential for ( Index Term Link )
 
 TGT, in SEAM ( Index Term Link )
 
 ticket file
  See credential cache
 
 ticket-granting service
  See TGS
 
 Ticket-Granting Ticket
  See TGT
 
 tickets
  creating ( Index Term Link )
  creating with kinit ( Index Term Link )
  definition ( Index Term Link )
  description ( Index Term Link )
  destroying ( Index Term Link )
  file
   See credential cache
  forwardable ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  initial ( Index Term Link )
  invalid ( Index Term Link )
  klist command ( Index Term Link )
  lifetime ( Index Term Link )
  maximum renewable lifetime ( Index Term Link )
  obtaining ( Index Term Link )
  or credentials ( Index Term Link )
  postdatable ( Index Term Link )
  postdated ( Index Term Link )
  proxiable ( Index Term Link )
  proxy ( Index Term Link )
  renewable ( Index Term Link )
  types of ( Index Term Link )
  viewing ( Index Term Link )
  warning about expiration ( Index Term Link )
 
 time stamps in audit files ( Index Term Link )
 
 /tmp/krb5cc_uid file, description ( Index Term Link )
 
 /tmp/ovsec_adm.xxxxx file, description ( Index Term Link )
 
 tmpfile string, audit_warn script ( Index Term Link )
 
 tmpfs file system ( Index Term Link )
 
 trail audit policy
  description ( Index Term Link )
  trailer token and ( Index Term Link )
 
 trailer token
  description ( Index Term Link )
  format ( Index Term Link )
  order in audit record ( Index Term Link )
  praudit display ( Index Term Link )
 
 transferring files, using Secure Shell ( Index Term Link )
 
 transparency, definition in SEAM ( Index Term Link )
 
 Trojan horse ( Index Term Link )
 
 trusted host ( Index Term Link )
 
 try_first_pass ( Index Term Link )
 
 ttymon service name, PAM ( Index Term Link )
 
 tune files (ASET)
  description ( Index Term Link ) ( Index Term Link )
  example files ( Index Term Link )
  format ( Index Term Link )
  modifying ( Index Term Link ) ( Index Term Link )
  rules ( Index Term Link )
 
 tune.rpt file
  description ( Index Term Link ) ( Index Term Link )
 
 types of tickets ( Index Term Link )
    
U
 
 -U option
  allocate command ( Index Term Link )
  list_devices command ( Index Term Link )
 
 ua audit flag ( Index Term Link )
 
 UDP, Secure Shell, and ( Index Term Link )
 
 UDP address ( Index Term Link )
 
 uid_aliases file
  description ( Index Term Link )
  specifying ( Index Term Link )
 
 UID_ALIASES variable (ASET)
  aliases file specification ( Index Term Link ) ( Index Term Link )
  description ( Index Term Link )
 
 umask setting ( Index Term Link )
 
 unix_account module, description ( Index Term Link )
 
 unix_auth module, description ( Index Term Link )
 
 unix module, description ( Index Term Link )
 
 unix_session module, description ( Index Term Link )
 
 URL for online help ( Index Term Link )
 
 UseLogin keyword, sshd_config file ( Index Term Link )
 
 user
  adding first user ( Index Term Link )
  assigning RBAC defaults ( Index Term Link )
  changing user properties from command line ( Index Term Link )
  database
   See user_attr database
  modifying properties ( Index Term Link )
 
 user accounts
  ASET check ( Index Term Link )
  displaying login status ( Index Term Link ) ( Index Term Link )
 
 User Accounts tool, description ( Index Term Link )
 
 user ACL entries
  default entries for directories ( Index Term Link )
  description ( Index Term Link )
  setting ( Index Term Link )
 
 user administration audit class ( Index Term Link )
 
 user_attr database
  description ( Index Term Link ) ( Index Term Link )
  RBAC relationships ( Index Term Link )
 
 user audit fields ( Index Term Link ) ( Index Term Link )
 
 user classes of files ( Index Term Link )
 
 user ID
  audit ID and ( Index Term Link )
  in NFS services ( Index Term Link )
 
 user ID (audit ID) ( Index Term Link )
 
 User keyword, ssh_config file ( Index Term Link )
 
 user-level events, auditing and ( Index Term Link )
 
 user principal, description ( Index Term Link )
 
 useradd command, description ( Index Term Link )
 
 userdel command, description ( Index Term Link )
 
 UserKnownHostsFile keyword, ssh_config file ( Index Term Link )
 
 usermod command, description ( Index Term Link )
 
 UseRsh, ssh_config file ( Index Term Link )
 
 using privileged applications, task description ( Index Term Link )
 
 /usr/aset/asetenv file ( Index Term Link )
  modifying ( Index Term Link )
  running ASET periodically ( Index Term Link )
 
 /usr/aset directory ( Index Term Link )
 
 /usr/aset/masters/tune files ( Index Term Link )
  example files ( Index Term Link )
  format ( Index Term Link )
  modifying ( Index Term Link ) ( Index Term Link )
  rules ( Index Term Link )
 
 /usr/aset/masters/uid_aliases file ( Index Term Link )
 
 /usr/aset/reports directory
  structure ( Index Term Link ) ( Index Term Link )
 
 /usr/aset/reports/latest directory ( Index Term Link )
 
 /usr/lib/krb5/kadmind daemon, SEAM and ( Index Term Link )
 
 /usr/lib/krb5/kprop command, description ( Index Term Link )
 
 /usr/lib/krb5/kpropd daemon, SEAM and ( Index Term Link )
 
 /usr/lib/krb5/krb5kdc daemon, SEAM and ( Index Term Link )
 
 /usr/sbin/gkadmin command, description ( Index Term Link )
 
 /usr/sbin/kadmin command, description ( Index Term Link )
 
 /usr/sbin/kadmin.local command, description ( Index Term Link )
 
 /usr/sbin/kdb5_util command, description ( Index Term Link )
 
 /usr/share/lib/xml directory ( Index Term Link )
 
 usrgrp.rpt file
  description ( Index Term Link ) ( Index Term Link )
  example ( Index Term Link )
 
 uucico command, login program ( Index Term Link )
 
 uucp service name, PAM ( Index Term Link )
    
V
 
 v1 protocol, Secure Shell ( Index Term Link )
 
 v2 protocol, Secure Shell ( Index Term Link )
 
 /var/adm/loginlog file, saving failed login attempts ( Index Term Link )
 
 /var/krb5/.k5.REALM file, description ( Index Term Link )
 
 /var/krb5/kadmin.log file, description ( Index Term Link )
 
 /var/krb5/kdc.log file, description ( Index Term Link )
 
 /var/krb5/principal.db file, description ( Index Term Link )
 
 /var/krb5/principal.kadm5 file, description ( Index Term Link )
 
 /var/krb5/principal.kadm5.lock file, description ( Index Term Link )
 
 /var/krb5/principal.ok file, description ( Index Term Link )
 
 /var/krb5/slave_datatrans file, description ( Index Term Link )
 
 /var/run/sshd.pid file, description ( Index Term Link )
 
 variables
  ASET environment variables
   ASETDIR ( Index Term Link )
   ASETSECLEVEL ( Index Term Link )
   CKLISTPATH_level ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   PERIODIC_SCHEDULE ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   summary table ( Index Term Link )
   TASKS ( Index Term Link ) ( Index Term Link )
   UID_ALIASES ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   YPCHECK ( Index Term Link ) ( Index Term Link )
 
 verifiers
  description ( Index Term Link )
  returned to client ( Index Term Link )
  window ( Index Term Link )
 
 viewing
  keylist buffer with list command ( Index Term Link ) ( Index Term Link )
  list of policies ( Index Term Link )
  list of principals ( Index Term Link )
  policy attributes ( Index Term Link )
  principal's attributes ( Index Term Link )
  tickets ( Index Term Link )
 
 viruses
  denial of service attack ( Index Term Link )
  Trojan horse ( Index Term Link )
 
 vnode token, format ( Index Term Link )
    
W
 
 warn.conf file, description ( Index Term Link )
 
 warning about ticket expiration ( Index Term Link )
 
 wildcard characters, in ASET tune files ( Index Term Link )
 
 window verifier ( Index Term Link )
 
 write permissions, symbolic mode ( Index Term Link )
 
 writing new device-clean scripts ( Index Term Link )
    
X
 
 X11, use in Secure Shell ( Index Term Link )
 
 X11 forwarding, configuring ssh_config ( Index Term Link )
 
 -x option, praudit command ( Index Term Link )
 
 X Window system, and SEAM Administration Tool ( Index Term Link )
 
 xauth command, X11 forwarding ( Index Term Link )
 
 XAuthLocation keyword
  Secure Shell port forwarding ( Index Term Link )
  sshd_config file ( Index Term Link )
 
 Xylogics tape drive clean script ( Index Term Link )
    
Y
 
 YPCHECK variable (ASET)
  specifying system configuration file tables ( Index Term Link ) ( Index Term Link )