Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: What to remove from a Solaris Kernel
From: Matthew Keenan <matt @ firstpac . com . au>
Date: Fri, 26 Jul 1996 08:21:38 +1000 (EST)
To: darkwing @ prolog . net (PTD-001299)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . SOL . 3 . 91 . 960725162049 . 6364A-100000 @ ns1 . ptd . net> from "PTD-001299" at Jul 25, 96 04:22:09 pm

PTD-001299 wrote this...

> On Thu, 25 Jul 1996, Terry Glanfield wrote:

>> I'm starting to pair down the kernel on a Solaris 2.5 box that will
>> be used as a firewall.  I've remove a number of modules but, before
>> getting carried away, I thought I'd ask around to see what other
>> people have done.  What modules is is safe/recommend to remove?

[snip]

> I thought the SOlaris 2.5 kernel was dynamically loading (and
> unloading) so there was no need to do this.  Perhaps a few settings
> in /etc/system but that is it.  What exeactly did you remove?

the Solaris 2.x kernels are infact dynamically loading kernels, but it
will only load "drivers" that have been "registered" (via add_drv). so
by removing ones that ship with the OS (via rem_drv) you can restrict
what services the kernel has access to (provided someone doesnt upload
another driver and install it). easy way to disable sun's default
rlogin is to remove the kernel driver for it :) (but this doesnt stop
someone from compiling up a BSDish one and inserting that on your
system).

			Matt
-- 
Matthew Keenan    Network Administrator    First Pacific Stockbrokers
			  Sydney,  Australia


References:
Indexed By Date Previous: Re: Solaris Doc
From: "Todd Glassey, Consultant" <tglassey @ earthlink . net>
Next: Summary: What to remove from a Solaris Kernel
From: Terry Glanfield <terry @ ppsl . demon . co . uk>
Indexed By Thread Previous: Re: What to remove from a Solaris Kernel
From: PTD-001299 <darkwing @ prolog . net>
Next: Re: What to remove from a Solaris Kernel
From: Craig Bishop <csb @ connect . com . au>

Google
 
Search Internet Search www.greatcircle.com