- Introduction
- Installation and Configuration
- System Controllers
- Platform and Domain Configuration
- Memory and I/O Configuration
- Domain Administration
- Platform Security
- Error Analysis and Diagnosis
- Dynamic Reconfiguration
- Hot-Swappable PCI Adaptors
- About the Author
- Acknowledgments
- Related Resources
- Ordering Sun Documents
- Accessing Sun Documentation Online
Platform Security
This section provides best practices for securing the system, components, and OS.
Sun Fire 15K Server Domain Security
To properly secure a Sun Fire 15K server domain, you must understand the implications of the software modifications. Refer to the Sun BluePrintsTM OnLine article titled "Securing Sun Fire 12K and 15K Domains" for guidelines.
TIP
Follow the guidelines in the latest version of the referenced Sun BluePrints OnLine article.
System Controller Security
Securing the SC is critical in order to maintain operational control and environmental monitoring of Sun Fire server systems. Domain management is not possible without at least one SC operating as main.
Preserving SC security is paramount in mission critical environments. Best practice dictates that the system administrator maintain the system at the latest software and patch levels. Upgrade to SMS version 1.4 or greater for the latest SMS security features. Refer to the Sun Online BluePrints OnLine article titled "Securing the Sun FireTM 12K and 15K System Controller" for detailed information on this subject.
TIP
Follow the guidelines in the latest version of the referenced Sun BluePrints OnLine article.
Domains and OS Minimization
Minimizing Sun systems is the process of removing the packages from the system that are not needed to fulfill a customer's business requirements.
Traditionally, systems are shipped with all functionality enabled but they are likely to be dedicated to a particular use. This means they have services and applications installed by default which are not used.
These default services and applications can become the source for security compromises. It is the accepted view of the security community that it is easier to administer and secure systems that have only key applications and services used installed.
For more information about minimizing domains and the OS, refer to the following Sun BluePrint OnLine articles:
"Part I: Minimizing Domains for the Sun Fire V1280, 6800, 12K, and 15K Systems"
"Part II: Minimizing Domains for the Sun Fire V1280, 6800, 12K, and 15K Systems"
"Minimizing the Solaris Operating Environment for Security: Updated for Solaris 9 Operating Environment"
Sun Fire 15K Server Network Topology Security
The overall security of the Sun Fire 15K server can be improved by understanding and minimizing all required system network connections and network traffic between the SC and the domains. Refer to the Sun BluePrints OnLine article titled "Solaris Operating Environment Network Settings for Security: Updated for the Solaris 9 Operating Environment."
TIP
Follow the guidelines in the latest version of the referenced Sun BluePrints OnLine article.
OpenSSH Security
OpenSSH is a tool developed to counter threats on network security such as password theft and session hijacking. OpenSSH provides secure replacement for network commands such as rlogin, rsh, rcp, telnet, and ftp. For more information, refer to the Sun BluePrints OnLine article "Building and Deploying OpenSSH in the Solaris Operating Environment."
TIP
Follow the guidelines in the latest version of the referenced Sun BluePrints OnLine article.