Solaris
2013年3月
主机操作系统加固规范 目 录
1
账号管理、认证授权 .................................................................................................. 1 1.1 账号 ...................................................................................................................... 1 1.1.1 SHG-Solaris-01-01-01 ...................................................................................... 1 1.1.2 SHG-Solaris-01-01-02 ...................................................................................... 2 1.1.3 SHG-Solaris-01-01-03 ...................................................................................... 3 1.1.4 SHG-Solaris-01-01-04 ...................................................................................... 4 1.1.5 SHG-Solaris-01-01-05 ...................................................................................... 5 1.2 口令 ...................................................................................................................... 6 1.2.1 SHG-Solaris-01-02-01 ...................................................................................... 6 1.2.2 SHG-Solaris-01-02-02 ...................................................................................... 7 1.2.3 SHG-Solaris-01-02-03 ...................................................................................... 8 1.2.4 SHG-Solaris-01-02-04 ...................................................................................... 9 1.2.5 SHG-Solaris-01-02-05 .................................................................................... 10 1.3 授权 .................................................................................................................... 12 1.3.1 SHG-Solaris-01-03-01 .................................................................................... 12 1.3.2 SHG-Solaris-01-03-02 .................................................................................... 13 1.3.3 SHG-Solaris-01-03-03 .................................................................................... 15 1.3.4 SHG-Solaris-01-03-04 .................................................................................... 17 1.3.5 SHG-Solaris-01-03-05 .................................................................................... 18 1.3.6 SHG-Solaris-01-03-06 .................................................................................... 18 1.3.7 SHG-Solaris-01-03-07 .................................................................................... 19 2
日志配置 .................................................................................................................... 20 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 3
SHG-Solaris-02-01-01 .................................................................................... 20 SHG-Solaris-02-01-02 .................................................................................... 21 SHG-Solaris-02-01-03 .................................................................................... 22 SHG-Solaris-02-01-04 .................................................................................... 23 SHG-Solaris-02-01-05 .................................................................................... 24 SHG-Solaris-02-01-06 .................................................................................... 25 SHG-Solaris-02-01-07 .................................................................................... 26
通信协议 .................................................................................................................... 27 3.1 IP协议安全 ....................................................................................................... 27
3.1.1 SHG-Solaris-03-01-01 .................................................................................... 27 3.1.2 SHG-Solaris-03-01-02 .................................................................................... 28 3.1.3 SHG-Solaris-03-01-03 .................................................................................... 29 3.1.4 SHG-Solaris-03-01-04 .................................................................................... 30 3.2 路由协议安全 .................................................................................................... 31 3.2.1 SHG-Solaris-03-02-01 .................................................................................... 31 3.2.2 SHG-Solaris-03-02-02 .................................................................................... 32
4 设备其他安全要求 .................................................................................................... 34
4.1 补丁管理 ............................................................................................................ 34 4.1.1 SHG-Solaris-04-01-01 .................................................................................... 34 4.1.2 SHG-Solaris-04-01-02 .................................................................................... 35 4.2 服务进程和启动 ................................................................................................ 37 4.2.1 SHG-Solaris-04-02-01 .................................................................................... 37 4.2.2 SHG-Solaris-04-02-02 .................................................................................... 39 4.2.3 SHG-Solaris-04-02-03 .................................................................................... 41 4.2.4 SHG-Solaris-04-02-04 .................................................................................... 42 4.2.5 SHG-Solaris-04-02-05 .................................................................................... 42 4.2.6 SHG-Solaris-04-02-06 .................................................................................... 43 4.2.7 SHG-Solaris-04-02-07 .................................................................................... 44 4.3 BANNER与屏幕保护 .......................................................................................... 45 4.3.1 SHG-Solaris-04-03-01 .................................................................................... 45 4.3.2 SHG-Solaris-04-03-02 .................................................................................... 46 4.4 内核调整 ............................................................................................................ 47 4.4.1 SHG-Solaris-04-04-01 .................................................................................... 47 4.4.2 SHG-Solaris-04-04-02 .................................................................................... 48 5
附录:SOLARIS可被利用的漏洞(截止2009-3-8) .......................................... 49
本文档是Solaris 操作系统的对于Solaris操作系统设备账号认证、日志、协议、补丁升级、文件系统管理等方面的43项安全配置要求,对系统的安全配置审计、加固操作起到指导性作用。
1 账号管理、认证授权
1.1 账号
1.1.1 SHG-Solaris-01-01-01
编号 名称 实施目的 问题影响 系统当前状态 SHG-Solaris-01-01-01 为不同的管理员分配不同的账号 根据不同类型用途设置不同的帐户账号,提高系统安全。 账号混淆,权限不明确,存在用户越权使用的可能。 cat /etc/passwd 记录当前用户列表 1、参考配置操作 为用户创建账号: #useradd username #创建账号 #passwd username #设置密码 实施步骤 修改权限: #chmod 750 directory #其中755为设置的权限,可根据实际情况设置相应的权限,directory是要更改权限的目录) 使用该命令为不同的用户分配不同的账号,设置不同的口令及权限信息等。
相关推荐: