home *** CD-ROM | disk | FTP | other *** search
-
-
-
- SSSSEEEECCCCUUUURRRREEEESSSSYYYYSSSSTTTTEEEEMMMM((((1111MMMM)))) SSSSEEEECCCCUUUURRRREEEESSSSYYYYSSSSTTTTEEEEMMMM((((1111MMMM))))
-
-
-
- NNNNAAAAMMMMEEEE
- securesystem - improve system security
-
- SSSSYYYYNNNNOOOOPPPPSSSSIIIISSSS
- ////uuuussssrrrr////ssssyyyyssssaaaaddddmmmm////pppprrrriiiivvvvbbbbiiiinnnn////sssseeeeccccuuuurrrreeeessssyyyysssstttteeeemmmm [ ----llll <_l_o_g_i_n_N_a_m_e> [ ----jjjj _j_a_v_a | _j_a_v_a_s_c_r_i_p_t
- | _b_o_t_h | _n_o_n_e ][ ----PPPP | ----LLLL | ----DDDD ] ] [ ----nnnn _y_e_s ] [ ----kkkk _y_e_s|_n_o ] [ ----ssss _y_e_s|_n_o ]
- [ ----cccc _y_e_s|_n_o ] [ ----oooo _y_e_s|_n_o ] [ ----xxxx _y_e_s|_n_o ] [ ----ffff _y_e_s|_n_o ] [ ----uuuu _y_e_s ] [ ----wwww
- _y_e_s|_n_o ]
-
- DDDDEEEESSSSCCCCRRRRIIIIPPPPTTTTIIIIOOOONNNN
- This command tries to improve the security of the system by modifying
- parameters that affect the security of the system. They include disable
- or enable Java and/or JavScript for user accounts, add password, lock or
- delete user accounts, remove NIS accounts, lock out an account if it has
- no password, use shadow password, turn off graphical login (_c_l_o_g_i_n(_1)),
- disable the use of privilege accounts on system adminitration tools (see
- _P_r_i_v_i_l_e_g_e_M_a_n_a_g_e_r(_1_M)), disable the display of windows of remote systems
- on the local system, turn off IP forwarding in the kernel, change _U_M_A_S_K
- to be readable and writable by owner only when a new file is created, and
- turn off outbox web server.
-
- Specifying the _y_e_s option improves the security of the system. The _n_o
- option reverse the process. There are a few things that this command
- cannot reverse, that is, it does not remove user account password,
- unlock, or add user accounts including the ones are deleted by the remove
- NIS account option. See the _U_s_e_r_M_a_n_a_g_e_r(_1_M) if you want to perform these
- functions. Another option that cannot be reversed is _U_M_A_S_K, it cannot be
- reset.
-
- OOOOPPPPTTTTIIIIOOOONNNNSSSS
- ----llll _l_o_g_i_n Specifies the name of the account to be modified. It is needed
- for the following options that deal with user accounts.
-
- ----JJJJ _j_a_v_a|_j_a_v_a_s_c_r_i_p_t|_b_o_t_h|_n_o_n_e
- _J_a_v_a is to disable Java and enable JavaScript; _j_a_v_a_s_c_r_i_p_t is to
- disable JavaScript and enable Java; _b_o_t_h is disable Java and
- Javascript; _n_o_n_e is to enable Java and Javascript.
-
- ----PPPP Add a password to the specified account. The command will
- prompt for the password on stdin.
-
- ----LLLL||||----DDDD Lock or delete the specified account.
-
- ----kkkk _y_e_s|_n_o _Y_e_s means lock out account if it has no password and _n_o means
- accounts without password can still login. The _M_A_N_D_P_A_S_S option
- in /_e_t_c/_d_e_f_a_u_l_t/_l_o_g_i_n is updated.
-
- ----ssss _y_e_s|_n_o _Y_e_s means create shadow password and _n_o means if /_e_t_c/_s_h_o_w_d_o_w
- file exists, merge it back into /_e_t_c/_p_a_s_s_w_d.
-
-
-
-
-
-
- PPPPaaaaggggeeee 1111
-
-
-
-
-
-
- SSSSEEEECCCCUUUURRRREEEESSSSYYYYSSSSTTTTEEEEMMMM((((1111MMMM)))) SSSSEEEECCCCUUUURRRREEEESSSSYYYYSSSSTTTTEEEEMMMM((((1111MMMM))))
-
-
-
- ----nnnn _y_e_s _Y_e_s means remove all NIS accounts from /_e_t_c/_p_a_s_s_w_d and the
- process can not be reversed by this command.
-
- ----cccc _y_e_s|_n_o _Y_e_s means do not display the graphical login application and _n_o
- means use it.
-
- ----oooo _y_e_s|_n_o _Y_e_s means only root has the privilege to run system
- administration task and _n_o means assigned user accounts can run
- the tasks.
-
- ----xxxx _y_e_s|_n_o _Y_e_s means turn _x_h_o_s_t(_1) off and _n_o means turn it on.
-
- ----ffff _y_e_s|_n_o _Y_e_s means turn off ipforwarding in the kernel and _n_o means turn
- it on.
-
- ----uuuu _y_e_s _Y_e_s means change _U_M_A_S_K in /_e_t_c/_d_e_f_a_u_l_t/_l_o_g_i_n to _0_2_2.
-
- ----wwww _y_e_s|_n_o _Y_e_s means disable Outbox Web Server and _n_o means enabling it.
-
- FFFFIIIILLLLEEEESSSS
- /etc/passwd User account password file
- /etc/shadow User account shadow password file
- /etc/default/login
- Login parameters
- /usr/lib/desktop/xhoston
- Remote display flag
- /etc/config/ns_fasttrack
- Outbox web server control flag
- /etc/config/visuallogin
- Graphical login window control flag
- SSSSEEEEEEEE AAAALLLLSSSSOOOO
- sysmgr(1M), UserManager(1M), PrivilegeManager(1M), clogin(1), xhost(1),
- runpriv(1M).
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- PPPPaaaaggggeeee 2222
-
-
-
-