| Solaris |
|
|
Copyright 1991-2007, Sun Microsystems, Inc
All security relevant operations must be auditable
| Category | Software.Solaris.All |
|---|---|
| Owner | SAC |
| Author | Gary Winiger (gww |
| Changes | gww |
| Authority | PSARC |
| Policy Version | 1.0-1.3 |
| Status | Approved 2007/01/31 |
| Effective | Solaris 2.3 All security relevant operations must be auditable |
Solaris Trusted Extensions (TX) (and Trusted Solaris before it) is additionally evaluated against the Labeled Security Protection Profile (LSPP).
The majority of the audit for system calls is table driven. New system calls should fit in easily, but do require review by the Solaris Audit Project team to ensure they meet the Evaluation Criteria.
If the project does administration through smf(5) properties, and the project meets the SMF policy of individual authorizations and delivery of those authorizations in Rights Profiles, administrative audit is generally handled by the SMF framework.
If the project does administration through CLI where the entire operation is specified on the command line and the project delivers Rights Profiles, administrative audit is generally handled by the RBAC framework.
If the project does anything security relevant (e.g., authentication, authorization or privilege enforcement, administration) that is not covered by one of the preceding areas, audit must be provided for with the C interfaces described in PSARC/2000/517 and PSARC/2003/397 or their Java equivalents described in LSARC/2001/409.
Note, this possible exemption does not include the administration/configuration of those programs on Solaris.
Case|=Type|=Name|=Comment
| /PSARC/2000/517 | OnePager | Thread-safe audit API | Thread-safe audit API |
| /LSARC/2001/409 | FastTrack | Java Audit Session for Viper and WBEM | Java Audit Session for Viper and WBEM |
| /PSARC/2003/397 | FastTrack | Contracted audit interfaces for open source | Contracted audit interfaces for open source |
Document|=Description
| bsmrecord.1m | display Solaris audit record formats |
| audit.log.4 | audit trail file |
| audit_class.4 | audit class definitions |
| audit_control.4 | control information for system audit daemon |
| audit_event.4 | audit event definition and class mapping |
| audit_user.4 | per-user auditing data file |
Terms of Use
|
Privacy
|
Trademarks
|
Copyright Policy
|
Site Guidelines
|
Site Map
|
Help
Your use of this web site or any of its content or software indicates your agreement to be bound by these Terms of Use.
© 2012, Oracle Corporation and/or its affiliates.