User Tools

Site Tools


tips:irix:security

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
tips:irix:security [2026/10/02 09:36] – created mattieutips:irix:security [2026/10/02 14:27] (current) – mattieu
Line 24: Line 24:
         noiconlogin          off         noiconlogin          off
         nostickytmp          off         nostickytmp          off
 +        pmcd                 off
         pmie                 off         pmie                 off
         proclaim_relayagent  off         proclaim_relayagent  off
Line 33: Line 34:
         routed               off         routed               off
         rsvpd                off         rsvpd                off
 +        rtmond               off
         rwhod                off         rwhod                off
         sar                  off         sar                  off
Line 65: Line 67:
         nsd                  on         nsd                  on
         ntp                  on         ntp                  on
-        pmcd                 on 
         privileges           on         privileges           on
-        rtmond               on 
         savecore             on         savecore             on
         sendmail             on         sendmail             on
Line 79: Line 79:
 ===== Secure inetd ===== ===== Secure inetd =====
 Edit /etc/inetd.conf, and comment out everything but the "sgi_" stuff. You will need it for the desktop to work. Edit /etc/inetd.conf, and comment out everything but the "sgi_" stuff. You will need it for the desktop to work.
 +<code>
 +sgi_videod/1 stream rpc/tcp wait    root    ?/usr/etc/videod         videod
 +sgi_fam/1-2 stream  rpc/tcp wait/lc    root    ?/usr/etc/fam            fam
 +sgi_snoopd/1 stream rpc/tcp wait    root    ?/usr/etc/rpc.snoopd     snoopd
 +sgi_pcsd/1  dgram   rpc/udp wait    root    ?/usr/etc/cvpcsd        pcsd
 +sgi_pod/1   stream  rpc/tcp wait    root    ?/usr/etc/podd           podd
 +sgi_xfsmd/1 stream  rpc/tcp wait    root    ?/usr/etc/xfsmd     xfsmd
 +sgi_espd/1 stream   rpc/tcp wait    root    ?/usr/etc/rpc.espd  espd
 +tcpmux/sgi_scanner stream tcp nowait root   ?/usr/lib/scan/net/scannerd scannerd
 +tcpmux/sgi_printer stream tcp nowait root   ?/usr/lib/print/printerd printerd
 +tcpmux/sgi_sysadm stream tcp nowait root   ?/usr/sysadm/bin/sysadmd sysadmd
 +tcpmux/sgi_dmusrcmd stream tcp nowait root ?/usr/etc/dmusrcmd /usr/etc/dmusrcmd
 +</code>
 Then: Then:
 <code> <code>
 # killall -HUP inetd # killall -HUP inetd
 </code> </code>
 +===== Improve kernel security =====
 +Add a bit of entropy to the TCP sequence number and drop ICMP redirects:
 +<code>
 +# systune ipforwarding 0
 +# systune ip6forwarding 0
 +# systune tcpiss_md5 1
 +# systune icmp_dropredirects 1
 +# systune restricted_chown 1
 +# systune allow_brdaddr_srcaddr 0
 +# systune tcp_2msl 60
 +</code>
 +These kernel settings can be found in the /var/sysgen/stune file.
 +
 +Finally:
 +<code>
 +# autoconfig -vf
 +# reboot
 +</code>
 +===== Make sendmail just listen on localhost =====
 +Edit /etc/mail/sendmail.mc. Switch the two lines to be:
 +<code>
 +DAEMON_OPTIONS(`Name=MTA-v4,Family=inet,Addr=127.0.0.1')dnl
 +dnl DAEMON_OPTIONS(`Name=MTA-v6,Family=inet6')dnl
 +</code>
 +Then run configmail to update sendmail.cf and restart it:
 +<code>
 +# configmail mc2cf
 +# /etc/init.d/mail restart
 +</code>
 +~~NOTOC~~
tips/irix/security.1790926596.txt.gz · Last modified: by mattieu