====== Secure the system ======
===== Disable useless daemons =====
To disable useless daemons, use chkconfig :
# chkconfig off
For a workstation, here is a list of daemons you should disable:
appletalk off
automount off
cesag off
dtlogin off
esp off
fcagent off
fontserver off
gated off
ldap off
lp off
miser off
mrouted off
named off
nds off
nfsd off
noiconlogin off
nostickytmp off
pmcd off
pmie off
proclaim_relayagent off
proclaim_server off
proxymngr off
quickpage off
rarpd off
route6d off
routed off
rsvpd off
rtmond off
rwhod off
sar off
sdpd off
sesdaemon off
sgi_apache off
tfxd off
timed off
timeslave off
ts off
verbose off
videod off
vswap off
webface off
webface_apache off
yp off
ypmaster off
ypserv off
To just keep these on:
autoconfig_ipaddress on
autofs on
desktop on
ipaliases on
lockd on
mediad on
ndpd on
neko_sshd on
network on
nfs on
nsd on
ntp on
privileges on
savecore on
sendmail on
sendmail_cf on
snetd on
soundscheme on
visuallogin on
windowsystem on
xdm on
===== Secure inetd =====
Edit /etc/inetd.conf, and comment out everything but the "sgi_" stuff. You will need it for the desktop to work.
sgi_videod/1 stream rpc/tcp wait root ?/usr/etc/videod videod
sgi_fam/1-2 stream rpc/tcp wait/lc root ?/usr/etc/fam fam
sgi_snoopd/1 stream rpc/tcp wait root ?/usr/etc/rpc.snoopd snoopd
sgi_pcsd/1 dgram rpc/udp wait root ?/usr/etc/cvpcsd pcsd
sgi_pod/1 stream rpc/tcp wait root ?/usr/etc/podd podd
sgi_xfsmd/1 stream rpc/tcp wait root ?/usr/etc/xfsmd xfsmd
sgi_espd/1 stream rpc/tcp wait root ?/usr/etc/rpc.espd espd
tcpmux/sgi_scanner stream tcp nowait root ?/usr/lib/scan/net/scannerd scannerd
tcpmux/sgi_printer stream tcp nowait root ?/usr/lib/print/printerd printerd
tcpmux/sgi_sysadm stream tcp nowait root ?/usr/sysadm/bin/sysadmd sysadmd
tcpmux/sgi_dmusrcmd stream tcp nowait root ?/usr/etc/dmusrcmd /usr/etc/dmusrcmd
Then:
# killall -HUP inetd
===== Improve kernel security =====
Add a bit of entropy to the TCP sequence number and drop ICMP redirects:
# systune ipforwarding 0
# systune ip6forwarding 0
# systune tcpiss_md5 1
# systune icmp_dropredirects 1
# systune restricted_chown 1
# systune allow_brdaddr_srcaddr 0
# systune tcp_2msl 60
These kernel settings can be found in the /var/sysgen/stune file.
Finally:
# autoconfig -vf
# reboot
===== Make sendmail just listen on localhost =====
Edit /etc/mail/sendmail.mc. Switch the two lines to be:
DAEMON_OPTIONS(`Name=MTA-v4,Family=inet,Addr=127.0.0.1')dnl
dnl DAEMON_OPTIONS(`Name=MTA-v6,Family=inet6')dnl
Then run configmail to update sendmail.cf and restart it:
# configmail mc2cf
# /etc/init.d/mail restart
~~NOTOC~~