====== Secure the system ====== ===== Disable useless daemons ===== To disable useless daemons, use chkconfig : # chkconfig off For a workstation, here is a list of daemons you should disable: appletalk off automount off cesag off dtlogin off esp off fcagent off fontserver off gated off ldap off lp off miser off mrouted off named off nds off nfsd off noiconlogin off nostickytmp off pmcd off pmie off proclaim_relayagent off proclaim_server off proxymngr off quickpage off rarpd off route6d off routed off rsvpd off rtmond off rwhod off sar off sdpd off sesdaemon off sgi_apache off tfxd off timed off timeslave off ts off verbose off videod off vswap off webface off webface_apache off yp off ypmaster off ypserv off To just keep these on: autoconfig_ipaddress on autofs on desktop on ipaliases on lockd on mediad on ndpd on neko_sshd on network on nfs on nsd on ntp on privileges on savecore on sendmail on sendmail_cf on snetd on soundscheme on visuallogin on windowsystem on xdm on ===== Secure inetd ===== Edit /etc/inetd.conf, and comment out everything but the "sgi_" stuff. You will need it for the desktop to work. sgi_videod/1 stream rpc/tcp wait root ?/usr/etc/videod videod sgi_fam/1-2 stream rpc/tcp wait/lc root ?/usr/etc/fam fam sgi_snoopd/1 stream rpc/tcp wait root ?/usr/etc/rpc.snoopd snoopd sgi_pcsd/1 dgram rpc/udp wait root ?/usr/etc/cvpcsd pcsd sgi_pod/1 stream rpc/tcp wait root ?/usr/etc/podd podd sgi_xfsmd/1 stream rpc/tcp wait root ?/usr/etc/xfsmd xfsmd sgi_espd/1 stream rpc/tcp wait root ?/usr/etc/rpc.espd espd tcpmux/sgi_scanner stream tcp nowait root ?/usr/lib/scan/net/scannerd scannerd tcpmux/sgi_printer stream tcp nowait root ?/usr/lib/print/printerd printerd tcpmux/sgi_sysadm stream tcp nowait root ?/usr/sysadm/bin/sysadmd sysadmd tcpmux/sgi_dmusrcmd stream tcp nowait root ?/usr/etc/dmusrcmd /usr/etc/dmusrcmd Then: # killall -HUP inetd ===== Improve kernel security ===== Add a bit of entropy to the TCP sequence number and drop ICMP redirects: # systune ipforwarding 0 # systune ip6forwarding 0 # systune tcpiss_md5 1 # systune icmp_dropredirects 1 # systune restricted_chown 1 # systune allow_brdaddr_srcaddr 0 # systune tcp_2msl 60 These kernel settings can be found in the /var/sysgen/stune file. Finally: # autoconfig -vf # reboot ===== Make sendmail just listen on localhost ===== Edit /etc/mail/sendmail.mc. Switch the two lines to be: DAEMON_OPTIONS(`Name=MTA-v4,Family=inet,Addr=127.0.0.1')dnl dnl DAEMON_OPTIONS(`Name=MTA-v6,Family=inet6')dnl Then run configmail to update sendmail.cf and restart it: # configmail mc2cf # /etc/init.d/mail restart ~~NOTOC~~