Solaris Security

This page contains information about how to secure Solaris systems.

General guidelines

When working on any UNIX based system, be sure to check the following:

Solaris guidelines

For a step-by-step guide to securing and configuring a new Solaris machine, try our Securing Solaris Guide.

Best practices

To enable logging of failed login attempts, you will need to create the /var/adm/loginlog file and change the permissions to restrict read and write access to owner only. The owner must be root and the group must be sys.

Remote X logins can be a security hazard. To minimize the risk, change /usr/dt/config/Xaccess to disallow XDMCP connections from everywhere. Because this change will be lost during upgrades, it is a good idea to copy /usr/dt/config/Xaccess to /etc/dt/config/Xaccess.