Looking to address vulnerabilities in SunOne 6 1

Hi,
Our security team found the following vulnerabilities:
1)Disable TLS Renegotiation - SP 17 takes care of this
2)Add the HttpOnly to all cookies
3)Add the Secure flag to cookies sent over SSL
4)Upgrade to latest SSL (I am assuming I can just download and install the latest openssl)
Please let me know how to address these vulnerabilities.
Thank you.

ok, when you installed the webserver, did you have to run the install as the root user or just any user? The package based installer requires root user privileges and puts the binaries under /opt/SUNWwebserver and the configuration under /var/opt/SUNWwebserver/https-instancename. The file/zip based installer lets you install anywhere and as any user and also puts the instances under the same directory structure.
So you have two things to worry about, the binaries and the instance configurations. The config is more important. Basically the directories starting https- are where the configurations for each instance is stored. There are additionally also the alias and httpacl directories for the SSL certificates and ACLs which you should also backup. If it is a file/zip based installation, all you need is to just zip/tar up the entire directory.

Similar Messages

  • Applications Icon in Dock looks like Address Book

    Hi -
    I'm suspicious about why my Applcations icon in the dock doesnt look like the Applications icon in the Finder window. Instead it looks like the Address Book with something hiding behind it. Really!
    Is this correct?
    If not, how do I remedy this?
    Thanks,
    J2
    Message was edited by: Josh2000

    I believe you have the folder set to "Display as Stack". In this display mode the dock icon tries to show you the icon representing the topmost object in the folder, which is usually Address Book in the case of the Applications folder. You can have the dock display the Applications folder as just a folder by clicking and holding the button down on the Applications dock icon (or control clicking on it) and selecting that option in the list of options that appears.
    charlie

  • How do I get calendar in iOS7 to look up address when entered into location field of appt?

    With Mavericks on iMac, when I start to enter a location into a calendar event, the address gets looked up, completed and a map shows up on the event. The map is there when that event is sync'd with iPhone or iPad running iOS7. But on iPhone or iPad, when I enter an address into a calendar item, no lookup takes place and therefore I don't have a "live" address to click on for directions. Is there some setting in iOS7 that determines whether an address gets looked up in the calendar?

    A quick look at their web site shows I've misinterpreted what you said - Notational Velocity isn't related to iCal. However if you are still having a problem with that the makers would be the people to ask.
    I'm not sure why you can't get iCal files to work if they are in the correct place. In 10.6.8 the Calendar folder includes a folder for each calendar, and these contain the .ics files which represent the actual events. I don't know whether 10.8 has altered the format as I don't use it.
    You originally said ' I found the old calendar data in Users/my name/Library/Calendars, and copied it over into the Library file on my new machine.' - did you copy the entire Calendars folder intact?

  • Search should look at address book notes & application data

    Search is basically useless to me, I used to have the ability to categorize my address book, or at the very least make a note in a contact that was searchable. (For example, "work" in the note section of a contact would result in search results of just the contacts with this note, go figure!) I also have lots of stuff in alternate notes programs that is not searchable. Not much of a reach to make data entered into an "i-device" searchable, I think a few software engineers should be able to tackle this insurmountable problem! I paid $500 for a device that has fewer options than my Palm Pilot did 8 years ago!(and in regards to searches, is absolutely inferior)Sounds like the only way to get apple to address an issue is to make lots of noise in this support forum. Sorry to waste anyone's time.

    I just had this same problem. I use multiple mac computers that I sync manually because of a previous idisk issue. I noticed as I updated my cloud, the search function in address book quit working properly on each computer.
    So created a new group list and I attempted to copy "All Contacts" into that group. It would not copy all my contacts into that group in one paste function. So I took all the the first 25 names and copied them. That worked. Then I moved to the next 26-50 names and so on. I noticed when I got to the fourth group of copying contacts that it did not paste and froze the application.
    I quit address book, reopened it. All the contacts before the the fourth group were in the file. The search function worked on those names. I then went card by card and found one that had a "string" of data listed where an email address should I have been. So I deleted the corrupt card and now my address book search is working again.
    Here is the short solve. Look for a corrupt card in your address book. I found the corrupt card by trying to copy it over to a new address group. The card that was corrupt just happened to be one that I had updated in the last week or so...
    Hope this helps.

  • Network error looking up address: 'No address associated with nodename"

    This shows up in the console log when I try to launch a program I just installed - Lego Digital Designer.
    Any thoughts how to associate an address with nodename??
    Thanks in advance!

    No. I ended up installing on my IBM laptop instead. Sorry. However, I did get some tips from the Lego team that might help you. I'll cut and paste them here.
    first one:
    [Try loging onto http://www.openal.org/downloads.html I think you will find the drivers there. Once you update the drivers your game should work fine.
    If you run into any problems with the downloadable version of LEGO Digital Designer , you can use the Help tool by clicking on What's this and selecting the item on the screen that you want help with. You can also look at the user manual or visit www.lego.com/ldd for more information. Live support is not available for the download versions.]
    next one:
    The From the Vaults CD-ROM works best when used with the very latest version of Apple QuickTime Player. As of this writing, the latest version is QuickTime Player 7. If you don't have the latest version of QuickTime player, the software -- for both Windows and Macintosh computers -- can be downloaded free of charge from the Apple website at this web address:
    http://www.apple.com/quicktime/download/standalone.html
    last one:
    [Use the link below to get the drivers.
    <http://developer.creative.com/articles/article.asp?cat=1&sbcat=31&top=38&aid=97 >.
    Please note that we cannot provide additional support, we ONLY support the CD Version, the download version is supported only via the FAQs on the website; there is no live support for the download version.]

  • Always Looking Up Address DNS

    I notice that many times in a day when I browse, for example to forecast.weather.gov, the browser is looking it up ... I see the "looking up ..." at the bottom of the browser ...
    If I have visited that site many times in a day, why is OS/X looking it up again/
    And just what could I change; install; run, that would cache these URL's ?
    Thanks

    Ummm ... not understanding why caching the DNS Lookup data for a particular site, is related to any site I visit changing Data ... like for example the Weather Service .. their general URL Octet bunch is the same from periodic update to the next periodic weather update.
    And it seems that somehwere on this box, I am not setting something correctly .. or .. I need to be running some DNS caching server ... or someting ... becasue I don't think the O/S is supposed to keep asking fir a resolution to forecast dot weather dot gov ... or ... my-mailbox dot that_ISP dot com or some such

  • Looking for Address Book Cleaning Programm?

    Hallo
    I have export (txt tab format) a large Database (2400 records) from our PABX-System (Habimat). The Field are very dynamic. Now I want to clean this file an make for every records correct fields to that I am later able to import them in the Address Book.
    Is their such a Program to generate "own" fields for each record, e.g. Spouse-Name, Spouse-GSM, Spouse-Birthday, Secretary, Child etc. I sorted out that the iphone is able to handle all these different field names, but it very frustrating to edit 2400 record within the Address Book or on the iPhone.
    I tried to edit them in Excel but I need to prepare field that will be import in the Adress Book.
    Is their a tool availible on Mac (or Windows) that helps me to edit all this records to the correct fields?
    Regards
    Gérard

    I'm in the same boat, Tor...
    ...The Apple Address Book is the most awkward of all the contact management programs I've used. I too have trouble with duplicates. One source is when I merged two data bases. One had middle initials and the other didn't. I've been pecking away at deleting them one by one and with over 5,000 contacts it'll take me all year. Please keep me informed if you get a descent response to your posting. Good luck and know you aren't alone if that's any consolation.

  • UC540 SIP trunk "allowed IP addresses" limitation?

    Testing out a UC540 and I'm using Callcentric.  Working great, but the feature under the SIP trunk configuring/Advanced that allows you to set the IP addresses of machines allowed to connect to the UC540 only supports a maximum of 100 entries.  Callcentric wants 204.11.192.0/24 or 204.11.192.0-204.11.192-255 unblocked.
    The UC540 doesn't seem to support inputting a range in any notation I'm aware of, maybe I'm missing something?
    I contacted Callcentric and asked if they could be more specific, LOL, but they said they change things on their end from time to time.
    Anyone else figure out a way around this?

    Okay, follow-up to the question.
    How bad an idea is it to leave this security feature disabled?
    I have a bit of experience in this area, I use an Asterisk (FreePBX distro) for my work phone system, and Callcentric is my SIP trunker.  Before I limited incoming connections to my FreePBX server to the Callcentric range above, there would be occasions (maybe once every 2-3 weeks) where someone (probably up to no good) found my open port(s) and all my phones would start ringing simultaneously.  It lasted for about 20-30 seconds, and then would stop.
    My assumption was that someone was looking for security vulnerabilities so they could use my Asterisk box to place their LD (maybe even overseas) calls.  They never got anywhere, though, as the Asterisk was fully patched, and my passwords for my handsets were strong.
    I wonder if the Cisco UC540 will suffer the same sort of result, or worse, or maybe even not so much.
    Obviously I can simply select another trunker.  The thing I like about Callcentric are the rates and also the dashboard that allows me to make a lot of adjustments (like forwarding calls to a cell phone number, and the ability to configure faxing reception, too).  So if anyone has a suggestion for a supported SIP trunker that supports the same types of features, I'd be open to that, as well.
    BTW, I did ask Callcentric one more time, with a link to this topic, whether they can restrict that range to better than 0-255, but they declined.  I see their point, just wish there was another simple way around this.

  • Contact disappeared from iPhone but not deleted from Address Book on sync

    FYI, I have an iPhone 3G running iOS 4.2 (the latest), and I have never so much as thought about MobileMe.
    Until two days ago, I have had no reason to doubt that my iPhone's Contact list is the same as my MacBook's Address Book list. I now have no confidence that the same info. exists in both: I know for sure that at least one contact long present in both has disappeared from the iPhone, yet syncing all contacts neither returns it to the iPhone nor deletes it from Address Book! I need help troubleshooting this contact as well as verifying that there aren't other similar anomalies corrupting my data, hopefully without manually comparing all 685 entries...
    Two days ago, a certain number, let's call it (310) 555-5555, popped up in my recents list as a missed call and in my visual voicemail. When I listened to the voicemail, I discovered that (310) 555-5555 was Jane Smith. I remembered entering Jane Smith several months ago, so I thought hmmm, does she have a second number? I tried to add (310) 555-5555 to an existing entry, only to find my iPhone had no entry for Jane Smith anymore at all! I did not delete her myself, and I'm not aware of any 3rd-party app that ought to have affected the entry. I haven't called Jane Smith or (310) 555-5555 in quite some time, so I have no idea how long the entry may have been missing. I searched the whole phone (left of the first home screen)
    At the next opportunity, I looked in Address Book on my laptop, and indeed found the expected entry for Jane Smith, (310) 555-5555. I have no idea how she disappeared from my iPhone -- did I or some third-party program delete her? Or did it happen through some sync issue? -- but I naturally worried that when I next synced, the deletion would sync, too, and I would lose the Address Book entry, leaving me without Jane Smith's number at all.
    Such an event would defeat the entire purpose of backing up my phone contacts to my computer; I just moved to iPhone this spring after being a Palm user since 1997, and the idea that iPhone might not be reliably syncing my contacts is frankly terrifying. I checked and saw that my Address Book listed 685 contacts to iPhone Contacts's 684, so I decided to risk a sync in hopes that maybe I had caused a one-off deletion. I wrote down Jane Smith (310) 555-5555 just in case and hit sync.
    The results of the sync and my subsequent troubleshooting have seriously undermined my confidence in the fidelity of the sync process. The first time, nothing changed--I still had 684 iPhone, no Jane Smith, and 685 Address Book, including Jane Smith.
    Thanks in advance for any assistance.
    Message was edited by: Lindsey Worth

    Before conecting your phone, open iTunes on your computer and go to Preferences, on the Devices tab check "Prevent...from syncing automatically".  Now connect your phone and when it appears in iTunes on the left sidebar click on its name.  Go to the Info tab and confirm than your have checked Sync Contacts with Address Book.  Now further down on the Info tab under Advanced>Replace information on this iPhone check Contacts.  Click Apply and sync your phone.  This will replace the contacts on your phone with the contacts in Address Book.  (When complete you can go back to iTunes preferences and uncheck "Prevent..." to re-establish automatic syncing if your prefer this.)

  • DNS - Can't resolve website address because it is the same as domain name:

    Our internal users can't resolve a web address because their domain name is the same as the address.  I'm hoping I can get some advice on what I should do on the DNS server.  My first challenge is, when I look-up address on Arin.net it does not
    come up with anything. CUAMERICA.COM is the domain.  I don't even know the ip address it is resolving to. 

    If I ping www.cuamerica.com I get 38.108.184.171, so in your DNS, in the Forward Lookup Zone for CUAMERICA.COM create a new Host (A) record, call it
    www and give it the IP address of 38.108.184.171

  • How can I restore automatic display & selection of addresses of contacts when I type the first letter on my Yahoo addressee bar?

    When filling out the addressees (T0, Cc, and Bcc bars) on a new mail in Yahoo, I would type the first few letters of each addressee, and get a display of the names and e-mail addresses starting with those letters. I would simply highlight the ones I wanted to include, and these would be automatically placed on the corresponding bar. For some reason, this display/autotext is not functioning. So I now have to go to "Contacts" to look up addresses that I haven't memorized.

    Hi Silky-Milky!
    If I understand your question correctly, you are attempting to merge your contacts from your previous phone's backup into your iCloud account, then go back to using your new phone as normal, with the new merged database of contacts. I have an article that can tell you how to do exactly that:
    Recovering iCloud or MobileMe data from iTunes backups for an iOS device
    http://support.apple.com/kb/TS4108
    Take care, and thanks for visiting the Apple Support Communities.
    -Braden

  • How to Block Specific IP Address (YouTube)

    This is a follow-up question to one I posted earlier this week. I want to block YouTube (and a handful of other sites) from my stepson's new iMac and it was suggested I try/use Leopard's "Parental Control" feature.
    I tried that, but the problem is, when he attempts to visit the site, a warning page pops up informing him Parental Controls have blocked the site, then gives him the option to log in as the administrator or to email the admin for access...and that's pretty much the worst thing that could happen. He has serious Obsessive Compulsive Disorder (OCD) and it HUGELY upsets him that he can't guess the Admin password.
    Soooooo...can anyone suggest an alternative means of blocking a specific IP address that does so WITHOUT serving up a "Contact the Administrator" message? Someone has suggested blocking the IP address via the network router, but I haven't a clue how to do that.
    Any help?
    Thanks.

    Something else you might look at to see if it is suitable for you is to use the DNS servers from www.opendns.com (on your router for example) and set up an account on there, then exclude the sites you don't want accessed - either by the names of the sites OR by the category of site they are.
    What that does is NOT actually "blocking the site" as such, what it does is when the workstation wants to resolve the hostname into an IP address, OpenDNS will fail the request. The user will see a browser page from OpenDNS saying that the site was blocked by the network administrator - you can change the wording and even add an icon if you like.
    If the user doesn't have admin access to the workstation (whereby they could change the DNS server locally to your ISP's normal DNS, which presumably doesn't offer this sort of lookup-filtering) and they don't know the IP address(es) of the sites they want to access - obviously if the workstation doesn't have to go to a DNS to look the address up, it doesn't matter whether the DNS is blocking the lookup for you - this works well.
    There's more information on www.opendns.com - as I said maybe it won't be appropriate for you, but if it is, it's pretty easy to set up and to administer.

  • Is there a way to change the look of the new ical in Lion?

    Is there a way to change the look of the ical in Lion?

    David Armstrong (SE) wrote:
    Ha ha ha yes!
    The new OS will be called Macindows 01 beta of the beta v.1.000.001a 
    Arggggh I just had a nightmare whilst being awake!
    Wow, one interface change in iCal and you Mac world falls apart? I have not even noticed the change to it over the other great features included in Lion. Not a hiccup, increased stability and speed on all my Macs, Loving Mission Control, iCloud is a great selling point and Mountain Lion, due out later in the year will yet again change the face of Computing forever. Windows is following along the same path, struggling to keep up (yes I run Windows as well - trecherous isn't it!), but yet we are all doomed because a handful of people don't like the leather bound look of Address Book which will probably change again in ML if a hack isn't written in the meantime. Petty arguement here. Just give feedback to Apple, I am sure it is on the top of their agenda.
    Good Luck
    Pete

  • How to revert to Classic view in Address Book?

    I tried to use it, but this NEW look of Address Book in LION is just a worthless pile of junk!
    Not only is fake book look out of place and a ridiculous addition to a MODERN OS, but I'm also getting sick of the new trend to hide info that was once easy to see with no extraneous need for interaction. 
    This new 2 column view is full of new extra mouse clicks.
    I want the old CLEAN CLASSIC 3 COLUMN VIEW back!! 
    I want to see "Groups", "Names" and "Individual" info all at the same times!

    The 10.8 Beta is under NDA, which is why I did not want to get more specific. I am one of the testers and can assure Address Book salvation there. But I still think it should be fixed in 10.7 as well…

  • How to Remove duplicate entries in address book

    After syncing with iCloud (three computers and a phone) suddenly I am seeing multiple entries for the same contact in the address book and multiple entries in the calendars for the same event.  Can anyone suggest how to stop this and how to delete the multiple entries without having to manually delete each item?  The new Address book does noit seem to have a list view that shows the entire address book 9only shows addresses with two or three alphabets...
    Is there a setting to prevent this from happening?  I had similar experiences with the old Mobile.me and was hoping the problem had been fixed.
    The value of iCloud is lessened when these issues crop up and there seems to be no defined method to fix the problem.  I see numerous entries on the Support Community boards with the same problem.
    Any suggestions?  Thank you.

    Hi,
    Take a look at Address Book Account Basics (with iCloud). and Duplicate address Book entries.
    I too had the same issue and this helped solve it.
    Hope this helps.

Maybe you are looking for

  • URGENT : display only overall result

    hi........my query to track the performance of dealer. in the selection i've added customer creation date (user entry), customer group as Dealer, branch (user entry), division (user entry) & fiscal year varient. the structure is: in the row : bill-to

  • Horrible network performance when transfering from Vista to OS 10.4.11

    When I connect from my MacBook Pro running OS 10.4.11 to my PC running Windows Vista and attempt to transfer large files, the speed is painfully slow. A 1GB file can take several hours. It sends in bursts: 3-4MB come quickly, then it stops for a whil

  • I have xml file in which i want to edit or add or delete the contents..

    Hi I need your help, How to remove some contents and modify some contents from xml file... <book> <peson> <name> AAA</name> <age>12 </age> </person> <peson> <name> DAA</name> <age>21 </age> </person> <peson> <name> CAA</name> <age>32 </age> </person>

  • Default Exchange rate type at document type level for parallel currencies

    Hi, I have a scenario wherein 2 parallel currencies have been maintained (Grp & index based) against a Co Code and have maintained a default exchange type (Z2) in the Document type settings (OBA7). But when I want to post a foreign currency document,

  • Migration from Oracle Collaboration Suite

    Hello all. I am having some trouble to migrate an Oracle Collaboration Suite from one server to another one. We are seriously considering to migrate to Sun Collab instead. Is it possible to use Oracle Collab's directory, mail and calendar information