Various about Zone Security

Hello,
Lets say I'm running a web hotel with 1000 clients with a dedicated server (zone), all which are setup in the global zone. Now to start with, this machine has to have alot of processing power and RAM. Lets say we have a Sun Fire 6900, dual core CPU:s with all boards dedicated to this super machine. For disk we have connected a huge SAN LUN with 2TB space.
The zone resources are controlled by Resource Manager in the global zone and a percentage of CPU, Disk and RAM are dedicated to each virtual box.
What would be the best practice of a setup like this?
1. Should all zones share MySQL and Apache binaries, but with a separate config in their own /etc ?
2. Integrity checking with BART. Are there any GUI:s for setup? 1000 zones would be nice to administer with a GUI. How does BART compare to Tripwire?
3. Packet filtering with IP Filter. Best place to put a filter should be in the Global Zone? Can a filter in the global zone filter traffic between the interfaces ce0:1, ce0:2 etc? Theoretically I see no limit. For a smaller configuration, would it help to have physical interfaces for each zone, ce1, ce2? What would be the disadvantage of using a single NIC for all zones?
4. Can JASS and FixModes be installed in a global zone to secure all zones at the same time?
5. Is it wise to put layers of a web portal in the same machine, but in different zones? ie www, app, db zone, and use global filter for filtering between them.
Now for the most important question. Lets say any program in the global zone has a security hole, it would affect all Zones (since they are sharing binaries). You say "the root user in one zone isn't able to affect anything outside his or her zone ". What if a hacker somehow gains control over the global zone? He could wipe out 1000 zones and get access to huge disk and CPU power. How can we be sure zoneadmd can't be broken from a zone?
A lot of questions :)
I will be attenting the Expert Exchange about N1 grid containers tomorrow.
Thanks..
Magnus

>
Any chance of posting the answers?
The ExpertExchange session in PDF (and multimedia) format is available at www.sun.com/expertexchange ; go to Archives -> "Fast Track to Solaris 10 Adoption: N1 Grid Containers"
Vlad

Similar Messages

  • Help about Warning Security IE 8.0

    Hello Guys,
    I need help about warning security IE 8.0.
    When I try install a software from my webserver is display the following message:
    I can't check the publisher.Are you sure install the software?
    This file does not have a valide digital signature that verifies its publisher.
    You should only install software from publishers you trust.
    Well, I already enable:
    Download signed ActiveX controls
    Download unsigned ActiveX controls
    Allow active content from CDs to run on user machines Enabled 
    Allow software to run or install even if the signature is invalid Enabled 
    Check for server certificate revocation Disabled 
    Check for signatures on downloaded programs Disabled 
    Is there somewhere I disable all settings warning's about IE or one specific GPO I need disable for this warning don't display for me?
    In the same installation a lot of about file .cab are installed, only one specifc I don't have sucess.
    I try some troubleshootings too:
    https://social.technet.microsoft.com/Forums/windows/en-US/8f8293c4-0920-462f-9c69-0a8e3f92aa02/unknown-publishers-warning
    https://www.youtube.com/watch?v=UknQn6tZZis
    http://windows-3322.blogspot.com.br/2011/02/how-to-repair-activex-error.html
    Thanks a lot who answer me or about any idea about my issue.

    This file does not have a valide digital signature that verifies its publisher.
    Did you see your result
    https://social.technet.microsoft.com/Forums/windows/en-US/8f8293c4-0920-462f-9c69-0a8e3f92aa02/unknown-publishers-warning
    <quote>
    Changing the time zone actually worked.
    </quote>
    Robert Aldwinckle

  • What does setting the internet zone security level to high actually do?

    I was asked to set the Internet zone security level to high via a GPO, this has been done for a test group of users. The setting has been confirmed, but as far as I can see it has not actually done anything.
    Can anyone tell me what changes I should see to the behavior and/or access of websites now the security level is set to high?

    Hi,
    Setting the internet zone security level to high might prevent harmful content with maximum safeguards and less secure features are disabled.
    When you visit some sites with script pop up, the script will be disabled if you set the security level to the high level. For more information about
    the internet zone security level, please refer to this:
    http://blogs.technet.com/b/steriley/archive/2008/09/16/internet-explorer-security-levels-compared.aspx
    Regards.

  • When I tried to log into my itunes account, I was asked to update my credit card information. When I confirmed my credit card info, I got a response about my security code not being accurate -which is not the case-it is 100% accurate. How do I fix?

    I keep getting a message about my security code not being accurate. I tried 3 different cards & have the same issue. Is this a systems issue? I need to get my apps installed on my new iPhone 4. I am unable to download without confirming my credit card info- My security codes are 100% accurate.Anyone else having this issue? What is the fix for this?

    Ohemod,
    There are 120+ countries that have iTunes Stores, but that leaves many that do not.  You can consult this document:  iTunes Store: Which types of items can I buy in my country?
    Opening in a new country requires a tremendous amount of legal, commercial and financial investment, but I am sure Apple would be interested in knowing where there is unmet demand.  If you wish to make suggestions to Apple, you can use the iTunes Feedback page.

  • I am getting messages that I can't download and read .pdf files since I have the wrong Adobe reader. I know about their security disasters of course, but I downloaded the latest version of Adobe Reader from the Adobe web site and I have other ,pdf file re

    I am getting messages that I can't download and read .pdf files since I have the wrong Adobe reader. I know about their security disasters of course, but I downloaded the latest version of Adobe Reader from the Adobe web site and I have other ,pdf file readers as well, and for some reason they won't work either. I have 5 computers running top end processors and RAM. By this I mean I have one, this one which I am using that has an AMD Phenom Black 3.2 Quad-core with 8 GBs of Corsair top DDR2 RAM, my other two AMD have either an Athlon II triple core with 4 GBs of DDR2 Corsair RAM, one with the Phenom X4 965 3.4 GHz Quad-core with 8 GBs of their best DDR2 RAM, and two Intels with the i7 920 Processors using the triple channel 1366 socket processors and one with 8 GBs of low latency DDR3 RAM and the other with 4 GBs of the same RAM. I am getting the message on this one, which has a fresh install of XP Pro X64 operating system, as do the other 4 as well. I have run Avast Business Pro Anti-virus on this one, which I am getting the message on with a single result which I deleted, and also both Spybot Search and Destroy, which came back clean as well as Malwarebytes Antimalware, which got a lot of tracing cookies now removed, and SuperAntiSpware which also found a few cookies also now deleted. Can you tell me what I need to do to get these files to show as .pdf files rather than as a clean blank page. One other issue is that I wish to know how to turn off my downloads so they are saved and Mozilla will give me the option of returning them instead of me losing them all together as it does now. Thanks for your assistance. If there is another Adobe reader I should download and install, could you provide me with the link to it? I appreciate your assistance here
    == When I download and try to read a .pdf file and when I am asked to turn off all Firefox files and if I do, I lose them since I need to know how to save them without rebooting my computer.

    Brilliant! Problem solved! Thanks so much.

  • Please help me about question security because in my apple id no have for restart or chenge my answer

    please help me about answer security question in my apple id because im forgot for my answer, in my apple id no have for change answer, tell me for this please because i love my iphone.
    <Email Edited by Host>

    You need to ask Apple to reset your security questions; this can be done by clicking here and picking a method, or if your country isn't listed, filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (110899)

  • About Java Security

    Hi...I wrote a simple java class and want to execute it through script. I read about this security stuff to take care of. If I run my java class as a standalone application, there is no problem. But when executing it as an applet, I get huge chunk of errors. Then to debug the errors, I tried running the standalone application with security manager i.e.Run with same security as applet
    java -Djava.security.manager MyClass
    java -Djava.security.debug=help MyClass
    I have a few questions:
    1. If running the application with security manager has no problem does it mean that I will be able to execute the applet without problem? I noticed that though I can resolve the error in standalone application but I am still seeing errors when run as an applet.
    2.Can someone tell me what is the difference between signing a jar file and creating access rights using policy tool? I thought Java Plug-in is meant to ensure uniformity in security deployment so does it mean that creating access rights using policy tool is sufficient? Is there still a need to import certificates into browser?
    A million thanks!

    If you are really running the application with the same security manager as an applet uses, then yes, whatever you can do in the app would work in the applet.
    The signed jar provides a way of securing the jar file so that it can be determined that it comes from a trusted source and that the file hasn't been altered. Using a security policy to allow it to do normally disallowed actions does not provide that kind of security. The plug-in does provide uniformity (given the same JVM version) for many things, so one need not deal with bugs in a browser's built-in JVM (if one exists).
    I would recommend using the signed applet anyway, because to do the security policy thing, the user has to alter it on their system. I don't believe you can just provide it with the applet itself, otherwise that's not a very secure system.

  • I got chagred 1 USD while created AppleID .. Why ??.. I am worry about the security ... is this safe ..or should I raise this issue to my credit card bank ??

    I got chagred 1 USD while created AppleID .. Why ??.. I am worry about the security ... is this safe ..or should I raise this issue to my credit card bank ??

    Relax.  This is completely normal and is not unusual at all.
    It will be reversed.
    Read the following.
    iTunes Store & Mac App Store: About credit-card authorization holds

  • Three questions about replication/security

    Hello,
    We are currently planning to build software for our sales persons using C#. Each sales person has a laptop and should be able to sync the client information when he/she has access to the internet/intranet. Sales person can update client information and the local database will be synced back to master server when the user is connected to the internet/intranet. My option was to go with Oracle lite (as client DB) and Oracle enterprise (Server DB). But after readying the posts in this forum, I believe Oracle XE can do the trick. Am I right?
    Second question is about the security of the replication. Sales persons can connect using the internet to sync the information back and forth. Is there a built in mechanism to secure the connection between the two DBs ( Oracle XE and EE)?
    Third question is about the recovery options. I read Mark’s post about the feature of Oracle XE. I understood that PIT recovery and achivelog mode are supported. But, the post also says that Tablespace PIT is not supported. Can some tell me the difference between PITR and TSPITR? If PITR is supported, can I restore the database to a specific date and time (i.e. Dec 2, 2005 2:00PM)?
    Thanks a lot

    Comments inline
    Hello,
    We are currently planning to build software for our sales persons using C#. Each sales person has a laptop and should be able to sync the client information when he/she has access to the internet/intranet. Sales person can update client information and the local database will be synced back to master server when the user is connected to the internet/intranet. My option was to go with Oracle lite (as client DB) and Oracle enterprise (Server DB). But after readying the posts in this forum, I believe Oracle XE can do the trick. Am I right?
    Yes - except that Oracle Lite comes with the synchronization built in, and it's tested to handle all the weird corner cases you have to deal with. XE will give you basic replication, however, you will have to build the connect, replicate (refresh materialized views), disconnect logic yourself (and test it). Personally I would spend the $100 on the Oracle Lite option
    Second question is about the security of the replication. Sales persons can connect using the internet to sync the information back and forth. Is there a built in mechanism to secure the connection between the two DBs ( Oracle XE and EE)?
    It depends by what you mean secure. When you connect XE to Enterprise Edition, it will use a database link to refresh the materialized views (replicated tables). Userids/passwords across the database link will be sent in an encrypted form. The data will not. I'm guessing you could use Oracle's Advanced Security option to secure the database links from XE to EE, but I'm not 100% sure. Tom may be able to give us a clue on this one. Also, note that DBLinks by default use the TCP/IP transport, so thats a hole you would have to kick in the firewall if the EE database was behind it (as it should be). Although replication can use HTTP as a transport mechanism
    (You can see all the issues you start to get into - the $100 dollars per Oracle Lite deployment is looking real goo to me right about now)
    Third question is about the recovery options. I read Mark’s post about the feature of Oracle XE. I understood that PIT recovery and achivelog mode are supported. But, the post also says that Tablespace PIT is not supported. Can some tell me the difference between PITR and TSPITR? If PITR is supported, can I restore the database to a specific date and time (i.e. Dec 2, 2005 2:00PM)?
    Yes - you can roll forward the entire database to a given point in time using RMAN (which will be in production). You cannot however roll forward just a subset of tablespaces (i.e a subset of the data) in XE. Tablespace PITR is an EE feature (and not for the faint hearted).
    Thanks a lot

  • Are you aware about bash security issue CVE-2014-6271 ? Do you have a patch for that? The problem may exist in all Solaris versions.

    Are you aware about bash security issue CVE-2014-6271 ? Do you have a patch for that? The problem may exist in all Solaris versions.

    The official communication is now posted to
        https://blogs.oracle.com/security/entry/security_alert_cve_2014_7169

  • HT5312 My rescue email address is no longer used, I can't get any emails from apple about my security questions. What shall I do?

    My rescue email address is no longer used, I can't get any emails from apple about my security questions. What shall I do?

    You need to ask Apple to reset your security questions; ways of contacting them include phoning AppleCare and asking for the Account Security team, clicking here and picking a method for your country, and filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (104597)

  • How can i change the e-mail which receive a message about forgotten security questions ?

    i want to change the security question but i cant remember the answers or the password for the e-mail that recieve the message about forgotten security question .

    You need to ask Apple to reset your security questions; ways of contacting them include phoning AppleCare and asking for the Account Security team, clicking here and picking a method for your country, and filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (104167)

  • My friends has found he has, since 2006, accumulated multiple apple ids. he's very concerned about icloud security and security in general, having his pc hacked repeatedly. how can he permanently delete the extra, apple ids, please?

    my friend has found he has, since 2006, accumulated multiple apple ids. he's very concerned about icloud security – and security in general, having had his pc hacked repeatedly. how can he permanently delete the extra, apple ids, please? Thanks.

    Hello, windypinesands.  
    Thank you for visiting Apple Support Communities.  
    If your friend is concerned with the security of his Apple ID or iCloud account, I would recommend reaching out to our Apple ID Account Security team to assist him with this issue. 
    Apple ID: Contacting Apple for help with Apple ID account security
    http://support.apple.com/kb/HT5699
    Cheers,
    Jason H.

  • Document about Zone

    Hi
    Cab any one tell me where i will get the proper document about the solaris 10 zone ( with confiuration steps and all about zones)
    Thanks
    rj

    http://docs.sun.com/app/docs/doc/817-1592
    You should really make at least a token attempt to find out the answer before asking here.
    You could have found this by going to docs.sun.com and putting zones into the search box..

  • HT6011 SUPPORT TOPIC: About the security content of OS X Mavericks v10.9

    SUPPORT TOPIC: About the security content of OS X Mavericks v10.9
    This is a lot of technical information about security.
    1. How does it translate to the average user?
    2. Have the issues been resolved and included in the latest UPDATE?
    Many thanks.
    beebee08

    1. How does it translate to the average user?
    It doesn't.
    2. Have the issues been resolved and included in the latest UPDATE?
    That list is what known vulnerabilities have been fixed.

Maybe you are looking for

  • DM 4.7 freezing in Vista 64 bit

    Irratic and software lock  ups  for no apprent reason  are there issues with vista 64 bit I can sync no problem update no problem some times DM freezes after either action but not always sometimes it won't shutdown have to force DM to shut down using

  • Installed Win 8.1 and now no icloud?

    I installed wiin 8.1 Pro last night and Outlook works fine but when I clicked on my icloud contacts folder ini Outlook 2010, there were no contacts there. How do I get this to work with Win 8.1 pro (preview).

  • Header and footer problem

    How do you get header and footer to show infront of coloured page on the pages app for mac book

  • Malicious TornTV add-on continously returning after being disabled- How do I fix this?

    I've been having issues with an add-on to my browser by TornTV that continuously returns after being disabled via the link provided on the ads it invasively opens and via the Add-on Toolbar. I've done the process many times and even sent a formal req

  • Dimension - Repetive values

    If I am viewing a fact table (25 Million+ records) from SE11 is there anyway that I can easily check how often a value for one of the dimensions (columns) repeats itself. If there is another method to do the same could you advise. Thanks