Will zones inherit security/hardening settings made prior to zone creation?

Hi guys.
So the scenario is I've just finished hardening Solaris 10: disabling of services, configuring tcp wrappers and the such. I would now like to create a zone or zones but there are a few things I would like to make sure of, before proceeding.
The questions are:
i) After creating a zone, whether it's sparse or whole, will the non-global zone inherit the hardening settings that I have setup prior? Or is it a seperate entity that requires me to harden it.
ii)I understand that patching the global zone will patch the rest of the other zones. Does this include whole-root zone since it does not mount any filesystem outside its zone.
Thank you.
N.

No, except for the packages that get installed at zone creation time, they're separate.
Patches are applied to all zones. A zone may be temporarily booted just to apply a patch. Even though a whole-root zone may not mount external filesystems, that doesn't mean that it's independent. For instance, it's kernel files aren't actually loaded, since it doesn't have an independent kernel. When the global zone's kernel is patched, all others are as well. So the files within the zone will be patched as well to maintain consistency.
Darren

Similar Messages

  • Can Apple TV use the balance from my iTunes Store when renting a movie? I couldnt find the option so I believe it will charge my credit card it made me add to the iTunes Store settings.

    Can Apple TV use the balance from my iTunes Store when renting a movie? I couldnt find the option so I believe it will charge my credit card it made me add to the iTunes Store settings.

    For the avoidance of doubt, you must have enough of a balance to pay for the rental in full, it won't take the balance and the difference by credit card. If you don't have enough of a balance it will all be taken by credit card.

  • Fix calendar timezones for appointments made prior to timezone change?

    I have been tasked with building some new Citrix servers.
    One of our test users is in another time zone and was using our old citrix environment.
    He had a number of appointments that he had made in his calendar.
    For some reason the policy I had set for taking the time zone information from the clients system did not take effect and as he was the only outside tester, he didn't tell me for nearly a week. 
    Now I have the policy working in Citrix, and the time zone is working for all NEW appointments  - however all OLDER appointments made prior, including the ones that were set on the OLD citrix system (which was not having the time zone problem) are all
    stuck to the local time zone of our main branch.
    Is there a powershell command or exchange setting I can set for this individual to retro-actively re-set all his calendar objects back to his appropriate time zone?
    Our environment: Mix of Server 2012 R2 and Server 2008 R2
    Email Server: Exchange 2010
    Email/Calendar Client: Outlook 2010

    It's alright, just before the end of my shift last night I found a "solution"
    There is a tool offered by Microsoft to that will allow the user to fix settings for their outlook in relation to time zone. Once installed it has two options - 1) User is permanent moved to a new time zone, and 2) Time zone fix patch.  It
    was a matter of choosing the first option, selecting the incorrect timezone, selecting the correct time zone, and it completed it in no time.
    Its difficult to explain, but it worked - at least it fixed his outlook calendar.
    The app is called Microsoft Office Outlook Time Zone Move
    64 bit -
    http://www.microsoft.com/en-ca/download/details.aspx?id=16271
    32 bit -
    http://www.microsoft.com/en-ca/download/details.aspx?id=17291
    It installs to the start menu.
    As I our users connect to server via Citrix, it was necessary for me to do this on the connecting/destination server itself where the application is hosted.
    You will also need to be logged in and run this AS THE AFFECTED USER, with administrative rights (right click, run as administrator). Even though it gives you an option to select a user, it didn't work right for me.
    Also note, I had tracked down the GPO that was causing a bit of a flip flop with my Citrix settings in regards to time zone redirection - it was located in a GPO that was at a higher level with timezone redirection turned to disabled,  I had it enabled
    in the GPO governing our terminal servers, and the setting was active in Citrix Delivery Sevices Console. What resulted was the time zone flip flopping between Central Standard Time (where our servers are located) and Eastern Time (where this client was located).
    This was happening for a day or two until I figured this out. Really didn't make any sense because order of operations should have had it work or not work, not bounce somewhere in between.  Set the time zone redirection to not-configured
    in the offending GPO, and blamo. It's been working solid for the client for the past 5 hours now and he says the issue is fixed, so I'm chalking it up to that as its really the only thing I've changed so far.

  • Check access on page that inherit security

    Hi,
    I'm building a dynamic menu which needs to render a page_group with all his pages and subpages. I want to implement security in such a way that only pages are shown wherefore the current logged-in user has manage rights for.
    Currently I have 2 pages and each page has a subpage:
    Page 1
    ->Page 1.1
    Page 2
    ->Page 2.1
    On page 1 and 2, I specify access settings (grant a group to access these) and the subpages of both pages will inherit these access settings from there parent pages (respectively page 1 and 2).
    If I check whether a user (that belongs to the above mentioned group) has access to Page 1 or Page 2, the result is TRUE. (using wwsec_api.has_privilege)
    When I check whether a user has access to a subpage of page 1 or page 2, the result is FALSE, although they must inherit the access settings configured on there parent pages.
    My question now is: is there a function available which checks the access settings on pages that inherit these? If not, how can I easily implement this requirement.
    Thanks in advance,
    Koen

    > I am working with php so it constantly needs to be
    uploaded and checked
    > for
    > bugs.
    Why not do that locally?
    > And to top it all off i am not the only one working on
    the project, hence
    > the
    > checkin/out.
    All the more reason to do it locally. Can you install Apache
    or are you on
    a Mac?
    Murray --- ICQ 71997575
    Adobe Community Expert
    (If you *MUST* email me, don't LAUGH when you do so!)
    ==================
    http://www.projectseven.com/go
    - DW FAQs, Tutorials & Resources
    http://www.dwfaq.com - DW FAQs,
    Tutorials & Resources
    ==================
    "strubester" <[email protected]> wrote in
    message
    news:fn7u3f$kcr$[email protected]..
    > Well my situation is this:
    >
    > I am working on a test server (basically) and so there
    is no worry about
    > pushing stuff live accidentally because the whole site
    is not live.
    >
    > I am working with php so it constantly needs to be
    uploaded and checked
    > for
    > bugs.
    >
    > And to top it all off i am not the only one working on
    the project, hence
    > the
    > checkin/out.
    >
    > I dont shut down my computer.
    >
    > Case to case this *OPTION* of checking in on close may
    not be the best
    > situation, but thats why it is an *OPTION* - something
    that adobe
    > (macromedia)
    > has not even provided.
    >
    > I feel that the absence of even an option for this
    effect means the
    > software
    > is lacking.
    >
    > If you have a better method of development, i am all
    ears.
    >

  • Is it appropriate to apply the hardening settings for Windows 2008 R2 server to Windows 2008 server?

    We would like to adopt the hardening recommendation for Windows 2008 R2 from CIS to all our DC servers. However, but then we found some of our DC in remote sites are Windows 2008 server only.
    Is the hardening settings from Windows 2008 R2 from CIS also applicable to Windows 2008 DC?
    Thanks for your attention.

    Yes, this should be fine. Hardening only specific security settings, registry keys etc and there's not much difference if you consider hardening.
    Just for reference, here's the difference between 2008 and R2 :
    http://technet.microsoft.com/en-us/library/dd391932(WS.10).aspx
    Arnav Sharma | http://arnavsharma.net/ Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

  • Slideshow settings  made impossible by a big black rectangle covering the upper-left half of the screen/photo,

    Slideshow settings made impossible by big black rectangle covering the upper-left half of the screen/photo, appearing when I move the cursor. Disappears when I start the slideshow. Restart does not help.

    Thanks,
    -  First: Linc Davis' question seems to be relevant: Indeed, when I disconnect my second display, the problem disappears.  However, reconnecting the display makes the problem reappear again. 
    - I use iPhoto 9.5.1. and Mac OS 9.5.2.  The machine is a MacPro first part of 2008 (not a MacBook Pro as I inadvertantly said in my original question). Processor 2X2,8 GHz Quad-core intel Xeon. Memory 6 GB, with new (2yrs old) 2 TB SATA-disk (WDC WD2002FYPS-02w380 Media) as hard disk.
    - Here is a screenshot of what I am seeing - with only part of the settings display (in Norwegian) visible.
    - I have looked for a solution in the iPhoto settings, turned the program off& on, and restarted the computer, all without success.
    -  The library is, as I understand it, located in users/[me]/pictures/iPhoto Library.
    -  No, as I remember I did not apply any updates or upgrades just prior to the problem.  I have regularly updated the programs, as they come, without checking the results on each program.
    -  I run a managed library
    -  Apparently there is 1,29 TB free space (out of 2 TB) on my boot drive [=central hard drive, see above?].

  • Regional Settings - User Profile Time Zone

    The user profile property time zone will only apply to the users My Site. How can you apply that time zone to the web application or site collection? So that a user from San Francisco will see calendar events on the main intranet in PST, rather than
    CST.

    Hi Peter,
    Per my knowledge, if the time zone in the user profile is different from the time zone in the site, the time displayed in the site will be in the format based on the time zone setting in user profile.
    After changing the time zone in user profile, it needs some time to save the changes back to SharePoint, so there will be some time delay of changing the time format in the site.
    Please also make sure that the Always use my personal settings is selected in user profile.
    Even though the time zone is not changed in the site, the time format will change based on the time zone setting in user profile if the user chooses a different time zone in his user profile.
    Thanks,
    Victoria
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Victoria Xia
    TechNet Community Support

  • Samsung Note 4 issue opening Security in Settings

    I just got the phone yesterday and after setting everything up I cannot access Security settings in Settings.  When I select Security a message comes up "Unfortunately Settings has stopped".  I had the Fingerprint unlock activated so I turned that off and it still is happening and I tried to restart the device and it still will not open.

    I just chatted with VZW support and found a work around until they fix or narrow down the culprit app.  The rep had me start the phone in safe mode by holding the power button in and when the options appear press and hold power off icon until restart in safe mode appears, select to restart in safe mode.  When I did this I could access Security from Settings.  Restart the phone again to exit safe mode.  Hope this helps.  According to this result it appears one of the apps I downloaded is impacting the Security Settings.  You can do a reset but before doing so you have to set the phone up so it does not restore previous apps so you can add them one at a time to see which one is impacting the Security Settings.  I will put that off for now and hope the next update fixes this.  I do not want to set everything up again so soon after investing so much time doing so just these past two days.

  • Z61p - Clear security Chip settings

    How do I clear the security Chip settings on my Z61p? I have looked in Bios and Client Security but can not see a 'Clear' option?
    Peter R Hawkes

    This options are normally hidden by the Z series BIOS - to activate this options:
    During Booting (after a full power off) press rapidly ESC + F1 or. F2 (I don't remember this at te moment it's either F1 or F2 - try it) !
    After entering The BIOS Setup There is an additional option in the security Menu to clear the TPM and the Fingerprint Data !
    WARNING!
    All your Passports will be lost !
    have pHun ;-)

  • Trash will only empty securely. How do I turn of secure empty trash?

    Trash will only empty securely.  Have repeatedly turned this off in Finder with no results.  Running Mountain Lion on intel iMac.  Advice much appreciated,
    Geo

    Back up all data. Don't continue unless you're sure you can restore from a backup, even if you're unable to log in.
    This procedure will unlock all your user files (not system files) and reset their ownership and access-control lists to the default. If you've set special values for those attributes on any of your files, they will be reverted. In that case, either stop here, or be prepared to recreate the settings if necessary. Do so only after verifying that those settings didn't cause the problem. If none of this is meaningful to you, you don't need to worry about it.
    Step 1
    If you have more than one user account, and the one in question is not an administrator account, then temporarily promote it to administrator status in the Users & Groups preference pane. To do that, unlock the preference pane using the credentials of an administrator, check the box marked Allow user to administer this computer, then reboot. You can demote the problem account back to standard status when this step has been completed.
    Triple-click the following line to select it. Copy the selected text to the Clipboard (command-C):
    { sudo chflags -R nouchg,nouappnd ~ $TMPDIR.. ; sudo chown -R $UID:staff ~ $_ ; sudo chmod -R u+rwX ~ $_ ; chmod -R -N ~ $_ ; } 2> /dev/null
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window (command-V). You'll be prompted for your login password, which won't be displayed when you type it. You may get a one-time warning to be careful. If you don’t have a login password, you’ll need to set one before you can run the command. If you see a message that your username "is not in the sudoers file," then you're not logged in as an administrator.
    The command will take a noticeable amount of time to run. Wait for a new line ending in a dollar sign (“$”) to appear, then quit Terminal.
    Step 2 (optional)
    Step 1 should give you usable permissions in your home folder. This step will restore special attributes set by OS X on some user folders to protect them from unintended deletion or renaming. You can skip this step if you don't consider that protection to be necessary, and if everything is working as expected after step 1.
    Boot into Recovery by holding down the key combination command-R at startup. Release the keys when you see a gray screen with a spinning dial.
    When the OS X Utilities screen appears, select
    Utilities ▹ Terminal
    from the menu bar. A Terminal window will open.
    In the Terminal window, type this:
    res
    Press the tab key. The partial command you typed will automatically be completed to this:
    resetpassword
    Press return. A Reset Password window will open. You’re not  going to reset a password.
    Select your boot volume ("Macintosh HD," unless you gave it a different name) if not already selected.
    Select your username from the menu labeled Select the user account if not already selected.
    Under Reset Home Directory Permissions and ACLs, click the Reset button.
    Select
     ▹ Restart
    from the menu bar.

  • Security Hardening of Publish server

    Hi,
    I noticed when the CQ Cloud creates a publish instance that it can be accessed via the public internet on port 4503
    Also, the anonymous user is granted access to /etc/*
    Obviously there is extra security hardening that needs to take place in cloud installs.  This would usually not be an issue as /etc/ would be behind firewalls (in your APP zone)
    Should the publish server's port 4503 be blocked in AWS, or is there specific details on hardening the permissions?
    Thanks

    Hey Tim,
    The documentation points out to this page as a portal for all hardening of CQ
    https://dev.day.com/docs/en/cq/current/deploying/security_checklist.html
    Hope this is what you ment.

  • How to secure program settings from children?

    How do I secure program settings from children so they don't change them.

    Check Settings > General > Restrictions > Apps
    Hopefully that will have what you need.

  • I have a iPhone 4 in recovery mode and it will not restore to factory settings.

    I have a iphone 4 in recovery mode and it will not restore to factory settings. I get the error message error 21 and 2001. What can I do? I have tried all the steps.

    Alextails998 wrote:
    I have tried all the steps.
    All what steps?
    Did you go through the troubleshooting information here: http://support.apple.com/kb/TS3694?viewlocale=en_US&locale=en_US
    Check for hardware issues
    Related errors: 1, 3, 10, 11, 12, 13, 14, 16, 20, 21, 23, 26, 27, 28, 29, 34, 35, 36, 37, 40, 1000, 1002, 1004, 1011, 1012, 1014, 1667, or 1669.
    Try to restore your iOS device two more times while connected with a cable, computer, and network you know are good. Also, confirm your security software and settings are allowing communication between your device and update servers. If you still see the error message when you update or restore, contact Apple support.
    and
    Check USB connections
    Related errors: 13, 14, 1600, 1601, 1602, 1603, 1604, 1611, 1643-1650, 2000, 2001, 2002, 2005, 2006, 2009, 4000, 4005, 4013, 4014, 4016, “invalid response,” and being prompted to restore again after a restore completes.
    If there’s an issue with the USB port, cable, dock, or hub, or if the device becomes disconnected during restore, try troubleshooting the USB connection, then troubleshooting your security software.
    To narrow down the issue, you can also change up your hardware:
    Use another USB cable.
    Plug your cable into a different USB port on your computer.
    Try a different dock connector (or no dock).
    Add (or remove) a USB hub between your device and computer.
    Connect your computer directly to your Internet source, with no routers, hubs, or switches.
    If you checked your connections and are still seeing the error message, check for hardware issues.
    If so, then it's a hardware problem. Make an appointment at the genius bar and get it replaced. Based on the "it was water damaged", I think it's a safe bet that it's toast.

  • Security hardening and Bastille for OSX

    I write to enquire if others have had positive experiences using Bastille security hardening on Mac OSX 10.4 Tiger. The project's website at http://www.bastille-linux.org/osx.html indicates there is a new version for Tiger and to wait two weeks, unless that is February 22nd, 2005. The year is not marked.
    It appears that the UN-install is thorough because the origianl config files are saved and replaced. However, I am concerned I will lose importnat functionality with the changes. I found using SELinux was troublesome with different linux distributions.
    Cheers,
    fellow

    Hello and Welcome to Apple Discussions ...
    Try resetting the System Management Controller: http://support.apple.com/kb/HT1543?viewlocale=en_US
    Carolyn

  • Secure shell in a whole root zone

    Hello,
    I have two whole root zones running on my Solaris 10 server along with the global zone. I am able to secure shell in to the global zone, but not the whole root zones. Secure shell does not appear to be running in the whole root zones. I've tried svcadm restart ssh in the whole root zones,but no luck. What do I need to do to get secure shell working on the whole root zones?

    to create the necessary keys -
    # ssh-keygen -b 1024 -t rsa1 -f /etc/ssh/ssh_host_key -N ""
    # ssh-keygen -b 1024 -t rsa -f /etc/ssh/ssh_host_rsa_key -N ""
    # ssh-keygen -b 1024 -t dsa -f /etc/ssh/ssh_host_dsa_key -N ""-- Nick

Maybe you are looking for