OpenSolaris

  subsites   code review   repo   packages   bugs   defect   polls   planet
You are not signed in. Sign in or register.

OpenSolaris Community: Security

View the leaders for this community
Community Observers

Endorsed projects

What we cover:

Security projects in OpenSolaris: including but not limited to:

The technologies themselves and using them in other parts of the system.

  • Questions/FAQs/Docs on secure programming for OpenSolaris.
  • Place to discuss future/past/present security related changes for OpenSolaris. A place for Sun and the whole OpenSolaris community to share ideas for

improving OpenSolaris security.

The charter does NOT include:

A place to report security bugs/vulnerabilities in the binary Solaris product or other Sun products including the OpenSolaris source.

  • For security vulnerability information contact security dash alert at sun dot com for now. In the future we may have an opensolaris.org mail address for this.

We believe in full disclosure, but please don't send security vulnerability information to the security-discuss alias, due to agreements on responsible disclosure with groups such as CERT and other vendors it may be prudent to contact these discussions in a controlled manner with a reduced audience.

We have this process already documented on the SunSolve security pages.

Announcements

31 Jan 2008 UPDATE: Solaris Security Best Practices
02 Nov 2007 New Solaris Security Best Practices
25 Jan 2007 Crypto Project
30 Oct 2006 Trusted Extensions Developer Guide
31 May 2006 Google Summer of Code 2006

News

Network Security Presentation- Shawn Emery | FROSUG Aug 2008 | 08/27/2008

Shawn Emery gave a Network Security presentation at the August 21st meeting to the Front Range OpenSolaris User Group (FROSUG) in Broomfield, CO. Presentation contains info about the Crypto Framework, SASL, Kerberos, PAM, OpenSSl, Java, IPsec/IKE, and SSH.

Cryptographic Framework - Wolfgang Ley | OSDevCon 2008 - Prague | 06/26/2008

Presentation of the Cryptographic Framework by Wolfgang Ley at the OpenSolaris Developer Conference in Prague. Click on the link to see a video of the presentation, the slides, and a paper.

Multilevel Filesystems in Solaris Trusted Extensions | opensolaris.org | 07/21/2007

Glenn Faden presented a paper about the Multilevel Filesystems in Solaris Trusted Extensions at the 12th ACM symposium on Access control models and technologies. The paper is available at http://doi.acm.org/10.1145/1266840.1266859 or for your convenience, here: http://opensolaris.org/os/community/security/projects/tx/sacmat04s-faden-1.pdf

Comparitive Study of Containment Technologies | opensolaris.org | 06/14/2007

An interesting paper has been written by two Computer Science students, Magnus Eriksson and Staffan Palmroos, for their final thesis at Linköpings University in Sweden. The paper compares the use of Solaris zones, and SELinux Type Enforcement in implementing containment strategies. It explains the architectural elements of each system, and describes their experiences in deploying confined applications.

Google Summer of Code 2006 Results | opensolaris.org | 10/17/2006

The Google Summer of Code for 2006 has finished now and a copy of Johannes Nicolai's report is in the security community along with pointers to webrev's of the code changes.

Blogs

darren - ZFS Crypto Codereview starts today

Sep 5, 9:49 AM

Prelim codereview for the OpenSolaris ZFS Crypto project starts today (Friday 5th September 2008 at 1200 US/Pacific) and is scheduled to end on Friday 3rd October 2008 at 2359 US/Pacific. Comments ...

darren - Using the Mercurial Forest extension for OpenSolaris onnv-gate

Sep 5, 5:18 AM

Some background This is really only relevant to those people doing development on the OpenSolaris onnv-gate that are inside Sun, but it since there is nothing private about it I'm posting it publicly ...

darren - Auditing shell commands

Sep 5, 5:08 AM

Via OSnews I came across a IBM article on KornShell 93 command auditing . Even before reading the article I viewed it with some caution. Why ? because you can't actually trust the shell to do what I ...

bubbva - With Great Anticipation!

Aug 29, 1:33 PM

I am on the edge of my seat with excitement about this year's Grace Hopper conference.  The first time I went was in 1997 in San Jose. I was a recent graduate from Purdue University and enjoying my ...

bubbva - Pat Mitchell talks to Sun Women!

Aug 26, 5:23 PM

I was so lucky to get to attend in person the talk by Pat Mitchell , a Sun board member, given to women at Sun a few weeks back. Ms Mitchell, an energetic and intelligent speaker, captivated the "in ...