# Sample listing of titan modules for a Server system # version 4.0.6 May 2 09:47:39 PDT 2001 # # This config file will only run in verify mode # Change all the -v flags to -f to fix things # quick way is to use vi and run; g/\ \-v/s//\ \-f/g # add-umask.sh -v # adjust-arp-timers2.8.sh -v # note aset should be run in medium on a server aset.sh -v # If automount is used; comment these out automount.sh -v automount2.sh -v # BSM allows for greater logging, but may be a performance problem. By default # Titan doesn't set up a lot of logging, read Sun blueprints on auditing for # more bsm.sh -v # Might want to just do a pkgrm of all the CDE and windows modules on a Server # unless the windows needs to be run locally (doubtful on a server) cde.sh -v create-issue.sh -v cronset.sh -v decode.sh -v defloginparams.sh -v defpwparams.sh -v disable-L1-A.sh -v disable-NFS-2.6.sh -v disable-accounts.sh -v disable-core-sol8.sh -v disable-ping-echo.sh -v disable-services.sh -v disable_ip_holes.sh -v # DMI is aprt of snmp; some servers use this dmi-2.6.sh -v eeprom.sh -v file-own.sh -v fix-cronpath.sh -v fix-modes.sh -v fix-stack.sol2.6.sh -v ftp-2.6_secure.sh -v ftpusers.sh -v hosts.equiv.sh -v # inetd.sh -v inetd2.sh -v # inetsvc might need to be modified for DNS or DHCP Servers # inetsvc.sh -v keyserv2.8.sh -v # Probably don't need to log all tcp connections on a server unless # you see an intrusion # log-tcp.sh -v login_failed_retries.sh -v loginlog.sh -v # if this is a lp server comment out the next line lpsched.sh -v nddconfig2.8.sh -v nfs-portmon.sh -v nsswitch.sh -v nuke-dtlogin.sh -v nuke-nfs-client.sh -v # if this is a nfs server comment out the next line nuke-nfs-serv.sh -v # the NSCD can be poisoned but assuming the server is firewalled off # we don't need to disable it # nuke-nscd.sh -v nuke-powerd.sh -v # You may need RPC services such as calendar or on SSP's if so comment out # the next line nuke-rpc.sh -v # On sendmail servers leave sendmail enabled by commenting out the next line nuke-sendmail.sh -v pam-rhosts-2.6.sh -v passwd.sh -v powerd2.8.sh -v psfix.sh -v rf_create-motd.sh -v rhosts.sh -v rmmount.sh -v rootchk.sh -v routed.sh -v sendmail-forward.sh -v sendmail.sh -v smtpbanner-8.8.sh -v snmpdx-2.6.sh -v sulog.sh -v syslog-block-remote.sh -v syslog.sh -v syslog_failed_logins.sh -v tcp-sequence.sh -v telnet-banner.sh -v # Note this may need to be increased to 1048 for hugh oracle databases tmpfs-fixsize.sh -v useraddset.sh -v userumask.sh -v utmp2.7.sh -v vold.sh -v # ziplock.sh -v