OpenSolaris

You are not signed in. Sign in or register.

OpenSolaris Community: Security

View the leaders for this community
Community Observers

Endorsed projects

What we cover:

Security projects in OpenSolaris: including but not limited to:

The technologies themselves and using them in other parts of the system.

  • Questions/FAQs/Docs on secure programming for OpenSolaris.
  • Place to discuss future/past/present security related changes for OpenSolaris. A place for Sun and the whole OpenSolaris community to share ideas for

improving OpenSolaris security.

The charter does NOT include:

A place to report security bugs/vulnerabilities in the binary Solaris product or other Sun products including the OpenSolaris source.

  • For security vulnerability information contact security dash alert at sun dot com for now. In the future we may have an opensolaris.org mail address for this.

We believe in full disclosure, but please don't send security vulnerability information to the security-discuss alias, due to agreements on responsible disclosure with groups such as CERT and other vendors it may be prudent to contact these discussions in a controlled manner with a reduced audience.

We have this process already documented on the SunSolve security pages.

Announcements

31 Jan 2008 UPDATE: Solaris Security Best Practices
02 Nov 2007 New Solaris Security Best Practices
25 Jan 2007 Crypto Project
30 Oct 2006 Trusted Extensions Developer Guide
31 May 2006 Google Summer of Code 2006

News

Multilevel Filesystems in Solaris Trusted Extensions | opensolaris.org | 07/21/2007

Glenn Faden presented a paper about the Multilevel Filesystems in Solaris Trusted Extensions at the 12th ACM symposium on Access control models and technologies. The paper is available at http://doi.acm.org/10.1145/1266840.1266859 or for your convenience, here: http://opensolaris.org/os/community/security/projects/tx/sacmat04s-faden-1.pdf

Comparitive Study of Containment Technologies | opensolaris.org | 06/14/2007

An interesting paper has been written by two Computer Science students, Magnus Eriksson and Staffan Palmroos, for their final thesis at Linköpings University in Sweden. The paper compares the use of Solaris zones, and SELinux Type Enforcement in implementing containment strategies. It explains the architectural elements of each system, and describes their experiences in deploying confined applications.

Google Summer of Code 2006 Results | opensolaris.org | 10/17/2006

The Google Summer of Code for 2006 has finished now and a copy of Johannes Nicolai's report is in the security community along with pointers to webrev's of the code changes.

Solaris Common Criteria Evaluation Updates | opensolaris.org | 06/27/2006

*Solaris 10 Release 11/06* and *Solaris Trusted Extensions* officially entered evaluation under the Common Criteria Certification Scheme. Solaris 10 11/06 will be evaluated against the *Controlled Access Protection Profile* and the *Role-Based Access Protection Profile*. The Solaris Trusted Extensions layer will be evaluated against the *Labeled Security Protection Profile*. Both products are seeking certification at the EAL4+ assurance level. The evaluation is being done in Canada by *CGI Information Systems and Management Consultants, Inc*. The products are listed under the Canadian Common Criteria web [Products in Evaluation](http://www.cse-cst.gc.ca/services/common-criteria/ongoing-evals-e.html) web site.

Blogs

bubbva - Biking to work & biking to save lives

May 14, 4:08 PM

This is a big week for bicycling and me, with Bike to Work Day coming up tomorrow (May 15) and my 65 mile ride for the American Lung Association on Saturday (May 17) . I'm excited about Bike to Work ...

darren - Worst (and Best) keyboards

May 9, 1:11 PM

Seems like for some reason I didn't actually post this when I wrote it on Jan 10th 2008, so I'll post it now I've just read over the PC World "10 Worst Keyboards of all time" article . Out of the 10 ...

darren - Missing Apple Mac hardware

May 9, 1:10 PM

My current home machine is a first generation (ordered the day after the announcement) PPC Mac Mini. I initially ordered it with 512Mb RAM and no WiFi or Bluetooth. It has since been upgraded to 1G ...

bubbva - Last Chance: Valerie in Best Little W****house in Texas!

May 8, 3:36 PM

Hi everyone! We're down to our last three performances for Best Little W****house in Texas with Actor's Theatre Center in th Historic Hoover Theater in San Jose. Reviews have been great, but ...

martin - The decay of the Swedish model

May 8, 11:05 AM

I just read a good blog entry about the decay of the Swedish model which touched on many subjects discussed during dinner today. People here (in Sweden) seem to think the someone else will take care ...