<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-417</id>
	<title>Nabble - Security - Sun</title>
	<updated>2009-11-20T16:07:11Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Security---Sun-f417.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security---Sun-f417.html" />
	<subtitle type="html"></subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26452535</id>
	<title>Replicating the Gonzalez Cyber Attacks through Penetration Testing</title>
	<published>2009-11-20T16:07:11Z</published>
	<updated>2009-11-20T16:07:11Z</updated>
	<author>
		<name>Norwich University</name>
	</author>
	<content type="html">--------------------------------------------------------------------------------
&lt;br&gt;YOU'RE INVITED: IT SECURITY ON DEMAND WEBCAST
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;quot;Replicating the Gonzalez Cyber Attacks through Penetration Testing&amp;quot;
&lt;br&gt;Register: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;---------------------------------------------------------------------------------
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Recently, we saw the indictment of cybercrime kingpin Albert Gonzalez, one of the accused masterminds behind high-profile data breaches at Heartland Payment Systems, Hannaford Bros. Supermarkets, 7-Eleven, and TJX. Next week, Core Security Technologies will present a hands-on look at the attacks Gonzalez and his co-conspirators are believed to have used in breaching these organizations.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Leveraging the actual indictment document as a guide, Core Security senior product manager Alex Horan will use CORE IMPACT Pro penetration testing software to demonstrate the techniques by which Gonzales allegedly stole millions of credit card numbers* - showing you how to identify IT exposures in your own environment before cybercriminals do.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;During the webcast, you'll see a step-by-step depiction of an attack similar to that described in the Gonzalez indictment, including the following critical stages:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;the initial web application compromise via SQL Injection
&lt;br&gt;* &amp;nbsp;the use of a well-known backend database command to make the attacks even
&lt;br&gt;* &amp;nbsp;more invasive
&lt;br&gt;* &amp;nbsp;the planting of malware on the backend database server
&lt;br&gt;* &amp;nbsp;the collection and transmission of credit card transactions to the
&lt;br&gt;* &amp;nbsp;attackers
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Through the demonstration, you'll also learn how commercial-grade penetration testing software enables you to see your IT systems as an attacker would -- not only by determining if the kinds of issues that Gonzalez reportedly leveraged are present in your environment, but also by ...
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;assessing how deployed defenses react to specific threats
&lt;br&gt;* &amp;nbsp;revealing what systems and data would be exposed by a breach
&lt;br&gt;* &amp;nbsp;depicting how chains of vulnerabilities open paths to mission-critical
&lt;br&gt;* &amp;nbsp;systems and information
&lt;br&gt;* &amp;nbsp;providing actionable data for immediately mitigating critical exposures
&lt;br&gt;* &amp;nbsp;repeating tests to ensure the effectiveness of remediation efforts
&lt;br&gt;&amp;nbsp;
&lt;br&gt;This webcast is ideal for anyone interested in proactively assessing their security posture against real-world cyber threats.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Replicating-the-Gonzalez-Cyber-Attacks-through-Penetration-Testing-tp26452535p26452535.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14331704</id>
	<title>Re: LDAP in Unix</title>
	<published>2007-12-14T00:08:01Z</published>
	<updated>2007-12-14T00:08:01Z</updated>
	<author>
		<name>technofin</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;We conduct regular courses on Sun Solaris for system administarators at Dubai and Bangalore,India.If you are interested,please revert back.
&lt;br&gt;Regards,
&lt;br&gt;Sreekumar.
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;dubaisans dubai wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;I have 100 + unix servers primarily Linux and solaris.
&lt;br&gt;&lt;br&gt;I am new to LDAP.
&lt;br&gt;&lt;br&gt;I would like to use Sun ONE Directory server and centralise the user
&lt;br&gt;&lt;br&gt;creation. Once I have LDAP based Directory server &amp;nbsp;is the following true?
&lt;br&gt;&lt;br&gt;1. Whenever a new user has to be created I will create on the SunOne
&lt;br&gt;&lt;br&gt;server and say it is valid only on this host(s).There is no need to
&lt;br&gt;create the user at the host
&lt;br&gt;&lt;br&gt;2. There is no /etc/passwd and &amp;nbsp;/etc/shadow files on the individual hosts
&lt;br&gt;&lt;br&gt;anymore or they are not of any importance. All the passwords are
&lt;br&gt;&lt;br&gt;stored only in the Directory server.
&lt;br&gt;&lt;br&gt;3. As a later stage I would like to give RSA securID authentication to
&lt;br&gt;selected set of high privilege users.
&lt;br&gt;&lt;br&gt;Is LDAP and Sun one the right direction?
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/LDAP-in-Unix-tp6538309p14331704.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12962724</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-09-29T22:26:53Z</published>
	<updated>2007-09-29T22:26:53Z</updated>
	<author>
		<name>belinda</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp;Do you know AyRecovery?it is a very good software which can fix system files missing, BSOD and so on in seconds.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Remove unwanted software, spyware, ad ware, spam software completely,you can choice the new software AyRecovery. www.ayrecovery.com
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Larry Cashdollar wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi,
&lt;br&gt;&amp;nbsp; &amp;nbsp;I am working on getting Solaris 2.7 compliant with the new DST changes for March 2007. &amp;nbsp;I downloaded the latest updates from:
&lt;br&gt;&lt;br&gt;wget ftp://elsie.nci.nih.gov/pub/tz*.tar.gz
&lt;br&gt;&lt;br&gt;Ran zic on northamerica
&lt;br&gt;Then tested with a zdump:
&lt;br&gt;&lt;br&gt;&lt;br&gt;zdump -v EST5EDT |grep 2007
&lt;br&gt;&lt;br&gt;&lt;br&gt;which still reported April when the DST would occur. &amp;nbsp;What am I missing? this worked for linux.
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p12962724.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12962716</id>
	<title>Re: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-09-29T22:25:44Z</published>
	<updated>2007-09-29T22:25:44Z</updated>
	<author>
		<name>belinda</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp;AyRecovery provides the protection without the need for backups or carrying duplicate images of hard drives. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; AyRecovery allows users to create a “snapshot” of the entire system and data at a specific time. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; Technically speaking, a snapshot is a map of the hard disk sectors and the map’s indexing system. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; Practically speaking, a snapshot is a “picture” of the system and data at a specific time. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; Users can select a specific snapshot to recover files from or restore the entire system to.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12962716.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12434743</id>
	<title>Check Point SmartCenter in Non-Global Zone</title>
	<published>2007-08-30T13:16:14Z</published>
	<updated>2007-08-30T13:16:14Z</updated>
	<author>
		<name>Crist J. Clark-2</name>
	</author>
	<content type="html">I would like to get a Check Point SmartCenter (the management
&lt;br&gt;server, not the firewall itself) software running in a non-
&lt;br&gt;global zone on Solaris 10. You would think this is not too
&lt;br&gt;hard. But it appears the Check Point licensing checks are once
&lt;br&gt;again making the paying customers' lives difficult. The
&lt;br&gt;SmartCenter keeps insisting that there is no valid license.
&lt;br&gt;It thinks the IP address on the zone does not match the IP
&lt;br&gt;address on the license. They do match. I just think the
&lt;br&gt;software cannot find the address in the non-global zone.
&lt;br&gt;&lt;br&gt;I've already gone to some Check Point forums and my VAR, and
&lt;br&gt;I am waiting on Check Point support (through the VAR), but
&lt;br&gt;I have not made progress. I thought I'd ask a Solaris crowd
&lt;br&gt;if they have experience or ideas with this. Is there a way to
&lt;br&gt;help the application figure out the IP address? Is there
&lt;br&gt;a way to get a &amp;quot;real&amp;quot; interface, bge1, in a non-global zone
&lt;br&gt;rather than what looks like a secondary, logical address,
&lt;br&gt;bge1:1? That would probably do it.
&lt;br&gt;&lt;br&gt;Solaris 10 06/06 and Check Point SmartCenter R65.
&lt;br&gt;-- 
&lt;br&gt;Crist J. Clark &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12434743&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cjclark@...&lt;/a&gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Check-Point-SmartCenter-in-Non-Global-Zone-tp12434743p12434743.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12039238</id>
	<title>RE: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-08-06T11:25:06Z</published>
	<updated>2007-08-06T11:25:06Z</updated>
	<author>
		<name>Edward Reiss</name>
	</author>
	<content type="html">&amp;nbsp;
&lt;br&gt;Christina,
&lt;br&gt;&lt;br&gt;We cannot use OpenSSH because our policies forbid us to use open source
&lt;br&gt;software with no support contract.
&lt;br&gt;&lt;br&gt;Anyway, we got it to work by specifying keyboard interactive in the
&lt;br&gt;/etc/ssh/sshd_config file. Now it works flawlessly. For some reason, RSA is
&lt;br&gt;unaware of this fix.
&lt;br&gt;&lt;br&gt;Thanks to all for their input, especially Reg Quinton and Asif Iqbal! Both
&lt;br&gt;of you pointed us in the right direction.
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cell
&lt;br&gt;631.681.7181
&lt;br&gt;Landline
&lt;br&gt;518.533.9764
&lt;br&gt;Fax
&lt;br&gt;631.881.5545
&lt;br&gt;Quis custodiet ipsos custodes?
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Christian Lete Viesca [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;clete@...&lt;/a&gt;] 
&lt;br&gt;Sent: Monday, August 06, 2007 12:41 PM
&lt;br&gt;To: Edward Reiss; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Subject: RE: SSHD with Secured authentication, using RSA PAM client
&lt;br&gt;&lt;br&gt;Hi Edward,
&lt;br&gt;&lt;br&gt;I have deployed Openssh aling with SecurID, Id recommend you to get openssh
&lt;br&gt;from sunfreeware, its very simple and straightforward to do it that way, is
&lt;br&gt;there a particula reason you are sticking to Solaris' ssh?
&lt;br&gt;&lt;br&gt;Cheers, 
&lt;br&gt;&lt;br&gt;&lt;br&gt;Christian Lete Viesca
&lt;br&gt;&lt;br&gt;UNIX/Jboss Administrator- IT Convergence Support Services
&lt;br&gt;&lt;br&gt;IT Convergence
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Toll-free USA: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[1] (800) 675-0032 Ext. 2652
&lt;br&gt;&lt;br&gt;International: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [1] (415) 675-7935 Ext. 2652
&lt;br&gt;&lt;br&gt;Argentina: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[54 11] 4000-8400 or 0800-122-4821 Ext. 2652
&lt;br&gt;&lt;br&gt;México: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 01-800-777-0051 Ext. 2652
&lt;br&gt;&lt;br&gt;Shanghai: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[86] (21) 6279-8030 Ext. 2652
&lt;br&gt;&lt;br&gt;Cell Phone: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[54 911] 62014732
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Email: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;clete@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Website: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.itconvergence.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.itconvergence.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Confidentiality Notice
&lt;br&gt;&lt;br&gt;The information transmitted in this email is intended only for the person or
&lt;br&gt;entity to which it is addressed and may contain confidential and/or
&lt;br&gt;privileged material from IT Convergence. Any review, retransmission,
&lt;br&gt;dissemination or other use of the information contained in this email by
&lt;br&gt;persons or entities other than the intended recipient is prohibited. If you
&lt;br&gt;are not the intended recipient, you are not authorized to forward or
&lt;br&gt;otherwise distribute this e-mail.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of Edward Reiss
&lt;br&gt;Sent: Tuesday, July 31, 2007 7:20 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Subject: SSHD with Secured authentication, using RSA PAM client
&lt;br&gt;&lt;br&gt;Greetings,
&lt;br&gt;&lt;br&gt;Has anyone got ssh to authenticate to SecureID? We have to use the version
&lt;br&gt;of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
&lt;br&gt;seems Solaris always tries to authenticate locally even after I configure
&lt;br&gt;pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work
&lt;br&gt;around. RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&lt;br&gt;Any help would be appreciated.
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039238&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cell
&lt;br&gt;631.681.7181
&lt;br&gt;Landline
&lt;br&gt;518.533.9764
&lt;br&gt;Fax
&lt;br&gt;631.881.5545
&lt;br&gt;Quis custodiet ipsos custodes?
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12039238.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12039073</id>
	<title>RE: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-08-06T10:40:46Z</published>
	<updated>2007-08-06T10:40:46Z</updated>
	<author>
		<name>Christian Lete Viesca</name>
	</author>
	<content type="html">Hi Edward,
&lt;br&gt;&lt;br&gt;I have deployed Openssh aling with SecurID, Id recommend you to get openssh from sunfreeware, its very simple and straightforward to do it that way, is there a particula reason you are sticking to Solaris' ssh?
&lt;br&gt;&lt;br&gt;Cheers, 
&lt;br&gt;&lt;br&gt;&lt;br&gt;Christian Lete Viesca
&lt;br&gt;&lt;br&gt;UNIX/Jboss Administrator- IT Convergence Support Services
&lt;br&gt;&lt;br&gt;IT Convergence
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Toll-free USA: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[1] (800) 675-0032 Ext. 2652
&lt;br&gt;&lt;br&gt;International: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [1] (415) 675-7935 Ext. 2652
&lt;br&gt;&lt;br&gt;Argentina: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[54 11] 4000-8400 or 0800-122-4821 Ext. 2652
&lt;br&gt;&lt;br&gt;México: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 01-800-777-0051 Ext. 2652
&lt;br&gt;&lt;br&gt;Shanghai: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[86] (21) 6279-8030 Ext. 2652
&lt;br&gt;&lt;br&gt;Cell Phone: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[54 911] 62014732
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Email: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039073&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;clete@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Website: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.itconvergence.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.itconvergence.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;Confidentiality Notice
&lt;br&gt;&lt;br&gt;The information transmitted in this email is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material from IT Convergence. Any review, retransmission, dissemination or other use of the information contained in this email by persons or entities other than the intended recipient is prohibited. If you are not the intended recipient, you are not authorized to forward or otherwise distribute this e-mail.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039073&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039073&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Edward Reiss
&lt;br&gt;Sent: Tuesday, July 31, 2007 7:20 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039073&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Subject: SSHD with Secured authentication, using RSA PAM client
&lt;br&gt;&lt;br&gt;Greetings,
&lt;br&gt;&lt;br&gt;Has anyone got ssh to authenticate to SecureID? We have to use the version of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It seems Solaris always tries to authenticate locally even after I configure pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work around. RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&lt;br&gt;Any help would be appreciated.
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039073&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cell
&lt;br&gt;631.681.7181
&lt;br&gt;Landline
&lt;br&gt;518.533.9764
&lt;br&gt;Fax
&lt;br&gt;631.881.5545
&lt;br&gt;Quis custodiet ipsos custodes?
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12039073.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12039021</id>
	<title>RE: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-08-06T10:04:11Z</published>
	<updated>2007-08-06T10:04:11Z</updated>
	<author>
		<name>Reg Quinton</name>
	</author>
	<content type="html">Edward, I don't know if this helps but we've had similar problems with RSA
&lt;br&gt;clients, OpenSSH servers and PAM (at least on earlier versions of OpenSSH).
&lt;br&gt;&lt;br&gt;If you're using the RSA SSH client and you specify &amp;quot;Authentication Method&amp;quot;
&lt;br&gt;as &amp;quot;password&amp;quot; that means traditional /etc/passwd an /etc/shadow file
&lt;br&gt;methods. As I recall to get PAM you need to specify &amp;quot;Keyboad Interactive&amp;quot;.
&lt;br&gt;Try that, it might help.
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039021&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039021&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of Edward Reiss
&lt;br&gt;Sent: July 31, 2007 6:20 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039021&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Subject: SSHD with Secured authentication, using RSA PAM client
&lt;br&gt;&lt;br&gt;Greetings,
&lt;br&gt;&lt;br&gt;Has anyone got ssh to authenticate to SecureID? We have to use the version
&lt;br&gt;of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
&lt;br&gt;seems Solaris always tries to authenticate locally even after I configure
&lt;br&gt;pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work
&lt;br&gt;around. RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&lt;br&gt;Any help would be appreciated.
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039021&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cell
&lt;br&gt;631.681.7181
&lt;br&gt;Landline
&lt;br&gt;518.533.9764
&lt;br&gt;Fax
&lt;br&gt;631.881.5545
&lt;br&gt;Quis custodiet ipsos custodes?
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12039021.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12038973</id>
	<title>Re: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-08-03T22:39:26Z</published>
	<updated>2007-08-03T22:39:26Z</updated>
	<author>
		<name>K Kadow</name>
	</author>
	<content type="html">On 7/31/07, Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12038973&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Has anyone got ssh to authenticate to SecureID? We have to use the version
&lt;br&gt;&amp;gt; of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
&lt;br&gt;&amp;gt; seems Solaris always tries to authenticate locally even after I configure
&lt;br&gt;&amp;gt; pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work
&lt;br&gt;&amp;gt; around.
&lt;br&gt;&lt;br&gt;I've set up a number of machines for SecurID authentication with ssh,
&lt;br&gt;but haven't tried it on any recent Solaris version.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt; RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&lt;br&gt;I believe you've answered your own question.
&lt;br&gt;&lt;br&gt;Kevin
&lt;br&gt;--
&lt;br&gt;Moderator, unofficial RSA ACE/Server + SecurID users group:
&lt;br&gt;&lt;a href=&quot;http://tech.groups.yahoo.com/group/securid-users/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tech.groups.yahoo.com/group/securid-users/&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12038973.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-12039191</id>
	<title>Re: SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-08-03T21:01:16Z</published>
	<updated>2007-08-03T21:01:16Z</updated>
	<author>
		<name>Asif Iqbal-9</name>
	</author>
	<content type="html">On 7/31/07, Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039191&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Greetings,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Has anyone got ssh to authenticate to SecureID? We have to use the version
&lt;br&gt;&amp;gt; of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
&lt;br&gt;&lt;br&gt;&amp;nbsp;- You have make sure your sshd is pam enabled.
&lt;br&gt;&amp;nbsp; ldd `which sshd` should &amp;nbsp;have libpam in there.
&lt;br&gt;&lt;br&gt;- man sshd_config. Depending on your sshd_config file you need enable
&lt;br&gt;&amp;nbsp; either one of the two `UsePAM' or `PAMAuthenticationViaKBDInt'
&lt;br&gt;&lt;br&gt;We enabled the radius daemon on our SecurID ACE server (RSA) and using
&lt;br&gt;pam_radius (of Freeradius) instead. If you choose that path you need to
&lt;br&gt;pick a radius secret key and need to add that key for your client on
&lt;br&gt;ACE database.
&lt;br&gt;&lt;br&gt;Most of our servers using some flavor of ssh (openssh or sunssh or
&lt;br&gt;ssh) and pam_radius
&lt;br&gt;It basically prompts for Password: (you put your passcode here). We
&lt;br&gt;also have sudo
&lt;br&gt;with pam enabled. So there is no local password needed for users.
&lt;br&gt;&lt;br&gt;These are files I needed to modify
&lt;br&gt;- /etc/raddb/server (only can access raddb dir)
&lt;br&gt;- /etc/pam.conf - just two extra lines; one for sshd and one for sudo
&lt;br&gt;- /etc/ssh/sshd_config OR /usr/local/etc/sshd_config
&lt;br&gt;&lt;br&gt;&amp;gt; seems Solaris always tries to authenticate locally even after I configure
&lt;br&gt;&lt;br&gt;It has nothing to do with Solaris. It is SSHD that you need to configure right.
&lt;br&gt;&lt;br&gt;&amp;gt; pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work
&lt;br&gt;&amp;gt; around. RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;The problem is not ssh difference. It is all handled by pam. Both
&lt;br&gt;SunSSH and OpenSSH
&lt;br&gt;knows how to communicate with PAM if they are compiled with pam library.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Any help would be appreciated.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=12039191&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cell
&lt;br&gt;&amp;gt; 631.681.7181
&lt;br&gt;&amp;gt; Landline
&lt;br&gt;&amp;gt; 518.533.9764
&lt;br&gt;&amp;gt; Fax
&lt;br&gt;&amp;gt; 631.881.5545
&lt;br&gt;&amp;gt; Quis custodiet ipsos custodes?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Asif Iqbal
&lt;br&gt;PGP Key: 0xE62693C5 KeyServer: pgp.mit.edu
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p12039191.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-11992862</id>
	<title>SSHD with Secured authentication, using RSA PAM client</title>
	<published>2007-07-31T16:19:44Z</published>
	<updated>2007-07-31T16:19:44Z</updated>
	<author>
		<name>Edward Reiss</name>
	</author>
	<content type="html">Greetings,
&lt;br&gt;&lt;br&gt;Has anyone got ssh to authenticate to SecureID? We have to use the version
&lt;br&gt;of sshd included with Solaris 9, 1.0.1, and we cannot get it to work. It
&lt;br&gt;seems Solaris always tries to authenticate locally even after I configure
&lt;br&gt;pam.conf. RSA has a &amp;quot;work around&amp;quot; but they do not support even the work
&lt;br&gt;around. RSA will support OpenSSH, but not the sshd included with Solaris.
&lt;br&gt;&lt;br&gt;Any help would be appreciated.
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;Edward Reiss &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11992862&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ed.reiss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cell
&lt;br&gt;631.681.7181
&lt;br&gt;Landline
&lt;br&gt;518.533.9764
&lt;br&gt;Fax
&lt;br&gt;631.881.5545
&lt;br&gt;Quis custodiet ipsos custodes?
&lt;br&gt;&lt;br&gt;_______________________________
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSHD-with-Secured-authentication%2C-using-RSA-PAM-client-tp11992862p11992862.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10973390</id>
	<title>SSL Cert for patchpro.sun.com Invalid?</title>
	<published>2007-06-04T15:46:32Z</published>
	<updated>2007-06-04T15:46:32Z</updated>
	<author>
		<name>Eoin Miller</name>
	</author>
	<content type="html">In our IDS logs, I saw some of our servers making some outgoing 
&lt;br&gt;connections over SSL wrapped HTTP. So, being curious, I decided to see 
&lt;br&gt;where they were going. The connections were going to patchpro.sun.com, 
&lt;br&gt;but the SSL certificate being used for this site is signed by Sun's 
&lt;br&gt;internal certificate authority and the site its self displays the 
&lt;br&gt;default Apache page. This happens for both the FQDN and the IP address 
&lt;br&gt;URL's:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;https://192.18.108.39/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://192.18.108.39/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;https://patchpro.sun.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://patchpro.sun.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Without digging to much deeper, my mind has begun wondering. Do systems 
&lt;br&gt;with support contracts download patches from this system over SSL 
&lt;br&gt;wrapped HTTP without a 3rd party validated certificate? Does the update 
&lt;br&gt;client even attempt to validate the certificate that is being presented 
&lt;br&gt;to it prior to downloading and installing patches? Perhaps Solaris 
&lt;br&gt;already has the Sun Microsystems Inc CA (Class B) certificate authority 
&lt;br&gt;public certificate installed and trusted 
&lt;br&gt;(&lt;a href=&quot;https://www.sun.com/pki/ca/smicacert.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.sun.com/pki/ca/smicacert.html&lt;/a&gt;). Hmm.... I wonder. Guess I 
&lt;br&gt;need to build a box and screw around with it. Anyone else have any in 
&lt;br&gt;depth knowledge on this matter? Something seems a little weird here. 
&lt;br&gt;Generally you don't see default Apache pages sitting around on major 
&lt;br&gt;sites unless some kind of misconfiguration is happening.
&lt;br&gt;&lt;br&gt;Here is a copy (Base64 encoded) of the certificate currently being 
&lt;br&gt;presented by &lt;a href=&quot;https://patchpro.sun.com:&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://patchpro.sun.com:&lt;/a&gt;&lt;br&gt;-----BEGIN CERTIFICATE-----
&lt;br&gt;MIIEETCCAvmgAwIBAgIEFAAQbTANBgkqhkiG9w0BAQUFADBLMSowKAYDVQQDEyFT
&lt;br&gt;dW4gTWljcm9zeXN0ZW1zIEluYyBDQSAoQ2xhc3MgQikxHTAbBgNVBAoTFFN1biBN
&lt;br&gt;aWNyb3N5c3RlbXMgSW5jMB4XDTAyMDkxOTIyNTgzN1oXDTA3MDkxODIyNTgzN1ow
&lt;br&gt;OjEdMBsGA1UEChMUU3VuIE1pY3Jvc3lzdGVtcyBJbmMxGTAXBgNVBAMTEHBhdGNo
&lt;br&gt;cHJvLnN1bi5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANdGSE7Usa2R
&lt;br&gt;lsHnJoJzY4yQvkp2uWlyAzg6y+Z/Ex8mBH0cjhmIjNCUH1A7072ubA9PzwG/VCE2
&lt;br&gt;EDvO7gOjDKn8UAuvykiQNEirS+OfVgpQpvl8P6AgydQVE8Rbyxx27UwrWuFS6SEZ
&lt;br&gt;KhHtyTYjKx4eEQJZO/GdZg5UvTjndmE3AgMBAAGjggGQMIIBjDAOBgNVHQ8BAf8E
&lt;br&gt;BAMCBaAwHQYDVR0OBBYEFIPdShEhWpzZy4SOp+n+JTWMImdvMEcGA1UdIARAMD4w
&lt;br&gt;PAYLYIZIAYb3AIN9k18wLTArBggrBgEFBQcCARYfaHR0cDovL3d3dy5zdW4uY29t
&lt;br&gt;L3BraS9jcHMuaHRtbDCBhQYDVR0fBH4wfDB6oCegJYYjaHR0cDovL3d3dy5zdW4u
&lt;br&gt;Y29tL3BraS9wa2lzbWljYS5jcmyiT6RNMEsxKjAoBgNVBAMTIVN1biBNaWNyb3N5
&lt;br&gt;c3RlbXMgSW5jIENBIChDbGFzcyBCKTEdMBsGA1UEChMUU3VuIE1pY3Jvc3lzdGVt
&lt;br&gt;cyBJbmMwHwYDVR0jBBgwFoAUT7ZnqR/EEBSgG6h1wdYMI5RiiWswVAYIKwYBBQUH
&lt;br&gt;AQEESDBGMB0GCCsGAQUFBzABhhFodHRwOi8vdmEuc3VuLmNvbTAlBggrBgEFBQcw
&lt;br&gt;AYYZaHR0cDovL3ZhLmNlbnRyYWwuc3VuLmNvbTATBgNVHSUEDDAKBggrBgEFBQcD
&lt;br&gt;ATANBgkqhkiG9w0BAQUFAAOCAQEAo8QI/x1PKIhrw3GtyeZyty8QHzcKQQNXT3fX
&lt;br&gt;CXo9P094mIIwwFqk3cHYA8HWd65ieKihwTRYM9FQo8ZajeANI6Y2m2iJ2smHM5p/
&lt;br&gt;tnSmnkh9DYFbwvE9pm8fLoKD8ZMKgGUeeI74h77Cni6A+1quOCzcL+605aHDmhqg
&lt;br&gt;/R4OXSXMUkXpOOyHczdPgDPAyHeTM9MH8w71zyIjOoNVfiyRAY/2mtvq9kVYvOo1
&lt;br&gt;NYexlU+x7u6dFjScuVf3RiXdAIwSmLlR3OlO7+zDlMRThiclv2ldrfQQbMQS6OhA
&lt;br&gt;+2dN9luEiI93yO7CsPPcFlZR+JkqFAWOndz94XvdzAhB/V1MLA==
&lt;br&gt;-----END CERTIFICATE-----
&lt;br&gt;&lt;br&gt;--Eoin Miller
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SSL-Cert-for-patchpro.sun.com-Invalid--tp10973390p10973390.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10626021</id>
	<title>BSM Audit - system call argument</title>
	<published>2007-05-15T10:15:12Z</published>
	<updated>2007-05-15T10:15:12Z</updated>
	<author>
		<name>nvk</name>
	</author>
	<content type="html">&lt;br&gt;hello ....
&lt;br&gt;&lt;br&gt;If anybody knows about sun's bsm audit
&lt;br&gt;record format, please help me.
&lt;br&gt;&lt;br&gt;I am not able to understand how an audit
&lt;br&gt;record for system call can have duplicate
&lt;br&gt;token for the same system call argument.
&lt;br&gt;For example - 
&lt;br&gt;&lt;br&gt;header,182,2,ioctl(2),,Mon Jun 01 07:56:56 1998, + 788290611 msec
&lt;br&gt;path,/devices/pseudo/cn@0:console
&lt;br&gt;attribute,20620,2122,tty,8388608,11409,0
&lt;br&gt;argument,2,0x7415,cmd
&lt;br&gt;argument,3,0xeffff2b0,arg
&lt;br&gt;argument,2,0x501cd434,strioctl:vnode
&lt;br&gt;subject,2122,root,other,root,other,273,258,0 0 pascal.eyrie.af.mil
&lt;br&gt;return,success,0
&lt;br&gt;trailer,182
&lt;br&gt;&lt;br&gt;Above, token argument 2 is repeated.
&lt;br&gt;I dint find anything in the BSM guide on
&lt;br&gt;sun's site.
&lt;br&gt;&lt;br&gt;I would highly appreciate it if anybody
&lt;br&gt;could throw any light on this.
&lt;br&gt;&lt;br&gt;Regards,</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/BSM-Audit---system-call-argument-tp10626021p10626021.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10219498</id>
	<title>Re: Sun Application Server Drop Privs</title>
	<published>2007-04-26T04:54:05Z</published>
	<updated>2007-04-26T04:54:05Z</updated>
	<author>
		<name>Alexander Klimov</name>
	</author>
	<content type="html">On Wed, 25 Apr 2007, haim [howard] roman wrote:
&lt;br&gt;&amp;gt; Regarding (b), even if you run the server as root, you can change the
&lt;br&gt;&amp;gt; owners &amp;/or groups of the files so that non-root users can change them.
&lt;br&gt;&lt;br&gt;It may happen that controlling configuration files is enough to force
&lt;br&gt;the application to do nasty things (e.g., reading /etc/shadow, or even
&lt;br&gt;overwriting it). If an application is run as root, the result can be
&lt;br&gt;that you allow the one who controls the configuration files to do this
&lt;br&gt;nasty things.
&lt;br&gt;&lt;br&gt;If your only problem is the ports, you could run the server on some
&lt;br&gt;other ports (say, 20080 instead of 80) and use ipf to redirect 80 to
&lt;br&gt;20080.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Regards,
&lt;br&gt;ASK
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Application-Server-Drop-Privs-tp10163109p10219498.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10182928</id>
	<title>Re: Sun Application Server Drop Privs</title>
	<published>2007-04-25T06:41:40Z</published>
	<updated>2007-04-25T06:41:40Z</updated>
	<author>
		<name>Haim (Howard) Roman</name>
	</author>
	<content type="html">Regarding (b), even if you run the server as root, you can change the
&lt;br&gt;owners &amp;/or groups of the files so that non-root users can change them.
&lt;br&gt;&lt;br&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
&lt;br&gt;Haim (Howard) Roman
&lt;br&gt;Computer Center, Jerusalem College of Technology
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182928&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;roman@...&lt;/a&gt;
&lt;br&gt;Phone: 052-8-592-599 (6022 from within Machon Lev)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-------- Original Message &amp;nbsp;--------
&lt;br&gt;Subject: Sun Application Server Drop Privs
&lt;br&gt;From: Crist J. Clark &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182928&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cristclark@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182928&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Date: Tue 24 Apr 2007 03:11:02 AM IDT
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; We're using Sun Java System Application Server 8.1. I know
&lt;br&gt;&amp;gt; the software is designed so it can be run as a non-root user,
&lt;br&gt;&amp;gt; but right now, we have to run it as root since it binds to ports
&lt;br&gt;&amp;gt; 80/tcp and 443/tcp.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I've hit SunSolve, docs.sun.com, and Google, but can't seem to
&lt;br&gt;&amp;gt; find out how to get it to drop privs to a non-root user after
&lt;br&gt;&amp;gt; grabbing the low-numbered ports. Anyone know how to do this?
&lt;br&gt;&amp;gt; I'd rather (a) not have this monster run as root if it doesn't
&lt;br&gt;&amp;gt; have to and (b) not have the web app developers have to get a
&lt;br&gt;&amp;gt; sys admin to make changes as root for them whenever they want
&lt;br&gt;&amp;gt; to tweak some file.
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Application-Server-Drop-Privs-tp10163109p10182928.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10182844</id>
	<title>RE: Sun Application Server Drop Privs</title>
	<published>2007-04-24T09:41:11Z</published>
	<updated>2007-04-24T09:41:11Z</updated>
	<author>
		<name>Tony UcedaVelez-2</name>
	</author>
	<content type="html">Have you tried creating a properties file or editing the existing properties
&lt;br&gt;file that contains the environment variables associated with launching the
&lt;br&gt;app server? &amp;nbsp;I know for the Sun Proxy server you can create a properties
&lt;br&gt;page that contains the user that will run the service as well as the ports
&lt;br&gt;to which it will bind to. &amp;nbsp;The properties file may be accessed by root, but
&lt;br&gt;privs will be dropped to the user defined within the config file.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Tony UcedaVélez, CISM, CISA, GIAC
&lt;br&gt;Managing Partner
&lt;br&gt;VerSprite, LLC
&lt;br&gt;(office) 678.938.3434
&lt;br&gt;(email) &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182844&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tonyuv@...&lt;/a&gt;
&lt;br&gt;(web) &amp;nbsp; www.versprite.com
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182844&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182844&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On
&lt;br&gt;Behalf Of Crist J. Clark
&lt;br&gt;Sent: Monday, April 23, 2007 8:11 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182844&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;
&lt;br&gt;Subject: Sun Application Server Drop Privs
&lt;br&gt;&lt;br&gt;We're using Sun Java System Application Server 8.1. I know
&lt;br&gt;the software is designed so it can be run as a non-root user,
&lt;br&gt;but right now, we have to run it as root since it binds to ports
&lt;br&gt;80/tcp and 443/tcp.
&lt;br&gt;&lt;br&gt;I've hit SunSolve, docs.sun.com, and Google, but can't seem to
&lt;br&gt;find out how to get it to drop privs to a non-root user after
&lt;br&gt;grabbing the low-numbered ports. Anyone know how to do this?
&lt;br&gt;I'd rather (a) not have this monster run as root if it doesn't
&lt;br&gt;have to and (b) not have the web app developers have to get a
&lt;br&gt;sys admin to make changes as root for them whenever they want
&lt;br&gt;to tweak some file.
&lt;br&gt;-- 
&lt;br&gt;Crist J. Clark &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182844&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cjclark@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Application-Server-Drop-Privs-tp10163109p10182844.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10182764</id>
	<title>Re: Sun Application Server Drop Privs</title>
	<published>2007-04-24T09:36:45Z</published>
	<updated>2007-04-24T09:36:45Z</updated>
	<author>
		<name>Stephen Hauskins</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;If the main issue is your webservers then what should happen
&lt;br&gt;is that the initial run as root should get reassigned to
&lt;br&gt;the webserver owner, i.e. nobody, web, etc.
&lt;br&gt;&lt;br&gt;Stephen Hauskins
&lt;br&gt;Divisional Liaison
&lt;br&gt;Academic Computing Group
&lt;br&gt;Division of Physical and Biological Sciences
&lt;br&gt;&lt;br&gt;We can't solve problems by using the same kind of thinking we used
&lt;br&gt;when we created them. &amp;nbsp; Albert Einstein
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Mon, 23 Apr 2007, Crist J. Clark wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; We're using Sun Java System Application Server 8.1. I know
&lt;br&gt;&amp;gt; the software is designed so it can be run as a non-root user,
&lt;br&gt;&amp;gt; but right now, we have to run it as root since it binds to ports
&lt;br&gt;&amp;gt; 80/tcp and 443/tcp.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I've hit SunSolve, docs.sun.com, and Google, but can't seem to
&lt;br&gt;&amp;gt; find out how to get it to drop privs to a non-root user after
&lt;br&gt;&amp;gt; grabbing the low-numbered ports. Anyone know how to do this?
&lt;br&gt;&amp;gt; I'd rather (a) not have this monster run as root if it doesn't
&lt;br&gt;&amp;gt; have to and (b) not have the web app developers have to get a
&lt;br&gt;&amp;gt; sys admin to make changes as root for them whenever they want
&lt;br&gt;&amp;gt; to tweak some file.
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Crist J. Clark &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10182764&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cjclark@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Application-Server-Drop-Privs-tp10163109p10182764.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10163109</id>
	<title>Sun Application Server Drop Privs</title>
	<published>2007-04-23T18:11:02Z</published>
	<updated>2007-04-23T18:11:02Z</updated>
	<author>
		<name>Crist J. Clark-2</name>
	</author>
	<content type="html">We're using Sun Java System Application Server 8.1. I know
&lt;br&gt;the software is designed so it can be run as a non-root user,
&lt;br&gt;but right now, we have to run it as root since it binds to ports
&lt;br&gt;80/tcp and 443/tcp.
&lt;br&gt;&lt;br&gt;I've hit SunSolve, docs.sun.com, and Google, but can't seem to
&lt;br&gt;find out how to get it to drop privs to a non-root user after
&lt;br&gt;grabbing the low-numbered ports. Anyone know how to do this?
&lt;br&gt;I'd rather (a) not have this monster run as root if it doesn't
&lt;br&gt;have to and (b) not have the web app developers have to get a
&lt;br&gt;sys admin to make changes as root for them whenever they want
&lt;br&gt;to tweak some file.
&lt;br&gt;-- 
&lt;br&gt;Crist J. Clark &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10163109&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cjclark@...&lt;/a&gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Application-Server-Drop-Privs-tp10163109p10163109.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10036524</id>
	<title>Re: Sun Studio 11: C++ 5.8 Compiler</title>
	<published>2007-04-17T00:53:42Z</published>
	<updated>2007-04-17T00:53:42Z</updated>
	<author>
		<name>Jonathan Leffler</name>
	</author>
	<content type="html">focus-sun Digest 16 Apr 2007 17:18:39 -0000 Issue 372
&lt;br&gt;&lt;br&gt;Sun Studio 11: C++ 5.8 Compiler
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1456 by: neelabhsharma1.gmail.com
&lt;br&gt;&lt;br&gt;[...]
&lt;br&gt;&lt;br&gt;As per the specifications the compiler should be based on C99. But i think 
&lt;br&gt;it still does not handle the function call strtoll(). This issue did not 
&lt;br&gt;arise with RHL 9.0
&lt;br&gt;&lt;br&gt;If it did the handling properly then the result of the program should not 
&lt;br&gt;be 0.
&lt;br&gt;&lt;br&gt;&lt;br&gt;/*Snippet of the Code */
&lt;br&gt;#include&amp;lt;stdio.h&amp;gt;
&lt;br&gt;#include&amp;lt;stdlib.h&amp;gt;
&lt;br&gt;&lt;br&gt;int main()
&lt;br&gt;{
&lt;br&gt;char *a = &amp;quot;89abcdef&amp;quot;;
&lt;br&gt;long long int c;
&lt;br&gt;a[8] = '\0';
&lt;br&gt;c = strtoll(a, NULL, 16); 
&lt;br&gt;printf(&amp;quot;the num is %8x&amp;quot;, c); 
&lt;br&gt;return 0;
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;&lt;br&gt;My understanding of the OS, Platform (SPARC), ofcourse C is just of a 
&lt;br&gt;beginner and am eager to learn, please provide supporting comments..
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;[JL:
&lt;br&gt;Did you say C or C++? &amp;nbsp;C++ is still based on the 1998 C++ standard, which 
&lt;br&gt;in turn is based on C90 and not on C99. &amp;nbsp;Hence things like long long are 
&lt;br&gt;(most likely) not part of the base C++ configuration - it is likely that 
&lt;br&gt;you would have to enable such extensions in C++ by special options. &amp;nbsp;{That 
&lt;br&gt;was a guess - investigation shows it is a wrong guess...read on.}
&lt;br&gt;&lt;br&gt;Which bits of the manual did you read?
&lt;br&gt;&lt;br&gt;Tested on Solaris 10 with
&lt;br&gt;Black JL: cc -V
&lt;br&gt;cc: Sun C 5.8 2005/10/13
&lt;br&gt;usage: cc [ options] files. &amp;nbsp;Use 'cc -flags' for details
&lt;br&gt;Black JL: CC -V
&lt;br&gt;CC: Sun C++ 5.8 2005/10/13
&lt;br&gt;&lt;br&gt;Also, the code must be fixed - %8x prints an integer, not a long long int, 
&lt;br&gt;so the format string needs to end &amp;quot;%8llx\n&amp;quot;.
&lt;br&gt;&lt;br&gt;The C compiler is fine with the fixed code. &amp;nbsp; The C++ compiler says:
&lt;br&gt;&lt;br&gt;CC -O x.c -o x &amp;&amp; ./x
&lt;br&gt;&amp;quot;x.c&amp;quot;, line 6: Warning: String literal converted to char* in 
&lt;br&gt;initialization.
&lt;br&gt;1 Warning(s) detected.
&lt;br&gt;Segmentation Fault(coredump)
&lt;br&gt;&lt;br&gt;Hmmm...that's because you try to modify the string literal at x[8] = '\0' 
&lt;br&gt;- which is a pointless exercise (the value is already '\0'). &amp;nbsp;The warning 
&lt;br&gt;is because it should be a const char * you assign to. &amp;nbsp;With that fixed, 
&lt;br&gt;even CC compiles it and runs it OK.
&lt;br&gt;&lt;br&gt;So, you don't even have to enable long long in CC - it just works with 
&lt;br&gt;correct code.
&lt;br&gt;]
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Jonathan Leffler (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10036524&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jleffler@...&lt;/a&gt;)
&lt;br&gt;STSM, Informix Database Engineering, IBM Information Management Division
&lt;br&gt;4100 Bohannon Drive, Menlo Park, CA 94025-1013
&lt;br&gt;Tel: +1 650-926-6921 &amp;nbsp; &amp;nbsp;Tie-Line: 630-6921
&lt;br&gt;&amp;quot;I don't suffer from insanity; I enjoy every minute of it!&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Studio-11%3A-C%2B%2B-5.8-Compiler-tp10019849p10036524.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10036424</id>
	<title>Re: Sun Studio 11: C++ 5.8 Compiler</title>
	<published>2007-04-16T12:05:47Z</published>
	<updated>2007-04-16T12:05:47Z</updated>
	<author>
		<name>Steven Leikeim</name>
	</author>
	<content type="html">On Mon, Apr 16, 2007 at 01:22:07AM -0000, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10036424&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;neelabhsharma1@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; As per the specifications the compiler should be based on C99. But i think it still does not handle the function call strtoll(). This issue did not arise with RHL 9.0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; If it did the handling properly then the result of the program should not be 0.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; /*Snippet of the Code */
&lt;br&gt;&amp;gt; #include&amp;lt;stdio.h&amp;gt;
&lt;br&gt;&amp;gt; #include&amp;lt;stdlib.h&amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; int main()
&lt;br&gt;&amp;gt; {
&lt;br&gt;&amp;gt; char *a = &amp;quot;89abcdef&amp;quot;;
&lt;br&gt;&amp;gt; long long int c;
&lt;br&gt;&amp;gt; a[8] = '\0';
&lt;br&gt;&amp;gt; c = strtoll(a, NULL, 16); 
&lt;br&gt;&amp;gt; printf(&amp;quot;the num is %8x&amp;quot;, c); 
&lt;br&gt;&amp;gt; return 0;
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; My understanding of the OS, Platform (SPARC), ofcourse C is just of a beginner and am eager to learn, please provide supporting comments..
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;This is consistent with Sun WorkShop 6 and gcc 3.4.2 (Both on Solaris/Sparc).
&lt;br&gt;Gcc 3.4.5 on Linux (Intel) appears to do what you were expecting, but actually
&lt;br&gt;does not. If you change the &amp;quot;char a...&amp;quot; definition to a hex value longer than
&lt;br&gt;8 characters you will not see the last 8 characters on Sparc. On Intel you will
&lt;br&gt;only see the last 8 characters. This is due to differences in byte ordering on
&lt;br&gt;these processors.
&lt;br&gt;&lt;br&gt;The problem is in your printf format. %8x expects to print something of type
&lt;br&gt;&amp;quot;int&amp;quot;. Most current compilers specify type &amp;quot;int&amp;quot; to be the same as &amp;quot;long int&amp;quot;
&lt;br&gt;which is 32 bits. &amp;quot;long long int&amp;quot; is 64 bits. What is happening here is you
&lt;br&gt;are printing the first 32 bits of the argument. If you use the correctly
&lt;br&gt;typed format string &amp;quot;%8llx&amp;quot;, you should see the correct value printed in all
&lt;br&gt;cases.
&lt;br&gt;&lt;br&gt;I hope this helps your understanding of what has happened here.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Steven Leikeim
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Steven Leikeim, GSEC-Gold &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | We, the willing
&lt;br&gt;Department of Electrical and Computer &amp;nbsp; &amp;nbsp; | led by the unknowing
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Engineering &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| are doing the impossible
&lt;br&gt;Schulich School of Engineering &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| for the ungrateful.
&lt;br&gt;University of Calgary &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | We have done so much
&lt;br&gt;Calgary, Alberta &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| for so long with so little
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | we are now qualified
&lt;br&gt;Phone: (403) 220-5373 Fax: (403) 282-6855 | to do anything with nothing.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Studio-11%3A-C%2B%2B-5.8-Compiler-tp10019849p10036424.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10036370</id>
	<title>Re: Sun Studio 11: C++ 5.8 Compiler</title>
	<published>2007-04-16T11:22:38Z</published>
	<updated>2007-04-16T11:22:38Z</updated>
	<author>
		<name>Michael T Pins</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10036370&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;neelabhsharma1@...&lt;/a&gt; writes:
&lt;br&gt;&lt;br&gt;&amp;gt;As per the specifications the compiler should be based on C99. But i think it still does not handle the function call strtoll(). This issue did not arise with RHL 9.0
&lt;br&gt;&lt;br&gt;&amp;gt;If it did the handling properly then the result of the program should not be 0.
&lt;br&gt;&lt;br&gt;By &amp;quot;result of the program&amp;quot; I assume you mean the output of the printf
&lt;br&gt;command. &amp;nbsp;As your code is broken (and lint will show you where), the output
&lt;br&gt;is undefined. &amp;nbsp;Fix your code and the output becomes what you expect.
&lt;br&gt;&lt;br&gt;&amp;gt;/*Snippet of the Code */
&lt;br&gt;&amp;gt;#include&amp;lt;stdio.h&amp;gt;
&lt;br&gt;&amp;gt;#include&amp;lt;stdlib.h&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;gt;int main()
&lt;br&gt;&amp;gt;{
&lt;br&gt;&amp;gt;char *a = &amp;quot;89abcdef&amp;quot;;
&lt;br&gt;&amp;gt;long long int c;
&lt;br&gt;&amp;gt;a[8] = '\0';
&lt;br&gt;&amp;gt;c = strtoll(a, NULL, 16); 
&lt;br&gt;&amp;gt;printf(&amp;quot;the num is %8x&amp;quot;, c); 
&lt;br&gt;&amp;gt;return 0;
&lt;br&gt;&amp;gt;}
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Michael T Pins &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|	&amp;quot;A year from now I'd be surprised if
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=10036370&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mtpins@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|	there's not some grand square in Baghdad
&lt;br&gt;keeper of the nn sources &amp;nbsp; &amp;nbsp;|	that is named after President Bush.&amp;quot;
&lt;br&gt;ftp://ftp.nndev.org/pub &amp;nbsp; &amp;nbsp; |	-Richard Perle, 9/22/03
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Studio-11%3A-C%2B%2B-5.8-Compiler-tp10019849p10036370.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-10019849</id>
	<title>Sun Studio 11: C++ 5.8 Compiler</title>
	<published>2007-04-15T19:22:07Z</published>
	<updated>2007-04-15T19:22:07Z</updated>
	<author>
		<name>neelabhsharma1</name>
	</author>
	<content type="html">As per the specifications the compiler should be based on C99. But i think it still does not handle the function call strtoll(). This issue did not arise with RHL 9.0
&lt;br&gt;&lt;br&gt;If it did the handling properly then the result of the program should not be 0.
&lt;br&gt;&lt;br&gt;&lt;br&gt;/*Snippet of the Code */
&lt;br&gt;#include&amp;lt;stdio.h&amp;gt;
&lt;br&gt;#include&amp;lt;stdlib.h&amp;gt;
&lt;br&gt;&lt;br&gt;int main()
&lt;br&gt;{
&lt;br&gt;char *a = &amp;quot;89abcdef&amp;quot;;
&lt;br&gt;long long int c;
&lt;br&gt;a[8] = '\0';
&lt;br&gt;c = strtoll(a, NULL, 16); 
&lt;br&gt;printf(&amp;quot;the num is %8x&amp;quot;, c); 
&lt;br&gt;return 0;
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;&lt;br&gt;My understanding of the OS, Platform (SPARC), ofcourse C is just of a beginner and am eager to learn, please provide supporting comments..
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks and Regards 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sun-Studio-11%3A-C%2B%2B-5.8-Compiler-tp10019849p10019849.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-9370549</id>
	<title>Re: Dealing with BSM Audit Logs</title>
	<published>2007-03-08T00:36:45Z</published>
	<updated>2007-03-08T00:36:45Z</updated>
	<author>
		<name>auditd</name>
	</author>
	<content type="html">&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Crist J. Clark-2 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Anyway, I am in search of tools to deal with audit logs. For
&lt;br&gt;example, I suspect that this noise is from ufsdump/restore,
&lt;br&gt;but this is hard to back out. It'd be sweet to have a tool
&lt;br&gt;where I could pull out all of the logs related to a process,
&lt;br&gt;including its children, and look at them. Something interactive
&lt;br&gt;would be so-o cool. Using auditreduce(1M) and praudit(1M) with
&lt;br&gt;grep, perl, and awk only goes so far, especially when it
&lt;br&gt;comes to GBs of logs.
&lt;br&gt;&lt;br&gt;Are there tools out there for this? Any leads, from Sun, free
&lt;br&gt;stuff, your scripts, or third-party commercial, would help.
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
We are working on an audit trail tool which will be available as beta shortly:
&lt;br&gt;&lt;a href=&quot;http://auditanalyzer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://auditanalyzer.com/&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Dealing-with-BSM-Audit-Logs-tp6907955p9370549.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-9014288</id>
	<title>Sol DST issues - revisited</title>
	<published>2007-02-16T10:21:25Z</published>
	<updated>2007-02-16T10:21:25Z</updated>
	<author>
		<name>Andy_Bach</name>
	</author>
	<content type="html">Just a note, Amy Rich, in the Q&amp;A section of Sys Admin:
&lt;br&gt;&lt;a href=&quot;http://www.samag.com/documents/s=10118/sam0703j/0703j.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.samag.com/documents/s=10118/sam0703j/0703j.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;gives a list of fixes - including Java updates needed and firmware patches 
&lt;br&gt;for various Sun boxes.
&lt;br&gt;&lt;br&gt;a
&lt;br&gt;&lt;br&gt;Andy Bach
&lt;br&gt;Systems Mangler
&lt;br&gt;Internet: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=9014288&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andy_bach@...&lt;/a&gt;
&lt;br&gt;VOICE: (608) 261-5738 &amp;nbsp;FAX 264-5932
&lt;br&gt;&lt;br&gt;&amp;quot;Procrastination is like putting lots and lots of commas in the sentence 
&lt;br&gt;of your life.&amp;quot;
&lt;br&gt;Ze Frank 
&lt;br&gt;&lt;a href=&quot;http://lifehacker.com/software/procrastination/ze-frank-on-procrastination-235859.php&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lifehacker.com/software/procrastination/ze-frank-on-procrastination-235859.php&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Sol-DST-issues---revisited-tp9014288p9014288.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8869492</id>
	<title>Re: Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-02-06T08:52:41Z</published>
	<updated>2007-02-06T08:52:41Z</updated>
	<author>
		<name>Challie</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;Ron Jack (Systems Network) wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This seems to work for us for US/Eastern (note - no changes to existing 
&lt;br&gt;&amp;gt; zdump/zic):
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 3) edit /usr/share/lib/zoneinfo/northamerica.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Zone &amp;nbsp; &amp;nbsp;EST5EDT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-5:00 &amp;nbsp;US &amp;nbsp; &amp;nbsp; &amp;nbsp;E%sT &amp;lt;-- yank this line. paste 
&lt;br&gt;&amp;gt; below.
&lt;br&gt;&amp;gt; Zone &amp;nbsp; &amp;nbsp;Eastern &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-5:00 &amp;nbsp;US &amp;nbsp; &amp;nbsp; &amp;nbsp;E%sT &amp;lt;-- change to &amp;quot;Eastern&amp;quot;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;I am a little unclear with step 3.
&lt;br&gt;Do I yank the line and copy it. &amp;nbsp;Then modify it, to now have two (2) lines
&lt;br&gt;representing that zone (I am in Central)? &amp;nbsp;With the Eastern ahead of the
&lt;br&gt;ESTDST?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;View this message in context: &lt;a href=&quot;http://www.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tf2955037.html#a8829564&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tf2955037.html#a8829564&lt;/a&gt;&lt;br&gt;Sent from the Security - Sun mailing list archive at Nabble.com.
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8869492.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8754777</id>
	<title>Re: Solaris 2.7 Daylight saving time fix</title>
	<published>2007-01-31T08:37:12Z</published>
	<updated>2007-01-31T08:37:12Z</updated>
	<author>
		<name>Casper.Dik</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt;The specification that I can find (SUS3 at Open Group) leaves it 
&lt;br&gt;&amp;gt;completely unspecified what rules might apply to the switch between winter 
&lt;br&gt;&amp;gt;and summer (or standard and daylight saving) times. &amp;nbsp;It shows how to set 
&lt;br&gt;&amp;gt;the rule by including the information in the TZ variable, but it does not 
&lt;br&gt;&amp;gt;state what the rule is in the absence of a specific setting.
&lt;br&gt;&lt;br&gt;I misremembered this. &amp;nbsp;But remember that in the old zoneinfo files
&lt;br&gt;GMT+/-xx was defined backward and using such timezones would result
&lt;br&gt;in non-POSIX compliant timestamps. &amp;nbsp;(GMT+5 was interpreted as POSIX GMT-5
&lt;br&gt;and vice versa)
&lt;br&gt;&lt;br&gt;It appears we stopped shipping those in Solaris 2.4 so I guess it's about time
&lt;br&gt;that we removed the hardcoded defaults from libc and rely on the rule
&lt;br&gt;files from now on.
&lt;br&gt;&lt;br&gt;(And make it so that changes to the rule files do not require a reboot)
&lt;br&gt;&lt;br&gt;Casper
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Solaris-2.7-Daylight-saving-time-fix-tp8732334p8754777.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8732334</id>
	<title>Re: Solaris 2.7 Daylight saving time fix</title>
	<published>2007-01-30T19:12:22Z</published>
	<updated>2007-01-30T19:12:22Z</updated>
	<author>
		<name>Jonathan Leffler</name>
	</author>
	<content type="html">Casper Dik &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8732334&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;casper.dik@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;The POSIX standard *requires* that the ?STx?DT format precludes
&lt;br&gt;&amp;gt;the use of zone files.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Any OS which uses the zoneinfo files is not compliant when the $TZ
&lt;br&gt;&amp;gt;variable can be parsed under the POSIX rules.
&lt;br&gt;&lt;br&gt;Please can you indicate chapter and verse in POSIX where it says that?
&lt;br&gt;&lt;br&gt;The specification that I can find (SUS3 at Open Group) leaves it 
&lt;br&gt;completely unspecified what rules might apply to the switch between winter 
&lt;br&gt;and summer (or standard and daylight saving) times. &amp;nbsp;It shows how to set 
&lt;br&gt;the rule by including the information in the TZ variable, but it does not 
&lt;br&gt;state what the rule is in the absence of a specific setting.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Quoting some standard (Base Definitions, Environment Variables)
&lt;br&gt;&lt;br&gt;&lt;br&gt;TZ
&lt;br&gt;This variable shall represent timezone information. The contents of the 
&lt;br&gt;environment variable named TZ shall be used by the ctime(), localtime(), 
&lt;br&gt;strftime(), mktime(), ctime_r(), and localtime_r() functions, and by 
&lt;br&gt;various utilities, to override the default timezone. The value of TZ has 
&lt;br&gt;one of the two forms (spaces inserted for clarity): 
&lt;br&gt;:characters
&lt;br&gt;or:
&lt;br&gt;std offset dst offset, rule
&lt;br&gt;If TZ is of the first format (that is, if the first character is a colon), 
&lt;br&gt;the characters following the colon are handled in an 
&lt;br&gt;implementation-defined manner.
&lt;br&gt;The expanded format (for all TZ s whose value does not have a colon as the 
&lt;br&gt;first character) is as follows:
&lt;br&gt;stdoffset[dst[offset][,start[/time],end[/time]]]
&lt;br&gt;Where:
&lt;br&gt;std and dst
&lt;br&gt;Indicate no less than three, nor more than {TZNAME_MAX}, bytes that are 
&lt;br&gt;the designation for the standard ( std) or the alternative ( dst -such as 
&lt;br&gt;Daylight Savings Time) timezone. Only std is required; if dst is missing, 
&lt;br&gt;then the alternative time does not apply in this locale. 
&lt;br&gt;Each of these fields may occur in either of two formats quoted or 
&lt;br&gt;unquoted:
&lt;br&gt;In the quoted form, the first character shall be the less-than ( '&amp;lt;' ) 
&lt;br&gt;character and the last character shall be the greater-than ( '&amp;gt;' ) 
&lt;br&gt;character. All characters between these quoting characters shall be 
&lt;br&gt;alphanumeric characters from the portable character set in the current 
&lt;br&gt;locale, the plus-sign ( '+' ) character, or the minus-sign ( '-' ) 
&lt;br&gt;character. The std and dst fields in this case shall not include the 
&lt;br&gt;quoting characters.
&lt;br&gt;In the unquoted form, all characters in these fields shall be alphabetic 
&lt;br&gt;characters from the portable character set in the current locale.
&lt;br&gt;The interpretation of these fields is unspecified if either field is less 
&lt;br&gt;than three bytes (except for the case when dst is missing), more than 
&lt;br&gt;{TZNAME_MAX} bytes, or if they contain characters other than those 
&lt;br&gt;specified.
&lt;br&gt;offset
&lt;br&gt;Indicates the value added to the local time to arrive at Coordinated 
&lt;br&gt;Universal Time. The offset has the form: 
&lt;br&gt;hh[:mm[:ss]]
&lt;br&gt;The minutes ( mm) and seconds ( ss) are optional. The hour ( hh) shall be 
&lt;br&gt;required and may be a single digit. The offset following std shall be 
&lt;br&gt;required. If no offset follows dst, the alternative time is assumed to be 
&lt;br&gt;one hour ahead of standard time. One or more digits may be used; the value 
&lt;br&gt;is always interpreted as a decimal number. The hour shall be between zero 
&lt;br&gt;and 24, and the minutes (and seconds)-if present-between zero and 59. The 
&lt;br&gt;result of using values outside of this range is unspecified. If preceded 
&lt;br&gt;by a '-', the timezone shall be east of the Prime Meridian; otherwise, it 
&lt;br&gt;shall be west (which may be indicated by an optional preceding '+' ).
&lt;br&gt;rule
&lt;br&gt;Indicates when to change to and back from the alternative time. The rule 
&lt;br&gt;has the form: 
&lt;br&gt;date[/time],date[/time]
&lt;br&gt;where the first date describes when the change from standard to 
&lt;br&gt;alternative time occurs and the second date describes when the change back 
&lt;br&gt;happens. Each time field describes when, in current local time, the change 
&lt;br&gt;to the other time is made.
&lt;br&gt;The format of date is one of the following:
&lt;br&gt;Jn
&lt;br&gt;The Julian day n (1 &amp;lt;= n &amp;lt;= 365). Leap days shall not be counted. That is, 
&lt;br&gt;in all years-including leap years-February 28 is day 59 and March 1 is day 
&lt;br&gt;60. It is impossible to refer explicitly to the occasional February 29.
&lt;br&gt;n
&lt;br&gt;The zero-based Julian day (0 &amp;lt;= n &amp;lt;= 365). Leap days shall be counted, and 
&lt;br&gt;it is possible to refer to February 29.
&lt;br&gt;Mm.n.d
&lt;br&gt;The d'th day (0 &amp;lt;= d &amp;lt;= 6) of week n of month m of the year (1 &amp;lt;= n &amp;lt;= 5, 
&lt;br&gt;1 &amp;lt;= m &amp;lt;= 12, where week 5 means &amp;quot;the last d day in month m&amp;quot; which may 
&lt;br&gt;occur in either the fourth or the fifth week). Week 1 is the first week in 
&lt;br&gt;which the d'th day occurs. Day zero is Sunday.
&lt;br&gt;The time has the same format as offset except that no leading sign ( '-' 
&lt;br&gt;or '+' ) is allowed. The default, if time is not given, shall be 02:00:00.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Jonathan Leffler (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8732334&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jleffler@...&lt;/a&gt;)
&lt;br&gt;STSM, Informix Database Engineering, IBM Information Management Division
&lt;br&gt;4100 Bohannon Drive, Menlo Park, CA 94025-1013
&lt;br&gt;Tel: +1 650-926-6921 &amp;nbsp; &amp;nbsp;Tie-Line: 630-6921
&lt;br&gt;&amp;quot;I don't suffer from insanity; I enjoy every minute of it!&amp;quot;
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Solaris-2.7-Daylight-saving-time-fix-tp8732334p8732334.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8718869</id>
	<title>Re: BSM, SSH, and Session ID</title>
	<published>2007-01-30T13:47:49Z</published>
	<updated>2007-01-30T13:47:49Z</updated>
	<author>
		<name>Crist J. Clark-2</name>
	</author>
	<content type="html">On Fri, Jan 26, 2007 at 08:03:04PM -0500, Jalex wrote:
&lt;br&gt;&amp;gt; Solaris BSM makes more sense. &amp;nbsp;I didn't realize it was the praudit xml 
&lt;br&gt;&amp;gt; output.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Are you logging in as root through ssh or is that just the way it is 
&lt;br&gt;&amp;gt; logging it?
&lt;br&gt;&lt;br&gt;Yes. The particular example below is a &amp;quot;forced command&amp;quot;
&lt;br&gt;assocaited with a specific &amp;quot;authorized key.&amp;quot; Root cannot
&lt;br&gt;log in except &amp;quot;without password&amp;quot; and all authorized keys
&lt;br&gt;have forced commands for some specific tasks.
&lt;br&gt;&lt;br&gt;&amp;gt; I can't recall how Sun SSH on Solaris 9 behaves but recent versions of 
&lt;br&gt;&amp;gt; Sun SSH/OpenSSH should fork off before the login because the sshd 
&lt;br&gt;&amp;gt; process that a user is connected to after authentication runs with their 
&lt;br&gt;&amp;gt; privileges, not root's. &amp;nbsp;It should always be a different session, even 
&lt;br&gt;&amp;gt; if the user login is root.
&lt;br&gt;&lt;br&gt;Something like that is going on, but it's not turning out
&lt;br&gt;how I would expect. Here's the process tree,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;sshd
&lt;br&gt;&amp;nbsp; [26065]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| \
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp;sh -c locale -a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp;[26066]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; \
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;locale -a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;|\ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[26067]
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| \
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp;sshd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp;[26068] 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; \
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ksh -c etc/security/sox_baseline
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[26069]
&lt;br&gt;&amp;nbsp;(auditon) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; \...
&lt;br&gt;(ssh - login)
&lt;br&gt;&lt;br&gt;So, we start with the sshd child spawned by the listening daemon,
&lt;br&gt;26065. It runs the locale command. Then it spins off another
&lt;br&gt;child, 26068. This child runs the forced command and all of
&lt;br&gt;those children sprout off of that branch. The parent sshd doesn't
&lt;br&gt;call auditon, log the login, or change the session ID until
&lt;br&gt;_after_ it's forked the child doing all of the work.
&lt;br&gt;&lt;br&gt;I've trussed sshd, but it just made my head hurt more.
&lt;br&gt;&lt;br&gt;What gets annoying in other cases is that if the user logging
&lt;br&gt;in is non-root, the &amp;quot;audit user&amp;quot; is root for all of the children
&lt;br&gt;processes doing the work, like 26068 in this case, and the
&lt;br&gt;&amp;quot;do nothing&amp;quot; main sshd process is the one that gets its audit
&lt;br&gt;user changed to the user loging in. I end up with a bunch of
&lt;br&gt;logs that I don't want.
&lt;br&gt;&lt;br&gt;&amp;gt; Are you just auditing the root user?
&lt;br&gt;&lt;br&gt;For all exec's and fork's, yes, just root.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;Crist J. Clark wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;I am trying to write a script that does the following:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;	1) Finds all root logins and su's to root.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;	2) Tracks all commands run after that login.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;	3) Associates each command with its login.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;Sounds easy, huh? Devil's in the details.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;Current method of attack is to find all of the su's and logins,
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;and save the session ID. Then I can go through and pick out the
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;'exec' events with that session ID and run as root. My old
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;method was to follow all of the forks from a login. It was not
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pretty, but seemed to work most of the time. I thought following
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;session IDs would be more robust and less error prone.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;But I have a audit trail here that is confounding my best
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;efforts. What we have is a &amp;quot;forced&amp;quot; SSH command. There are a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;few problems with the trail. First, it looks like it starts
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;forking children before the login. Second, the login has a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;different session ID than its children. I'm a bit confused
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;about what is going on here. Here's the audit trail. It's in
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;XML format. I find that easier to read with the labels.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;What's killing me is that the login (the 'login - ssh' event)
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;has a different session ID that its children (the 'exec(2)'
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;of 'ksh -c /etc/security/sox_baseline'). Bug? Feature? Do I
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;need to revert to my old method? This is Solaris 9 using
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;the Sun SSH daemon.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;?xml version='1.0' encoding='UTF-8' ?&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;?xml-stylesheet type='text/xsl' 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;href='file:///usr/share/lib/xml/style/adt_record.xsl.1' ?&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;!DOCTYPE audit PUBLIC '-//Sun Microsystems, Inc.//DTD Audit V1//EN' 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;'file:///usr/share/lib/xml/dtd/adt_record.dtd.1'&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;audit&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;file time=&amp;quot;Thu Jan 11 10:46:19 PST 2007&amp;quot; msec=&amp;quot;0&amp;quot;&amp;gt;&amp;lt;/file&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;vfork(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;731&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;argument arg-num=&amp;quot;0&amp;quot; value=&amp;quot;0x5e02&amp;quot; desc=&amp;quot;child PID&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;execve(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;2007&amp;quot; msec=&amp;quot;732&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;path&amp;gt;/usr/bin/sh&amp;lt;/path&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;attribute mode=&amp;quot;100555&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; fsid=&amp;quot;136&amp;quot; nodeid=&amp;quot;8469&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;device=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;exec_args&amp;gt;&amp;lt;arg&amp;gt;sh&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;-c&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;/usr/bin/locale -a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/arg&amp;gt;&amp;lt;/exec_args&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24066&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;fork(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;741&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;argument arg-num=&amp;quot;0&amp;quot; value=&amp;quot;0x5e03&amp;quot; desc=&amp;quot;child PID&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24066&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;execve(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;2007&amp;quot; msec=&amp;quot;764&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;path&amp;gt;/usr/bin/locale&amp;lt;/path&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;attribute mode=&amp;quot;100555&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;bin&amp;quot; fsid=&amp;quot;136&amp;quot; nodeid=&amp;quot;347411&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;device=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;exec_args&amp;gt;&amp;lt;arg&amp;gt;/usr/bin/locale&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;-a
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/arg&amp;gt;&amp;lt;/exec_args&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24067&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;exit(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;800&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24067&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;exit(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:19 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;801&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24066&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;fork(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;548&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;argument arg-num=&amp;quot;0&amp;quot; value=&amp;quot;0x5e04&amp;quot; desc=&amp;quot;child PID&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;auditon(2) - get audit state&amp;quot; time=&amp;quot;Thu Jan 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;11 10:46:21 PST 2007&amp;quot; msec=&amp;quot;557&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;getaudit_addr(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;PST 2007&amp;quot; msec=&amp;quot;557&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;auditon(2) - get audit policy flags&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;time=&amp;quot;Thu Jan 11 10:46:21 PST 2007&amp;quot; msec=&amp;quot;557&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;root&amp;quot; ruid=&amp;quot;root&amp;quot; rgid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;login - ssh&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 PST 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;2007&amp;quot; msec=&amp;quot;568&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;other&amp;quot; ruid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;rgid=&amp;quot;other&amp;quot; pid=&amp;quot;24065&amp;quot; sid=&amp;quot;3603920788&amp;quot; tid=&amp;quot;11953 196630 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;fork(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 PST 2007&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;msec=&amp;quot;583&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;argument arg-num=&amp;quot;0&amp;quot; value=&amp;quot;0x5e05&amp;quot; desc=&amp;quot;child PID&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;other&amp;quot; ruid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;rgid=&amp;quot;other&amp;quot; pid=&amp;quot;24068&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;execve(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 PST 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;2007&amp;quot; msec=&amp;quot;598&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;path&amp;gt;/usr/bin/ksh&amp;lt;/path&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;attribute mode=&amp;quot;100555&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;bin&amp;quot; fsid=&amp;quot;136&amp;quot; nodeid=&amp;quot;42497&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;device=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;exec_args&amp;gt;&amp;lt;arg&amp;gt;ksh&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;-c&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;/etc/security/sox_baseline
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/arg&amp;gt;&amp;lt;/exec_args&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;other&amp;quot; ruid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;rgid=&amp;quot;other&amp;quot; pid=&amp;quot;24069&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;record version=&amp;quot;2&amp;quot; event=&amp;quot;execve(2)&amp;quot; time=&amp;quot;Thu Jan 11 10:46:21 PST 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;2007&amp;quot; msec=&amp;quot;614&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;path&amp;gt;/etc/security/sox_baseline&amp;lt;/path&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;attribute mode=&amp;quot;100755&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;other&amp;quot; fsid=&amp;quot;136&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;nodeid=&amp;quot;64371&amp;quot; device=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;exec_args&amp;gt;&amp;lt;arg&amp;gt;/bin/sh&amp;lt;/arg&amp;gt;&amp;lt;arg&amp;gt;/etc/security/sox_baseline
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/arg&amp;gt;&amp;lt;/exec_args&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;subject audit-uid=&amp;quot;root&amp;quot; uid=&amp;quot;root&amp;quot; gid=&amp;quot;other&amp;quot; ruid=&amp;quot;root&amp;quot; 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;rgid=&amp;quot;other&amp;quot; pid=&amp;quot;24069&amp;quot; sid=&amp;quot;3539585011&amp;quot; tid=&amp;quot;11953 196630 
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;spa.example.com&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;return errval=&amp;quot;success&amp;quot; retval=&amp;quot;0&amp;quot;/&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;lt;/record&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;Crist J. Clark &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8718869&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cjclark@...&lt;/a&gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/BSM%2C-SSH%2C-and-Session-ID-tp8527870p8718869.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8718825</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-30T10:00:10Z</published>
	<updated>2007-01-30T10:00:10Z</updated>
	<author>
		<name>Andy_Bach</name>
	</author>
	<content type="html">&amp;gt; The cheesy file copy update appears to work for non-POSIX time zones.
&lt;br&gt;&lt;br&gt;% &amp;nbsp;zdump -v US/Pacific | egrep 2007
&lt;br&gt;&lt;br&gt;The regular process works for &amp;quot;US/Pacific&amp;quot; as does the standard Sol zdump 
&lt;br&gt;- its only the POSIX ?STX?DT format that the original Sun zdump won't do 
&lt;br&gt;correctly. &amp;nbsp;Casper from Sun says this is the way its supposed to be in 
&lt;br&gt;that format is hard coded into some lib and that lib is not being updated 
&lt;br&gt;(yet). &amp;nbsp;But the &amp;quot;Olson&amp;quot; format (&amp;quot;US/xxxxx&amp;quot;) works as does most anything 
&lt;br&gt;that makes zdump go to the zoneinfo file. The POSIX format isn't supposed 
&lt;br&gt;to and won't be fixed (for the pre-10 Sol zdump) until the appropriate 
&lt;br&gt;library is updated. &amp;nbsp;I don't know what lib that is though.
&lt;br&gt;&lt;br&gt;a
&lt;br&gt;&lt;br&gt;Andy Bach
&lt;br&gt;Systems Mangler
&lt;br&gt;Internet: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8718825&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andy_bach@...&lt;/a&gt;
&lt;br&gt;VOICE: (608) 261-5738 &amp;nbsp;FAX 264-5932
&lt;br&gt;&lt;br&gt;If GM had developed technology like Microsoft:
&lt;br&gt;5. Only one person at a time could use the car, unless you bought 'Car95' 
&lt;br&gt;&amp;nbsp; &amp;nbsp;or 'CarNT', and then added more seats.
&lt;br&gt;&lt;a href=&quot;http://www.snopes.com/humor/jokes/autos.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.snopes.com/humor/jokes/autos.asp&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8718825.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8711977</id>
	<title>RE: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-29T19:18:29Z</published>
	<updated>2007-01-29T19:18:29Z</updated>
	<author>
		<name>Riddle, Bruce (Bruce) %</name>
	</author>
	<content type="html">Terix seems to be handing out a patch for free:
&lt;br&gt;&lt;a href=&quot;http://www.terix.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.terix.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;It looks to me as it doesn't fix Sun's zdump or zic,
&lt;br&gt;but it is in patch format so you can check your showrev -p output.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Andy_Bach@...&lt;/a&gt;
&lt;br&gt;Sent: Monday, January 29, 2007 11:37 AM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Casper.Dik@...&lt;/a&gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;casper@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;daniel.raymer@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Solaris 2.7 Daylight saving time fix.
&lt;br&gt;&lt;br&gt;&amp;gt; The POSIX standard *requires* that the ?STx?DT format precludes
&lt;br&gt;the use of zone files.
&lt;br&gt;&lt;br&gt;&amp;gt; Any OS which uses the zoneinfo files is not compliant when the $TZ
&lt;br&gt;variable can be parsed under the POSIX rules.
&lt;br&gt;&lt;br&gt;Okay, well the NIH zdump (and, as it happens, the Sol 10 zdump.c I got
&lt;br&gt;to compile on Sol 2.7), &amp;quot;trussed&amp;quot; shows:
&lt;br&gt;open(&amp;quot;/usr/share/lib/zoneinfo/GMT&amp;quot;, O_RDONLY) &amp;nbsp; = 3
&lt;br&gt;open(&amp;quot;/usr/share/lib/zoneinfo/CST6CDT&amp;quot;, O_RDONLY) = 3
&lt;br&gt;&lt;br&gt;So I guess the reason it 'works' is its not properly POSIX ... so the
&lt;br&gt;question (to my mind) remains - where does Sol's POSIX-valid zdump get
&lt;br&gt;its TZ info? &amp;nbsp;From a library file? &amp;nbsp;That would be the one we need to
&lt;br&gt;update.
&lt;br&gt;&lt;br&gt;a
&lt;br&gt;&lt;br&gt;Andy Bach
&lt;br&gt;Systems Mangler
&lt;br&gt;Internet: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711977&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andy_bach@...&lt;/a&gt;
&lt;br&gt;VOICE: (608) 261-5738 &amp;nbsp;FAX 264-5932
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Although few may originate a policy, we are all able to judge it.
&lt;br&gt;&amp;nbsp; &amp;nbsp; Pericles of Athens, c.430 B.C.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8711977.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8711919</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-29T17:25:47Z</published>
	<updated>2007-01-29T17:25:47Z</updated>
	<author>
		<name>Keith Farrar</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8711919&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;daniel.raymer@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt; Sadly, this script still leaves me with zdump -v showing April 1st for DST changeover.
&lt;br&gt;&lt;br&gt;&lt;br&gt;The cheesy file copy update appears to work for non-POSIX time zones.
&lt;br&gt;&lt;br&gt;% &amp;nbsp;zdump -v US/Pacific | egrep 2007
&lt;br&gt;US/Pacific &amp;nbsp;Tue Jan 30 01:20:52 2007 GMT = Mon Jan 29 17:20:52 2007 PST isdst=0
&lt;br&gt;US/Pacific &amp;nbsp;Sun Mar 11 09:59:59 2007 GMT = Sun Mar 11 01:59:59 2007 PST isdst=0
&lt;br&gt;US/Pacific &amp;nbsp;Sun Mar 11 10:00:00 2007 GMT = Sun Mar 11 03:00:00 2007 PDT isdst=1
&lt;br&gt;US/Pacific &amp;nbsp;Sun Nov &amp;nbsp;4 08:59:59 2007 GMT = Sun Nov &amp;nbsp;4 01:59:59 2007 PDT isdst=1
&lt;br&gt;US/Pacific &amp;nbsp;Sun Nov &amp;nbsp;4 09:00:00 2007 GMT = Sun Nov &amp;nbsp;4 01:00:00 2007 PST isdst=0
&lt;br&gt;&lt;br&gt;% date -u
&lt;br&gt;Tue Jan 30 01:21:11 GMT 2007
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8711919.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8697674</id>
	<title>RES: Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-29T11:16:39Z</published>
	<updated>2007-01-29T11:16:39Z</updated>
	<author>
		<name>Cleverson de Freitas Ferla</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;-----Mensagem original-----
&lt;br&gt;De: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] Em
&lt;br&gt;nome de &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Andy_Bach@...&lt;/a&gt;
&lt;br&gt;Enviada em: sexta-feira, 26 de janeiro de 2007 16:43
&lt;br&gt;Para: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;daniel.raymer@...&lt;/a&gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-sun@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;
&lt;br&gt;Assunto: Re: Re: Solaris 2.7 Daylight saving time fix.
&lt;br&gt;&lt;br&gt;&amp;gt; Sadly, this script still leaves me with zdump -v showing April 1st for 
&lt;br&gt;DST changeover.
&lt;br&gt;&lt;br&gt;Yeah, it appears you need to do a couple things - one is change from the 
&lt;br&gt;old school &amp;quot;?STx?DT&amp;quot; &amp;nbsp;TZ format (to US/Central for example) and the other 
&lt;br&gt;is to ditch the solaris zdump for the nih one. &amp;nbsp;I'm still hoping for a 
&lt;br&gt;response but it was indicated that Sun holds that the ?STx?DT format 
&lt;br&gt;precludes using any zoneinfo files - not sure where it gets the info then 
&lt;br&gt;(one of libc or libdl? time()?) but ....
&lt;br&gt;&lt;br&gt;Not sure if the &amp;quot;problem&amp;quot; extends beyond just zdump, that is, what other 
&lt;br&gt;programs might not use the zoneinfo info
&lt;br&gt;&lt;br&gt;a
&lt;br&gt;&lt;br&gt;&lt;br&gt;Andy Bach
&lt;br&gt;Systems Mangler
&lt;br&gt;Internet: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8697674&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andy_bach@...&lt;/a&gt;
&lt;br&gt;VOICE: (608) 261-5738 &amp;nbsp;FAX 264-5932
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Although few may originate a policy, we are all able to judge it.
&lt;br&gt;&amp;nbsp; &amp;nbsp; Pericles of Athens, c.430 B.C.
&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/8697674/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8697674.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8701222</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-29T08:43:08Z</published>
	<updated>2007-01-29T08:43:08Z</updated>
	<author>
		<name>Casper.Dik</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; The POSIX standard *requires* that the ?STx?DT format precludes
&lt;br&gt;&amp;gt;the use of zone files.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any OS which uses the zoneinfo files is not compliant when the $TZ
&lt;br&gt;&amp;gt;variable can be parsed under the POSIX rules.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Okay, well the NIH zdump (and, as it happens, the Sol 10 zdump.c I got to 
&lt;br&gt;&amp;gt;compile on Sol 2.7), &amp;quot;trussed&amp;quot; shows:
&lt;br&gt;&amp;gt;open(&amp;quot;/usr/share/lib/zoneinfo/GMT&amp;quot;, O_RDONLY) &amp;nbsp; = 3
&lt;br&gt;&amp;gt;open(&amp;quot;/usr/share/lib/zoneinfo/CST6CDT&amp;quot;, O_RDONLY) = 3
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;So I guess the reason it 'works' is its not properly POSIX ... so the 
&lt;br&gt;&amp;gt;question (to my mind) remains - where does Sol's POSIX-valid zdump get its 
&lt;br&gt;&amp;gt;TZ info? &amp;nbsp;From a library file? &amp;nbsp;That would be the one we need to update.
&lt;/div&gt;&lt;br&gt;If Solaris zdump does not dump the zone file, then that's somewhat
&lt;br&gt;strange; these POSIX rules are hardcoded in the library
&lt;br&gt;file.
&lt;br&gt;&lt;br&gt;What you really should do is switch to the appriate Olson timezone.
&lt;br&gt;&lt;br&gt;(US/...)
&lt;br&gt;&lt;br&gt;Casper
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8701222.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8701952</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-29T08:37:22Z</published>
	<updated>2007-01-29T08:37:22Z</updated>
	<author>
		<name>Andy_Bach</name>
	</author>
	<content type="html">&amp;gt; The POSIX standard *requires* that the ?STx?DT format precludes
&lt;br&gt;the use of zone files.
&lt;br&gt;&lt;br&gt;&amp;gt; Any OS which uses the zoneinfo files is not compliant when the $TZ
&lt;br&gt;variable can be parsed under the POSIX rules.
&lt;br&gt;&lt;br&gt;Okay, well the NIH zdump (and, as it happens, the Sol 10 zdump.c I got to 
&lt;br&gt;compile on Sol 2.7), &amp;quot;trussed&amp;quot; shows:
&lt;br&gt;open(&amp;quot;/usr/share/lib/zoneinfo/GMT&amp;quot;, O_RDONLY) &amp;nbsp; = 3
&lt;br&gt;open(&amp;quot;/usr/share/lib/zoneinfo/CST6CDT&amp;quot;, O_RDONLY) = 3
&lt;br&gt;&lt;br&gt;So I guess the reason it 'works' is its not properly POSIX ... so the 
&lt;br&gt;question (to my mind) remains - where does Sol's POSIX-valid zdump get its 
&lt;br&gt;TZ info? &amp;nbsp;From a library file? &amp;nbsp;That would be the one we need to update.
&lt;br&gt;&lt;br&gt;a
&lt;br&gt;&lt;br&gt;Andy Bach
&lt;br&gt;Systems Mangler
&lt;br&gt;Internet: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=8701952&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andy_bach@...&lt;/a&gt;
&lt;br&gt;VOICE: (608) 261-5738 &amp;nbsp;FAX 264-5932
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Although few may originate a policy, we are all able to judge it.
&lt;br&gt;&amp;nbsp; &amp;nbsp; Pericles of Athens, c.430 B.C.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8701952.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-8693381</id>
	<title>Re: Solaris 2.7 Daylight saving time fix.</title>
	<published>2007-01-27T13:54:45Z</published>
	<updated>2007-01-27T13:54:45Z</updated>
	<author>
		<name>Casper.Dik</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt;old school &amp;quot;?STx?DT&amp;quot; &amp;nbsp;TZ format (to US/Central for example) and the other 
&lt;br&gt;&amp;gt;is to ditch the solaris zdump for the nih one. &amp;nbsp;I'm still hoping for a 
&lt;br&gt;&amp;gt;response but it was indicated that Sun holds that the ?STx?DT format 
&lt;br&gt;&amp;gt;precludes using any zoneinfo files - not sure where it gets the info then 
&lt;br&gt;&amp;gt;(one of libc or libdl? time()?) but ....
&lt;br&gt;&lt;br&gt;The POSIX standard *requires* that the ?STx?DT format precludes
&lt;br&gt;the use of zone files.
&lt;br&gt;&lt;br&gt;Any OS which uses the zoneinfo files is not compliant when the $TZ
&lt;br&gt;variable can be parsed under the POSIX rules.
&lt;br&gt;&lt;br&gt;Casper
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Solaris-2.7-Daylight-saving-time-fix.-tp8265968p8693381.html" />
</entry>

</feed>
