1 # 2 # CDDL HEADER START 3 # 4 # The contents of this file are subject to the terms of the 5 # Common Development and Distribution License, Version 1.0 only 6 # (the "License"). You may not use this file except in compliance 7 # with the License. 8 # 9 # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 10 # or http://www.opensolaris.org/os/licensing. 11 # See the License for the specific language governing permissions 12 # and limitations under the License. 13 # 14 # When distributing Covered Code, include this CDDL HEADER in each 15 # file and include the License file at usr/src/OPENSOLARIS.LICENSE. 16 # If applicable, add the following below this CDDL HEADER, with the 17 # fields enclosed by brackets "[]" replaced with your own identifying 18 # information: Portions Copyright [yyyy] [name of copyright owner] 19 # 20 # CDDL HEADER END 21 # 22 # 23 # Copyright 2004 Sun Microsystems, Inc. All rights reserved. 24 # Use is subject to license terms. 25 # 26 27 #pragma ident "%Z%%M% %I% %E% SMI" 28 29 Notes Regarding Modification of generic_open.xml 30 31 Any changes made to generic_open.xml will need to be considered for 32 inclusion in generic_limited_net.xml, the "Secure By Default" (see 33 http://solsec.eng.sun.com/sbd/) profile. The details are discussed 34 in PSARC/2004/781: 35 36 ... 37 The generic_limited_net profile explicitly disables all 38 smf(5) converted inetd services that are not required to 39 run the window system, SVM, or vold. It retains ssh and 40 X remote login as the remote login methods available. 41 ... 42 43 In general, _any_ service that allows inbound net access should be 44 added to generic_limited_net and disabled, unless its activation 45 has been:approved by SBD. 46