1.3 Install Solaris Encryption Kit - Check if Package SUNWcrman is installed

Information

The Solaris 10 Encryption Kit contains kernel modules that implement various encryption algorithms for IPsec and Kerberos, utilities that encrypt and decrypt files from the command line, and libraries with functions that application programs call to perform encryption.

The Encryption Kit enables larger key sizes (> 128) of the following algorithms -
AES (128, 192, and 256-bit key sizes) Blowfish (32 to 448-bit key sizes in 8-bit increments) RCFOUR/RC4 (8 to 2048-bit key sizes)

Please see the documentation included with the package for more information. Regulations on the export of encryption software are subject to change. This action is not needed for systems running Solaris 10 08/07 and newer as the Solaris 10 Encryption Kit is installed by default. Do not use this software download on systems running Solaris 10 08/07 or newer versions of the operating system.

Note - If you are installing the Encryption Kit on Solaris 10 11/06 or older versions of the Solaris OS, the package will also install SUNWcrman. On newer versions, the manual pages are included in the system manual pages by default.

Solution

For Solaris 10 11/06 or older versions of the Solaris OS, obtain the Solaris 10 Encryption Kit from https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMISite/ en_US/-/USD/ViewProductDetail-Start?ProductRef=Sol10-GA-Encryption-G-F@CDSCDS_ SMI
After downloading the software, to implement this action, execute the following commands -

unzip -qq sol-10-encrypt-GA-iso.zip
lofiadm -a `pwd`/sol-10-encrypt-GA.iso /dev/lofi/1
mount -F hsfs -o ro /dev/lofi/1 /mnt

Note that the device returned in the step above is the one to be used in the next step.

mount -F hsfs -o ro /dev/lofi/1 /mnt
cd /mnt/Encryption_10/`uname -p`/Packages
pkgadd -d . all [respond to pkgadd questions]
cd
umount /mnt
lofiadm -d /dev/lofi/1

See Also

https://workbench.cisecurity.org/files/614

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Unix

Control ID: 931653270c0f8cdb8843b8eb8beacfcb4649363b372b1b91173d0afb4df87abc