SOL-11.1-040315 - Access to a domain console via telnet must be restricted to the local host.

Information

Telnet is an insecure protocol.

Solution

The root role is required. This action applies only to the control domain.

Determine the domain that you are currently securing.

# virtinfo
Domain role: LDoms control I/O service root
The current domain is the control domain, which is also an I/O domain, the service domain, and a root I/O domain.

If the current domain is not the control domain, this action does not apply.

Create a password-controlled role that has the solaris.vntsd.consoles authorization, which permits access to all domain consoles.

# roleadd -A solaris.vntsd.consoles [role-name]
# passwd [role-name]

Assign the new role to a user.
# usermod -R [role-name] [username]

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-216348r959010_rule, STIG-ID|SOL-11.1-040315, STIG-Legacy|SV-86119, STIG-Legacy|V-71495, Vuln-ID|V-216348

Plugin: Unix

Control ID: f62b74cea3e61815c2d51c2e74fad9f339a77b291d00e8d2ee1318d9a3ef1f6f