SOL-11.1-040316 - Access to a logical domain console must be restricted to authorized users.

Information

A logical domain is a discrete, logical grouping with its own operating system, resources, and identity within a single computer system. Access to the logical domain console provides system-level access to the OBP of the domain.

Solution

The root role is required. This action applies only to the control domain.

Determine the domain that you are currently securing.

# virtinfo
Domain role: LDoms control I/O service root
The current domain is the control domain, which is also an I/O domain, the service domain, and a root I/O domain.

If the current domain is not the control domain, this action does not apply.

Configure the vntsd service to require authorization.

# svccfg -s vntsd setprop vntsd/authorization = true

The vntsd service must be restarted for the changes to take effect.

# svcadm restart vntsd

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-216349r959010_rule, STIG-ID|SOL-11.1-040316, STIG-Legacy|SV-86121, STIG-Legacy|V-71497, Vuln-ID|V-216349

Plugin: Unix

Control ID: 68646abdc2f1d8b3ab5368ba7062fb8bf4753dfea794625698e05dc22a2f272a