I have the agent installed and running, but I still cannot see it from the media server. I would not recommend automatically applying patches on important (high availability) servers. FastPatch is a replacement for patchadd, the same but a lot faster.

SSH note:SSH is a good thing, essential for every UNIX box. download from Sunfreeware.com and 'pkgadd -d perl-5.6.0-sol8-sparc-local'). add a hostname.YOURDOMAIN.COM alias for your machine. (This is to stop sendmail from complaining). Press[Return]tocontinue: CheckingifsystemusesNISserver:...............................No Theinstallerwillnowcheckyoursystemforthe'beoper'usergroupandrootmembership.

Aide is a new GPL tripwire replacement [12] that looks interesting, I've not had a chance to test it so far. JASS_FILES Files are only installed from the Files directory if they are listed in the JASS_FILES variable in Driver/hardening.driver. The media server is Backup Exec for Windows Servers 11d and I do have the RALUS serial number enabled in License Keys and Installations. Going live Preparing to go live You probably won't need CD-ROMs or floppies anymore, so disable the volume manager in /etc/yassp.conf (if it was still enabled, which it not by default).

This can consume quite a lot of time. So, to run a central syslog server, remove the '-t' option to the syslogd startup line in /etc/init.d/syslog and create the logs if they don't yet exist, for example: ## Syslog It's easier to isolate applications, harden, troubleshoot and upgrade hw/sw. Be regularly informed of new vulnerabilities and security issues, either by subscribing directly to CERT, CIAC [18] and the vendor security lists (Sun, Microsoft, etc.) and/or subscribing to newsletters such as

The problem is that Disksuite uses RPC (specifically: two programs rpc.metamhd and rpc.metad which run from inetd). The SCRIPTS* and FILES* variables now use the JASS_ prefix (i.e., JASS_SCRIPTS and JASS_FILES) for consistency. Thank You! These variables still can be overridden by the user in the user.init file.

This script also assumes that the commercial tripwire is used on the central trusted host (only). It's free and works on older Solaris, not just 8. High-numbered ports are opened by the rpcbind server as a side effect of other activity. to /opt/install.

But its preferred to have the entries of the servername in the host file for hostname lookup.

Patchadd on Solaris 7 needs a little tweak to work with core only packages though: cd /usr/sbin; mv patchadd patchadd-orig; sed s/\\/xpg4// patchadd-orig > patchadd; chown root:bin patchadd; chmod 555 patchadd; The uncompressed versions can run to over 150MB. [ubuntu] Symantec backup exec ralus Cannot /usr/bin/rsh to XServerInitial system check failed.in log the errore is:VxIF::Error:: Unable to obtain host information for XServer.

[email protected]#: apt-get install libstdc++5 Complete the installation. Edit the file "/etc/modprobe.d/aliases" and comment out the line "alias net-pf-10 ipv6".

Does the system behave as expected? Two free partitions are needed for the Veritas Volume manager. Next we try the 'undo' feature which allows us to go back to the configuration before Jass was run.

If the systems runs highly specialised software like databases, be very wary of installing Kernel, I/O and driver patches.

Installer log------------------------------------------------------------------------------------------------------------------"Following each set of questions, the information you have entered will bepresented for confirmation. First copy /opt/SUNWjass/Drivers/user.init.SAMPLE to /opt/SUNWjass/Drivers/user.init and add the following to the bottom: # user.init # sb, 02.Oct.01 JASS_AGING_MAXWEEKS="26" JASS_AGING_WARNWEEKS="1" JASS_AGING_MINWEEKS="0" JASS_LOGIN_RETRIES="5" JASS_PASS_LENGTH="6" JASS_SENDMAIL_MODE="\"\"" JASS_TMPFS_SIZE="200m" JASS_UMASK="027" JASS_SHELL_DISABLE="/sbin/noshell" JASS_CRON_LOG_SIZE="20480"; ## v0.3.1 ## Don't Going Live Connect to the live network. Now test the network connections, to ensure the rules have the desired effect.

The steps I did to allow VRTSralus to install (as root): $ apt-get install rpm $ cd /etc $ ln -s . Close Sign In Print Article Products Related Articles Article Languages Subscribe to this Article Manage your Subscriptions Problem Installation of RALUS ( Remote Agent for Linux and Unix Server) or Sendmail is left running is Queue mode (will deliver but not accept remote emails), which is fine. The "metamhd" service can be disabled but this means you cannot share metadevices between systems.

If you would like a copy of logs to be kept locally, as well as remotely, uncomment the line in /etc/syslog.conf: *.err;auth.info;kern.debug /var/adm/messages If syslog does not work as expected, read For increased security and automated checking of several systems from one trusted host, copy tripwire and it's database and run it remotely at regular intervals using SSH. Installingonsystemsconsecutivelytakesmoretimebutallowsforbettererrorhandling. Otherwise, edit /etc/mail/aliases, at least point mailer-daemon, root and other system accounts to real addresses.