    Descriptive info: .. c0t0d0s0.. org.. the sun in a lighthungry universe.. Quicksearch.. Disclaimer.. The individual owning this blog works for Oracle in Germany.. The opinions expressed here are his own, are not necessarily reviewed in advance by anyone but the individual author, and neither Oracle nor any other party necessarily agrees with them.. Navigation.. Home.. Impressum.. Datenschutzhinweis.. Favorites.. Das Archiv.. Essays.. Blogroll.. Tour dates ;).. solaristutorials.. Solaris 11 Security presentation.. Friday, October 11.. 2013.. The mails with the slides for the attendees of the Oracle Breakfasts should be out by now, so i want to link people to the presentation i've held at the breakfast.. I just whitened them (the c0t0d0s0//org is just a kind of an ineffective watermark.. ) as i don't think that my blog is the right location to publish oracle branded slides as it's by no means an official Oracle blog.. (click to view).. It is more a live demo put into slides and without the voice track it may be a little bit hard to understand, but maybe it is useful to some or the other.. Posted by.. Joerg Moellenkamp.. in.. English.. ,.. Security.. Solaris.. at.. 19:29.. |.. Comment (1).. Trackbacks (0).. Defined tags for this entry:.. english.. security.. solaris.. Markus Flierl about Solaris.. Monday, October 7.. Markus Flierl , VP in charge of Solaris Engineering at Oracle, wrote an interesting article about his impressions from the OOW2013 in.. "Impressions from Oracle Open World 2013".. At first he gives an nice example what happens when engineers work together.. well.. to engineer things to work together:.. When we initially tested the Oracle DB on this large machine it took 2800s to fill a 30TB SGA when running Oracle DB 11g on S11.. 1.. Working closely with the Oracle DB team we have been able to get this down to about 130s now! That's a 21x speed-up! We had to do a whole bunch of work on both sides to accomplish that!.. However he speaks a little about the future like Solaris Kernel Zones, the Unified Template Builder and the integration of OpenStack and Puppet as well.. Really worth a read.. 19:40.. Oracle Runner.. Okay, i know this will annihilate productivity for today, but just in case you have some brain cycles to spare: Here is a small jump and run game called.. SPARC.. 11:40.. Comments (0).. sparc.. Handling of IDRs in Solaris 11.. Sunday, October 6.. Interesting article about stuff you have to know when you have to use IDR (Interim Diagnostics / Relief) on your system:.. "Top Tip: Managing Solaris 11 IDRs".. 10:34.. Using X.. 509 support for SSH on Solaris 11.. Monday, September 30.. Since Solaris 11.. 1 the ssh implementation of Solaris supports the usage of X.. 509 certificates.. There is a tutorial of a colleague that explains the setup however when i linked to it a while ago, i got some mails telling me, that it was a little bit on the hard side to understand.. So i thought it would be a nice idea to explain the stuff Hai-May Chao wrote in her article on OTN the LKSF way.. However there are a few differences: I won't explain that much about command lines and - more important - i'm using.. openssl.. instead of.. pktool.. to create keys and certificates.. Continue reading "Using X.. 1".. 20:25.. Solaris 11 Security presentations.. Saturday, September 21.. That was really cool in the recent days.. I made my 4 "Solaris Security 11" events as part of the Oracle Business breakfast series talks in the last 2 weeks.. I don't have the final count, but the final numbers of attendees were north of 100 people, not bad for such small event series (it's organized by local technical colleagues) with extremely technical content.. There is really a lot of interest in this kind of topics.. I'm doing a final release at the preso at the moment for distribution.. Think i will put a deoracleized version on the blog.. Friday was a little stressful.. Did  ...   the pre-nineeleven sense and terrorists in the inflationary post-nineeleven sense, but especially against people that offer you a little bit of security with the price tag of large dents in your civil rights.. 08:30.. ::linkbuf for 12-Sep-2013.. Schneier on Security: iPhone Fingerprint Authentication.. (tags:.. ).. Cause and effect.. Wednesday, September 11.. Sometimes i would like to be able to do the jedi mind trick.. Like "This isn't the performance issue you are searching for".. Because it would be easier to convince people in that case that they saw the effect, but not the cause.. That said, I think the real root cause on what i will describe in this block of this problem is the separation of database admins and system admins.. But that's my personal opinion.. Imagine from one day to another, your storage goes mad.. The analytic tools of your storage show long latencies, the led of the storage just show massive use of the storage.. As you didn't made any change your first assumption is "storage has a defect" or "i just hit a bug in the storage firmware".. At the end he or she thinks "No major release changes.. Perhaps a few minor configuration changes.. And none of them has to do with storage".. Continue reading "Cause and effect".. Toolbox.. Work.. toolbox.. work.. Fingerprint Scanner.. Tuesday, September 10.. The new iPhone has a fingerprint scanner and some people are already complaining that this isn't good decision of Apple in this "NSA here, NSA there" times.. Perhaps it's really not a clever idea from the PR perspective.. However you have to do a threat analysis.. What's more reasonable and more dangerous and damanging to you.. The fear that the fingerprint (most often the sensor don't deliver a finger print but something like a hash code of the print) may leave the phone (you leave 1000 copies of your finger print a day around you just by grabbing stuff anyway).. Or thieves, friends preparing a prank or your significant other just following the grease traces on your phone to find out the unlock code (which you don't need with a finger print scanner)?.. 21:21.. Comments (2).. Never underestimate.. Never underestimate the tendency of the audience and the time you spend with the discussion to discuss NSA stuff when you do a security presentation these days.. I made my "Security with Solaris 11.. 1" preso in Hamburg without sildes and just demoing the security features live in front of the audience, however i think i need a slide version for it in oder to get back to speed when the discussion has diverted and you need to get to plan.. 21:03.. ::linkbuf for 10-Sep-2013.. Competition entry by.. David Cummins.. powered by.. Serendipity.. v1.. 0.. +1.. Facebook.. Books.. Recommended Sun and Solaris Books.. The LKSF book.. The book with the consolidated Less known Solaris Tutorials is available.. for download here.. Web 2.. 0.. Contact.. mail: joerg@c0t0d0s0.. icq: 144000169.. Identy@Web.. Me, myself and I.. openBC.. My del.. c0t0d0s0@twitter.. c0t0d0s0@last.. fm.. wiki@c0t0d0s0.. Amazon Wishlist.. Networking.. xing.. LinkedIn.. My LinkedIn-Profile.. My Facebook-Profile.. My photos.. auf Fotocommunity.. auf Flickr.. Comments.. Charly.. about.. Tue, 15.. 10.. 2013 09:41.. Thanx a lot, Jörg ! always happy to get some ppt / pdf /.. with some new topics from y ou.. Wed, 09.. 2013 11:32.. Habe die Präsentation gestern zur Verteilung weitergegeben.. Sven Buchholz.. 2013 08:38.. Du willst doch nicht etwa auf den letzten Metern den Löffel abgeben?.. Rob.. Tue, 08.. 2013 11:47.. The question though is what do es he mean by 30%B to be fille d? Filled with data or just al located? TO fill it with [.. ] Habe die Präsentation gestern zur Verteilung weitergegeben.. Sven Buchholz.. 2013 08:38.. Du willst doch nicht etwa auf den letzten Metern den Löffel abgeben?.. Rob.. Tue, 08.. 2013 11:47.. The question though is what do es he mean by 30%B to be fille d? Filled with data or just al located? TO fill it with [.. ]

    Descriptive info: |.. Monday, June 7.. 2004.. 21337 Lüneburg.. Die genaue, ladungsfähige Postaddresse kann bei mir via Mail erfragt werden oder via whois fuer die domain c0t0d0s0.. org abgefragt werden (dafür wurde whois schliesslich erfunden).. Ich moechte die hier nur nicht so offensichtlich spiderbar im Netz hinterlassen.. E-Mail: joerg@c0t0d0s0.. Internet: www.. c0t0d0s0.. Inhaltlich Verantwortlicher gemaess Paragraph 10 Absatz 3 MDStV: Joerg Moellenkamp (Anschrift wie oben).. Hinweise:.. 1.. Trotz sorgfaeltiger inhaltlicher Kontrolle uebernehme ich keine Haftung fuer die Inhalte externer Links.. Fuer den Inhalt der verlinkten Seiten sind ausschliesslich deren Betreiber verantwortlich.. 2.. Diese Webseite erlaubt das Veroeffentlichen von Kommentaren zu den Nachrichten.. Dies dient zur Diskussion unter den Lesern der Website.. Die Kommentare stellen ausdruecklich nur die Meinung des Verfassers dar.. 3.. Ich behalte mir das Loeschen von  ...   Trackback specific URI for this entry.. No Trackbacks.. Display comments as (.. Linear.. | Threaded).. No comments.. Add Comment.. Name.. Email.. Homepage.. In reply to.. [ Top level ].. Comment.. E-Mail addresses will not be displayed and will only be used for E-Mail notifications.. To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box.. Your comment will only be submitted if the strings match.. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.. Enter the string from the spam-prevention image above:.. Standard emoticons like :-) and ;-) are converted to images.. Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.. Remember Information?.. Subscribe to this entry..

    Descriptive info: Thursday, June 10.. Ja, ich bin Mitarbeiter der Firma Oracle.. Nein, das ist trotzdem eine rein private Angelegenheit hier.. Ja, ich weiss wahrscheinlich mehr ueber kommende Projekte, Probleme, geniale Dinge als die Presse oder andere Nicht-Sunnies.. 4.. Nein, ich werde mich darueber nicht aeussern.. Sun hat fuer sowas Presse- und Marketingleute.. 5.. Ja, ich linke auch auf Geruechte zu Produkten, die vielleicht da kommen werden (oder auch nicht).. 6.. Ich bestaetige oder dementiere dadurch diese Geruechte nicht.. Ich dokumentiere sie nur.. Eigenschaften werden dadurch erst recht nicht zugesichert.. Und um mit dem abgewandelten Disclaimer auf blogs.. sun.. com zu schliessen:..  ...   but the individual authors, and neither Oracle nor any other party necessarily agrees with them.. Yes, I'm working for Oracle.. No, This is a.. private.. weblog.. Yes, i know more about new projects and products than the press or non-sunnies.. No, i will not tell you about it.. Ask our management or the public relation or marketing people.. Yes, i link to to rumors of new products.. No, i do not confirm or deny them by linking.. I document the rumors.. And to close with the modified disclaimer of blogs.. com:.. The individuals who post here work at Oracle.. 19:16.. sun..

    Descriptive info: Photography.. Tuesday, June 15.. Musik.. Soundtrack zum Leben.. Soundtrack of a love affair.. 00:00..

    Descriptive info: Archives.. November.. 0 entries.. (view full).. (view topics).. October.. 4 entries.. (.. view full.. view topics.. September.. 18 entries.. August.. 27 entries.. July.. 3 entries.. June.. May.. 10 entries.. April.. 31 entries.. March.. 25 entries.. February.. January.. 2012.. December.. 7 entries.. 19 entries.. 17 entries.. 1 entries.. 6 entries.. 14 entries.. 12 entries.. 9 entries.. 2011.. 5 entries.. 15 entries.. 2010.. 13 entries.. 30 entries.. 28 entries.. 16 entries.. 58 entries.. 2009.. 73 entries.. 84 entries.. 88 entries.. 74 entries..  ...   entries.. 100 entries.. 110 entries.. 94 entries.. 99 entries.. 106 entries.. 82 entries.. 125 entries.. 2007.. 113 entries.. 145 entries.. 122 entries.. 101 entries.. 102 entries.. 96 entries.. 71 entries.. 133 entries.. 135 entries.. 140 entries.. 201 entries.. 2006.. 146 entries.. 123 entries.. 120 entries.. 116 entries.. 143 entries.. 144 entries.. 68 entries.. 111 entries.. 41 entries.. 2005.. 104 entries.. 65 entries.. 47 entries.. 80 entries.. 79 entries.. 70 entries.. 76 entries.. 21 entries.. 64 entries.. 43 entries.. 2003.. 2002.. 2001..

    Descriptive info: Essays.. Auf Deutsch:.. -.. Von der Professionalisierung der Deprofessionalisierung.. Löst Virtualisierung wirklich irgendein Problem?.. On english:.. Does Virtualization solves any subtantial problem?.. 2006-06-27..

    Descriptive info: Less known Solaris Features.. Donate.. Blogroll.. Recommended Blogs.. Desideria.. Juergen Luebeck.. ekm-consult.. Fragmente.. macophilia.. de.. Steffo´s Echolot.. Isotopp.. Auch gut!.. Gedankenträger.. Rolf Kersten.. hard bloggin´ scientist.. problematik.. net.. centronx.. Volker Weber.. 2007-09-03..

    Descriptive info: Solaris 11 Security present.. Thanx a lot, Jörg !.. always happy to get some ppt / pdf /.. with some new topics from you.. #1.. Charly.. on.. 2013-10-15 09:41.. #1: Charly on 2013-10-15 09:41..

    Descriptive info: Entries by Joerg Moellenkamp.. Monday, September 9.. When you are using kssl (like described in.. this blog entry.. ) there are some tricks and hints you should be aware of:.. When you try to configure kssl and you get always a connection refused when trying to connect, please check if you have configured the.. Listen.. in your apache configuration (for example) if it's configured with an IP address.. and.. port number like:.. Listen 192.. 168.. 20:8080.. A listen with just a port number is not enough.. If you want to change the default ciphers for kssl, you have to resequence the ciphers with.. -c.. of.. ksslcfg.. The command line should look like.. ksslcfg create -f pem -i /etc/keys/my.. pem -x 8080 \ -p /etc/keys/my.. pass -c "rsa_aes_256_cbc_sha,rsa_aes_128_cbc_sha,rsa_rc4_128_sha,rsa_rc4_128_md5" \ 192.. 102 445.. LKSF.. 13:49.. lksf.. Friday, September 6.. There was once a comment stating "If privacy is outlawed, only outlaws will have privacy".. I would change that "If privacy is broken to catch terrorists, only terrorists will have privacy".. I have my doubts that any interesting data transmitted by terrorists will be transmitted by communication means that are breakable.. There are unbreakable means of encrypting and decrypting data, you can even look  ...   Wie sperrt man Applikationen in eine Sandbox ein, um die Fähigkeiten einer Applikation auf das notwendige Minimum einzuschränken?.. Wie nutzt man Zertifikate, um sich gegenüber anderen Systemen zu authentisieren und warum ist das besser als Username und Passwort?.. Wie kann ich bei Solaris 11.. 1 auf Basis der Open Vulnerability Assessement Language automatisierte Tests aufbauen, um auf die Compliance bezüglich Sicherheitsrichtlinien zu testen?.. Wie kann ich die Tätigkeiten meiner Mitadministratoren und die meinen auditieren.. Beim Arbeiten auf dem Systemen mit Kommandos genauso wie beim Editieren von Konfigurieren von Applikationen?.. Kleinere Features, so lange die Zeit reicht: Wie kann ich Kryptographie auf Solaris 11.. 1 einsetzen? Wie nutze ich die Firewall? Wie reiche ich Erlaubnis Services neu zu starten an nicht-Root-User weiter?.. Dabei werden diese Features "in Farbe und bunt" live vorgeführt.. 09:43.. Wednesday, September 4.. Auf der Anmeldeseite für das Oracle Business Breakfast am 10.. 9 gab es einen Fehler.. Im.. Überblickstext.. für das Hamburger Event war für einige Tage "Potsdam" zu lesen.. Das war auf der Seite natürlich falsch.. Das Breakfast am 10.. 9 findet wie ansonsten auch richtig auf der Seite beschrieben in.. Hamburg.. statt.. Ich bitte diesen Fehler zu entschuldigen!.. 13:26.. (Page 1 of 342, totaling 5127 entries)..

    Descriptive info: Actually it's a n-way mirror.. Just as an reminder - many people think of the ZFS mirroring as two or three disk configurations.. But actually it's a n-way mirroring:.. You could use two disks:.. root@template:/testdev# zpool create testpool mirror /testdev/test0 /testdev/test1 root@template:/testdev# zpool status testpool pool: testpool state: ONLINE scan: none requested config: NAME STATE READ WRITE CKSUM testpool ONLINE 0 0 0 mirror-0 ONLINE 0 0 0 /testdev/test0 ONLINE 0 0 0 /testdev/test1 ONLINE 0 0 0 errors: No known data errors.. You could use three disks:.. root@template:/testdev# zpool create testpool mirror /testdev/test0 /testdev/test1 /testdev/test2 root@template:/testdev# zpool status testpool pool: testpool state: ONLINE scan: none requested config: NAME STATE READ WRITE CKSUM testpool ONLINE 0 0 0 mirror-0 ONLINE 0 0 0 /testdev/test0 ONLINE 0 0 0 /testdev/test1 ONLINE 0 0 0 /testdev/test2 ONLINE 0 0 0 errors: No known data errors.. However you could do 11 mirrors as well:.. root@template:/testdev# zpool create testpool mirror \ /testdev/test0 /testdev/test1 \ /testdev/test2 /testdev/test3 \ /testdev/test4 /testdev/test5 \ /testdev/test6 /testdev/test7 \ /testdev/test8 /testdev/test9 \ /testdev/test10 root@template:/testdev# zpool status testpool pool: testpool state: ONLINE scan: none requested config: NAME STATE READ WRITE CKSUM testpool ONLINE 0 0 0 mirror-0 ONLINE 0 0 0 /testdev/test0 ONLINE 0 0 0 /testdev/test1 ONLINE 0 0 0 /testdev/test2 ONLINE 0 0 0 /testdev/test3 ONLINE 0 0 0 /testdev/test4 ONLINE 0 0 0 /testdev/test5 ONLINE 0  ...   root@template:/testdev# zpool split testpool testpool1_9 /testdev/test9 root@template:/testdev# zpool split testpool testpool1_8 /testdev/test8 root@template:/testdev# zpool split testpool testpool1_7 /testdev/test7 root@template:/testdev# zpool split testpool testpool1_6 /testdev/test6 root@template:/testdev# zpool split testpool testpool1_5 /testdev/test5 root@template:/testdev# zpool split testpool testpool1_4 /testdev/test4 root@template:/testdev# zpool split testpool testpool1_3 /testdev/test3 root@template:/testdev# zpool split testpool testpool1_2 /testdev/test2 root@template:/testdev# zpool split testpool testpool1_1 /testdev/test1.. Afterwards you could just take one of the disks and import as a separate pool:.. root@template:/testdev# zpool import -d /testdev testpool1_1 root@template:/testdev# zpool status testpool1_1 pool: testpool1_1 state: ONLINE scan: none requested config: NAME STATE READ WRITE CKSUM testpool1_1 ONLINE 0 0 0 /testdev/test1 ONLINE 0 0 0 errors: No known data errors.. Let's check the content:.. root@template:~# cd /testpool1_1/ root@template:/testpool1_1# md5sum testfile 788d23ef58a5e5f9c60d17958a6c4aca testfile.. 10:37.. Less^H^H^H^HUnknown features of Solaris 11: Virtual Consoles.. Thursday, August 29.. A customer looked at me really puzzled when doing this.. When we were working at setting up a system at the console, i needed more than one command line.. Customer: "On Linux systems we would use virtual consoles" Joerg: "On this operating system, too".. Continue reading "Less^H^H^H^HUnknown features of Solaris 11: Virtual Consoles".. 10:35.. Comments (3).. Register about M6 and Bixby.. Wednesday, August 28.. Surprisingly positive article about the SPARC M6 and Bixby presentations at Hotchips25:.. Oracle revs up Sparc M6 chip for seriously big iron.. Technology.. 22:35.. technology.. (Page 1 of 233, totaling 3486 entries).. Category English..

    Descriptive info: 1 Security in Düsseldorf.. Auch für Düsseldorf steht nun der Anmeldelink für das Oracle Breakfast zum Thema "Solaris 11.. 1 Security" bereit: Ihr könnt euch unter.. diesem Link.. für das Event anmelden.. Die Themen sind die gleichen wie.. in Hamburg und Berlin.. Um zahlreiches Erscheinen zum mampfen, lernen und diskutieren wird gebeten.. 22:03.. Anmeldungen für Oracle Business Breakfasts Solaris 11.. 1 Security.. Die Anmeldelinks für die Business Breakfasts in Hamburg und Berlin sind nunmehr verfügbar.. Für das Event in Hamburg am 10.. 2013 könnt ihr euch.. Für Berlin am 13.. 2013 ist die Anmeldung an.. dieser Stelle.. möglich.. Es werden jede Menge sicherheitsrelevanter Features besprochen.. Es wird zudem in praktischen Beispielen darum gehen, wie man Applikationen Korsettstangen einzieht und in eine Box einsperrt, wie man Vorgänge auf dem System auditieren kann, wie man mit SSH und Zertifikaten arbeitet, wie man automatisierte Compliancetests in Solaris 11.. 1 implementieren kann, welche Securityfeatures allgemein in Solaris 11.. 1 zur Verfügung stehen und wie das ganze in ein gemeinsames, aufeinander aufbauendes Bild passt.. Um zahlreiches Erscheinen wird gebeten.. 09:57.. Less known Solaris features: pfedit - editing is not everything.. Sunday, August 18.. You have allowed.. junior.. to.. edit the httpd.. conf.. and.. you are capable to monitor the changes.. with.. pfedit.. However there is a little problem.. She or he can't restart the apache demon to make the new config active.. When.. tries to restart , he or she just gets:.. junior@template:~$ svcadm refresh apache22 svcadm: svc:/network/http:apache22: Permission denied.. Of course you don't want to restart the service every time.. changes the the config yourself.. On the other side you don't want to give.. the root privileges.. So what can you do?.. Continue reading "Less known Solaris features: pfedit - editing is not everything".. 15:58.. Less known Solaris 11.. 1 features: pfedit.. Friday, August 16.. It's a really nifty feature: Let's assume, you have a config file in your system and you want to allow your junior fellow admin to edit it from time to time, but don't want him to pass any further rights to him, because this machine is too important.. Solaris 11.. 1 has an interesting feature to delegate the privilege  ...   of the day, the number of events isn't that small as you would assume at first:.. "Bitsquatting: DNS Hijacking without exploitation".. The IT Business.. the it business.. X.. 509 for SSH.. Saturday, April 6.. Hai-May Chao created a nice tutorial on the task how to use certificates for SSH authentication:.. "How to Set Up X.. 509 Support for SunSSH on Oracle Solaris 11".. Operating Systems.. 09:19.. Less known, but frequently used Solaris feature: Address space layout randomisation.. Thursday, March 28.. One of the features introduced with 11.. 1 is the Address Space Layout Randomization (ASLR).. And when you work with 11.. 1 you are already using it.. So it's a less known, but frequently used feature: less known in the point that it exists, less known in the point of the methods to control it, frequently used as it's activated per default for selected binaries (and many were selected).. Continue reading "Less known, but frequently used Solaris feature: Address space layout randomisation".. 2blogsoraclecom.. 14:42.. Glenn Faden about the extended policy feature in Solaris.. Tuesday, March 26.. Glenn Faden strikes again: In the article.. "Oracle Solaris Extended Policy and MySQL".. he describes, how to use the Extended Policy feature to lock down the mysql service.. 14:44.. Application sandbox with Solaris.. Glenn Faden wrote a really great article about the sandboxing of applications with privileges:.. Application Containment via Sandboxing.. Worth a read.. 13:08.. Hotel doors.. Wednesday, July 25.. News like this are the reason why i'm carrying my notebook and my iPad always with me when on travel as i don't trust hotel doors.. However i didn't thought it's possible to open a door that fast:.. "Black Hat hacker gains access to 4 million hotel rooms with Arduino microcontroller".. Business Travel.. 13:30.. business travel.. Protecting your data with two factors and ZFS dataset encryption.. Tuesday, November 23.. It's really easy to use ZFS dataset encryption to protect your data in a way so you have to know something and to own something to get access to encrypted data.. Continue reading "Protecting your data with two factors and ZFS dataset encryption".. 08:01.. Trackback (1).. (Page 1 of 6, totaling 89 entries).. Category Security..

