- ZFS on disk encryption: zfs create -o encryption=on [ With pam_zfs_key PAM module for per-user key management]
- Immutable Zones: zonecfg -z myzone set file-mac-profile=fixed-configuration
- New package system - with cryptographically signed packages [ pkg(5) ] and multiple signature support
- Root as a role by default & authentication with user password with authentication cacheing [pam_tty_tickets ]
- Network virtualisation dladm(1M) & bandwidth control flowadm(1M)
- Automatic VNICs for Zones - one line zone creation: zonecfg -z myzone 'create ; set zonepath=/zones/myzone'
- IPfilter SMF integration - per service firewall rules
- New basic privileges: file_read/file_write/net_access
- Default root shell is bash (I'd personally prefer zsh but bash is good enough)
- 'man -k' works by default
- sudo with Solaris Audit support and priv_exec removal for NOEXEC
Hello Friends, This is Gaurav Gupta from Gurgaon, India. By profession I am an UNIX Systems Administrator and have proven career track on UNIX Systems Administration. This blog is written from both my research and my experience. The methods I describe herein are those that I have used and that have worked for me. It is highly recommended that you do further research on this subject. If you choose to use this document as a guide, you do so at your own risk.
Wednesday, November 30, 2011
Solaris 11 features
Subscribe to:
Posts (Atom)