Virtual I/O Server
The Virtual I/O Server (VIOS) resides in a separate LPAR partition and provides basic discretionary access control between VIOS SCSI device drivers acting on behalf of LPAR partitions and SCSI-based logical volumes and physical volumes through mappings.
An LPAR partition (through a VIOS SCSI device driver) may be mapped to 0 or more logical and physical volumes, but a volume can only be mapped to one LPAR partition. This mapping limits an LPAR partition to only the volumes assigned to it. VIOS also controls the mapping of VIOS Ethernet adapter device drivers to VIOS Ethernet device drivers acting on behalf of groups of LPAR partitions sharing a virtual network. In the evaluated configuration, only a one-to-one mapping of an Ethernet adapter device driver to an Ethernet device driver acting on behalf of a group of LPAR partitions is allowed. The one-to-one mapping is configured by the administrator and enforced by the device drivers. Also, the Ethernet packets must not be tagged with a VLAN tag in the evaluated configuration. This mechanism can be used to limit which LPAR partitions see certain Ethernet packets.
- maxage
- 8
- maxexpired
- 1
- minother
- 2
- minlen
- 8
- maxrepeats
- 2
- loginretries
- 3
- histexpire
- 52
- histsize
- 20
type oem_setup_env
chsec -f /etc/security/user -s default -a maxage=8 -a maxexpired=1 -a minother=2
-a minlen=8 -a maxrepeats=2 -a loginretries=3 -a histexpire=52 -a histsize=20
mkuser maxage=8 maxexpired=1 minother=2 minlen=8 maxrepeats=2 loginretries=3
histexpire=52 histsize=20 davis
- To remove writesrv and ctrmc from the /etc/inittab file:
sshd: stopsrc -s sshd
- To prevent the daemon from starting at boot time, remove the /etc/rc.d/rc2.d/Ksshd and /etc/rc.d/rc2.d/Ssshd files. After reboot stop the RSCT daemons:
stopsrc -g rsct_rm stopsrc -g rsct
All users, regardless of their roles, are to be considered as administrative users.
- chdate
- chuser
- cleargcl
- de_access
- diagmenu
- invscout
- loginmsg
- lsfailedlogin
- lsgcl
- mirrorios
- mkuser
- motd
- oem_platform_level
- oem_setup_env
- redefvg
- rmuser
- shutdown
- unmirrorios