Security Blueprints

Searching Blueprints

Click here for tips on how to improve your search.

Additional Resources

Follow us on Twitter

Recent Security Papers

Designing an Adaptive Security Architecture (Blueprints) — November 2008
Labels: new, blueprint, security
Security Advantages of the Solaris Zones Software (Blueprints) — December 2008
Labels: new, blueprint, security, virtualization
Understanding the Security Capabilities of Solaris Zones Software (Blueprints) — December 2008
Labels: new, blueprint, security, virtualization
Cryptographic Solutions for Financial Services (Blueprints) — February, 2008
Labels: security, new, blueprint
Accelerating IBM HTTP Server Cryptographic Operations Using Sun Servers with CoolThreads Technology (Blueprints) — May 2009
Labels: new, bluerpint, blueprints, cryptography, cmt, security, coolthreads

Security Related Blogs

Amazon S3 Silent Data Corruption

by Glenn Brunett

While catching up on my reading, I came across an interesting article focused on the Amazon's Simple Storage Service (S3). The author points to a number of complaints where Amazon S3 customers had experienced silent data corruption. The author recommends calculating MD5 digital fingerprints of files before posting them to S3 and validating those fingerprints after later retrieving them from the service.

OpenSSO Servers and Sites Configuration with SSL and SSQ

by Michael Teger

Here is some information regarding how you might configure OpenSSO sites and servers for a sample SAMLv2 deployment. The requirement in this SAMLv2 deployment is to allow normal users to access OpenSSO via pure SSL and administrative users to access OpenSSO via SSL with certificate authentication.

Security Concerns and the ESB

by Michael Jenkins

I would like to share some points from a recent conversation about requirements in a distributed ESB platform.This post is not going to talk about WS-Security or LDAP or encryption or any specific technology. Instead it is going to cover some of the different and maybe unexpected ways that security concerns are applied in the ESB/SOA space.

Towards Running Trusted Extension with OpenSolaris 2008.11

by Christoph Schuba

This blog entry is related to the one that Glenn Faden published recently, entitled "Running Trusted Extensions with opensolaris.2008.05" (see below). I updated Glenn's posting to describe how to get Trusted Extensions running on the OpenSolaris 2008.11 distribution.

Running Trusted Extensions with opensolaris.2008.05

by Glenn Faden

When the LiveCD for opensolaris was released last May there was no support for Trusted Extensions. We've made some progress, and I'm happy to report that I am posting this blog in a labeled zone running opensolaris. There are workarounds for the zone installation, X11 remote connections, and desktop login, which are all temporary until the underlying bugs are fixed.

Adaptive Security Architecture Principles

by Glenn Brunett

Building upon the last posting, this article describes the security architectural principles than are used to guide the design, development, implementation and operation of an adaptively secure environment. Not all principles will necessarily be used in every architecture. These should be used as guiding principles and not considered mandates. Their use is dependent upon the business and technical requirements that the architecture must satisfy.

Adaptive Security and Security Architecture

by Glenn Brunett

This article discusses a new perspective of security architecture that is capable of not only reducing threats but anticipating threats before they are manifested. The proposed approach is called adaptive security. Adaptive security will be discussed using biological and ecosystems metaphors as these provide interesting parallels to the issues, threats and countermeasures applicable to IT systems.

Solaris 10 Security Deep Dive Presentation

by Glenn Brunett

A lot has changed in Solaris since Solaris 10 Security Deep Dive presentation was first released back in 2005. If you have not taken a look into what Solaris can offer recently you will be in for a pleasant surprise.

Angry about your personal data being "lost" to criminals? Tell someone about Sun Ray!

by Brian Nitz

If the SunRay/Gobi laptop or any of the Sun Ray clients in our office were ever stolen, the criminal would get nothing, zip, zero, nada.



Other Resources of Interest


Security Blueprints

Restricting Service Administration in the Solaris 10 Operating System (Blueprints) — June, 2005
Labels: security, solaris, blueprint
Privilege Bracketing in the Solaris 10 Operating System (Blueprints) — April, 2006
Labels: security, solaris, blueprint
Using pGINA to Authenticate Users in Microsoft Windows Environments (Blueprints) — June, 2004
Labels: security, microsoft, blueprint
Toward Systemically Secure IT Architectures (Blueprints) — February, 2006
Labels: datacenter, security, architecture, blueprint
Designing an Adaptive Security Architecture (Blueprints) — November 2008
Labels: new, blueprint, security
Privilege Debugging in the Solaris 10 Operating System (Blueprints) — February, 2006
Labels: security, solaris, blueprint
Limiting Service Privileges in the Solaris 10 Operating System (Blueprints) — May, 2005
Labels: security, solaris, blueprint
IPsec--A Secure Deployment Option (Blueprints) — June, 2004
Labels: security, blueprint
Securing the Sun Fire 12K&15K Domains (Blueprints) — January, 2004
Labels: security, sparc, sys_mgmt, blueprint
Using Computer Forensics When Investigating System Attacks (Blueprints) — April, 2005
Labels: security, datacenter, blueprint
Integrating BART and the Solaris Fingerprint Database in the Solaris 10 Operating System (Blueprints) — April, 2005
Labels: security, solaris, blueprint
Automating Solaris 10 File Integrity Checks (Blueprints) — March, 2005
Labels: security, solaris, sys_mgmt, blueprint
Security Advantages of the Solaris Zones Software (Blueprints) — December 2008
Labels: new, blueprint, security, virtualization
Understanding the Security Capabilities of Solaris Zones Software (Blueprints) — December 2008
Labels: new, blueprint, security, virtualization
The Solaris Fingerprint Database - A Security Validation Tool for Solaris Environment System Files (Blueprints) — March, 2006
Labels: solaris, security, blueprint
Cryptographic Solutions for Financial Services (Blueprints) — February, 2008
Labels: security, new, blueprint
Securing the Sun Fire 12K&15K System Controller (Blueprints) — January, 2004
Labels: security, sparc, sys_mgmt, blueprint
Using the Cryptographic Accelerators (Blueprints) — November, 2007
Labels: cmt, security, blueprint
Enforcing the Two-Person Rule Via Role-Based Access Control in the Solaris 10 Operating System (Blueprints) — August, 2005
Labels: security, solaris, blueprint
Building OpenSSH--Tools and Tradeoffs, Updated for OpenSSH 3.7.1p2 (Blueprints) — April, 2004
Labels: security, solaris, blueprint

Other Technical Papers

(Book) JumpStart Technology (Blueprints) — September, 2001
Labels: book, datacenter, solaris, security, sys_mgmt, archive, other
(Book) Enterprise Security - Solaris Operating System (Blueprints) — June, 2002
Labels: book, archive, security, solaris, other
(Book) Secure Shell in the Enterprise (Blueprints) — June, 2003
Labels: book, security, archive, other
(Book) Making the Net Work - Deploying a Secure Portal on Sun Systems (Blueprints) — May, 2004
Labels: book, security, other


Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.

Sign up or Log in to add a comment or watch this page.


The individuals who post here are part of the extended Sun Microsystems community and they might not be employed or in any way formally affiliated with Sun Microsystems. The opinions expressed here are their own, are not necessarily reviewed in advance by anyone but the individual authors, and neither Sun nor any other party necessarily agrees with them.

Copyright 1994-2009 Sun Microsystems, Inc.
Powered by Atlassian Confluence
Sun Guidelines on Public Discourse Privacy Policy Terms of Use Trademarks Site Map Employment Investor Relations Contact