I had three replies to my query about SunSHIELD - two reporting problems,
and one (from a Sun SSE) who said he had "no real problems".

Some of the problems that were reported are:

- It installs off the CD-ROM without execute permission on the binaries
(have you ever tried to boot a Sun that can't execute init?)

- When installed with C2 auditing turned on, C2 ignores all of the auditing
flags and audits everything...

- If you have /etc/resolv.conf (DNS) and ARM authenticates your hosts via
lookup to the nameservers, then *all* of the nameservers in resolv.conf are
checked. If one of them is down, ARM will NOT authenticate you, and you will
NOT be able to login. Sun's solution: never let your nameservers go down. Never.

- Invalid login attempts are logged in cleartext. ARM does not tell you when
you run out of invalid login attempts.

- If the armd_transact file gets over around 100K in size, armd goes berserk,
chewing up wads of CPU time and not authenticating. Sun's solution: move the
transaction file and send a SIGHUP to rpc.armd.

You also need to install 2 patches to use it - 100632 and 100653. These
patches may fix some or all of the above problems.

Thanks all. I have kept these replies; email me if you would like a copy.

