SUMMARY: How to re-enable remote Gnome login on Solaris 10 8/07 withSecureBy Default Network Profile ON.

From: <Loris.Serena_at_pfpc.ie>
Date: Thu Sep 13 2007 - 07:02:38 EDT
Thanks a mill to Greg Marsh, whose solution (below) worked perfectly fine 
for me.

Loris


=====================================================================
As a security measure dtlogin is disabled by running it on port 0 
instead of the default port 177
   milly / # ps -ef | grep dtlogin
       root   530     1   0   Aug 06 ?           0:00 
/usr/dt/bin/dtlogin -daemon -udpPort 0

To remove the port argument run,
   svccfg -s cde-login setprop dtlogin/args=\"\"
   svcadm restart cde-login
NB If cde-login enters maintenance state run,
   svcadm clear cde-login

Remote graphical login still not working also had to,
   svccfg -s x11-server setprop options/tcp_listen=true     # false by 
default
   svcadm restart cde-login
   svcadm enable svc:/application/x11/xfs:default           # disabled 
by default

CDE now working but not Java desktop system!
Modified the /etc/X11/gdm/gdm.conf file,
   [xdmcp]
   #Enable=false
   Enable=true
and restarted gdm login service,
   svcadm restart svc:/application/gdm2-login:default
=====================================================================






Loris.Serena@pfpc.ie 
Sent by: sunmanagers-bounces@sunmanagers.org
13/09/2007 10:50

To
sunmanagers@sunmanagers.org
cc

Subject
How to re-enable remote Gnome login on Solaris 10 8/07 withSecure 
ByDefault Network Profile ON.






Guys, 

I've just installed Solaris 10 8/07 on a SPARC SunBlade 2500 enabling the 
"Secure By Default Network Profile".
Remote SSH login works fine and Gnome graphical login only works locally.
How do I re-enable (and then restrict per user and/or per host) remote 
graphical login?
Running, "netservices open" is not an option, that will open far too much!

Thanks in advance
 
Loris



# svcs -a
STATE          STIME    FMRI
legacy_run     18:42:28 lrc:/etc/rc2_d/S00set-tmp-permissions
legacy_run     18:42:29 lrc:/etc/rc2_d/S07set-tmp-permissions
legacy_run     18:42:31 lrc:/etc/rc2_d/S10lu
legacy_run     18:42:31 lrc:/etc/rc2_d/S20sysetup
legacy_run     18:42:32 lrc:/etc/rc2_d/S40llc2
legacy_run     18:42:32 lrc:/etc/rc2_d/S42ncakmod
legacy_run     18:42:34 lrc:/etc/rc2_d/S70nddconfig
legacy_run     18:42:34 lrc:/etc/rc2_d/S73cachefs_daemon
legacy_run     18:42:34 lrc:/etc/rc2_d/S81dodatadm_udaplt
legacy_run     18:42:34 lrc:/etc/rc2_d/S89bdconfig
legacy_run     18:42:34 lrc:/etc/rc2_d/S91ifbinit
legacy_run     18:42:35 lrc:/etc/rc2_d/S91jfbinit
legacy_run     18:42:35 lrc:/etc/rc2_d/S94ncalogd
legacy_run     18:42:35 lrc:/etc/rc2_d/S98deallocate
legacy_run     18:42:35 lrc:/etc/rc3_d/S16boot_server
legacy_run     18:42:37 lrc:/etc/rc3_d/S22acct
legacy_run     18:42:37 lrc:/etc/rc3_d/S52imq
disabled       18:42:08 svc:/network/iscsi_initiator:default
disabled       18:42:08 svc:/system/metainit:default
disabled       18:42:08 svc:/system/device/mpxio-upgrade:default
disabled       18:42:08 svc:/network/rpc/keyserv:default
disabled       18:42:08 svc:/network/rpc/nisplus:default
disabled       18:42:08 svc:/network/nis/server:default
disabled       18:42:09 svc:/network/nis/client:default
disabled       18:42:09 svc:/network/dns/client:default
disabled       18:42:09 svc:/network/ldap/client:default
disabled       18:42:09 svc:/network/nfs/status:default
disabled       18:42:09 svc:/network/nfs/nlockmgr:default
disabled       18:42:09 svc:/network/nfs/cbd:default
disabled       18:42:09 svc:/network/nfs/mapid:default
disabled       18:42:09 svc:/network/inetd-upgrade:default
disabled       18:42:09 svc:/network/nfs/client:default
disabled       18:42:09 svc:/application/print/server:default
disabled       18:42:09 svc:/network/smtp:sendmail
disabled       18:42:09 svc:/system/auditd:default
disabled       18:42:09 svc:/system/patch-finish:delete
disabled       18:42:09 svc:/system/mdmonitor:default
disabled       18:42:09 svc:/system/pools:default
disabled       18:42:09 svc:/system/rcap:default
disabled       18:42:10 svc:/application/management/seaport:default
disabled       18:42:10 svc:/application/management/snmpdx:default
disabled       18:42:10 svc:/application/management/dmi:default
disabled       18:42:10 svc:/network/rpc/bootparams:default
disabled       18:42:10 svc:/network/samba:default
disabled       18:42:10 svc:/network/winbind:default
disabled       18:42:10 svc:/network/wins:default
disabled       18:42:10 svc:/network/nfs/server:default
disabled       18:42:10 svc:/network/rarp:default
disabled       18:42:10 svc:/network/dhcp-server:default
disabled       18:42:10 svc:/application/management/webmin:default
disabled       18:42:11 svc:/application/management/sma:default
disabled       18:42:11 svc:/application/print/ipp-listener:default
disabled       18:42:11 svc:/application/database/postgresql:version_81
disabled       18:42:11 svc:/application/database/postgresql:version_82
disabled       18:42:11 svc:/application/gdm2-login:default
disabled       18:42:11 svc:/network/dns/server:default
disabled       18:42:11 svc:/network/routing/legacy-routing:ipv4
disabled       18:42:11 svc:/network/routing/legacy-routing:ipv6
disabled       18:42:11 svc:/network/routing/ndp:default
disabled       18:42:11 svc:/network/routing/rdisc:default
disabled       18:42:11 svc:/network/ipv6-forwarding:default
disabled       18:42:11 svc:/network/routing/ripng:default
disabled       18:42:11 svc:/network/routing/ripng:quagga
disabled       18:42:11 svc:/network/routing/zebra:quagga
disabled       18:42:11 svc:/network/routing/route:default
disabled       18:42:11 svc:/network/ipv4-forwarding:default
disabled       18:42:11 svc:/network/routing/rip:quagga
disabled       18:42:11 svc:/network/routing/ospf:quagga
disabled       18:42:11 svc:/network/routing/ospf6:quagga
disabled       18:42:11 svc:/network/routing/bgp:quagga
disabled       18:42:12 svc:/network/security/kadmin:default
disabled       18:42:12 svc:/network/security/krb5kdc:default
disabled       18:42:12 svc:/network/ipmievd:default
disabled       18:42:12 svc:/network/nis/passwd:default
disabled       18:42:12 svc:/network/nis/update:default
disabled       18:42:13 svc:/network/nis/xfr:default
disabled       18:42:14 svc:/network/http:apache2
disabled       18:42:14 svc:/network/apocd/udp:default
disabled       18:42:14 svc:/network/slp:default
disabled       18:42:15 svc:/system/consadm:default
disabled       18:42:16 svc:/system/pools/dynamic:default
disabled       18:42:16 svc:/system/iscsitgt:default
disabled       18:42:16 svc:/system/sar:default
disabled       18:42:16 
svc:/application/management/common-agent-container-1:default
disabled       18:42:18 svc:/system/filesystem/autofs:default
disabled       18:42:18 svc:/system/power:default
disabled       18:42:18 svc:/network/rpc/bind:default
disabled       18:42:19 svc:/application/print/cleanup:default
disabled       18:42:27 svc:/network/rpc/meta:default
disabled       18:42:27 svc:/application/x11/xfs:default
disabled       18:42:28 svc:/network/rpc/rstat:default
disabled       18:42:28 svc:/application/print/rfc1179:default
disabled       18:42:31 svc:/network/rpc/cde-ttdbserver:tcp
disabled       18:42:31 svc:/network/rpc/ocfserv:default
disabled       18:42:33 svc:/network/rpc/mdcomm:default
disabled       18:42:33 svc:/network/rpc/metamed:default
disabled       18:42:33 svc:/network/rpc/metamh:default
disabled       18:42:33 svc:/network/rpc/rex:default
disabled       18:42:33 svc:/network/rpc/rusers:default
disabled       18:42:34 svc:/network/rpc/spray:default
disabled       18:42:34 svc:/network/rpc/wall:default
disabled       18:42:34 svc:/network/security/krb5_prop:default
disabled       18:42:34 svc:/network/swat:default
disabled       18:42:34 svc:/network/cde-spc:default
disabled       18:42:35 svc:/network/tname:default
disabled       18:42:35 svc:/network/telnet:default
disabled       18:42:35 svc:/network/nfs/rquota:default
disabled       18:42:35 svc:/network/uucp:default
disabled       18:42:35 svc:/network/chargen:dgram
disabled       18:42:35 svc:/network/chargen:stream
disabled       18:42:35 svc:/network/daytime:dgram
disabled       18:42:35 svc:/network/daytime:stream
disabled       18:42:35 svc:/network/discard:dgram
disabled       18:42:35 svc:/network/discard:stream
disabled       18:42:35 svc:/network/echo:dgram
disabled       18:42:35 svc:/network/echo:stream
disabled       18:42:35 svc:/network/time:dgram
disabled       18:42:35 svc:/network/time:stream
disabled       18:42:36 svc:/network/ftp:default
disabled       18:42:36 svc:/network/comsat:default
disabled       18:42:36 svc:/network/finger:default
disabled       18:42:37 svc:/network/login:eklogin
disabled       18:42:37 svc:/network/login:klogin
disabled       18:42:37 svc:/network/login:rlogin
disabled       18:42:39 svc:/network/rexec:default
disabled       18:42:39 svc:/network/shell:default
disabled       18:42:39 svc:/network/shell:kshell
disabled       18:42:39 svc:/network/talk:default
disabled       18:42:39 svc:/network/stdiscover:default
disabled       18:42:39 svc:/network/stlisten:default
disabled       18:42:39 svc:/application/font/stfsloader:default
disabled       18:42:40 svc:/network/security/ktkt_warn:default
disabled       18:42:40 svc:/network/rpc-100235_1/rpc_ticotsord:default
disabled       18:42:40 svc:/network/rpc/smserver:default
disabled       18:42:40 svc:/network/rpc/gss:default
online         18:42:07 svc:/system/svc/restarter:default
online         18:42:08 svc:/network/pfil:default
online         18:42:09 svc:/network/loopback:default
online         18:42:09 svc:/system/filesystem/root:default
online         18:42:10 svc:/system/installupdates:default
online         18:42:10 svc:/milestone/name-services:default
online         18:42:11 svc:/system/boot-archive:default
online         18:42:11 svc:/system/scheduler:default
online         18:42:12 svc:/network/physical:default
online         18:42:12 svc:/system/filesystem/usr:default
online         18:42:13 svc:/milestone/network:default
online         18:42:13 svc:/system/identity:node
online         18:42:13 svc:/system/keymap:default
online         18:42:14 svc:/system/device/local:default
online         18:42:14 svc:/system/filesystem/minimal:default
online         18:42:15 svc:/system/identity:domain
online         18:42:16 svc:/system/cryptosvc:default
online         18:42:16 svc:/system/name-service-cache:default
online         18:42:16 svc:/system/resource-mgmt:default
online         18:42:16 svc:/system/rmtmpfiles:default
online         18:42:16 svc:/system/sysevent:default
online         18:42:16 svc:/system/device/fc-fabric:default
online         18:42:16 svc:/system/coreadm:default
online         18:42:17 svc:/milestone/devices:default
online         18:42:17 svc:/system/picl:default
online         18:42:17 svc:/network/initial:default
online         18:42:18 svc:/network/service:default
online         18:42:20 svc:/network/ipfilter:default
online         18:42:21 svc:/system/manifest-import:default
online         18:42:21 svc:/milestone/single-user:default
online         18:42:22 svc:/system/filesystem/local:default
online         18:42:22 svc:/system/cron:default
online         18:42:22 svc:/system/sysidtool:net
online         18:42:23 svc:/network/ntp:default
online         18:42:23 svc:/application/stosreg:default
online         18:42:23 svc:/system/sysidtool:system
online         18:42:23 svc:/system/dumpadm:default
online         18:42:24 svc:/milestone/sysconfig:default
online         18:42:25 svc:/system/sac:default
online         18:42:25 svc:/system/utmp:default
online         18:42:25 svc:/network/inetd:default
online         18:42:25 svc:/application/management/wbem:default
online         18:42:26 svc:/application/font/fc-cache:default
online         18:42:26 svc:/system/system-log:default
online         18:42:26 svc:/system/fmd:default
online         18:42:27 svc:/system/console-login:default
online         18:42:29 svc:/network/ssh:default
online         18:42:34 svc:/network/routing-setup:default
online         18:42:35 svc:/milestone/multi-user:default
online         18:42:37 svc:/application/graphical-login/cde-login:default
online         18:42:37 svc:/application/cde-printinfo:default
online         18:42:37 svc:/milestone/multi-user-server:default
online         18:42:39 svc:/system/zones:default
online         18:42:39 svc:/system/basicreg:default
online         18:43:11 svc:/system/webconsole:console
offline        18:42:14 svc:/system/filesystem/volfs:default
offline        18:42:29 svc:/network/rpc/cde-calendar-manager:default
#





--
Loris Serena | Senior Unix Systems Specialist | PFPC International Ltd.
Phone: +353-1-7903697 | mailto:loris.serena_at_pfpc.ie | http://www.pfpc.com
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers
Received on Thu Sep 13 07:03:10 2007

This archive was generated by hypermail 2.1.8 : Thu Mar 03 2016 - 06:44:06 EST