Solaris 10 Filesystem Integrity Protection Using Radmind
- Abstract
- This report is intended to provide information of value to security engineers who are choosing among various solutions to protect their Solaris systems from undesirable changes. In particular, the open-source product "Radmind" is described so it may be effectively compared to other, perhaps more well-known, commercial and open-source filesystem integrity applications. Radmind seems to be most popular in the Mac OS X community, and much of the online documentation is heavily Mac OS X flavored. Therefore, a second objective of this report is to provide support for Solaris security administrators who choose to use Radmind, in the form of a "step-by-step" guide for the installation, configuration, and operation of Radmind on a Solaris 10 system. For this guide, a Solaris 10 server and client were used, but the guide should also be useful for older versions of the Solaris operating system or for other UNIX flavors.