tune.sh revision 7c478bd95313f5f23a4c958a745db2134aa03244
#
# CDDL HEADER START
#
# The contents of this file are subject to the terms of the
# Common Development and Distribution License, Version 1.0 only
# (the "License"). You may not use this file except in compliance
# with the License.
#
# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
# See the License for the specific language governing permissions
# and limitations under the License.
#
# When distributing Covered Code, include this CDDL HEADER in each
# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
# If applicable, add the following below this CDDL HEADER, with the
# fields enclosed by brackets "[]" replaced with your own identifying
# information: Portions Copyright [yyyy] [name of copyright owner]
#
# CDDL HEADER END
#
#
# Copyright 1990, 1991 Sun Microsystems, Inc. All Rights Reserved.
#
#
#ident "%Z%%M% %I% %E% SMI"
#
# Tune attributes on system object
#
# This script is intended to set system object attributes
# to values more appropriate for security-conscious environments.
#
# -p : preview flag
mychmod()
{
tmode=$1
file=$2
sgbit=0
then
then
return 1
fi
fi
then
fi
return 0
}
echo
echo "*** Begin Tune Task ***"
then
echo
echo "You are not authorized to change system object attributes."
echo "Task Skipped!"
exit
fi
then
echo
echo "... just previewing - objects attributes not changed"
echo
CHMOD="echo chmod"
CHOWN="echo chown"
CHGRP="echo chgrp"
fi
if [ "$DOWNGRADE" = "true" ]
then
# exit $?
fi
echo
echo "... setting attributes on the system objects defined in"
if [ "$PREV_ASETSECLEVEL" != "$ASETSECLEVEL" ]
then
# we know we are not downgrading, so we must be upgrading.
need_archive="true"
echo "# This file contains original settings of files or" > $archive
echo "# directories that have been changed by ASET." >> $archive
echo >> $archive
else
need_archive="false"
fi
then
echo
echo "tune.task: master file not found: \c"
exit
fi
do
# Skip comments and white lines
if [ "$path" = "#" ]
then
continue;
elif [ "$path" = "" ]
then
continue;
fi
# Warn and skip lines without all the required fields
if [ "$type" = "" ]
then
echo
echo "Warning: bad entry:"
continue;
fi
# Warn and skip lines with too many fields
if [ "$junk" != "" ]
then
echo
echo "Warning: bad entry:"
continue;
fi
do
#
# If the object does not exist on this system then skip it.
#
then
continue;
fi
# If a "?" is found in the mode, user, group field, that
# field is treated as a don't-care and ignored.
#
# If the object is a symbolic link then do not chmod(1) it.
#
changed=false
then
if [ $? -eq 0 ]
then
then
changed=true
fi
fi
fi
if [ "$user" != "?" -a \
then
changed=true
fi
if [ "$group" != "?" -a \
then
changed=true
fi
then
fi
done # for loop
echo
echo "*** End Tune Task ***"