17c478bd9Sstevel@tonic-gate<?xml version='1.0'?> 27c478bd9Sstevel@tonic-gate<!DOCTYPE service_bundle SYSTEM '/usr/share/lib/xml/dtd/service_bundle.dtd.1'> 37c478bd9Sstevel@tonic-gate<!-- 47c478bd9Sstevel@tonic-gate CDDL HEADER START 57c478bd9Sstevel@tonic-gate 67c478bd9Sstevel@tonic-gate The contents of this file are subject to the terms of the 70ea5e3a5Sjjj Common Development and Distribution License (the "License"). 80ea5e3a5Sjjj You may not use this file except in compliance with the License. 97c478bd9Sstevel@tonic-gate 107c478bd9Sstevel@tonic-gate You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 117c478bd9Sstevel@tonic-gate or http://www.opensolaris.org/os/licensing. 127c478bd9Sstevel@tonic-gate See the License for the specific language governing permissions 137c478bd9Sstevel@tonic-gate and limitations under the License. 147c478bd9Sstevel@tonic-gate 157c478bd9Sstevel@tonic-gate When distributing Covered Code, include this CDDL HEADER in each 167c478bd9Sstevel@tonic-gate file and include the License file at usr/src/OPENSOLARIS.LICENSE. 177c478bd9Sstevel@tonic-gate If applicable, add the following below this CDDL HEADER, with the 187c478bd9Sstevel@tonic-gate fields enclosed by brackets "[]" replaced with your own identifying 197c478bd9Sstevel@tonic-gate information: Portions Copyright [yyyy] [name of copyright owner] 207c478bd9Sstevel@tonic-gate 217c478bd9Sstevel@tonic-gate CDDL HEADER END 227c478bd9Sstevel@tonic-gate 2313aeadf3SDan OpenSolaris Anderson Copyright 2010 Sun Microsystems, Inc. All rights reserved. 240ea5e3a5Sjjj Use is subject to license terms. 250ea5e3a5Sjjj 260ea5e3a5Sjjj The purpose of the limited_net profile is to provide a set of 270ea5e3a5Sjjj active services that allow one to connect to the machine via ssh 280ea5e3a5Sjjj (requires sshd). The services which are deactivated here are those 290ea5e3a5Sjjj that are at odds with this goal. Those which are activated are 300ea5e3a5Sjjj explicit requirements for the goal's satisfaction. 317c478bd9Sstevel@tonic-gate 327c478bd9Sstevel@tonic-gate NOTE: Service profiles delivered by this package are not editable, 337c478bd9Sstevel@tonic-gate and their contents will be overwritten by package or patch 347c478bd9Sstevel@tonic-gate operations, including operating system upgrade. Make customizations 35*9444c26fSTom Whitten in a distinct file. The paths, /etc/svc/profile/site.xml and 36*9444c26fSTom Whitten /var/svc/profile/site.xml, are distinguished locations for site-specific 37*9444c26fSTom Whitten service profile, treated otherwise equivalently to this file. 387c478bd9Sstevel@tonic-gate--> 397c478bd9Sstevel@tonic-gate<service_bundle type='profile' name='generic_limited_net' 407c478bd9Sstevel@tonic-gate xmlns:xi='http://www.w3.org/2003/XInclude' > 417c478bd9Sstevel@tonic-gate <!-- 427c478bd9Sstevel@tonic-gate Include name service profile, as set by system id tools. 437c478bd9Sstevel@tonic-gate --> 44*9444c26fSTom Whitten <xi:include href='file:/etc/svc/profile/name_service.xml' /> 457c478bd9Sstevel@tonic-gate 467c478bd9Sstevel@tonic-gate <!-- 477c478bd9Sstevel@tonic-gate svc.startd(1M) services 487c478bd9Sstevel@tonic-gate --> 497c478bd9Sstevel@tonic-gate <service name='system/coreadm' version='1' type='service'> 507c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 517c478bd9Sstevel@tonic-gate </service> 527c478bd9Sstevel@tonic-gate <service name='system/cron' version='1' type='service'> 537c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 547c478bd9Sstevel@tonic-gate </service> 557c478bd9Sstevel@tonic-gate <service name='system/cryptosvc' version='1' type='service'> 567c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 577c478bd9Sstevel@tonic-gate </service> 58930e8f32Sartem <service name='system/dbus' version='1' type='service'> 59930e8f32Sartem <instance name='default' enabled='true'/> 60930e8f32Sartem </service> 61074e084fSml93401 <service name='system/extended-accounting' version='1' type='service'> 62074e084fSml93401 <instance name='flow' enabled='false'/> 63074e084fSml93401 <instance name='process' enabled='false'/> 64074e084fSml93401 <instance name='task' enabled='false'/> 65da14cebeSEric Cheng <instance name='net' enabled='false'/> 66074e084fSml93401 </service> 6718c2aff7Sartem <service name='system/hal' version='1' type='service'> 6818c2aff7Sartem <instance name='default' enabled='true'/> 6918c2aff7Sartem </service> 707c478bd9Sstevel@tonic-gate <service name='system/identity' version='1' type='service'> 717c478bd9Sstevel@tonic-gate <instance name='domain' enabled='true'/> 727c478bd9Sstevel@tonic-gate </service> 73bd335c64Sesolom <service name='system/intrd' version='1' type='service'> 74bd335c64Sesolom <instance name='default' enabled='true'/> 75bd335c64Sesolom </service> 767c478bd9Sstevel@tonic-gate <service name='system/keymap' version='1' type='service'> 777c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 787c478bd9Sstevel@tonic-gate </service> 797c478bd9Sstevel@tonic-gate <service name='system/picl' version='1' type='service'> 807c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 817c478bd9Sstevel@tonic-gate </service> 827c478bd9Sstevel@tonic-gate <service name='system/sac' version='1' type='service'> 837c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 847c478bd9Sstevel@tonic-gate </service> 85d98ed3d7Srm88369 <service name='system/scheduler' version='1' type='service'> 86d98ed3d7Srm88369 <instance name='default' enabled='true'/> 87d98ed3d7Srm88369 </service> 887c478bd9Sstevel@tonic-gate <service name='system/system-log' version='1' type='service'> 897c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 907c478bd9Sstevel@tonic-gate </service> 917c478bd9Sstevel@tonic-gate <service name='system/utmp' version='1' type='service'> 927c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 937c478bd9Sstevel@tonic-gate </service> 947c478bd9Sstevel@tonic-gate <service name='system/zones' version='1' type='service'> 957c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 967c478bd9Sstevel@tonic-gate </service> 977c478bd9Sstevel@tonic-gate <service name='network/rpc/bind' version='1' type='service'> 987c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 997c478bd9Sstevel@tonic-gate </service> 1007c478bd9Sstevel@tonic-gate <service name='system/name-service-cache' version='1' type='service'> 1017c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 1027c478bd9Sstevel@tonic-gate </service> 1037c478bd9Sstevel@tonic-gate <service name='network/nfs/status' version='1' type='service'> 1040ea5e3a5Sjjj <instance name='default' enabled='false'/> 1057c478bd9Sstevel@tonic-gate </service> 1067c478bd9Sstevel@tonic-gate <service name='network/nfs/nlockmgr' version='1' type='service'> 1070ea5e3a5Sjjj <instance name='default' enabled='false'/> 1087c478bd9Sstevel@tonic-gate </service> 1097c478bd9Sstevel@tonic-gate <service name='network/nfs/client' version='1' type='service'> 1100ea5e3a5Sjjj <instance name='default' enabled='false'/> 1117c478bd9Sstevel@tonic-gate </service> 1127c478bd9Sstevel@tonic-gate <service name='network/nfs/server' version='1' type='service'> 1130ea5e3a5Sjjj <instance name='default' enabled='false'/> 1147c478bd9Sstevel@tonic-gate </service> 1157c478bd9Sstevel@tonic-gate <service name='network/nfs/rquota' version='1' type='service'> 1160ea5e3a5Sjjj <instance name='default' enabled='false'/> 1177c478bd9Sstevel@tonic-gate </service> 1180ea5e3a5Sjjj <service name='network/nfs/cbd' version='1' type='service'> 1190ea5e3a5Sjjj <instance name='default' enabled='false'/> 1200ea5e3a5Sjjj </service> 1210ea5e3a5Sjjj <service name='network/nfs/mapid' version='1' type='service'> 1220ea5e3a5Sjjj <instance name='default' enabled='false'/> 1230ea5e3a5Sjjj </service> 1244bff34e3Sthurlow <service name='network/smb/client' version='1' type='service'> 1254bff34e3Sthurlow <instance name='default' enabled='false'/> 1264bff34e3Sthurlow </service> 1270ea5e3a5Sjjj 1287c478bd9Sstevel@tonic-gate <service name='network/ssh' version='1' type='service'> 1297c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 1307c478bd9Sstevel@tonic-gate </service> 1317c478bd9Sstevel@tonic-gate <service name='network/smtp' version='1' type='service'> 1327c478bd9Sstevel@tonic-gate <instance name='sendmail' enabled='true'/> 1337c478bd9Sstevel@tonic-gate </service> 134da978630SJohn Beck <service name='network/sendmail-client' version='1' type='service'> 135da978630SJohn Beck <instance name='default' enabled='true'/> 136da978630SJohn Beck </service> 1377c478bd9Sstevel@tonic-gate <service name='network/inetd' version='1' type='restarter'> 1387c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 1397c478bd9Sstevel@tonic-gate </service> 1407c478bd9Sstevel@tonic-gate <service name='system/filesystem/autofs' version='1' type='service'> 1417c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 1427c478bd9Sstevel@tonic-gate </service> 14318c2aff7Sartem <service name='system/filesystem/rmvolmgr' version='1' type='service'> 144b5ff8f93Sfrits <instance name='default' enabled='true'/> 145b5ff8f93Sfrits </service> 1467c478bd9Sstevel@tonic-gate <service name='system/power' version='1' type='service'> 1477c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 1487c478bd9Sstevel@tonic-gate </service> 1497c478bd9Sstevel@tonic-gate 150ead1f93eSLiane Praza <service name='network/dns/multicast' version='1' type='service'> 151ead1f93eSLiane Praza <instance name='default' enabled='false'/> 152ead1f93eSLiane Praza </service> 1537c478bd9Sstevel@tonic-gate <service name='network/dhcp-server' version='1' type='service'> 1547c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1557c478bd9Sstevel@tonic-gate </service> 1567c478bd9Sstevel@tonic-gate <service name='network/ntp' version='1' type='service'> 1577c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1587c478bd9Sstevel@tonic-gate </service> 1597c478bd9Sstevel@tonic-gate <service name='network/rarp' version='1' type='service'> 1607c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1617c478bd9Sstevel@tonic-gate </service> 1627c478bd9Sstevel@tonic-gate <service name='network/slp' version='1' type='service'> 1637c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1647c478bd9Sstevel@tonic-gate </service> 1657c478bd9Sstevel@tonic-gate <service name='network/security/kadmin' version='1' type='service'> 1667c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1677c478bd9Sstevel@tonic-gate </service> 1687c478bd9Sstevel@tonic-gate <service name='network/security/krb5_prop' version='1' type='service'> 1697c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1707c478bd9Sstevel@tonic-gate </service> 1717c478bd9Sstevel@tonic-gate <service name='network/security/krb5kdc' version='1' type='service'> 1727c478bd9Sstevel@tonic-gate <instance name='default' enabled='false' /> 1737c478bd9Sstevel@tonic-gate </service> 1747c478bd9Sstevel@tonic-gate 17569f689b5SVijay HN <service name='application/management/net-snmp' version='1' type='service'> 1760ea5e3a5Sjjj <instance name='default' enabled='false' /> 1770ea5e3a5Sjjj </service> 1780ea5e3a5Sjjj <service name='application/management/seaport' version='1' type='service'> 1790ea5e3a5Sjjj <instance name='default' enabled='false' /> 1800ea5e3a5Sjjj </service> 1810ea5e3a5Sjjj <service name='application/management/snmpdx' version='1' type='service'> 1820ea5e3a5Sjjj <instance name='default' enabled='false' /> 1830ea5e3a5Sjjj </service> 1840ea5e3a5Sjjj <service name='application/management/wbem' version='1' type='service'> 185e98e14f0Srotondo <instance name='default' enabled='true' /> 1860ea5e3a5Sjjj </service> 187c81d47afSceastha <service name='application/print/ipp-listener' version='1' type='service'> 188c81d47afSceastha <instance name='default' enabled='false' /> 189c81d47afSceastha </service> 190c81d47afSceastha <service name='application/print/ppd-cache-update' version='1' type='service'> 1910ea5e3a5Sjjj <instance name='default' enabled='true' /> 1920ea5e3a5Sjjj </service> 193c81d47afSceastha <service name='application/print/rfc1179' version='1' type='service'> 1940ea5e3a5Sjjj <instance name='default' enabled='false' /> 1950ea5e3a5Sjjj </service> 1969622934aSjacobs <service name='application/cups/in-lpd' version='1' type='service'> 1979622934aSjacobs <instance name='default' enabled='false' /> 1989622934aSjacobs </service> 199e047f683Spschow <service name='application/stosreg' version='1' type='service'> 200e047f683Spschow <instance name='default' enabled='true' /> 201e047f683Spschow </service> 2020ea5e3a5Sjjj 2037c478bd9Sstevel@tonic-gate <!-- 2040ea5e3a5Sjjj default inetd(1M) services 2057c478bd9Sstevel@tonic-gate --> 2067c478bd9Sstevel@tonic-gate <service name='network/finger' version='1' type='service'> 2077c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2087c478bd9Sstevel@tonic-gate </service> 2097c478bd9Sstevel@tonic-gate <service name='network/login' version='1' type='service'> 2107c478bd9Sstevel@tonic-gate <instance name='rlogin' enabled='false'/> 2117c478bd9Sstevel@tonic-gate <instance name='klogin' enabled='false'/> 2127c478bd9Sstevel@tonic-gate <instance name='eklogin' enabled='false'/> 2137c478bd9Sstevel@tonic-gate </service> 2147c478bd9Sstevel@tonic-gate <service name='network/shell' version='1' type='service'> 2157c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2167c478bd9Sstevel@tonic-gate <instance name='kshell' enabled='false'/> 2177c478bd9Sstevel@tonic-gate </service> 2187c478bd9Sstevel@tonic-gate <service name='network/telnet' version='1' type='service'> 2197c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2207c478bd9Sstevel@tonic-gate </service> 2217c478bd9Sstevel@tonic-gate 2227c478bd9Sstevel@tonic-gate <!-- 2230ea5e3a5Sjjj non-default inetd(1M) services 2247c478bd9Sstevel@tonic-gate --> 2257c478bd9Sstevel@tonic-gate <service name='network/uucp' version='1' type='service'> 2267c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2277c478bd9Sstevel@tonic-gate </service> 2287c478bd9Sstevel@tonic-gate <service name='network/chargen' version='1' type='service'> 2297c478bd9Sstevel@tonic-gate <instance name='stream' enabled='false'/> 2307c478bd9Sstevel@tonic-gate <instance name='dgram' enabled='false'/> 2317c478bd9Sstevel@tonic-gate </service> 2327c478bd9Sstevel@tonic-gate <service name='network/daytime' version='1' type='service'> 2337c478bd9Sstevel@tonic-gate <instance name='stream' enabled='false'/> 2347c478bd9Sstevel@tonic-gate <instance name='dgram' enabled='false'/> 2357c478bd9Sstevel@tonic-gate </service> 2367c478bd9Sstevel@tonic-gate <service name='network/discard' version='1' type='service'> 2377c478bd9Sstevel@tonic-gate <instance name='stream' enabled='false'/> 2387c478bd9Sstevel@tonic-gate <instance name='dgram' enabled='false'/> 2397c478bd9Sstevel@tonic-gate </service> 2407c478bd9Sstevel@tonic-gate <service name='network/echo' version='1' type='service'> 2417c478bd9Sstevel@tonic-gate <instance name='stream' enabled='false'/> 2427c478bd9Sstevel@tonic-gate <instance name='dgram' enabled='false'/> 2437c478bd9Sstevel@tonic-gate </service> 2447c478bd9Sstevel@tonic-gate <service name='network/time' version='1' type='service'> 2457c478bd9Sstevel@tonic-gate <instance name='stream' enabled='false'/> 2467c478bd9Sstevel@tonic-gate <instance name='dgram' enabled='false'/> 2477c478bd9Sstevel@tonic-gate </service> 2487c478bd9Sstevel@tonic-gate <service name='network/comsat' version='1' type='service'> 2497c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2507c478bd9Sstevel@tonic-gate </service> 2517c478bd9Sstevel@tonic-gate <service name='network/rexec' version='1' type='service'> 2527c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2537c478bd9Sstevel@tonic-gate </service> 2547c478bd9Sstevel@tonic-gate <service name='network/talk' version='1' type='service'> 2557c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2567c478bd9Sstevel@tonic-gate </service> 257e047f683Spschow <service name='network/stdiscover' version='1' type='service'> 258e047f683Spschow <instance name='default' enabled='false'/> 259e047f683Spschow </service> 260e047f683Spschow <service name='network/stlisten' version='1' type='service'> 261e047f683Spschow <instance name='default' enabled='false'/> 262e047f683Spschow </service> 2637c478bd9Sstevel@tonic-gate 2647c478bd9Sstevel@tonic-gate <!-- 2657c478bd9Sstevel@tonic-gate default inetd(1M) RPC services enabled 2667c478bd9Sstevel@tonic-gate --> 2677c478bd9Sstevel@tonic-gate <service name='network/rpc/gss' version='1' type='service'> 2687c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 2697c478bd9Sstevel@tonic-gate </service> 2707c478bd9Sstevel@tonic-gate <service name='network/rpc/mdcomm' version='1' type='service'> 2710ea5e3a5Sjjj <instance name='default' enabled='false'/> 2727c478bd9Sstevel@tonic-gate </service> 2737c478bd9Sstevel@tonic-gate <service name='network/rpc/smserver' version='1' type='service'> 2747c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 2757c478bd9Sstevel@tonic-gate </service> 2767c478bd9Sstevel@tonic-gate <service name='network/security/ktkt_warn' version='1' type='service'> 2777c478bd9Sstevel@tonic-gate <instance name='default' enabled='true'/> 2787c478bd9Sstevel@tonic-gate </service> 2797c478bd9Sstevel@tonic-gate 2807c478bd9Sstevel@tonic-gate <!-- 2817c478bd9Sstevel@tonic-gate default inetd(1M) RPC services disabled 2827c478bd9Sstevel@tonic-gate --> 2837c478bd9Sstevel@tonic-gate <service name='network/rpc/rstat' version='1' type='service'> 2847c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2857c478bd9Sstevel@tonic-gate </service> 2867c478bd9Sstevel@tonic-gate <service name='network/rpc/rusers' version='1' type='service'> 2877c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2887c478bd9Sstevel@tonic-gate </service> 2897c478bd9Sstevel@tonic-gate 2907c478bd9Sstevel@tonic-gate <!-- 2917c478bd9Sstevel@tonic-gate non-default inetd(1M) RPC services disabled 2927c478bd9Sstevel@tonic-gate --> 2937c478bd9Sstevel@tonic-gate <service name='network/rpc/rex' version='1' type='service'> 2947c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2957c478bd9Sstevel@tonic-gate </service> 2967c478bd9Sstevel@tonic-gate <service name='network/rpc/spray' version='1' type='service'> 2977c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 2987c478bd9Sstevel@tonic-gate </service> 2997c478bd9Sstevel@tonic-gate <service name='network/rpc/wall' version='1' type='service'> 3007c478bd9Sstevel@tonic-gate <instance name='default' enabled='false'/> 3017c478bd9Sstevel@tonic-gate </service> 3027c478bd9Sstevel@tonic-gate 3030ea5e3a5Sjjj <!-- 304ead1f93eSLiane Praza Disable Avahi mDNS bridge service 3050ea5e3a5Sjjj --> 306ead1f93eSLiane Praza <service name='system/avahi-bridge-dsd' version='1' type='service'> 307ead1f93eSLiane Praza <instance name='default' enabled='false'/> 3080ea5e3a5Sjjj </service> 309ead1f93eSLiane Praza 310ead1f93eSLiane Praza <!-- 311ead1f93eSLiane Praza Enable CDE/ToolTalk/GDM services. 312ead1f93eSLiane Praza --> 3136a42cb7bSjohnz <service name='network/rpc/cde-ttdbserver' version='1' type='service'> 3146a42cb7bSjohnz <instance name='tcp' enabled='true' /> 3156a42cb7bSjohnz </service> 31613aeadf3SDan OpenSolaris Anderson <service name='application/graphical-login/gdm' version='1' 3170ea5e3a5Sjjj type='service'> 3180ea5e3a5Sjjj <instance name='default' enabled='true' /> 3190ea5e3a5Sjjj </service> 3200ea5e3a5Sjjj <service name='network/rpc/cde-calendar-manager' version='1' type='service'> 3210ea5e3a5Sjjj <instance name='default' enabled='true'/> 3220ea5e3a5Sjjj </service> 3230ea5e3a5Sjjj 3240ea5e3a5Sjjj <!-- 325ead1f93eSLiane Praza Disable X11 services. 3260ea5e3a5Sjjj --> 3276a42cb7bSjohnz <service name='application/x11/xfs' version='1' type='service'> 3286a42cb7bSjohnz <instance name='default' enabled='false'/> 3296a42cb7bSjohnz </service> 3300ea5e3a5Sjjj 331ead1f93eSLiane Praza <!-- 332ead1f93eSLiane Praza Enable VNC config service for xVM 333ead1f93eSLiane Praza --> 334ead1f93eSLiane Praza <service name='system/xvm/vnc-config' version='1' type='service'> 335ead1f93eSLiane Praza <instance name='default' enabled='true'/> 336ead1f93eSLiane Praza </service> 337ead1f93eSLiane Praza 3387c478bd9Sstevel@tonic-gate</service_bundle> 339