Setup guide

UNCLASSIFIED
UNCLASSIFIED
v
iii
Table of Contents
Network..............................................................................................................36
Sharing ...............................................................................................................37
Accounts.............................................................................................................42
Date and Time....................................................................................................44
Software Update.................................................................................................45
Setting the Global umask .......................................................................................46
Securing Initial System Accounts ..........................................................................46
Restricting Administrator’s Home Folder Permissions....................................47
Securing the Root Account ................................................................................47
Using sudo ........................................................................................................49
Securing Single-User Boot.................................................................................49
Logon Warning Banners ........................................................................................52
Auditing and Log File Configuration .....................................................................53
Configuring syslogd ...........................................................................................54
Local Logging.....................................................................................................55
Remote Logging .................................................................................................56
Disabling Hardware Components..........................................................................56
Disabling Mac OS 9 ................................................................................................ 57
Configuring User Accounts......................................................................................... 61
Guidelines for Creating Accounts .......................................................................... 61
Creating User Accounts..........................................................................................62
Granting Administrative Privileges .......................................................................64
Limiting a User Account ........................................................................................65
Managed User: Some Limits .............................................................................65
Managed User: Simple Finder.......................................................................... 68
Securing Users’ Accounts...................................................................................... 68
Restrict Home Folder Permissions................................................................... 68
System Preferences Settings..............................................................................69
Overriding the Default umask ...........................................................................74
Setting Up Keychains for a User Account..............................................................74
Keychain Access................................................................................................. 75
Configuring the login keychain.......................................................................... 75
Creating Multiple Keychains .............................................................................79
Keychain Examples............................................................................................79
Setting the Default Keychain ............................................................................ 84
Additional Notes on Protecting Keychains........................................................85
Using an Account Securely.................................................................................... 86
Future Guidance .........................................................................................................87
Encrypting Files and Folders..................................................................................... 89
Using Disk Utility .................................................................................................. 89
Creating a New, Blank Disk Image With Encryption....................................... 89