Hardening an OpenSolaris 10 Sandbox Zone

John Burns

Open Solaris 10 sandbox

Version note (updated July 2026): This OpenSolaris/Solaris 10 sandbox note is historical. Do not rely on its JASS-era hardening approach or resource values without validating a supported platform and current security guidance.

Thanks to those friendly people from Digg.com who decided it would be fun to bring my Solaris box to its knees by forking and other things to DDOS my Solaris zone. I have learned many ways of enhancing the security of Solaris zones. I have limited the Sandbox zone to 1% of total CPU usage. I have limited the total number of processes to 1000 and I have installed the Solaris Jass security hardening script. I plan to post many of my discoveries in the future. Work has been busy lately and it is on the burner of things to be done along with part 2 of solaris zones.