---------------------------------------------------------------------------- The Florida SunFlash Account Resource Management(ARM) & Automated Security Enhancement Tool(ASET) SunFLASH Vol 31 #20 July 1991 ---------------------------------------------------------------------------- Software Security Solutions - Sun SHIELD(tm) Account Resource Management - Sun SHIELD Automated Security Enhancement Tool - Technology agreement with RSA - Security products from three new third party vendors SUN PRODUCT HIGHLIGHTS ---------------------- - Account Resource Management (ARM) enables system administrators to create solutions that meet their organizations' unique security needs in the area of login and user account access control. - Automated Security Enhancement Tool (ASET) enables administrators to adjust the level of security on their networks - from the most open access to the most restrictive. - Sun SHIELD is a newly named family of software security products, which includes ARM & ASET, and is offered by SunSoft and available on Sun hardware. ANNOUNCEMENT BRIEF ------------------ As the popularity of open, networked computing has grown, so has the need for securing and protecting the information on the network. The need for software security is especially critical in the commercial marketplace as well as in government and university installations. Now, with SunSoft's new comprehensive set of security offerings, UNIX can better address users' needs for effective, flexible software security tools. Sun Microsystems, demonstrating its commitment to security, is making all of these products available to its end users. Account Resource Management (ARM) and Automated Security Enhancement Tool (ASET) enable corporate MIS managers and network administrators to create customized security solutions that help protect their Unix networks from security breaches. ARM and ASET expand SunSoft's Sun SHIELD security product family which includes data encryption, authentication and a variety of government-required software security features. SunSoft and RSA Data Technologies signed a joint agreement that will incorporate RSA's data encryption technology into existing and future SunSoft security products. The agreement focuses on the addition of RSA's network authentication technology into SunSoft's ONC/NFS (R), an industry standard in multi-vendor networks with an installed base of more than 1.3 million systems. Network authentication helps users control access to sensitive information stored on the network. The agreement will allow the more than 300 licensees of the ONC/NFS networking environment to obtain RSA technology for use in their networking product lines. Pricing and availability will be announced at a later date DEMAX Software, San Mateo, Calif; Security Dynamics, Cambridge, Mass and Software Security, Stamford, Conn today unveiled new products which provide significant security capabilities for SunOS. The new products address critical network security issues such as security management, software piracy and user authentication. SunOS will be the first Unix operating system to feature these new capabilities. FEATURES AND BENEFITS --------------------- ARM: A set of administrative security features which aid system administrators in controlling user account access. All of ARM's features can be customized and are network extensible. ARM capabilities include: -Password aging A password is valid for a user-specified minimum and maximum amount of time. -Disable login after invalid attempts After a specified number of consecutive unsuccessful login attempts, an account is locked for a chosen amount of time. -Account Expiration An account will expire on a specified date. An account may be deleted or placed in an inactive state (i.e. it can be re-activated by the system administrator). -Access Hours The days of the week and the range of hours for which a user is allowed to access the system. -Auto-lockscreen After a specified time limit, idle workstations are automatically put into lockscreen. -Autologout After a specified time limit, idle login sessions are terminated. Login sessions still active after access hours are terminated. -Dialpass When a user attempts to log in to a protected port, s/he has to enter an additional password in order to get logged into the system. -Password qualification Users can define specific requirements for system passwords. The password qualifier is run in order to accept new password. ASET: ASET provides administrators with the ability to easily increase a system's security level. It has three basic capabilities: - Automatically brings systems to a low, medium or high security setting. - Provides warnings of potential security hazards. - Performs system file integrity checks. HARDWARE AND SOFTWARE CONSIDERATIONS ------------------------------------ Both ARM & ASET require SunOS 4.1.x. They are available on SPARC only. Media is CD-ROM. SPECIFIC US ANNOUNCEMENT INFORMATION PRICING AND ORDERING INSTRUCTIONS --------------------------------- ARM & ASET are co-packaged and available in the SMCC End User and Reseller Price Lists. They are in the Sun Server Software Section, under "Sun SHIELD Account Resource Management (ARM) & Automated Security Enhancement Tool (ASET)". THE FOLLOWING APPEAR ON BOTH THE END USER AND RESELLER PRICE LISTS Description Order Number List Discount Software Price Price Category Support Price* ----------------------------------------------------------------------------- ARM/ASET media, documentation, single RTU SEC-1.0-411-4-21 $295 A N/C ARM/ASET documentation only SEC-1.0-X-X-9 $100 A N/C THE FOLLOWING APPEARS ON THE END USER PRICE LIST ONLY Description Order Number List Discount Software Price Price Category Support Price* ----------------------------------------------------------------------------- ARM/ASET media, documentation, site RTU license SEC-1.0-411-4-21S $4500 A N/C *Customer Support is included for those who have existing SunOS Support Agreements. AVAILABILITY ------------ Late Q3CY91. CONTACTS -------- Beverly Ulbrich (bju@Eng) SunSoft Security Product Manager 3rd Party Contacts: DEMAX: Jim Dickey VP Marketing (415) 341-9017 Security Dynamics: Jim Geary VP Marketing (617) 547-7820 Software Security: Jan Norman Marketing (203) 329-8870 RSA: Jim Bidzos President (415) 595-8782 Sun SHIELD is a registered trademark of Sun Microsystems Inc. ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ For information send mail to info-sunflash@sunvice.East.Sun.COM. Subscription requests should be sent to sunflash-request@sunvice.East.Sun.COM. Archives are on solar.nova.edu and paris.cs.miami.edu. All prices, availability, and other statements relating to Sun or third party products are valid in the U.S. only. Please contact your local Sales Representative for details of pricing and product availability in your region. Descriptions of, or references to products or publications within SunFlash does not imply an endorsement of that product or publication by Sun Microsystems. In the US, use 1-800-USA-4-SUN to locate your local sales office, for hardware and software support, and telemarketing (SunEXPRESS). John McLaughlin, SunFlash editor, flash@sunvice.East.Sun.COM. (305) 776-7770.