
By Glenn Brunette | Article Rating: |
|
September 21, 2009 07:00 AM EDT | Reads: |
11,575 |

Cloud Computing on Ulitzer
Back in June, we released the very first security hardened virtual machine images for the Amazon Web Services Elastic Compute Cloud (EC2) environment. These original images were based upon the OpenSolaris 2008.11 release and were configured in accordance with the guidelines published by Sun the Center for Internet Security.
Since its initial release, we have provided an update to offer this image in the European Region. In August, we took another step forward with the release of a security-enhanced image based upon the OpenSolaris 2009.06 release.
This image went beyond just the simple hardening of its predecessor to add functionality such as encrypted swap, non-executable stacks and auditing that was enabled by default. With such a strong foundation, it should have been no surprise that it was likely to be used as a foundation for layered functionality. Just this month, for example, we announced the release of an image pre-configured with Drupal (v6.10) along with Apache (v2.2), MySQL (v5.0), and PHP (v5.2).
In parallel, the Immutable Service Containers project was announced back in June. This project was focused on the creation of secure execution environments for services. One of the key deliverables from this project has been the OpenSolaris ISC Construction Kit (Preview) that transforms an OpenSolaris 2009.06 system into an ISC configuration. Interestingly, several of the functional elements used today as part of the security-enhanced AMIs actually got their start as part of the ISC Construction Kit.
This brings us to today.
For the first time, we have been able to create ISCs in the Cloud on Amazon EC2! Using the OpenSolaris ISC Construction Kit and the security-enhanced OpenSolaris 2009.06 AMI, we have deployed an ISC that exposes a representative service (in this case, a web server).
HELLO WORLD!
The nice thing about this is that the installation process was essentially the same as the one we used to create our pre-configured OVF image. There were two settings that needed to be adjusted in order for the ISC Construction Kit to properly work on EC2:
These two parameters had to be set before running the iscadm.ksh command. The first parameter simply removes steps that have already been completed in the base AMI (or are not needed for EC2). The second parameter changes the network interface name from e1000g0 (default) to xnf0 which is needed on EC2. That's all there was to it!
If you are interested in ISCs and how you can use them in your environment, I would love to hear from you!
Also, just in case you missed it, I had the pleasure of joining Hal Stern to discuss ISCs on a recent Innovating@Sun podcast. Check it out and send us your feedback! Thanks in advance!
Published September 21, 2009 Reads 11,575
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Glenn Brunette
Glenn Brunette is a Distinguished Engineer and Chief Security Architect at Sun Microsystems. For over 15 years, he has designed and delivered security architectures and solutions supporting a wide array of global customers. Currently, he has focused his efforts on improving security for cloud computing and other highly dynamic and scalable architectures.
![]() Sep. 17, 2017 12:15 AM EDT Reads: 1,097 |
By Elizabeth White ![]() Sep. 16, 2017 08:15 PM EDT Reads: 1,490 |
By Liz McMillan ![]() Sep. 16, 2017 06:30 PM EDT Reads: 4,118 |
By Liz McMillan ![]() Sep. 16, 2017 05:45 PM EDT Reads: 832 |
By Elizabeth White ![]() Sep. 16, 2017 05:15 PM EDT Reads: 1,607 |
By Elizabeth White ![]() Sep. 16, 2017 04:30 PM EDT Reads: 1,662 |
By Liz McMillan ![]() Sep. 16, 2017 04:15 PM EDT Reads: 1,509 |
By Pat Romanski ![]() Sep. 16, 2017 02:15 PM EDT Reads: 4,006 |
By Pat Romanski ![]() Sep. 16, 2017 01:45 PM EDT Reads: 1,677 |
By Yeshim Deniz ![]() Sep. 16, 2017 01:30 PM EDT Reads: 2,074 |
By Elizabeth White ![]() Sep. 16, 2017 01:00 PM EDT Reads: 574 |
By Elizabeth White ![]() Sep. 16, 2017 12:30 PM EDT Reads: 1,750 |
By Elizabeth White ![]() Sep. 16, 2017 12:15 PM EDT Reads: 735 |
By Pat Romanski ![]() Sep. 16, 2017 12:00 PM EDT Reads: 482 |
By Liz McMillan ![]() Sep. 16, 2017 12:00 PM EDT Reads: 1,539 |
By Liz McMillan ![]() Sep. 16, 2017 11:30 AM EDT Reads: 1,931 |
By Carmen Gonzalez ![]() Sep. 16, 2017 11:30 AM EDT Reads: 1,960 |
By Elizabeth White ![]() Sep. 16, 2017 10:00 AM EDT Reads: 550 |
By Pat Romanski ![]() Sep. 16, 2017 08:00 AM EDT Reads: 3,897 |
By Liz McMillan ![]() Sep. 16, 2017 07:00 AM EDT Reads: 586 |