Oracle VM Template for Oracle Solaris 10 Zone 1. Overview 2. Prerequisites 3. Download and Setup 4. Template Details 4.1. File Names And Sizes 4.2. Passwords And Access 5. Deploying The Template 5.1. Running The Template 5.2. Hardening Security 6. ZFS Best Practices 7. Uninstall 1. Overview This Oracle VM Template for Oracle Solaris Zones is a pre-built Oracle Solaris 10 8/11 Zone (also known as Oracle Solaris zone) ready to download and install. The template is provided as a simple way of establishing an Oracle Solaris 10 Zone on a system running Oracle Solaris 11 11/11. An administrator can therefore easily deploy an Oracle Solaris 10 Zone on an Oracle Solaris 11 system without the need for an Oracle Solaris 10 system to create the zone. The instructions below set out how to deploy these templates. 2. Prerequisites The system must meet following requirements: * A minimum 1 GB of free RAM and a minimum 1 GB of swap memory * At least one network interface connected and configured * A minimum of 10.5 GB of free disk space under UFS or 6.5 GB under ZFS * Oracle Solaris 11 11/11 Operating System * To support Oracle Solaris 10 zones on Oracle Solaris 11, the administrator will need to install the pkg:/system/zones/brand/brand-solaris10 on the Oracle Solaris 11 system prior to deployment of this template. Other notes and requirements * On Oracle Solaris 11, this template requires ZFS * The VM Template supports English language only. * The VM Template has tested on Solaris 11 11/11. It has not been tested on Oracle Solaris 10. 3. Download and Setup For SPARC solaris-10u10-sparc.bin : 1.6GB md5: c425196d276b479954bdc84d614f8e22 For x86 solaris-10u10-x86.bin : 1.2GB md5: 20c34040fe8f70e4cceb0ebd4383f2d2 Rename the file to remove the .bin extension, this is important to ensure proper functioning of the image. e.g. # mv solaris-10u10-sparc.bin solaris-10u10-sparc Make the download file executable: e.g. # chmod +x solaris-10u10-x86.bin 4. Template Details 4.1. Embedded Software Oracle Solaris 10 8/11 Zone (Container) 4.2. Passwords And Access The zone's 'root' password is set to be the same as the root password of the host. The 'root' user can log into the zone from the global zone with the zlogin command. 5. Deploying The Template 5.1. Running The Template Deployment Command - Copy the template to your local file system. - Execute the following command to deploy the template, substituting your own IP address, network interface, directory location, and zone name: # ./solaris-10u10-sparc -p -a -i -z For example: # ./solaris-10u10-sparc -p /cpool -a 192.168.1.2 -i nge0 -f -z dbzone In the above command: * 'solaris-10u10-sparc' is the name of the executable template file (Note that this example is based on the sparc template and the name needs to be changed for the X86 template.) * -a specifies an IP address and optionally a netmask. This is the only required argument * -i specifies network interface. This argument is optional. If not supplied, the user is invited to choose from a list of plumbed NIC * -p specifies the path where the zone is installed. This argument is optional. If not supplied, the user is invited to choose from a list of active ZFS pools, if any. If no active ZFS pool is found, the user is asked to supply a directory path and the execution stops. Note that the template can be install in the pool but it can't be installed in the root directory * -z specifies the name of the zone. This argument is optional. If not supplied, the zone's name defaults to the name of the template * -f fast deployment. Skip the data integrity check to speed up the deployment. This is not recommended when deploying the template for the first time since it may have been altered during download - The logs can be found in /var/sadm/install/logs/solaris-10u10-x86.log. 5.2. Security The Oracle VM Template for Solaris Zone already includes security best practices: insecure network services such as telnet are disabled. Login to the zone is only possible through ssh using a non-root account or through zlogin which requires the user be logged into the 'root' account on the host. Since there is no default or documented password for 'root', the access to the zone is limited to users who know the host 'root' password. To harden the security further, modify the password of the zone's 'root' user. To proceed, log in as 'root' into the zone using 'zlogin'. Once logged in, change the 'root' password with the 'passwd' command. Note: this advice is intended to be a guideline only. For specific Solaris security resources refer to : http://www.oracle.com/us/products/servers-storage/solaris/security/index.html 6. ZFS Best Practices There are many advantages to ZFS, some of which this zone will use : - ZFS compression is automatically turned on, reducing disk-space consumption and possibly reducing disk I/O load and power consumption. - ZFS file-systems are created for the zone. If cloning the zone (using the 'zoneadm clone' command), the resulting zone's file-systems are automatically created by ZFS-cloning the file-systems of the original zone, hence reducing even more disk-space consumption and speeding up the cloning process.. 7. Uninstall To completely remove the template from the system, perform the following actions: (Note that the following commands remove all data associated with the zone, you should ensure any data you wish to retain is backed up prior to this procedure.) - Halt the zone : 'zoneadm -z halt' - Remove the zone : 'zoneadm -z uninstall' - Remove the vnic for this zone e.g. : # zonecfg -z info net net: address not specified allowed-address not specified configure-allowed-address: true physical: vnic9999 defrouter not specified Use the "physical" property to destroy the vnic": # dladm delete-vnic vnic9999 - Remove the zone configuration : 'zonecfg -z delete' - Remove the zonepath directory. If you deployed the template on ZFS : 'zfs destroy '