We're upgrading a server from Solaris 9 to Solaris 10. This would be a good opportunity to convert our init.d scripts into SMF services. Creating a manifest and a method is relatively easy. However, there are a group of users who use sudo to stop and start the process as root. How do we give them the ability to run svcadm to enable or disable the service on Solaris 10? Can this be done in the manifest or the method script? We can't modify the executable itself.
-- -Gary Mills- -Unix Support- -U of M Academic Computing and Networking-
That seems to be exactly what I want. I'd like to eliminate sudo in favour of RBAC, as you noticed. Is this portion of the manifest documented someplace? Is there an existing service that I can use as a model?
-- -Gary Mills- -Unix Support- -U of M Academic Computing and Networking-
In article <KJ7Nj.6123$R_4.4818@newsb.telia.net>, Thommy M. <eclipsed9876543210@hotmail.com> wrote:
Chris Ridd wrote:
I thought some bits of RBAC only appeared in a Solaris 10 update?
I think RBAC was introduced back in the Solaris 8 days...
You are correct. I asked one of our local RBAC wizards, and he says:
The RBAC basis as we know it today was fully in S8 and later.
<SNIP!>
He even reminded me of the first putback into S8:
D 1.1 99/05/13 10:22:39 XXX 1 0 00066/00000/00000 MRs: COMMENTS: PSARC 1997/332; make libsecdb, initial databases and help files *** CHANGED *** 99/05/13 10:23:15 XXX date and time created 99/05/13 10:22:39 by XXX
That ARC case isn't opened up for perusal on opensolaris.org, alas.
Point is --> If you're on a system with SMF, it already has RBAC. -- Daniel L. McDonald - Solaris Security & Networking Engineering Mail: danmcd@sun.com | * MY OPINIONS ARE NOT NECESSARILY SUN'S! * 35 Network Drive Burlington, MA |"rising falling at force ten http://blogs.sun.com/danmcd/ | we twist the world and ride the wind" - Rush
Thommy M. <eclipsed9876543210@hotmail.com> wrote:
Thanks Dan. What about the page listing when different features was
introduced? Or was that only something I remember from inside SWAN?
I don't think I've ever seen such a page from Sun, although I would assume that gathering the details from the "What's New" pages wouldn't be overly tedious.
-- Darren Dunham ddunham@taos.com Senior Technical Consultant TAOS http://www.taos.com/ Got some Dr Pepper? San Francisco, CA bay area < This line left intentionally blank to confuse you. >