summaryrefslogtreecommitdiff
path: root/usr/src/lib/libsecdb
diff options
context:
space:
mode:
authorBrian Kuyper <Brian.Kuyper@Sun.COM>2008-09-12 14:37:47 -0500
committerBrian Kuyper <Brian.Kuyper@Sun.COM>2008-09-12 14:37:47 -0500
commita8aa2499030d2f9e4115a6da397fe6592058b788 (patch)
tree9d053b4271f622c0f390c0362962ce4308ef846b /usr/src/lib/libsecdb
parentc3b4ae1846dcc50dda26b0cf1a3d787b8077a0ff (diff)
downloadillumos-joyent-a8aa2499030d2f9e4115a6da397fe6592058b788.tar.gz
6744920 Move the rbac profiles in MMS to the ON standard location
Diffstat (limited to 'usr/src/lib/libsecdb')
-rw-r--r--usr/src/lib/libsecdb/auth_attr.txt12
-rw-r--r--usr/src/lib/libsecdb/exec_attr.txt4
-rw-r--r--usr/src/lib/libsecdb/prof_attr.txt4
3 files changed, 19 insertions, 1 deletions
diff --git a/usr/src/lib/libsecdb/auth_attr.txt b/usr/src/lib/libsecdb/auth_attr.txt
index 45afcf2fa3..f24cb88ed2 100644
--- a/usr/src/lib/libsecdb/auth_attr.txt
+++ b/usr/src/lib/libsecdb/auth_attr.txt
@@ -74,6 +74,13 @@ solaris.login.remote:::Remote Login::help=LoginRemote.html
solaris.mail.:::Mail::help=MailHeader.html
solaris.mail.mailq:::Mail Queue::help=MailQueue.html
#
+solaris.mms.media:::MMS Media Import, Export, Label and Move::help=AuthMMSMedia.html
+solaris.mms.request:::Handle MMS Device Manager Requests::help=AuthMMSRequest.html
+solaris.mms.device.state:::Start and Stop MMS Device Managers::help=AuthMMSDeviceState.html
+solaris.mms.device.log:::Change MMS Trace and Message Levels::help=AuthMMSDeviceLog.html
+solaris.mms.io.read:::Read Permission for MMS Volumes::help=AuthMMSIORead.html
+solaris.mms.io.write:::Read and Write Permission for MMS Volumes::help=AuthMMSIOWrite.html
+#
solaris.network.:::Network::help=NetworkHeader.html
solaris.network.link.security:::Link Security::help=LinkSecurity.html
solaris.network.wifi.config:::Wifi Config::help=WifiConfig.html
@@ -168,3 +175,8 @@ solaris.smf.manage.iscsitgt:::Manage ISCSI Target Service States::help=SmfValueI
solaris.smf.read.iscsitgt:::Read ISCSI Target secrets::help=SmfValueIscsitgt.html
solaris.smf.modify.iscsitgt:::Add/Remove Values of ISCSI Target Service Properties::help=SmfValueIscsitgt.html
solaris.smf.value.iscsitgt:::Change Values of ISCSI Target Service Properties::help=SmfValueIscsitgt.html
+#
+solaris.smf.manage.mms:::Manage MMS Service States::help=SmfManageMMS.html
+solaris.smf.modify.mms:::Add/Remove Values of MMS Service Properties::help=SmfModifyMMS.html
+solaris.smf.value.mms:::Change Values of MMS Service Properties::help=SmfValueMMS.html
+solaris.smf.read.mms:::Read Permission for Protected MMS Service Properties::help=SmfReadMMS.html
diff --git a/usr/src/lib/libsecdb/exec_attr.txt b/usr/src/lib/libsecdb/exec_attr.txt
index 186da4dff7..a41c0ace1c 100644
--- a/usr/src/lib/libsecdb/exec_attr.txt
+++ b/usr/src/lib/libsecdb/exec_attr.txt
@@ -151,6 +151,10 @@ Media Restore:suser:cmd:::/usr/bin/cpio:euid=0
Media Restore:suser:cmd:::/usr/bin/mt:euid=0
Media Restore:suser:cmd:::/usr/lib/fs/ufs/ufsrestore:euid=0
Media Restore:suser:cmd:::/usr/sbin/tar:euid=0
+MMS Administrator:solaris:cmd:::/usr/bin/mmsinit:uid=0
+MMS Administrator:solaris:cmd:::/usr/bin/mmsadm:uid=0
+MMS Operator:solaris:cmd:::/usr/bin/mmsadm:uid=0;privs=file_dac_read
+MMS User:solaris:cmd:::/usr/bin/mmsmnt:uid=0;privs=file_dac_read
Name Service Management:suser:cmd:::/usr/bin/nischttl:euid=0
Name Service Management:suser:cmd:::/usr/bin/nisln:euid=0
Name Service Management:suser:cmd:::/usr/lib/nis/nisctl:euid=0
diff --git a/usr/src/lib/libsecdb/prof_attr.txt b/usr/src/lib/libsecdb/prof_attr.txt
index 6f96046c52..c3815f128a 100644
--- a/usr/src/lib/libsecdb/prof_attr.txt
+++ b/usr/src/lib/libsecdb/prof_attr.txt
@@ -23,7 +23,6 @@
# Copyright 2008 Sun Microsystems, Inc. All rights reserved.
# Use is subject to license terms.
#
-# ident "%Z%%M% %I% %E% SMI"
#
#
@@ -56,6 +55,9 @@ Mail Management:::Manage sendmail & queues:auths=solaris.smf.manage.sendmail;hel
Maintenance and Repair:::Maintain and repair a system:auths=solaris.smf.manage.system-log,solaris.label.range;help=RtMaintAndRepair.html
Media Backup:::Backup files and file systems:profiles=NDMP Management;help=RtMediaBkup.html
Media Restore:::Restore files and file systems from backups:profiles=NDMP Management;help=RtMediaRestore.html
+MMS Administrator:::MMS Media Manager Administrator:auths=solaris.smf.manage.mms,solaris.smf.modify.mms,solaris.smf.value.mms,solaris.mms.*
+MMS Operator:::MMS Media Manager Operator:auths=solaris.smf.manage.mms,solaris.mms.media.*,solaris.mms.request.*,solaris.mms.device.state.*,solaris.mms.device.log.*
+MMS User:::MMS Tape User:auths=solaris.mms.io.*
NDMP Management:::Manage the NDMP service:auths=solaris.smf.manage.ndmp,solaris.smf.value.ndmp,solaris.smf.read.ndmp;help=RtNdmpMngmnt.html
Network Management:::Manage the host and network configuration:auths=solaris.smf.manage.name-service-cache,solaris.smf.manage.bind,solaris.smf.value.routing,solaris.smf.manage.routing,solaris.smf.value.nwam,solaris.smf.manage.nwam,solaris.smf.manage.tnd,solaris.smf.manage.tnctl,solaris.smf.manage.wpa,solaris.smf.value.mdns,solaris.smf.manage.mdns;profiles=Network Wifi Management,Inetd Management;help=RtNetMngmnt.html
Network Security:::Manage network and host security:auths=solaris.smf.manage.ssh,solaris.smf.value.tnd;profiles=Network Wifi Security,Network Link Security,Network IPsec Management;help=RtNetSecure.html