On 2009?03?02? 11:55, Sowmini.Varadhan at Sun.COM wrote:
> On (03/02/09 14:48), Sebastien Roy wrote:
>>> We are considering using a model similar to that used for dladm/flowadm:
>>> have an ipadm RBAC role with auths similar to those for dladm:
>>> i.e., auths=solaris.smf.manage.wpa,solaris.smf.modify.
>> The libdladm model requires that writing to the database be done by
>> dlmgmtd which is run as the dladm user (the datalink.conf file is only
>> writable by the dladm user).  Permissions to write to the file are not
>> related to any authorizations AFAIK.  How will this work for libipadm?
> 
> How does this work for flowadm, which afaict writes to flowadm.conf
> without dlmgmtd being the intermediary?
> 
Looking at the code, I don't think RBAC is considered. In the common case, 
it is read/write by the root user.

The Crossbow team may know more about this.

Thanks
- Cathy

> --Sowmini
> 
> 
> _________________________________
> clearview-discuss mailing list
> clearview-discuss at opensolaris.org


Reply via email to