> > PRIV_SYS_IP_CONFIG > > > > Allow a process to configure a system's IP interfaces and > > routes. Allow a process to configure TCP/IP parameters. Allow a > > process to pop anchored STREAMS modules with matching zoneid. > > > > I think the question is whether we should allow "ndd -get .." to succeed > for non-root users. My answer to that question would be "yes", and > that would not require any changes to the above (i.e., to set anything, > you would still need to be privileged)- Girish?
The above is my new wording. The existing wording states that reading ndd parameters also requires PRIV_SYS_IP_CONFIG. -- meem
