>> We can do that, but it doesn't a good solution for me. It's not convenient.
>> I'd like to see that Console User has full authorizations and normal
>> user has *.read/refresh auths. If Console user is also using a
>> 'restricted' version gui I may think about it. But it requires add
>> 'Network Autoconf Admin:solaris:cmd:::/usr/bin/nwam-manager-properties:'
>> to exec_attr. And I'm not sure whether it works and whether we need ARC
>> it again.
>>
>> Renee, could you think it again to let Console User has Network Autoconf
>> Admin profile?
>>
>>     
>
> Doesn't this put us back into the same problem we were trying to avoid,
> namely that the person who is logged into the system has full
> administrative control of ipsec and ipfilter network policy?
>   
Yes, that's the problem this breakup of Network Autoconf is solving.

I can make the necessary changes to exec_attr.

Anurag

Reply via email to