>> We can do that, but it doesn't a good solution for me. It's not convenient. >> I'd like to see that Console User has full authorizations and normal >> user has *.read/refresh auths. If Console user is also using a >> 'restricted' version gui I may think about it. But it requires add >> 'Network Autoconf Admin:solaris:cmd:::/usr/bin/nwam-manager-properties:' >> to exec_attr. And I'm not sure whether it works and whether we need ARC >> it again. >> >> Renee, could you think it again to let Console User has Network Autoconf >> Admin profile? >> >> > > Doesn't this put us back into the same problem we were trying to avoid, > namely that the person who is logged into the system has full > administrative control of ipsec and ipfilter network policy? > Yes, that's the problem this breakup of Network Autoconf is solving.
I can make the necessary changes to exec_attr. Anurag
