>> >    Only authorizations seem to be explicitly addressed here.  How are
>> >    executables addressed?  That is the use of pfexec?
>> 
>> Through the profiles.  There are no "defaults" exec attributes listed in
>> policy.conf.
>
>       So you're saying that the pfexec search as well as the auth
>       search stops at the "Stop" reserved Rights Profile name.
>
>       That answers my question.

Yes, correct.

Casper

Reply via email to