Hi, 

   Solaris has the "Role Based  Access Control "  ( RBAC )   system for 
allowing users access to admin 
functions , base on the role the user is assigned. 

  there is four (4)  shell-level  commands  that can be used to run  commands 
with the elevated access
permission. 

   pfexec  pfsh  pfcsh    pfksh 

  The standard  shell's  does not act upon the RBAC  profile  in /etc/user_attr 

  You can also  make additional   Role-accounts    similar to the root- role  
in OpenSolaris. 
 Create a  role-account   "netadm"   give this account  the 
"network-management"  profile 
 and assign the role to the intended  useraccounts  so that they can  "su"  to 
the "netadm"  role. 

Here is a pointer to the manual: 

http://docs.sun.com/app/docs/doc/819-3321/prbactm-1?l=en&a=view
 
 
This message posted from opensolaris.org

Reply via email to