Has anyone come across their RBAC files ( 200906 - 111b ) being reduced from 
around 60-odd entries to less than 5 ? Are these files auto-generated now by 
any chance ?

Below is the full contents of the files. Incidentally exec_attr still has all 
it's contents. I know this because I've got the fresh installs bootenv.

$ cat /etc/security/auth_attr 
solaris.cluster.admin:::Manage Quorum Server Daemons::
solaris.cluster.read:::Print Quorum Server Configuration::
solaris.smf.manage.zfs-auto-snapshot:::Manage the ZFS Automatic Snapshot 
Service::

$ cat /etc/security/prof_attr 
Basic Solaris User::::auths=solaris.cluster.read
Quorum Server Management::::auths=solaris.cluster.admin

Looks very strange. I can't run pfexec anymore

pfexec /usr/bin/cat /etc/shadow
/usr/bin/cat: can't get execution attributes

$profiles 
Primary Administrator
Console User
Basic Solaris User
 .. but none of these profiles have any entries in /etc/security/prof_attr

$auths
solaris.device.cdrw,solaris.cluster.read

auths on the fresh install was solaris.*

I have never tried directly editing these files nor have I changed any default 
profiles, or RBAC settings, so I'm confused how this might have happened. Could 
an update has caused this ?

Possibly related to this is that my shutdown option from the menu has 
dissappeared.
-- 
This message posted from opensolaris.org

Reply via email to