Glenn Faden wrote: > It is a mistake to be telling users to constantly use pfexec. It was not > designed for that purpose. We should be telling people to assume roles, > via su, or to use sudo.
What? How would it be better if they were using sudo instead of RBAC? I can think of a couple of ways in which it would be worse. Scott -- Scott Rotondo Principal Engineer, Solaris Security Technologies President, Trusted Computing Group Phone/FAX: +1 408 850 3655 (Internal x68278)