xref: /titanic_53/usr/src/lib/libsecdb/prof_attr.txt (revision da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0)
17c478bd9Sstevel@tonic-gate#
27c478bd9Sstevel@tonic-gate# CDDL HEADER START
37c478bd9Sstevel@tonic-gate#
47c478bd9Sstevel@tonic-gate# The contents of this file are subject to the terms of the
5a532f31bSgbrunett# Common Development and Distribution License (the "License").
6a532f31bSgbrunett# You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate#
87c478bd9Sstevel@tonic-gate# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate# or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate# See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate# and limitations under the License.
127c478bd9Sstevel@tonic-gate#
137c478bd9Sstevel@tonic-gate# When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate# If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate# fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate# information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate#
197c478bd9Sstevel@tonic-gate# CDDL HEADER END
207c478bd9Sstevel@tonic-gate#
21a532f31bSgbrunett
22a532f31bSgbrunett#
23d71dbb73Sjbeck# Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
24a532f31bSgbrunett# Use is subject to license terms.
25a532f31bSgbrunett#
26a532f31bSgbrunett# ident	"%Z%%M%	%I%	%E% SMI"
27a532f31bSgbrunett#
28a532f31bSgbrunett
29a532f31bSgbrunett#
307c478bd9Sstevel@tonic-gate# /etc/security/prof_attr
317c478bd9Sstevel@tonic-gate#
327c478bd9Sstevel@tonic-gate# profiles attributes. see prof_attr(4)
337c478bd9Sstevel@tonic-gate#
347c478bd9Sstevel@tonic-gateAll:::Execute any command as the user or role:help=RtAll.html
357c478bd9Sstevel@tonic-gateAudit Control:::Configure BSM auditing:auths=solaris.audit.config,solaris.jobs.admin;help=RtAuditCtrl.html
367c478bd9Sstevel@tonic-gateAudit Review:::Review BSM auditing logs:auths=solaris.audit.read;help=RtAuditReview.html
377c478bd9Sstevel@tonic-gateContract Observer:::Reliably observe any/all contract events:help=RtContractObserver.html
387c478bd9Sstevel@tonic-gateDevice Management:::Control Access to Removable Media:auths=solaris.device.*;help=RtDeviceMngmnt.html
394e9cfc9aSjacobsPrinter Management:::Manage printers, daemons, spooling:auths=solaris.print.*,solaris.label.print,solaris.smf.manage.discovery.printers.*,solaris.smf.value.discovery.printers.*;help=RtPrntAdmin.html
407c478bd9Sstevel@tonic-gateCron Management:::Manage at and cron jobs:auths=solaris.jobs.*,solaris.smf.manage.cron;help=RtCronMngmnt.html
417c478bd9Sstevel@tonic-gateLog Management:::Manage log files:help=RtLogMngmnt.html
4218c2aff7SartemBasic Solaris User:::Automatically assigned rights:auths=solaris.profmgr.read,solaris.jobs.user,solaris.mail.mailq,solaris.device.mount.removable;profiles=All;help=RtDefault.html
437c478bd9Sstevel@tonic-gateDevice Security:::Manage devices and Volume Manager:auths=solaris.device.*;help=RtDeviceSecurity.html
447c478bd9Sstevel@tonic-gateDHCP Management:::Manage the DHCP service:auths=solaris.dhcpmgr.*;help=RtDHCPMngmnt.html
45*da6c28aaSamwFile System Management:::Manage, mount, share file systems:profiles=SMB Management;auths=solaris.smf.manage.autofs,solaris.smf.manage.shares.*,solaris.smf.value.shares.*;help=RtFileSysMngmnt.html
467c478bd9Sstevel@tonic-gateFile System Security:::Manage file system security attributes:help=RtFileSysSecurity.html
4718c2aff7SartemHAL Management:::Manage HAL SMF service:auths=solaris.smf.manage.hal;help=RtHALMngmnt.html
48fff9db26Svp157776Idmap Name Mapping Management:::Manage Name-based Mapping Rules of Identity Mapping Service:auths=solaris.admin.idmap.rules;help=RtIdmapNameRulesMngmnt.html
49fff9db26Svp157776Idmap Service Management:::Manage Identity Mapping Service:auths=solaris.smf.manage.idmap,solaris.smf.value.idmap;help=RtIdmapMngmnt.html
50fff9db26Svp157776Inetd Management:::Manage inetd configuration parameters:auths=solaris.smf.manage.inetd,solaris.smf.value.inetd;help=RtInetdMngmnt.html
517c478bd9Sstevel@tonic-gateMail Management:::Manage sendmail & queues:auths=solaris.smf.manage.sendmail;help=RtMailMngmnt.html
52f875b4ebSricaMaintenance and Repair:::Maintain and repair a system:auths=solaris.smf.manage.system-log,solaris.label.range;help=RtMaintAndRepair.html
537c478bd9Sstevel@tonic-gateMedia Backup:::Backup files and file systems:help=RtMediaBkup.html
547c478bd9Sstevel@tonic-gateMedia Restore:::Restore files and file systems from backups:help=RtMediaRestore.html
554b22b933Srs200217Network Management:::Manage the host and network configuration:auths=solaris.smf.manage.name-service-cache,solaris.smf.manage.bind,solaris.smf.value.routing,solaris.smf.manage.routing,solaris.smf.value.nwam,solaris.smf.manage.nwam,solaris.smf.manage.tnd,solaris.smf.manage.tnctl,solaris.smf.manage.wpa,solaris.smf.value.mdns,solaris.smf.manage.mdns;profiles=Network Wifi Management,Inetd Management;help=RtNetMngmnt.html
56f875b4ebSricaNetwork Security:::Manage network and host security:auths=solaris.smf.manage.ssh,solaris.smf.value.tnd;profiles=Network Wifi Security,Network Link Security,Network IPsec Management;help=RtNetSecure.html
57516fc7f3Shx147065Network Wifi Management:::Manage wifi network configuration:auths=solaris.network.wifi.config;help=RtNetWifiMngmnt.html
58516fc7f3Shx147065Network Wifi Security:::Manage wifi network security:auths=solaris.network.wifi.wep;help=RtNetWifiSecure.html
590ba2cbe9Sxc151355Network Link Security:::Manage network link security:auths=solaris.network.link.security;help=RtNetLinkSecure.html
60e3320f40SmarkfenNetwork IPsec Management:::Manage IPsec and IKE:auths=solaris.smf.manage.ipsec,solaris.smf.value.ipsec;help=RtNetIPsec.html
617c478bd9Sstevel@tonic-gateName Service Management:::Non-security name service scripts/commands:help=RtNameServiceAdmin.html
627c478bd9Sstevel@tonic-gateName Service Security:::Security related name service scripts/commands:help=RtNameServiceSecure.html
637c478bd9Sstevel@tonic-gateObject Access Management:::Change ownership and permission on files:help=RtObAccessMngmnt.html
647c478bd9Sstevel@tonic-gateProcess Management:::Manage current processes and processors:auths=solaris.smf.manage.cron,solaris.smf.manage.power;help=RtProcManagement.html
657c478bd9Sstevel@tonic-gateRights Delegation:::Delegate ability to assign rights to users and roles:auths=solaris.role.delegate,solaris.profmgr.delegate,solaris.grant;help=RtRightsDelegate.html
6618c2aff7SartemRmvolmgr Management:::Manage Removable Volume Manager SMF service:auths=solaris.smf.manage.rmvolmgr;help=RtRmvolmgrMngmnt.html
677c478bd9Sstevel@tonic-gateService Management:::Manage services:auths=solaris.smf.manage,solaris.smf.modify
687c478bd9Sstevel@tonic-gateService Operator:::Administer services:auths=solaris.smf.manage,solaris.smf.modify.framework
697c478bd9Sstevel@tonic-gateSoftware Installation:::Add application software to the system:help=RtSoftwareInstall.html
707c478bd9Sstevel@tonic-gateSystem Event Management:::Manage system events and system event channels:help=RtSysEvMngmnt.html
717c478bd9Sstevel@tonic-gateUser Management:::Manage users, groups, home directory:auths=solaris.profmgr.read;help=RtUserMngmnt.html
72f875b4ebSricaUser Security:::Manage passwords, clearances:auths=solaris.role.*,solaris.profmgr.*,solaris.label.range;help=RtUserSecurity.html
737c478bd9Sstevel@tonic-gateFTP Management:::Manage the FTP server:help=RtFTPMngmnt.html
747c478bd9Sstevel@tonic-gateCrypto Management:::Cryptographic Framework Administration:help=RtCryptoMngmnt.html
757c478bd9Sstevel@tonic-gateKerberos Client Management:::Maintain and Administer Kerberos excluding the servers:help=RtKerberosClntMngmnt.html
767c478bd9Sstevel@tonic-gateKerberos Server Management:::Maintain and Administer Kerberos Servers:profiles=Kerberos Client Management;help=RtKerberosSrvrMngmnt.html
777c478bd9Sstevel@tonic-gateDAT Administration:::Manage the DAT configuration:help=RtDatAdmin.html
78*da6c28aaSamwSMB Management:::Manage the SMB service:auths=solaris.smf.manage.smb,solaris.smf.value.smb,solaris.smf.read.smb;help=RtSMBMngmnt.html
79fa9e4066SahrensZFS File System Management:::Create and Manage ZFS File Systems:help=RtZFSFileSysMngmnt.html
80fa9e4066SahrensZFS Storage Management:::Create and Manage ZFS Storage Pools:help=RtZFSStorageMngmnt.html
817c478bd9Sstevel@tonic-gateZone Management:::Zones Virtual Application Environment Administration:help=RtZoneMngmnt.html
827c478bd9Sstevel@tonic-gateIP Filter Management:::IP Filter Administration:help=RtIPFilterMngmnt.html
837c478bd9Sstevel@tonic-gateProject Management:::Add/Modify/Remove projects:help=RtProjManagement.html
84f875b4ebSrica#
85f875b4ebSrica# Trusted Extensions profiles:
86f875b4ebSrica#
87f875b4ebSricaInformation Security:::Maintains MAC and DAC security policies:profiles=Device Security,File System Security,Name Service Security,Network Security,Object Access Management,Object Label Management;help=RtInfoSec.html
88f875b4ebSricaObject Label Management:::Change labels on files.:auths=solaris.device.allocate,solaris.label.file.downgrade,solaris.label.win.downgrade,solaris.label.win.upgrade,solaris.label.file.upgrade,solaris.label.range,solaris.smf.manage.labels;help=RtObjectLabelMngmnt.html
89f875b4ebSricaOutside Accred:::Allow a user to operate outside the user accreditation range.:auths=solaris.label.range;help=RtOutsideAccred.html
90a9fd9a9eSzl149053ISCSI Target Administration:::Configure ISCSI Target service:auths=solaris.smf.modify.iscsitgt,solaris.smf.read.iscsitgt,solaris.smf.value.iscsitgt
91a9fd9a9eSzl149053ISCSI Target Management:::Start/Stop ISCSI Target service:auths=solaris.smf.manage.iscsitgt
92