1 # 2 # CDDL HEADER START 3 # 4 # The contents of this file are subject to the terms of the 5 # Common Development and Distribution License (the "License"). 6 # You may not use this file except in compliance with the License. 7 # 8 # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9 # or http://www.opensolaris.org/os/licensing. 10 # See the License for the specific language governing permissions 11 # and limitations under the License. 12 # 13 # When distributing Covered Code, include this CDDL HEADER in each 14 # file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15 # If applicable, add the following below this CDDL HEADER, with the 16 # fields enclosed by brackets "[]" replaced with your own identifying 17 # information: Portions Copyright [yyyy] [name of copyright owner] 18 # 19 # CDDL HEADER END 20 # 21 # Copyright 2009 Sun Microsystems, Inc. All rights reserved. 22 # Use is subject to license terms. 23 # 24 # /etc/security/exec_attr 25 # 26 # execution attributes for profiles. see exec_attr(4) 27 # 28 # 29 All:suser:cmd:::*: 30 Audit Control:suser:cmd:::/etc/security/bsmconv:uid=0 31 Audit Control:suser:cmd:::/etc/security/bsmunconv:uid=0 32 Audit Control:solaris:cmd:::/usr/sbin/audit:privs=sys_audit,file_dac_read,proc_owner 33 Audit Control:suser:cmd:::/usr/sbin/audit:euid=0 34 Audit Control:suser:cmd:::/usr/sbin/auditconfig:euid=0 35 Audit Control:suser:cmd:::/usr/sbin/auditd:uid=0 36 Audit Review:suser:cmd:::/usr/sbin/auditreduce:euid=0 37 Audit Review:suser:cmd:::/usr/sbin/auditstat:euid=0 38 Audit Review:suser:cmd:::/usr/sbin/praudit:euid=0 39 Basic Solaris User:solaris:cmd:::/usr/lib/fs/smbfs/mount:privs=sys_mount 40 Basic Solaris User:solaris:cmd:::/usr/lib/fs/smbfs/umount:privs=sys_mount 41 Contract Observer:solaris:cmd:::/usr/bin/ctwatch:\ 42 privs=contract_event,contract_observer 43 Cron Management:suser:cmd:::/usr/bin/crontab:euid=0 44 Crypto Management:suser:cmd:::/usr/sbin/cryptoadm:euid=0 45 Crypto Management:suser:cmd:::/usr/bin/kmfcfg:euid=0 46 Crypto Management:suser:cmd:::/usr/sfw/bin/openssl:euid=0 47 Crypto Management:suser:cmd:::/usr/sfw/bin/CA.pl:euid=0 48 DHCP Management:suser:cmd:::/usr/lib/inet/dhcp/svcadm/dhcpconfig:uid=0 49 DHCP Management:suser:cmd:::/usr/lib/inet/dhcp/svcadm/dhtadm:uid=0 50 DHCP Management:suser:cmd:::/usr/lib/inet/dhcp/svcadm/pntadm:uid=0 51 Device Management:suser:cmd:::/usr/sbin/allocate:uid=0 52 Device Management:suser:cmd:::/usr/sbin/add_drv:uid=0 53 Device Management:suser:cmd:::/usr/sbin/deallocate:uid=0 54 Device Management:suser:cmd:::/usr/sbin/rem_drv:uid=0 55 Device Management:suser:cmd:::/usr/sbin/update_drv:uid=0 56 Device Security:suser:cmd:::/usr/sbin/add_drv:uid=0 57 Device Security:suser:cmd:::/usr/sbin/devfsadm:uid=0 58 Device Security:suser:cmd:::/usr/sbin/eeprom:uid=0 59 Device Security:solaris:cmd:::/usr/bin/kbd:uid=0;gid=sys 60 Device Security:suser:cmd:::/usr/sbin/list_devices:euid=0 61 Device Security:suser:cmd:::/usr/sbin/rem_drv:uid=0 62 Device Security:suser:cmd:::/usr/sbin/strace:euid=0 63 Device Security:suser:cmd:::/usr/sbin/update_drv:uid=0 64 Device Security:suser:cmd:::/usr/sbin/add_allocatable:euid=0 65 Device Security:suser:cmd:::/usr/sbin/remove_allocatable:euid=0 66 FTP Management:suser:cmd:::/usr/sbin/ftpaddhost:uid=0 67 FTP Management:suser:cmd:::/usr/sbin/ftpconfig:uid=0 68 FTP Management:suser:cmd:::/usr/sbin/ftprestart:euid=0 69 FTP Management:suser:cmd:::/usr/sbin/ftpshut:euid=0;egid=sys 70 FTP Management:suser:cmd:::/usr/sbin/privatepw:uid=0;egid=sys 71 File System Management:solaris:cmd:::/sbin/mount:privs=sys_mount 72 File System Management:solaris:cmd:::/sbin/umount:privs=sys_mount 73 File System Management:suser:cmd:::/usr/bin/eject:euid=0 74 File System Management:suser:cmd:::/usr/bin/mkdir:euid=0 75 File System Management:suser:cmd:::/usr/bin/rmdir:euid=0 76 File System Management:suser:cmd:::/usr/lib/autofs/automountd:euid=0 77 File System Management:suser:cmd:::/usr/lib/fs/autofs/automount:euid=0 78 File System Management:suser:cmd:::/usr/lib/fs/nfs/showmount:euid=0 79 File System Management:suser:cmd:::/usr/lib/fs/ufs/fsirand:euid=0 80 File System Management:suser:cmd:::/usr/lib/fs/ufs/newfs:euid=0 81 File System Management:suser:cmd:::/usr/lib/fs/ufs/tunefs:uid=0 82 File System Management:suser:cmd:::/usr/sbin/clri:euid=0 83 File System Management:suser:cmd:::/usr/sbin/devinfo:euid=0 84 File System Management:suser:cmd:::/usr/sbin/dfmounts:euid=0 85 File System Management:suser:cmd:::/usr/sbin/dfshares:euid=0 86 File System Management:suser:cmd:::/usr/sbin/ff:euid=0 87 File System Management:suser:cmd:::/usr/sbin/format:euid=0 88 File System Management:suser:cmd:::/usr/sbin/fsck:euid=0 89 File System Management:suser:cmd:::/usr/sbin/fsdb:euid=0 90 File System Management:suser:cmd:::/usr/sbin/fstyp:euid=0 91 File System Management:suser:cmd:::/usr/sbin/fuser:euid=0 92 File System Management:solaris:cmd:::/usr/sbin/iscsiadm:euid=0;privs=basic 93 File System Management:solaris:cmd:::/usr/sbin/iscsitadm:euid=0;privs=basic 94 File System Management:suser:cmd:::/usr/sbin/mkfile:euid=0 95 File System Management:suser:cmd:::/usr/sbin/mkfs:euid=0 96 File System Management:suser:cmd:::/usr/sbin/mount:uid=0 97 File System Management:suser:cmd:::/usr/sbin/mountall:uid=0 98 File System Management:solaris:cmd:::/usr/sbin/mpathadm:privs=sys_devices 99 File System Management:solaris:cmd:::/usr/sbin/quotacheck:uid=0;gid=sys 100 File System Management:solaris:cmd:::/usr/sbin/quotaoff:uid=0;gid=sys 101 File System Management:solaris:cmd:::/usr/sbin/quotaon:uid=0;gid=sys 102 File System Management:solaris:cmd:::/usr/sbin/raidctl:privs=sys_config,sys_devices;euid=0 103 File System Management:suser:cmd:::/usr/sbin/ramdiskadm:euid=0 104 File System Management:solaris:cmd:::/usr/sbin/sasinfo:privs=sys_devices 105 File System Management:solaris:cmd:::/usr/sbin/sbdadm:privs=sys_devices 106 File System Management:suser:cmd:::/usr/sbin/share:uid=0;gid=root 107 File System Management:suser:cmd:::/usr/sbin/sharemgr:uid=0;gid=root 108 File System Management:suser:cmd:::/usr/sbin/shareall:uid=0;gid=root 109 File System Management:solaris:cmd:::/usr/sbin/stmfadm:privs=sys_devices 110 File System Management:suser:cmd:::/usr/sbin/swap:euid=0 111 File System Management:suser:cmd:::/usr/sbin/umount:uid=0 112 File System Management:suser:cmd:::/usr/sbin/umountall:uid=0 113 File System Management:suser:cmd:::/usr/sbin/unshare:uid=0;gid=root 114 File System Management:suser:cmd:::/usr/sbin/unshareall:uid=0;gid=root 115 IP Filter Management:solaris:cmd:::/usr/sbin/ipf:privs=sys_ip_config 116 IP Filter Management:solaris:cmd:::/usr/sbin/ipfs:privs=sys_ip_config 117 IP Filter Management:solaris:cmd:::/usr/sbin/ipmon:privs=sys_ip_config 118 IP Filter Management:solaris:cmd:::/usr/sbin/ipfstat:privs=sys_ip_config;gid=sys 119 IP Filter Management:solaris:cmd:::/usr/sbin/ipnat:privs=sys_ip_config;gid=sys 120 IP Filter Management:solaris:cmd:::/usr/sbin/ippool:privs=sys_ip_config;gid=sys 121 Kerberos Server Management:solaris:cmd:::/usr/lib/krb5/krb5kdc:uid=0 122 Kerberos Server Management:solaris:cmd:::/usr/lib/krb5/kadmind:uid=0 123 Kerberos Server Management:solaris:cmd:::/usr/lib/krb5/kprop:euid=0;privs=none 124 Kerberos Server Management:solaris:cmd:::/usr/sbin/kadmin.local:euid=0;privs=none 125 Kerberos Server Management:solaris:cmd:::/usr/sbin/kdb5_util:euid=0;privs=none 126 Kerberos Server Management:solaris:cmd:::/usr/sbin/kdb5_ldap_util:euid=0;privs=none 127 Kerberos Server Management:solaris:cmd:::/usr/sbin/kdcmgr:euid=0;privs=none 128 Kerberos Client Management:solaris:cmd:::/usr/bin/klist:euid=0;privs=file_dac_read 129 Kerberos Client Management:solaris:cmd:::/usr/sbin/kadmin:euid=0;privs=none 130 Kerberos Client Management:solaris:cmd:::/usr/sbin/kclient:euid=0;privs=none 131 Log Management:suser:cmd:::/usr/sbin/logadm:euid=0 132 Mail Management:suser:cmd:::/usr/lib/sendmail:uid=0 133 Mail Management:suser:cmd:::/usr/sbin/editmap:euid=0 134 Mail Management:suser:cmd:::/usr/sbin/makemap:euid=0 135 Mail Management:suser:cmd:::/usr/sbin/newaliases:euid=0 136 Maintenance and Repair:solaris:cmd:::/usr/bin/mdb:privs=all 137 Maintenance and Repair:suser:cmd:::/usr/bin/mdb:euid=0 138 Maintenance and Repair:solaris:cmd:::/usr/bin/coreadm:euid=0;privs=proc_owner 139 Maintenance and Repair:suser:cmd:::/usr/bin/date:euid=0 140 Maintenance and Repair:suser:cmd:::/usr/bin/ldd:euid=0 141 Maintenance and Repair:suser:cmd:::/usr/bin/vmstat:euid=0 142 Maintenance and Repair:suser:cmd:::/usr/sbin/eeprom:euid=0 143 Maintenance and Repair:suser:cmd:::/usr/sbin/halt:euid=0 144 Maintenance and Repair:suser:cmd:::/sbin/init:uid=0 145 Maintenance and Repair:solaris:cmd:::/usr/sbin/pcitool:privs=all 146 Maintenance and Repair:suser:cmd:::/usr/sbin/poweroff:uid=0 147 Maintenance and Repair:suser:cmd:::/usr/sbin/prtconf:euid=0 148 Maintenance and Repair:suser:cmd:::/usr/sbin/reboot:uid=0 149 Maintenance and Repair:suser:cmd:::/usr/sbin/syslogd:euid=0 150 Maintenance and Repair:suser:cmd:::/sbin/bootadm:euid=0 151 Maintenance and Repair:solaris:cmd:::/usr/sbin/ucodeadm:privs=all 152 Media Backup:suser:cmd:::/usr/bin/mt:euid=0 153 Media Backup:suser:cmd:::/usr/lib/fs/ufs/ufsdump:euid=0;gid=sys 154 Media Backup:suser:cmd:::/usr/sbin/tar:euid=0 155 Media Catalog:solaris:cmd:::/usr/bin/bart:\ 156 privs=file_dac_read,file_dac_search 157 Media Restore:suser:cmd:::/usr/bin/cpio:euid=0 158 Media Restore:suser:cmd:::/usr/bin/mt:euid=0 159 Media Restore:suser:cmd:::/usr/lib/fs/ufs/ufsrestore:euid=0 160 Media Restore:suser:cmd:::/usr/sbin/tar:euid=0 161 MMS Administrator:solaris:cmd:::/usr/bin/mmsinit:uid=0 162 MMS Administrator:solaris:cmd:::/usr/bin/mmsadm:uid=0 163 MMS Operator:solaris:cmd:::/usr/bin/mmsadm:uid=0;privs=file_dac_read 164 MMS User:solaris:cmd:::/usr/bin/mmsmnt:uid=0;privs=file_dac_read 165 Name Service Management:suser:cmd:::/usr/sbin/nscd:euid=0 166 Name Service Security:suser:cmd:::/usr/bin/chkey:euid=0 167 Name Service Security:suser:cmd:::/usr/sbin/ldapclient:uid=0 168 Name Service Security:suser:cmd:::/usr/sbin/newkey:euid=0 169 Network Management:solaris:cmd:::/sbin/ifconfig:uid=0 170 Network Management:solaris:cmd:::/sbin/route:privs=sys_ip_config 171 Network Management:solaris:cmd:::/sbin/routeadm:euid=0;\ 172 privs=proc_chroot,proc_owner,sys_ip_config 173 Network Management:solaris:cmd:::/sbin/dladm:euid=dladm;egid=sys;\ 174 privs=sys_dl_config,net_rawaccess,proc_audit 175 Network Management:solaris:cmd:::/sbin/flowadm:euid=dladm;egid=sys;\ 176 privs=sys_dl_config,net_rawaccess,proc_audit 177 Network Management:suser:cmd:::/usr/bin/netstat:uid=0 178 Network Management:suser:cmd:::/usr/bin/rup:euid=0 179 Network Management:suser:cmd:::/usr/bin/ruptime:euid=0 180 Network Management:suser:cmd:::/usr/bin/setuname:euid=0 181 Network Management:suser:cmd:::/usr/sbin/asppp2pppd:euid=0 182 Network Management:suser:cmd:::/usr/sbin/ifconfig:uid=0 183 Network Management:suser:cmd:::/usr/sbin/ipaddrsel:euid=0 184 Network Management:suser:cmd:::/usr/sbin/ipqosconf:euid=0 185 Network Management:suser:cmd:::/usr/sbin/rndc:privs=file_dac_read 186 Network Management:suser:cmd:::/usr/sbin/route:uid=0 187 Network Management:suser:cmd:::/usr/sbin/snoop:uid=0 188 Network Management:solaris:cmd:::/usr/sbin/snoop:privs=net_observability 189 Network Management:suser:cmd:::/usr/sbin/spray:euid=0 190 Network Observability:solaris:cmd:::/usr/sbin/snoop:privs=net_observability 191 Network Link Security:solaris:cmd:::/sbin/dladm:euid=dladm;egid=sys;\ 192 privs=sys_dl_config,net_rawaccess,proc_audit 193 Network IPsec Management:solaris:cmd:::/usr/lib/inet/certdb:euid=0;privs=none 194 Network IPsec Management:solaris:cmd:::/usr/lib/inet/certlocal:euid=0;privs=none 195 Network IPsec Management:solaris:cmd:::/usr/lib/inet/certrldb:euid=0;privs=none 196 Network IPsec Management:solaris:cmd:::/usr/lib/inet/in.iked:euid=0 197 Network IPsec Management:solaris:cmd:::/usr/sbin/ikeadm:euid=0;privs=file_dac_write 198 Network IPsec Management:solaris:cmd:::/usr/sbin/ikecert:euid=0;privs=none 199 Network IPsec Management:solaris:cmd:::/usr/sbin/ipsecconf:euid=0;privs=sys_ip_config 200 Network IPsec Management:solaris:cmd:::/usr/sbin/ipseckey:uid=0;privs=sys_ip_config 201 Network IPsec Management:solaris:cmd:::/usr/sbin/ipsecalgs:privs=sys_ip_config 202 Network IPsec Management:suser:cmd:::/usr/lib/inet/certdb:euid=0 203 Network IPsec Management:suser:cmd:::/usr/lib/inet/certlocal:euid=0 204 Network IPsec Management:suser:cmd:::/usr/lib/inet/certrldb:euid=0 205 Network IPsec Management:suser:cmd:::/usr/lib/inet/in.iked:euid=0 206 Network IPsec Management:suser:cmd:::/usr/sbin/ikeadm:euid=0 207 Network IPsec Management:suser:cmd:::/usr/sbin/ikecert:euid=0 208 Network IPsec Management:suser:cmd:::/usr/sbin/ipsecconf:euid=0 209 Network IPsec Management:suser:cmd:::/usr/sbin/ipseckey:uid=0 210 Network IPsec Management:suser:cmd:::/usr/sbin/ipsecalgs:euid=0 211 Network Security:solaris:cmd:::/usr/sbin/ksslcfg:euid=0 212 Network Security:suser:cmd:::/usr/bin/ssh-keygen:uid=0;gid=sys 213 Object Access Management:solaris:cmd:::/usr/bin/chgrp:privs=file_chown 214 Object Access Management:solaris:cmd:::/usr/bin/chmod:privs=file_owner 215 Object Access Management:solaris:cmd:::/usr/bin/chown:privs=file_chown 216 Object Access Management:solaris:cmd:::/usr/bin/setfacl:privs=file_owner 217 Object Access Management:suser:cmd:::/usr/bin/chgrp:euid=0 218 Object Access Management:suser:cmd:::/usr/bin/chmod:euid=0 219 Object Access Management:suser:cmd:::/usr/bin/chown:euid=0 220 Object Access Management:suser:cmd:::/usr/bin/getfacl:euid=0 221 Object Access Management:suser:cmd:::/usr/bin/setfacl:euid=0 222 Printer Management:suser:cmd:::/usr/lib/lp/local/lpadmin:uid=lp;gid=lp 223 Printer Management:suser:cmd:::/usr/sbin/lpfilter:euid=lp;uid=lp 224 Printer Management:suser:cmd:::/usr/sbin/lpforms:euid=lp 225 Printer Management:suser:cmd:::/usr/sbin/lpusers:euid=lp 226 Printer Management:suser:cmd:::/usr/sbin/ppdmgr:euid=0 227 Process Management:solaris:cmd:::/usr/bin/kill:privs=proc_owner 228 Process Management:solaris:cmd:::/usr/bin/nice:privs=proc_owner,proc_priocntl 229 Process Management:solaris:cmd:::/usr/bin/pcred:privs=proc_owner 230 Process Management:solaris:cmd:::/usr/bin/pfiles:privs=proc_owner 231 Process Management:solaris:cmd:::/usr/bin/pflags:privs=proc_owner 232 Process Management:solaris:cmd:::/usr/bin/ppriv:privs=proc_owner 233 Process Management:solaris:cmd:::/usr/bin/renice:privs=proc_owner,proc_priocntl 234 Process Management:suser:cmd:::/usr/bin/crontab:euid=0 235 Process Management:suser:cmd:::/usr/bin/kill:euid=0 236 Process Management:suser:cmd:::/usr/bin/nice:euid=0 237 Process Management:suser:cmd:::/usr/bin/pcred:euid=0 238 Process Management:suser:cmd:::/usr/bin/pfiles:euid=0 239 Process Management:suser:cmd:::/usr/bin/pflags:euid=0 240 Process Management:suser:cmd:::/usr/bin/pldd:euid=0 241 Process Management:suser:cmd:::/usr/bin/pmap:euid=0 242 Process Management:suser:cmd:::/usr/bin/prun:euid=0 243 Process Management:suser:cmd:::/usr/bin/ps:euid=0 244 Process Management:suser:cmd:::/usr/bin/psig:euid=0 245 Process Management:suser:cmd:::/usr/bin/pstack:euid=0 246 Process Management:suser:cmd:::/usr/bin/pstop:euid=0 247 Process Management:suser:cmd:::/usr/bin/ptime:euid=0 248 Process Management:suser:cmd:::/usr/bin/ptree:euid=0 249 Process Management:suser:cmd:::/usr/bin/pwait:euid=0 250 Process Management:suser:cmd:::/usr/bin/pwdx:euid=0 251 Process Management:suser:cmd:::/usr/bin/renice:euid=0 252 Process Management:suser:cmd:::/usr/bin/truss:euid=0 253 Process Management:suser:cmd:::/usr/sbin/fuser:euid=0 254 Process Management:solaris:cmd:::/usr/sbin/rcapadm:uid=0 255 Project Management:solaris:cmd:::/usr/sbin/projadd:euid=0 256 Project Management:solaris:cmd:::/usr/sbin/projmod:euid=0 257 Project Management:solaris:cmd:::/usr/sbin/projdel:euid=0 258 Software Installation:suser:cmd:::/usr/bin/ln:euid=0 259 Software Installation:suser:cmd:::/usr/bin/pkginfo:uid=0 260 Software Installation:suser:cmd:::/usr/bin/pkgmk:uid=0 261 Software Installation:suser:cmd:::/usr/bin/pkgparam:uid=0 262 Software Installation:suser:cmd:::/usr/bin/pkgproto:uid=0 263 Software Installation:suser:cmd:::/usr/bin/pkgtrans:uid=0 264 Software Installation:suser:cmd:::/usr/ccs/bin/make:euid=0 265 Software Installation:suser:cmd:::/usr/sbin/install:euid=0 266 Software Installation:suser:cmd:::/usr/sbin/pkgadd:uid=0;gid=bin 267 Software Installation:suser:cmd:::/usr/sbin/pkgask:uid=0 268 Software Installation:suser:cmd:::/usr/sbin/pkgchk:uid=0 269 Software Installation:suser:cmd:::/usr/sbin/pkgrm:uid=0;gid=bin 270 System Event Management:suser:cmd:::/usr/sbin/syseventadm:uid=0 271 User Management:suser:cmd:::/usr/sbin/grpck:euid=0 272 User Management:suser:cmd:::/usr/sbin/pwck:euid=0 273 User Management:solaris:cmd:::/usr/sbin/useradd:uid=0 274 User Management:solaris:cmd:::/usr/sbin/userdel:uid=0 275 User Management:solaris:cmd:::/usr/sbin/usermod:uid=0 276 User Management:solaris:cmd:::/usr/sbin/roleadd:uid=0 277 User Management:solaris:cmd:::/usr/sbin/roledel:uid=0 278 User Management:solaris:cmd:::/usr/sbin/rolemod:uid=0 279 User Management:solaris:cmd:::/usr/sbin/groupadd:uid=0 280 User Management:solaris:cmd:::/usr/sbin/groupdel:uid=0 281 User Management:solaris:cmd:::/usr/sbin/groupmod:uid=0 282 User Security:suser:cmd:::/usr/bin/passwd:uid=0 283 User Security:solaris:cmd:::/usr/sbin/passmgmt:uid=0 284 User Security:suser:cmd:::/usr/sbin/pwck:euid=0 285 User Security:suser:cmd:::/usr/sbin/pwconv:euid=0 286 DAT Administration:solaris:cmd:::/usr/sbin/datadm:euid=0 287 ZFS File System Management:solaris:cmd:::/sbin/zfs:euid=0 288 ZFS Storage Management:solaris:cmd:::/sbin/zpool:uid=0 289 ZFS Storage Management:solaris:cmd:::/usr/lib/zfs/availdevs:uid=0 290 Zone Management:solaris:cmd:::/usr/sbin/txzonemgr:uid=0 291 Zone Management:solaris:cmd:::/usr/sbin/zonecfg:uid=0 292 Zone Management:solaris:cmd:::/usr/sbin/zoneadm:uid=0 293 Zone Management:solaris:cmd:::/usr/sbin/zlogin:uid=0 294 acctadm:solaris:cmd:::/usr/sbin/acctadm:euid=0;egid=0;privs=sys_acct,file_dac_write 295