2N/A# The contents of this file are subject to the terms of the
2N/A# Common Development and Distribution License (the "License").
2N/A# You may not use this file except in compliance with the License.
2N/A# See the License for the specific language governing permissions
2N/A# and limitations under the License.
2N/A# When distributing Covered Code, include this CDDL HEADER in each
2N/A# If applicable, add the following below this CDDL HEADER, with the
2N/A# fields enclosed by brackets "[]" replaced with your own identifying
2N/A# information: Portions Copyright [yyyy] [name of copyright owner]
2N/A# Copyright (c) 1999, 2012, Oracle
and/or its affiliates. All rights reserved.
2N/A# This file is formated in a very specific way to reduce the risk
2N/A# of accidental mismerging on updates. DO NOT change the formating of
2N/A# individual entries and DO follow the style for new entries.
2N/A# It uses \ continuation to break up what is basically one big long line
2N/A# The fields are : separated. The first three fields (and the first three
2N/A# colons) should all be on one line that is NOT indented).
2N/A# The remainder of the fields should all be indented one tab.
2N/A# Each comma separated auths or profile sub entry should be on its own line.
2N/A# and each semi-colon separated sub field should be on its own line too.
2N/A# Example Profile:RO::\
2N/A# An Example profile:\
2N/A# profiles=Sub Example One,\
2N/AExecute any command as the user or role:\
2N/AAdministrator Message Edit:RO::\
2N/AUpdate administrator message files:\
2N/AAudit Configuration:RO::\
2N/AConfigure Solaris Audit:\
2N/AControl Solaris Audit:\
2N/AReview Solaris Auditing logs:\
2N/AManage System as the Console User:\
2N/Aprofiles=Suspend To RAM,\
2N/ACPU Power Management,\
2N/ANetwork Autoconf User;\
2N/AContract Observer:RO::\
2N/ADevice Management:RO::\
2N/AControl Access to Removable Media:\
2N/ACron Management:RO::\
2N/AManage at and cron jobs:\
2N/APrinter Management:RO::\
2N/AManage printers, daemons, spooling:\
2N/ABasic Solaris User:RO::\
2N/AAutomatically assigned rights:\
2N/ADevice Security:RO::\
2N/AManage devices and Volume Manager:\
2N/ADHCP Management:RO::\
2N/AManage the DHCP service:\
2N/AExtended Accounting Flow Management:RO::\
2N/AManage the Flow Extended Accounting service:\
2N/AExtended Accounting Process Management:RO::\
2N/AManage the Process Extended Accounting service:\
2N/AExtended Accounting Task Management:RO::\
2N/AManage the Task Extended Accounting service:\
2N/AExtended Accounting Net Management:RO::\
2N/AManage the Net Extended Accounting service:\
2N/AFile System Management:RO::\
2N/AManage, mount, share file systems:\
2N/Aprofiles=SMB Management,\
2N/AShadow Migration Monitor,\
2N/AZFS File System Management;\
2N/AFile System Security:RO::\
2N/AManage file system security attributes:\
2N/ACommands with forced privileges associated with them:\
2N/AManage HAL SMF service:\
2N/AHotplug Management:RO::\
2N/AManage Hotplug Connections:\
2N/AIdmap Name Mapping Management:RO::\
2N/AManage Name-based Mapping Rules of Identity Mapping Service:\
2N/AIdmap Service Management:RO::\
2N/AManage Identity Mapping Service:\
2N/AInetd Management:RO::\
2N/AManage inetd configuration parameters:\
2N/AMail Management:RO::\
2N/AManage sendmail & queues:\
2N/AMaintenance and Repair:RO::\
2N/AMaintain and repair a system:\
2N/Aprofiles=Hotplug Management;\
2N/ABackup files and file systems:\
2N/Aprofiles=NDMP Management;\
2N/ACatalog files and file systems:\
2N/ARestore files and file systems from backups:\
2N/Aprofiles=NDMP Management;\
2N/ANDMP Management:RO::\
2N/AManage the NDMP service:\
2N/ANetwork Autoconf Admin:RO::\
2N/AManage Network Auto-Magic configuration via nwamd:\
2N/Aprofiles=Network Autoconf User,\
2N/AName Service Security;\
2N/ANetwork Autoconf User:RO::\
2N/ANetwork Auto-Magic User:\
2N/AManage ILB configuration via ilbadm:\
2N/AManage LLDP agents via lldpadm:\
2N/AManage VRRP instances:\
2N/ANetwork Management:RO::\
2N/AManage the host and network configuration:\
2N/Aprofiles=Name Service Management,\
2N/ANetwork Wifi Management,\
2N/ANetwork Observability,\
2N/ANetwork Autoconf Admin,\
2N/ANetwork Observability:RO::\
2N/AAllow access to observability devices:\
2N/Aprivs=net_observability;\
2N/ANetwork Security:RO::\
2N/AManage network and host security:\
2N/Aprofiles=Network Wifi Security,\
2N/ANetwork Link Security,\
2N/ANetwork IPsec Management;\
2N/ANetwork Wifi Management:RO::\
2N/AManage wifi network configuration:\
2N/ANetwork Wifi Security:RO::\
2N/AManage wifi network security:\
2N/ANetwork Link Security:RO::\
2N/AManage network link security:\
2N/ANetwork IPsec Management:RO::\
2N/AManage IPsec and IKE:\
2N/AName Service Management:RO::\
2N/AManage Naming Services:\
2N/AName Service Security:RO::\
2N/AObject Access Management:RO::\
2N/AChange ownership and permission on files:\
2N/ACan perform simple administrative tasks:\
2N/Aprofiles=Printer Management,\
2N/AProcess Management:RO::\
2N/AManage current processes and processors:\
2N/AManage the Reliable Datagram Service:\
2N/AReparse Management:RO::\
2N/AManage the reparse service:\
2N/ARights Delegation:RO::\
2N/ADelegate ability to assign rights to users and roles:\
2N/ARights Management:RO::\
2N/AManage rights profiles and authorizations:\
2N/ARmvolmgr Management:RO::\
2N/AManage Removable Volume Manager SMF service:\
2N/ASecurity Extensions Configuration:RO::\
2N/AConfigure Security Extensions:\
2N/AService Management:RO::\
2N/AService Operator:RO::\
2N/AAdminister services:\
2N/AShadow Migration Monitor:RO::\
2N/AObserve progress of shadow migrations:\
2N/ASoftware Installation:RO::\
2N/AAdd application software to the system:\
2N/Aprofiles=ZFS File System Management;\
2N/ALast Profile evaluated, default profiles are not considered:\
2N/ASystem Administrator:RO::\
2N/ACan perform most non-security administrative tasks:\
2N/Aprofiles=Audit Review,\
2N/AExtended Accounting Flow Management,\
2N/AExtended Accounting Net Management,\
2N/AExtended Accounting Process Management,\
2N/AExtended Accounting Task Management,\
2N/AFile System Management,\
2N/AMaintenance and Repair,\
2N/AName Service Management,\
2N/AObject Access Management,\
2N/AShadow Migration Monitor,\
2N/ASoftware Installation,\
2N/ASystem Configuration,\
2N/AZFS Storage Management;\
2N/ASystem Configuration:RO::\
2N/AManage System Configuration:\
2N/ASystem Event Management:RO::\
2N/AManage system events and system event channels:\
2N/AUser Management:RO::\
2N/AManage users and roles, groups, home directory:\
2N/AAdminister user security:\
2N/AManage the FTP server:\
2N/ACrypto Management:RO::\
2N/ACryptographic Framework Administration:\
2N/AKerberos Client Management:RO::\
2N/AMaintain and Administer Kerberos excluding the servers:\
2N/AKerberos Server Management:RO::\
2N/AMaintain and Administer Kerberos Servers:\
2N/Aprofiles=Kerberos Client Management;\
2N/ADAT Administration:RO::\
2N/AManage the DAT configuration:\
2N/AManage the SMB service:\
2N/ASMBFS Management:RO::\
2N/AManage the SMB client:\
2N/ASTMF Administration:RO::\
2N/AConfigure STMF service:\
2N/ASTMF Management:RO::\
2N/AZFS File System Management:RO::\
2N/ACreate and Manage ZFS File Systems:\
2N/AZFS Storage Management:RO::\
2N/ACreate and Manage ZFS Storage Pools:\
2N/AZones Virtual Application Environment Security:\
2N/AZone Management:RO::\
2N/AZones Virtual Application Environment Administration:\
2N/AIP Filter Management:RO::\
2N/AIP Filter Administration:\
2N/AProject Management:RO::\
2N/AVSCAN Management:RO::\
2N/AManage the VSCAN service:\
2N/AWUSB Management:RO::\
2N/AManage Wireless USB:\
2N/AEvent Notification Agent Management:RO::\
2N/AManage Event Notification Agents:\
2N/AInformation Security:RO::\
2N/AMaintains MAC and DAC security policies:\
2N/Aprofiles=Device Security,\
2N/AFile System Security,\
2N/AName Service Security,\
2N/AObject Access Management,\
2N/AObject Label Management;\
2N/AObject Label Management:RO::\
2N/AChange labels on files, networks, zones:\
2N/AAllow a user to operate outside the user accreditation range.:\
2N/ARAD Configuration:RO::\
2N/AFor authorized users to manage system power:\
2N/AFor authorized users to Suspend system:\
2N/ASuspend To Disk:RO::\
2N/AFor authorized users to Suspend to Disk:\
2N/AFor authorized users to Suspend to RAM:\
2N/AFor authorized users to Control LCD Brightness:\
2N/ACPU Power Management:RO::\
2N/AFor authorized users to manage CPU Power:\
2N/ADo not assign to users. Commands required for Extended Accounting \
2N/AManagement profiles:\
2N/AISNS Server Management:RO::\