I´ve wrote a quite long tutorial about RBAC and privileges. I had to divide it into 4 seperate parts:
PS: The topic is quite complex, thus i simplified some coherences. I hope i didn´t oversimplified them ...
The story of root - reprise
And then there was root again. And root was allmighty. And this time, it wasn´t a bad thing. root was able to distribute the powers between the servants. But no one was as powerful as root. They had only the powers to do their job. But not more. One servant had still the problem with to many prayers, but now this servant wasn´t able to destroy the world.
Continue reading "Less known Solaris features: RBAC and Privileges - Part 4: Epilogue"
Privileges
We´ve talked a lot about RBAC, roles, role profiles. But what are Privileges? Privileges are rights to do an operation in the kernel. This rights are enforced by the kernel. Whenever you do something within the kernel the access is controlled by the privileges.
Continue reading "Less known Solaris features: RBAC and Privileges - Part 3: Privileges"
Some basic terms
As usual the world of RBAC has some special terms. Before using it, i´m want to explain the jargon. I copy the exact definition from the RBAC manual:
Continue reading "Less known Solaris features: RBAC and Privileges - Part 2: Role based access control"
The Story of root
And then there was root. And root was allmighty. And that wasn´t a good thing. root was able to control the world without any control. And root needed control. It was only a short chant between the mere mortals and root. Everybody with the knowledge of the magic chant was able to speak through root.
Continue reading "Less known Solaris features: RBAC and Privileges - Part 1: Introduction"
Comments
Wed, 20.08.2008 11:51
There is a new download for X4 150, X4150 Tools and Drivers C D 2.0, which seems to contain ELOM- and ILOM-firmware. [...]
Wed, 20.08.2008 10:27
Die Wege des Product Engineeri ngs sind unergründlich. Muss i ch ganz ehrlich gesehen: Weiss ich so nicht ...
Wed, 20.08.2008 10:25
Maxing out the Opteron isn´t a problem, as the system would be an SunRay server as well .. .
Wed, 20.08.2008 09:54
"i was afraid of being forced to buy Intel for my next homes erver" Well, if you cannot max out a Opteron with u [...]
Wed, 20.08.2008 08:20
schicke Systeme, koennten mir auch gefallen. Aber warum sind die PCIe-Switches auf einmal von IDT, nicht mehr von [...]