|
| 1 | +# Example RBAC Profile (/etc/security/prof_attr) |
| 2 | +dn: cn=xVM Management,ou=SolarisProfAttr,__DOMAIN__ |
| 3 | +objectClass: SolarisProfAttr |
| 4 | +objectClass: top |
| 5 | +cn: xVM Management |
| 6 | +SolarisAttrKeyValue: help=RtxvmMngmnt.html |
| 7 | +SolarisAttrLongDesc: xVM Administration |
| 8 | + |
| 9 | +# Put Primary Administrator in LDAP, just in case its not present on a nodes local file. |
| 10 | +dn: cn=Primary Administrator,ou=SolarisProfAttr,__DOMAIN__ |
| 11 | +objectClass: SolarisProfAttr |
| 12 | +objectClass: top |
| 13 | +cn: Primary Administrator |
| 14 | +SolarisAttrKeyValue: auths=solaris.*,solaris.grant;help=RtPriAdmin.html |
| 15 | +SolarisAttrLongDesc: Can perform all administrative tasks |
| 16 | + |
| 17 | +dn: cn=Primary Administrator+SolarisKernelSecurityPolicy=suser+SolarisProfileType=cmd+SolarisProfileId=*,ou=SolarisProfAttr,__DOMAIN__ |
| 18 | +objectClass: SolarisExecAttr |
| 19 | +objectClass: SolarisProfAttr |
| 20 | +objectClass: top |
| 21 | +cn: Primary Administrator |
| 22 | +SolarisKernelSecurityPolicy: suser |
| 23 | +SolarisProfileType: cmd |
| 24 | +SolarisProfileId: * |
| 25 | +SolarisAttrKeyValue: uid=0;gid=0 |
| 26 | + |
| 27 | +# Example of a RBAC Meta-Profile (Profile of Profiles) |
| 28 | +dn: cn=Joyent Level 1,ou=SolarisProfAttr,__DOMAIN__ |
| 29 | +objectClass: SolarisProfAttr |
| 30 | +objectClass: top |
| 31 | +cn: Joyent Level 1 |
| 32 | +SolarisAttrKeyValue: profiles=Zone Management,xVM Administration;help=RtJoyentLvl1.html |
| 33 | +SolarisAttrLongDesc: Joyent General Staff |
| 34 | + |
| 35 | +dn: cn=Joyent Level 2,ou=SolarisProfAttr,__DOMAIN__ |
| 36 | +objectClass: SolarisProfAttr |
| 37 | +objectClass: top |
| 38 | +cn: Joyent Level 2 |
| 39 | +SolarisAttrKeyValue: profiles=Network Management,Network Management,Process Management,ZFS File System Management,Zone Management,Cron Management,File System Management,Maintenance and Repair,xVM Administration,Service Management;help=RtJoyentLvl2.html |
| 40 | +SolarisAttrLongDesc: Joyent Intermediate Engineers |
| 41 | + |
| 42 | +dn: cn=Joyent Level 3,ou=SolarisProfAttr,__DOMAIN__ |
| 43 | +objectClass: SolarisProfAttr |
| 44 | +objectClass: top |
| 45 | +cn: Joyent Level 3 |
| 46 | +SolarisAttrKeyValue: profiles=Primary Administrator;auths=solaris.*,solaris.grant;help=RtJoyentLvl2.html |
| 47 | +SolarisAttrLongDesc: Joyent Senior Engineers |
| 48 | + |
| 49 | +# Example of RBAC Exec (give UID=0 to "xVM Management" profile calling "xm") |
| 50 | +dn: cn=xVM Management+SolarisKernelSecurityPolicy=solaris+SolarisProfileType=cmd+SolarisProfileId=/usr/sbin/xm,ou=SolarisProfAttr,__DOMAIN__ |
| 51 | +objectClass: SolarisExecAttr |
| 52 | +objectClass: SolarisProfAttr |
| 53 | +objectClass: top |
| 54 | +cn: xVM Management |
| 55 | +SolarisKernelSecurityPolicy: solaris |
| 56 | +SolarisProfileType: cmd |
| 57 | +SolarisProfileId: /usr/sbin/xm |
| 58 | +SolarisAttrKeyValue: uid=0 |
| 59 | + |
| 60 | +# Example of RBAC Exec (give UID=0 to "xVM Management" profile calling "virsh") |
| 61 | +dn: cn=xVM Management+SolarisKernelSecurityPolicy=solaris+SolarisProfileType=cmd+SolarisProfileId=/bin/virsh,ou=SolarisProfAttr,__DOMAIN__ |
| 62 | +objectClass: SolarisExecAttr |
| 63 | +objectClass: SolarisProfAttr |
| 64 | +objectClass: top |
| 65 | +cn: xVM Management |
| 66 | +SolarisKernelSecurityPolicy: solaris |
| 67 | +SolarisProfileType: cmd |
| 68 | +SolarisProfileId: /bin/virsh |
| 69 | +SolarisAttrKeyValue: uid=0 |
| 70 | + |
| 71 | +# Example of RBAC Exec (give UID=0 to "xVM Management" profile calling "virt-install") |
| 72 | +dn: cn=xVM Management+SolarisKernelSecurityPolicy=solaris+SolarisProfileType=cmd+SolarisProfileId=/bin/virt-install,ou=SolarisProfAttr,__DOMAIN__ |
| 73 | +objectClass: SolarisExecAttr |
| 74 | +objectClass: SolarisProfAttr |
| 75 | +objectClass: top |
| 76 | +cn: xVM Management |
| 77 | +SolarisKernelSecurityPolicy: solaris |
| 78 | +SolarisProfileType: cmd |
| 79 | +SolarisProfileId: /bin/virt-install |
| 80 | +SolarisAttrKeyValue: uid=0 |
| 81 | + |
| 82 | + |
0 commit comments