[brussels-dev] IPADM-related Authorizations, Profiles and Privileges
Sebastien Roy
Sebastien.Roy at Sun.COM
Thu Jun 4 06:15:50 PDT 2009
On Wed, 2009-06-03 at 23:17 -0400, Girish M G wrote:
> Sebastien Roy wrote:
> > Ah, okay. Its use of the API is restricted to tweaking the running
> > system based on its own configuration data. Got it.
>
> Correct. nwamd wouldn't need ipadm persistence.
>
> However, on a related note, last time when I ran 'ppriv' on a running
> instance of 'nwamd', it already had 'file_dac_write' privilege.
That's because it currently runs as root with all privileges. My point
was that NWAM Phase 1 is changing that, but it's a moot point given
NWAM's use of the API, as you and Sowmini have pointed out.
Thanks,
-Seb
More information about the brussels-dev
mailing list