How to remove an SC authorization ?

Hi,
I want that ordinary user doesn't perform "list,show,status" operations.
I know that there is "solaris.cluster.read" authorization, but it is included in "Basic Solaris User" profile. How can I remove it for particular user ?
Thanks

HI jjj,
This is basically a Solaris RBAC Authorization management question. You are right that
by default all cluster "read" authorizations are granted to all Solaris users. Taking away
of individual authorizations (as you want to do), is not very straight-forward because
RBAC is basically designed with the philosophy of "Start with the minimum and ADD
what additional authorizations you need".
That makes it a bit round about to "take away" Cluster read authorizations from
basic Solaris users. Here is a quick and dirty procedure i use, you might wanna
think about this a little more carefully (particularly if you are using NIS or other network
based naming services).
1) Create a new profile in /etc/security/prof_attr which grants all regular Solaris authorizations
except the Sun Cluster related ones. eg
NoSC:::Execute any command as the user or role except Sun CLuster:help=RtNoSC.html
To define the set of authorizations this profile has, just copy the "Basic Solaris User" profile
a little later in that file and remove all authorizations related to SC in there. Name it "Solaris Non Cluster User". Make sure the profiles keyword is NoSC. Do read man prof_attr(4).
2) In /etc/security/policy.conf, change the line
PROFS_GRANTED=Basic Solaris User
To
PROFS_GRANTED=Solaris Non Cluster User
You are DONE!! Now all non-root users on your system cannot run any cluster commands, not
even the commands to view things.
3) For specific users, if you wanna give back cluster viewing priviledges, do, as root
# usermod -A solaris.cluster.whatever.XXX mygooduser
etc. etc.
Hope you get the picture. Please don't do this on a production system without first carefully
researching this. Also, treat that above just as a starting point, come up with your own
procedure after having gone thru appropriate Solaris man pages (start with auths(1)).
PS: Having said all that "philosphy" bit about RBAC and what not, don't i wish "useradd -A"
supported a "!auth" syntax (the way you can do with priviledges to REMOVE A SPECIFIC PRIVILEDGE FROM A SPECIFIC USER)?? Absolutely!! :-) :-). If you figure that out, please post.
Well... post your experience either way.
HTH,
-ashu

Similar Messages

  • How can i remove all PC authorizations from iTunes account?

    How can i remove all PC authorizations from iTunes account?

    Removing a credit card from an account - iTunes Store: Changing Account Information - http://support.apple.com/kb/HT1918 - More information at: https://discussions.apple.com/message/15891166

  • How to remove play authorization on a computer

    I received a reply recently on how to authorize multiple songs after the library was moved to a new computer.
    Now my question is how to remove the authorization on the songs still on my computer. I don't listen to the songs and I want to unauthorized those song on my computer prior to deleting.
    Thanks

    Sorry, but you can't authorize or deauthorize individual tracks, authorization is only done by computer.

  • How can I remove this extra authorization check for dynamic parameters

    Hello expert,
           I created a new dynamic hirarchical parameters as " client-->policy" in crystal report.   these parameter value are coming from a physical table.  the other part of report extract data by a oracle procedure. when I ran this report in client, it is ok for everything. but when I schedule it or run it in infoview,  I need extra authorization for access these dynamic parameter, eventhough this is not for accessing other parameters.  How can I remove this extra authorization check for dynamic parameters?

    Hi
    Open the crystal designer  Edit the parameter In the prompt window at the existing option you can find the LOV name.
    Open the Business view manager and find that prompt name in u201CRepository Exploreru201D window and select that parameter  right click that parameter  Select edit rights  provide rights for your user name in that window.
    --Naga

  • How to remove the Options and Task from the toolbar

    In the FLM portal initially we can see 'Options' in the menu bar after we log in. Below it there is 'Tasks' and 'Reports'. on clicking 'Tasks' and new menu bar 'Tasks' can be seen, under which 'New Tasks' option is there. When we click on 'New Forms' it shows the list of forms and when we select the desired form it opens the interactive form.
    My problem is when this form is opened on the header the 'Options' and 'Tasks' bar can be seen, under which the adobe menu bar comes (Print, Save, Zoom etc.) . This 'Options' and 'Tasks'  how to remove from the interactive forms page.
    Edited by: NIKHILKUMAR POOJARI on Feb 13, 2009 4:24 PM

    Dear Mano,
    By using Authorizations you can remove the Drag and Relate Menu
    Goto Administration ---> System Initialization -
    > Authorization -
    > General Authorization
    General -
    > Drag & Relate -
    > No authorization
    Regarding Authorizations, click the below link to get details
    [Define Authorizations|https://websmp205.sap-ag.de/~form/sapnet?_FRAME=CONTAINER&_HIER_KEY=701100035871000437965&_OBJECT=011000358700000481572006E&_SCENARIO=01100035870000000183&]
    Regards,
    Bala

  • How to remove esclamation mark from itunes

    how to remove esclamation mark from itunes???

    See these...
    -> One computer using multiple iTunes Store authorizations
    -> About iTunes Store authorization and deauthorization

  • Does anyone know how to REMOVE proxy requirement to sign in to CC?

    I've seen quite a few posts while searching on this topic on how to set up a proxy, but I need the opposite.  I made the mistake of using Creative Cloud once with my VPN software running (I only need to use VPN to update one specific program I use for work).  Now, any time I need to sign in to CC, either the updater or to authorize a program (Acrobat XI asks me almost every time I use it), it asks for my proxy username and password (that I use with my VPN), not my regular Adobe ID like it used to.  It's a giant pain to have to fire up my VPN software just to login to get my programs to work.  I'm using this on my personal laptop, and I don't need to use a proxy to get on the internet.  Does anyone know how to remove the proxy login requirement and set it back to just using my Adobe ID?

    Jgabren there should be no requirement to be on a specific network.  I am very concerned by the following statement in your first post, "I only need to use VPN to update one specific program I use for work."  Was this an Adobe application?  Why do you have the requirement to log into your VPN to update this application?
    It does sounds like your computer is managed by an I.T. organization.  I would recommend contacting your I.T. department to ensure this is not a requirement that they have put in place.

  • How to remove the Linked Button in particular forms

    How to remove the linked button in particular sap b1 forms.

    Hi,
    In standard B1 Forms, we can't remove the linked button.
    Why you want to remove linked button.
    I think, the user don't want open the master data?
    In such cases you can use the authorization for the users to access the master data.
    Hope this will help you.
    Regards,
    Venkatesan G.

  • How to remove games (which i doesn't exist in my iOS device) from game centre?

    How to remove games (which i doesn't exist in my iOS device) from game centre? Thanks for help.

    Take a look at this Apple support article; it may help:
    One computer using multiple iTunes Store authorizations
    When i want to buy items from itunes from a new device , it asks for my bank card number , and takes 1-2 dollars from it. Is this ok?
    I'm not sure what you mean by this. What "items"? If you are referring to music, videos or movies, you get only one download per purchase, so if you buy the items again, whether from another device or the same one, yes, you will be charged again. Only apps allow redownloading without additional charge.
    Regards.

  • How to remove approval templates in approval procedures

    Dear sir,
    How to remove approval templates in approval procedures. I have remove some approval templates but some one are not removed. that time i got one error that is "Cannot remove. There are existing authorization processes based on the current template.   [Message 3621-8]" , If it is not removed any solution is there to remove that approval template
    Plz tell me how to solve this problem with step by step procedure in sap business one 2007B.

    Dear sir,
    how to remove approval templates in approval prcedures.
    In this first i will give approval stage to one user, now i have to remove that user from the approval stage. but in my approval templates ( in that stages column) i have give to that approval stage user. now i remove that approval stage user. i have untik the active check also . when i remove that approval  template this error will come in to picture. "Cannot remove. There are existing authorization processes based on the current template.   [Message 3621-8]"
    now tel me the step by step procedure. bcoz iam sap b1 trainee

  • How to remove approval templates in approval proceduresDear sir,  how to re

    Dear sir,
    how to remove approval templates in approval prcedures.
    In this first i will give approval stage to one user, now i have to remove that user from the approval stage. but in my approval templates ( in that stages column) i have give to that approval stage user. now i remove that approval stage user. i have untik the active check also . when i remove that approval template this error will come in to picture. _"Cannot remove. There are existing authorization processes based on the current template. Message 3621-8"
    now tel me the step by step procedure. bcoz iam sap b1 trainee

    Hi,
    Perhaps this may help you. We have had a similar problem regarding making changes to an existing Approval Stage process since we updated to 8.81 PL07.
    We used to be able to make changes to the authoriser for an approval stage (i.e. change the authoriser to a different person), but in PL07 onwards I believe SAP have put in place checks to ensure better consistency of data. Basically, if there are pending approvals based on an approval stage, then you cannot make changes to that Approval Stage until those approval requests have all been processed, i.e. either APPROVED or REJECTED. You have to make sure that there are no outstanding approvals, before the system will let you change the Approval Stage.
    This was our scenario:
    We had an Approval Template using an Approval Stage. The approval was for Sales Orders. We had to make sure that there were no Pending Approvals for Sales Orders. You can check for these by Administration->Approval Procedures->Approval Status Report.
    After this, we also had to make sure that any Sales Orders (drafts) that have already been APPROVED, but have not yet been ADDED were either then ADDED, CLOSED or REMOVED. We used the DOCUMENT DRAFTS REPORT in SALES REPORTS to find any still OPEN draft orders that had an approval status of APPROVED. Use the Forms Setting to display the STATUS and APPROVAL STATUS columns in this report.
    Hope this helps.
    Kind Regards
    Brandon

  • IN PRODCUTION ORDER,REAMRKS FILED IS SET AS MANDATORY USING STORED PROCEDURE..HOW TO REMOVE IT?

    IN PRODCUTION ORDER,REAMRKS FILED IS SET AS MANDATORY USING STORED PROCEDURE..HOW TO REMOVE IT?

    Hi,
    Please try to simply your subject of posting. It is not necessary your subject and body of discussion should be same.
    Yes possible to remove under SQL management studio provided you have authorization to access.
    Thanks & Regards,
    Nagarajan

  • Im trying to associate my new computer to my itunes but it only explains how to remove devices????

    Im trying to associate my new computer to my itunes but it only explains how to remove devices and its incrediby frustrating!!

    See Here for full details... About authorization and deauthorization
    nicoleandfidget wrote:
    Im trying to associate my new computer to my itunes
    You need to Authorize a Computer...
    See this Discussion...
    https://discussions.apple.com/thread/4631735?tstart=0

  • How to remove previous owner's Apple ID request from App Store?

    When I try to update an app App Store asks for the previous owner's Apple ID and not for my Apple ID. How can I change it to ask for my details?How to remove previous owner's Apple ID from App Store?

    Before buying a second-hand computer, you should have run Apple Diagnostics or the Apple Hardware Test, whichever is applicable.
    The first thing to do after buying the computer is to erase the internal drive and install a clean copy of OS X. You—not the original owner—must do that. Changes made by Apple over the years have made this seemingly straightforward task very complex.
    How you go about it depends on the model, and on whether you already own another Mac. If you're not sure of the model, enter the serial number on this page. Then find the model on this page to see what OS version was originally installed.
    It's unsafe, and may be unlawful, to use a computer with software installed by a previous owner.
    1. If you don't own another Mac
    a. If the machine shipped with OS X 10.4 or 10.5, you need a boxed and shrink-wrapped retail Snow Leopard (OS X 10.6) installation disc from the Apple Store or a reputable reseller—not from eBay or anything of the kind. If the machine is very old and has less than 1 GB of memory, you'll need to add more in order to install 10.6. Preferably, install as much memory as it can take, according to the technical specifications.
    b. If the machine shipped with OS X 10.6, you need the installation media that came with it: gray installation discs, or a USB flash drive for a MacBook Air. You should have received the media from the original owner, but if you didn't, order replacements from Apple. A retail disc, or the gray discs from another model, will not work.
    To start up from an optical disc or a flash drive, insert it, then restart the computer and hold down the C key at the startup chime. Release the key when you see the gray Apple logo on the screen.
    c. If the machine shipped with OS X 10.7 or later, you don't need media. It should start up in Internet Recovery mode when you hold down the key combination option-command-R at the startup chime. Release the keys when you see a spinning globe.
    d. Some 2010-2011 models shipped with OS X 10.6 and received a firmware update after 10.7 was released, enabling them to use Internet Recovery. If you have one of those models, you can't reinstall 10.6 even from the original media, and Internet Recovery will not work either without the original owner's Apple ID. In that case, contact Apple Support, or take the machine to an Apple Store or another authorized service provider to have the OS installed.
    2. If you do own another Mac
    If you already own another Mac that was upgraded in the App Store to the version of OS X that you want to install, and if the new Mac is compatible with it, then you can install it. Use Recovery Disk Assistant to prepare a USB device, then start up the new Mac from it by holding down the C key at the startup chime. Alternatively, if you have a Time Machine backup of OS X 10.7.3 or later on an external hard drive (not a Time Capsule or other network device), you can start from that by holding down the option key and selecting it from the row of icons that appears. Note that if your other Mac was never upgraded in the App Store, you can't use this method.
    3. Partition and install OS X
    a. If you see a lock screen when trying to start up from installation media or in Recovery mode, then a firmware password was set by the previous owner, or the machine was remotely locked via iCloud. You'll either have to contact the owner or take the machine to an Apple Store or another service provider to be unlocked. You may be asked for proof of ownership.
    b. Launch Disk Utility and select the icon of the internal drive—not any of the volume icons nested beneath it. In the  Partition tab, select the default options: a GUID partition table with one data volume in Mac OS Extended (Journaled) format. This operation will permanently remove all existing data on the drive.
    c. An unusual problem may arise if all the following conditions apply:
              OS X 10.7 or later was installed by the previous owner
              The startup volume was encrypted with FileVault
              You're booted in Recovery mode (that is, not from a 10.6 installation disc)
    In that case, you won't be able to unlock the volume or partition the drive without the FileVault password. Ask for guidance or see this discussion.
    d. After partitioning, quit Disk Utility and run the OS X Installer. If you're installing a version of OS X acquired from the App Store, you will need the Apple ID and password that you used. When the installation is done, the system will automatically restart into the Setup Assistant, which will prompt you to transfer the data from another Mac, its backups, or from a Windows computer. If you have any data to transfer, this is usually the best time to do it.
    e. Run Software Update and install all available system updates from Apple. To upgrade to a major version of OS X newer than 10.6, get it from the Mac App Store. Note that you can't keep an upgraded version that was installed by the original owner. He or she can't legally transfer it to you, and without the Apple ID you won't be able to update it in Software Update or reinstall, if that becomes necessary. The same goes for any App Store products that the previous owner installed—you have to repurchase them.
    4. Other issues
    a. If the original owner "accepted" the bundled iLife applications (iPhoto, iMovie, and Garage Band) in the App Store so that he or she could update them, then they're irrevocably linked to that Apple ID and you won't be able to download them without buying them. Reportedly, Mac App Store Customer Service has sometimes issued redemption codes for these apps to second owners who asked.
    b. If the previous owner didn't deauthorize the computer in the iTunes Store under his Apple ID, you wont be able to  authorize it immediately under your ID. In that case, you'll either have to wait up to 90 days or contact iTunes Support.
    c. When trying to create a new iCloud account, you might get a failure message: "Account limit reached." Apple imposes a lifetime limit of three iCloud account setups per device. Erasing the device does not reset the limit. You can still use an iCloud account that was created on another device, but you won't be able to create a new one. Contact iCloud Support for more information. The setup limit doesn't apply to Apple ID accounts used for other services, such as the iTunes and Mac App Stores, or iMessage. You can create as many of those accounts as you like.

  • Firefox hangs on opening requiring force quit I have snow leopard mac It hangs when I try safe mode. I need to know how to remove all traces of firefox on my mac so I can reinstall. I have tried terminal as advised on firefox webpage. Please advise m

    Firefox hangs on opening requiring force quit I have snow leopard Mac It even hangs when I try safe mode. I need to know how to remove all traces of firefox on my mac so I can reinstall. I have tried terminal as advised on firefox webpage. Please advise me
    == This happened ==
    Every time Firefox opened
    == I tried to update firefox add-ons ==
    == User Agent ==
    Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-us) AppleWebKit/531.22.7 (KHTML, like Gecko) Version/4.0.5 Safari/531.22.7

    Try a new profile. See [[Recovering important data from an old profile]]

Maybe you are looking for

  • EXC_BAD_ACCESS (SIGBUS)--RAM problems???

    Crash help needed...repeatable with iPhoto, Photobooth, Skype, and general dogged-ness of the machine. AN example of one crash log: Process:         iPhoto [278] Path:            /Applications/iPhoto.app/Contents/MacOS/iPhoto Identifier:      com.app

  • Document Compare Function in Acrobat Professional 9

    Document Compare function I use the 'compare' function to compare documents versions etc for changes. It looks like only 250 pages is the maximum number of pages that can compared during each operation. I am using documents that are 900+ pages and I

  • How to do a file upload & download using Apache Commons FileUpload?

    Hi, I have read through the user guide but I don't understand what are the steps as to implementing the functions... http://commons.apache.org/fileupload/using.html How do I Create a servlet to read the contents(filename) of te dir where the files ar

  • How to reinstall (1st failed) SP4 udpate on same machine

    Dear All, We are on BOBI 4.1 SP2 and we are updating to SP4. This is imp as we want to integrate recent sharepoint server.  We are on SUSE linux. We got the tar files on shared location on Linux. This shared location is available on both Linux and HP

  • Code OARF=printable

    My customer has a customize OAF page and coded following OAF Developers Guide to show their customize OAF page with a printable page after clicking 'Printable Page' button with code OARF=printable. In R11i, on the printable page, only buttons other t