By default, an allocatable device has a label range from ADMIN_LOW to ADMIN_HIGH and must be allocated for use. Also, users must be authorized to allocate the device. These defaults can be changed.
You must be in the Security Administrator role in the global zone.
From the Trusted Path menu, select Allocate Device.
The Device Manager appears.
View the default security settings.
Click Device Administration, then highlight the device. The following figure shows a CD-ROM drive with default security settings.
(Optional) Restrict the label range on the device.
Set the minimum label.
Click the Min Label... button. Choose a minimum label from the label builder. For information about the label builder, see Label Builder in Trusted Extensions.
Set the maximum label.
Click the Max Label... button. Choose a maximum label from the label builder.
Specify if the device can be allocated locally.
In the Device Configuration dialog box, under For Allocations From Trusted Path, select an option from the Allocatable By list. By default, the Authorized Users option is checked. Therefore, the device is allocatable and users must be authorized.
Specify if the device can be allocated remotely.
In the For Allocations From Non-Trusted Path section, select an option from the Allocatable By list. By default, the Same As Trusted Path option is checked.
If the device is allocatable, and your site has created new device authorizations, select the appropriate authorization.
The following dialog box shows the solaris.device.allocate authorization is required to allocate the cdrom0 device.
To create and use site-specific device authorizations, see Customizing Device Authorizations in Trusted Extensions (Task Map).
To save your changes, click OK.