Solaris Trusted Extensions Administrator's Procedures

policy.conf File Defaults in Trusted Extensions

The Solaris /etc/security/policy.conf file contains the default security settings for the system. Trusted Extensions adds two keywords to this file. You can add these keyword=value pairs to the file if you want to change the system-wide value. These keywords are enforced by Trusted Extensions.

Table 12–1 Trusted Extensions Security Defaults in policy.conf File

Keyword 

Default Value 

Possible Values 

Notes 

IDLECMD 

LOCK 

LOCK | LOGOUT 

Does not apply to roles. 

IDLETIME 

30 

0 to 120 minutes 

Does not apply to roles. 

The authorizations and rights profiles that are defined in the policy.conf file are in addition to any authorizations and profiles that are assigned to individual accounts. For the other fields, the individual user's value overrides the system value.

Planning User Security in Trusted Extensions includes a table of every policy.conf keyword. See also the policy.conf(4) man page.