The global zone and each non-global zone has its own /system/cryptosvc service. When the cryptographic service is enabled or refreshed in the global zone, the kcfd daemon starts in the global zone, user-level policy for the global zone is set, and kernel policy for the system is set. When the service is enabled or refreshed in a non-global zone, the kcfd daemon starts in the zone, and user-level policy for the zone is set. Kernel policy was set by the global zone.
For more information about zones, see Introduction to Oracle Solaris Zones . For more information about using SMF to manage persistent applications, see Chapter 1, Introduction to the Service Management Facility, in Managing System Services in Oracle Solaris 11.2 and the smf (5) man page.