Go to main content

Trusted Extensions Configuration and Administration

Exit Print View

Updated: December 2017
 
 

How to Assign Device Authorizations

The Allocate Device authorization enables users to allocate a device. The Allocate Device authorization, and the Revoke or Reclaim Device authorization, are appropriate for administrative roles.

Before You Begin

You must be in the Security Administrator role in the global zone.

If the existing profiles are not appropriate, the security administrator can create a new profile. For an example, see How to Create a Rights Profile for Convenient Authorizations.

  • Assign to the user a rights profile that contains the Allocate Device authorization.

    For the step-by-step procedure, see Assigning Rights to Users in Securing Users and Processes in Oracle Solaris 11.3.

      The following rights profiles enable a role to allocate devices:

    • All Authorizations

    • Device Management

    • Media Backup

    • Object Label Management

    • Software Installation

      The following rights profiles enable a role to revoke or reclaim devices:

    • All Authorizations

    • Device Management

      The following rights profiles enable a role to create or configure devices:

    • All Authorizations

    • Device Security

    Example 53, Creating Fine-Grained Device Authorizations shows how to assign the authorizations.