Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX System Administrator's Guide: Security Management: HP-UX 11i Version 3 > Chapter 8 Fine-Grained Privileges

Available Privileges

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

Fine-grained privileges are primarily targeted for developers. However, an administrator may still need to understand the privileges to understand how such applications work and to find if any unauthorized applications have gained privileges.

Table 8-3 lists the privileges and their primary purposes.

Table 8-3 Available Privileges

Privilege

Description

PRIV_ACCOUNTINGAllows a process to control the process accounting system.
PRIV_AUDCONTROLAllows a process to start, modify, and stop the auditing system.
PRIV_CHANGECMPTGrants a process the ability to change its compartment.
PRIV_CHANGEFILEXSECAllows a process to grant privileges to binaries.

PRIV_CHOWN

Allows a process to access the chown() system calls.

PRIV_CHROOTAllows a process to change its root directory.
PRIV_CHSUBJIDENTAllows a process to change its UIDs, GIDs, and group lists. Also allows a process to leave the suid or sgid bits set on the file when the chown() system call is used.
PRIV_CMPTREADAllows a process to open a file or directory for reading, executing, or searching, bypassing compartment rules that otherwise would not permit these operations.
PRIV_CMPTWRITEAllows a process to write to a file or directory, bypassing compartment rules that otherwise would not permit this operation.
PRIV_COMMALLOWEDAllows a process to override compartment rules in the IPC and networking subsystems.
PRIV_DACREADAllows a process to override all discretionary read, execute, and search access restrictions.
PRIV_DACWRITEAllows a process to override all discretionary write access restrictions.
PRIV_DEVOPSAllows a process to do device-specific administrative operations, such as tape or disk formatting.
PRIV_DLKMAllows a process to load a kernel module, get information about a loaded kernel module, and change global search paths for a dynamically loadable kernel module.
PRIV_FSINTEGRITYAllows a process to perform disk operations such as removing or modifying the size or boundaries of disk partitions, or to import and export an LVM volume group across the system.
PRIV_LIMITAllows a process to set resource and priority limits beyond the maximum limit values.

PRIV_LOCKRDONLY

Allows a process to use the lockf() system call to lock files opened with read-only permission.

PRIV_MKNODAllows a process to create character or block special files using the mknod() system call.

PRIV_MLOCK

Allows a process to access the plock system call.

PRIV_MOUNTAllows a process to mount and unmount a file system using the mount() and umount() system calls.

PRIV_MPCTL

Allows a process to change processor binding, locality domain binding, or launch policy.

PRIV_NETADMINAllows a process to perform network administrative operations including configuring the network routing tables and querying interface information.

PRIV_NETPRIVPORT

Allows a process to bind to a privileged port. By default, port numbers 0-1023 are privileged ports.

PRIV_NETPROMISCUOUS

Allows a process to configure an interface to listen in promiscuous mode.

PRIV_NETRAWACCESS

Allows a process to access the raw internet network protocols.

PRIV_OBJSUID

Allows a process to set the suid or sgid bits on any file if the process has the OWNER privilege. It also allows a process to change the ownership of a file without clearing the suid or sgid bits, provided that the process is allowed to change the ownership of the file.

PRIV_OWNER

Allows a process to override all restrictions with respect to UID matching the owner of the file or resource.

PRIV_PSET

Allows a process to change the system pset configuration.

PRIV_REBOOT

Allows a process to perform reboot operations.

PRIV_RTPRIO

Allows a process to access the rtprio() system call.

PRIV_RTPSET

Allows a process to control RTE psets.

PRIV_RTSCHED

Allows a process to set POSIX.4 real-time priorities.

PRIV_RULESCONFIG

Allows a process to add and modify compartment rules on the system.

PRIV_SELFAUDIT

Allows a process to generate auditing records for itself using audwrite() system call.

PRIV_SERIALIZE

Allows a process to use the serialize() system call force a target process to run serially with other processes marked for serialization.

PRIV_SPUCTL

Allows a process to do certain administrative operations in the Instant Capacity product.

PRIV_SYSATTR

Allows a process to manage system attributes, including the setting of tunables, modifying the host name, domain name, and user quotas.

PRIV_SYSNFS

Allows a process to perform NFS operations like exporting a file system, the getfh() system call, NFS file locking, revoking NFS authentication, and creating an NFS kernel daemon thread.

PRIV_TRIALMODEAllows a process to log trial mode information to the syslog file.

 

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2008 Hewlett-Packard Development Company, L.P.