On 18/06/2010 16:08, John Fischer wrote:
4.4 User Installed as Primary Administrator
The initial user installed by the Caiman installers have been given the
Administrator role. The committee pointed out that this role is going
away. The
issue was discussed in the Solaris Modernization case (PSARC/2010/067).
In that
case the project team agreed to modify the installers to:

"Primary Administrator" is a Rights Profile not a Role. The distinction is very important. It is the fact that the profile is assigned directly to a user rather than a role what was the whole problem.

Also "Primary Administrator" as a Rights Profile is not planned to "go away".

The advice of the security team was not to assign "Primary Administrator" to the initial user directly. The main reason this was done early on in the Caiman GUI installer was because other technology like the RBAC "Console User" profile wasn't available and neither was sudo.

1. remove the root password prompt
2. require an initial user login name and password
3. set the root password to the initial user password
4. the root is type=role
5. the initial user is granted the root role (type=normal;roles=root)
6. the initial user is put in /etc/sudoers -- presumable with all commands
7. the initial use is no longer granted the Primary Administrator Rights

"initial user"

8. the password hash algorithm is sha256
9. the root account password is installed as expired (passwd -f).
sp_lstchg == 0

That is all fine.

The specification for this case will be modified to reflect this
requirement and
deposited in the case directory as commitment materials (Appendix C -
[1]). The
committee was fine with the issue.

5. Minority Opinion(s)


6. Advisory Information


7. Appendices
7.1 Appendix A: Technical Changes Required


7.2 Appendix B: Technical Changes Advised


7.3 Appendix C: Reference Material
Unless otherwise stated, path names are relative to the case directory

Standard PSARC Questionnaire
ARC cover page describing the case and documents included for review
Text Installer Design Document Open Document Text format
Text Installer Design Document Portable Document Format
Solaris Caiman Text-based Installer UI Specification non-graphical format

On 06/17/10 06:17 PM, John Fischer wrote:
PSARC members,

The project team has provided updated materials which have been placed
the commitment.materials directory. There is now an ARC cover page
(ARC-CoverPage.html) which describes the changes between the inception
commitment materials.

I have also added the attached draft opinion which is in the top level
There is also an HTML version of the draft opinion in the case directory.

Please review these new materials and the draft opinion. Either
provide feedback
or vote on the case by COB Wednesday, June 30th, 2010.



opensolaris-arc mailing list

Darren J Moffat
opensolaris-arc mailing list

Reply via email to