The RBAC Model

The RBAC model in the Solaris operating environment is based on users logging in as themselves and assuming roles that enable them to run restricted administration tools and utilities. The RBAC model introduces these four elements to the Solaris operating environment:

  • Privileged application An application that can override system controls and checks for specific UIDs, GIDs, or authorizations.

  • Role A special identity for running privileged applications that can be assumed by assigned users only.

  • Authorization A permission that can be assigned to a role or user (or be embedded in a rights profile) for performing a class of actions otherwise prohibited by security policy.

  • Rights profile A collection

