|
|
Whenever your system is powered up or rebooted, the default privileges apply to executable files. The default privileges are contained in the privilege data file (PDF) /etc/security/tcb/privs. If the system boots normally, (that is, initialized via /sbin/init) and the /sbin/initprivs command is executed, then the privileges in the PDF apply.
When the system is initialized, files that require process privileges have them set automatically.
You may want to change some of these privileges in accordance with your local security policy and needs. If you add software to your system, you may want to assign privileges to that software.
The following sections discuss how to display, set, and change privilege information. Always change privilege information with great care, since the privileges assigned to executables directly affects the security of the system.