SV-216349r603267_rule
V-216349
SRG-OS-000480
SOL-11.1-040316
CAT II
10
The root role is required. This action applies only to the control domain.
Determine the domain that you are currently securing.
# virtinfo
Domain role: LDoms control I/O service root
The current domain is the control domain, which is also an I/O domain, the service domain, and a root I/O domain.
If the current domain is not the control domain, this action does not apply.
Configure the vntsd service to require authorization.
# svccfg -s vntsd setprop vntsd/authorization = true
The vntsd service must be restarted for the changes to take effect.
# svcadm restart vntsd
The root role is required. This action applies only to the control domain.
Determine the domain that you are currently securing.
# virtinfo
Domain role: LDoms control I/O service root
The current domain is the control domain, which is also an I/O domain, the service domain, and a root I/O domain.
If the current domain is not the control domain, this check does not apply.
Determine if the vntsd service is online.
# pfexec svcs vntsd
If the service is not "online", this is not applicable.
Check the status of the vntsd authorization property.
# svcprop -p vntsd/authorization vntsd
If the state is not true, this is a finding.
V-216349
False
SOL-11.1-040316
The root role is required. This action applies only to the control domain.
Determine the domain that you are currently securing.
# virtinfo
Domain role: LDoms control I/O service root
The current domain is the control domain, which is also an I/O domain, the service domain, and a root I/O domain.
If the current domain is not the control domain, this check does not apply.
Determine if the vntsd service is online.
# pfexec svcs vntsd
If the service is not "online", this is not applicable.
Check the status of the vntsd authorization property.
# svcprop -p vntsd/authorization vntsd
If the state is not true, this is a finding.
M
4022