Use the -fconfigfile option to specify a file other than the default /etc/prmconf. The -soption displays warnings regarding the configuration file. (The -coption displays a subset of the -swarnings.)

5.Enable PRM’s application manager if it is not already enabled:

#prmconfig -e APPL

Alternatively, enable all PRM resource managers using prmconfig -ewithout any additional arguments:

#prmconfig -e

Assigning secure compartments to PRM groups

Use the HP-UX feature Security Containment (available starting with HP-UX 11i v2) to create secure compartments, which isolate files and processes. (You can also create secure compartment configurations using a PRM utility such as srpgen or prm2scomp.)

You can add, modify, and remove assignments of secure compartments to PRM groups as discussed in the following sections:

“Adding/modifying a compartment’s group assignment ” (page 76)

“Removing a compartment’s group assignment ” (page 76)

Compartment record syntax

This section explains the syntax of compartment records.

Compartment records assign secure compartments to the groups.

Use the following syntax when specifying a compartment record:

#!SCOMP:COMPARTMENT_NAME:{GROUP (NONE)} where

#!SCOMP

Indicates the start of a compartment record. (The # character does not

 

denote the start of a comment in this case.)

COMPARTMENT_NAME

Is the alphanumeric name (of no more than 255 characters) of an existing

 

secure compartment that you created using the HP-UX feature Security

 

Containment. (You can also create these compartments using a PRM

 

utility such as srpgen or prm2scomp.) The compartment must be active.

 

A compartment can have no more than one record.

 

This record type takes precedence over application records and user

 

records.

GROUP

The PRM group to which the secure compartment is to be mapped. If

 

you are using group hierarchies, the group you specify must not have

 

any child groups.

(NONE)

You can specify (NONE) in place of a group name if you would like to

 

explicitly show in your configuration file that a compartment is not to

 

be mapped to a PRM group.

Consider the following example compartment records:

#PRM compartment records

#!SCOMP:Comp1:development

#!SCOMP:Comp2:sales

#!SCOMP:Comp3:mktg

Configuring PRM 75