Best Practices for Deploying HP-UX Secure Resource Partitions (SRP) for SAP Whitepaper

10
To avoid the error message, enter “send signal <SAPOSCOL-compartment>” in the SRP rule file of the
respective SRP compartment for each compartment in order to communicate with saposcol, then
activate the new rules with the command “setrules”.
The configuration examples in this document describe the restricted approach without signaling to the
saposcol compartment, accepting the display issue in ST06.
Currently saposcol is not capable of displaying the data per compartment if PRM is used. The data
shown is valid for the complete host and all systems.
Figure 3. Overview of saposcol compartment
Figure 3 shows the setup of a separate SAPOSCOL compartment. The two SRP compartments do not
have execution privileges for their saposcol executables. Saposcol can only be started by a root user
in the SAPOSCOL compartment. Data collected by saposcol can be read by the SRP compartments
via IPC communication.