Software Distributor Administration Guide (March 2009)

Table Of Contents
NOTE: When a product object is created, it is automatically protected by a default
ACL from the depot/root source or, absent that, one from the host.
9.5.4 ACL Templates
There are two ACLs that are used to create the initial ACLs that protect newly created
objects: product ACL templates (global_product_template or
product_template) and container ACL templates (global_soc_template).
Figure 9-2 ACL Templates
Host Object ACL
Host Object
Depot Object ACL Depot Object ACL
Root A
Root Object ACL
Root B
Root Object ACL
Master Product ACL Template
(global_product_template )
Depot A Depot B
Container ACL Template
(global_soc_template )
Product
ACL
Product
M
Product
ACL
Product
N
Product
ACL
Product
P
Product
ACL
Product
Q
M P Q N M
(Installed Products protected
by Root ACLs.)
Product ACL Template
(product_acl )
Product ACL Template
(product_acl )
When a product is put into a depot with swcopy or swpackage, SD-UX uses a product
ACL template (provided by the depot that contains that product) to define the initial
permissions of the new product’s ACL.
SD-UX uses the product ACL template of the host system
(global_product_template) to initialize the product ACL template of the new
depot and uses the container ACL template of the host system
(global_soc_template) to initialize depot and root ACLs.
202 SD-UX Security