To activate compartment rules on the system, follow these steps:
Plan
the compartment rules. See Section for more information.
TIP: HP recommends you plan the compartment rules configuration
carefully. After you have edited the configuration and implemented
it on a production system, it becomes difficult to change. When you
change a compartment configuration, you must make changes to user
procedures, scripts, and tools.
Create
compartment rules. See Section for instructions on completing this step and for a complete description
of compartment rules syntax.
(Optional)
Preview the compartment rules by entering the following command:
# setrules -p
The -p option parses the configured
rules list and reports any discrepancies in syntax and semantics.
HP recommends that you follow this step before enabling compartment
rules on the system.
(Optional)
Make backup copies of the compartment configuration files. Either
put these files outside the /etc/cmpt directory
or omit the .rules suffix. Doing this lets you
easily revert to the starting point if an editing problem occurs.
Enable
the compartments feature by entering the following command:
# cmpt_tune -e
Reboot
the system. This step is mandatory.
TIP: Keep the backup files; this makes it easier to
revert to a prior configuration.