The Service Configuration profile should contain all commands that are door clients of the Service Configuration daemon, svc.configd. This profile should be included as a subprofile of each profile that contains any authorizations that are checked by svc.configd (authorizations beginning with solaris.smf). Profiles that are assigned to a user via the auth_profiles keyword require re-authentication to become effective. Since daemons like svc.configd lack an interface for such re-authentication, the re-authentication must be triggered by the execution of one of the programs included in this profile, by a decendent of a profile shell.

Upon successful re-authentication, all profiles in the auth_profiles list, including any subprofiles, and any included authorizations, are made effective for the client program and its child processes.