Safeguard Reference Manual (G06.24+, H06.03+ )

User Security Commands
Safeguard Reference Manual520618-013
5-7
ADD USER Command
When the Safeguard software is installed on a system that has an existing user
community, it expands the existing USERID file to add the Safeguard user
attributes for every user currently defined on the system. The record for each user
is expanded the first time that user logs on after the Safeguard software has been
installed. Safeguard retains existing security attributes that are common to both
Safeguard and standard Guardian security, such as OWNER and GUARDIAN
DEFAULT SECURITY. Each user security attribute unique to Safeguard security
is given its predefined value. For a description, see RESET USER Command on
page 5-34.
The user who implicitly creates a new group becomes the owner of that group.
When you add the first user to a group with the ADD USER command, you
implicitly create that group. The user who executes that ADD USER command
becomes the group owner and can subsequently use GROUP commands to
manage the group. For more information, see Section 7, Group Commands.
The ADD USER command does not check for group ownership.
If the group name and group number identify a group created explicitly with the
ADD GROUP command, the group already has an owner. Group ownership is not
relevant to the ADD USER command. However, only the group owner can use
GROUP commands to manage the group.
Implicitly created group names are treated as uppercase.
When you implicitly create a group with the ADD USER command, the group name
is not case-sensitive. It is assumed to contain uppercase alphabetic characters.
Therefore, to manage that group with GROUP commands, you must specify the
group name with capital letters in the GROUP commands.
A new user’s primary group is set to the user’s administrative group.
When you add a user, the administrative group for the user is also that user’s
primary group. To change the primary group, use the ALTER USER command to
alter the PRIMARY-GROUP attribute.
PASSWORD-EXPIRES takes precedence over PASSWORD-MUST-CHANGE
If the PASSWORD-EXPIRES and PASSWORD-MUST-CHANGE attributes are set
in the same ADD command, the setting of the PASSWORD-EXPIRES attribute
takes precedence over the PASSWORD-EXPIRES date calculated as a result of
setting the PASSWORD-MUST-CHANGE attribute.
Examples
1. The group manager for a new marketing group (group name PRS and group
number 86) uses this command to add the first member (other than the group
manager) to the group:
=ADD USER prs.darlene , 86,1 , PASSWORD market