Safeguard Reference Manual (G06.24+, H06.03+ )

Group Commands
Safeguard Reference Manual520618-013
7-5
ADD GROUP Command
You can specify up to 32 members to be added to the list in a single ADD
GROUP command.
DESCRIPTION [ text ]
specifies up to 255 characters of descriptive text. All text following the keyword
DESCRIPTION to the end of the command is considered to be descriptive text.
Therefore, if you specify a description, it must appear last in the command
string.
If you omit text, no descriptive text is included in the group record.
Considerations
There is no restriction on creating groups named SECURITY-ADMINISTRATOR
and SYSTEM-OPERATOR. However, such groups have no effect on the execution
of restricted commands protected by the Safeguard security groups, as described
in Section 13, Security Group Commands.
If you create a group that qualifies syntactically as an administrative group,
ownership of that group does not qualify you to use the ADD USER command to
add members to the group. The ADD USER command does not check for group
ownership. It is subject to different restrictions, as described in Section 5, User
Security Commands.
Although it is syntactically valid to create a group with a name that consists of all
numbers, HP does not recommend this practice. A numeric name might cause
confusion between the group name and group number even though the Safeguard
software can distinguish between them.
HP recommends that group numbers from 0 through 255 be reserved for
administrative groups.
Group ownership does not imply administrative control over the group members.
To alter a user or alias authentication record, you must own that record or be the
owner’s group manager.
You need not own user or alias authentication records to add them to a group’s
member list.
A single user or alias can be a member of up to 32 groups.
There is no restriction on the number of members in a group. An administrative
group is limited to 256 members for administration purposes, but it can have
additional members for file sharing.
Examples
1. The following command adds a group definition record for the group named
shift1-admin. The group is assigned group number 656. The command includes a