RDF System Management Manual

Table Of Contents
Installing and Configuring RDF
HP NonStop RDF System Management Manual524388-003
3-12
Security Guidelines
The following summarizes the reasons for the various security requirements of each
RDF program:
RDFAFXO. The RDFAFXO process uses privileged TMF procedures to fix the
audit trail files and reset the CRASHOPEN flag in the audit trail file label and must
be licensed with FUP or by running the RDFINST macro. RDFAFXO can be owned
by any user ID.
RDFCOM. The RDFCOM program communicates with the TMP in privileged
mode and must be licensed with FUP or by running the RDFINST macro.
RDFCOM can be owned by any user ID; however, it must be run by a member of
the super-user group (user ID 255,nnn) to change the running state of RDF.
Alternatively, RDFCOM supports the use of the SAFEGUARD PROGID attribute to
enable any user to start, stop, and manage RDF. Once the PROGID attribute is
set, you must limit EXECUTE access to the RDFCOM object so that only those
persons authorized to manage RDF can run RDFCOM.
RDFEXTO. The RDF extractor program communicates with the TMP in privileged
mode and must be licensed with FUP or by running the RDFINST macro.
RDFEXTO can be owned by any user ID.
MD5SRVO NO NO
RDFCOM YES; 255,nnn +YES
RDFEXTO YES ++ YES
RDFMONO YES ++ YES
RDFNETO YES ++ NO
RDFPRGO YES ++ YES
RDFRCVO YES ++ YES
RDFSCAN NO++++ NO
RDFSNOOP YES +++ YES
RDFUPDO YES ++ YES
READLIST NO NO
RDIMAGE YES ++ YES
+ RDFCOM operational commands require super-user group access; however, INFO and STATUS
commands can be issued by all users.
++ The RDF processes run under the userid of the user who set the PROGID attribute, or the RDF OWNER.
+++ RDFSNOOP requires super-user group access to read image files.
++++ Depends upon security of entry-sequenced file being accessed.
Table 3-1. RDF Process and Program Security Attributes
Program Name
Run Under a
Specific Logon ?
LICENSE Required
for Object File?