Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Warning Mode
Safeguard Administrator’s Manual523317-013
8-5
Using Warning Mode
To verify the results of the commands:
=INFO SAFEGUARD
The display shows:
You can now test your Safeguard access control lists in warning mode. Guardian
security is not checked for objects that have Safeguard protection records because the
warning mode fallback option has been set to GRANT.
To verify the results of warning mode access attempts, you can use SAFEART to
extract the audit records that were generated as a result of warning mode. For
example, the following sequence of commands prints each audit record in the current
audit file that has WARNING in the OUTCOME field. The example assumes that the
current audit file is named $SECURE.AUDIT.A0000005.
=SAFEART
<=AUDIT FILE $secure.audit.A0000005
<=SET DESTINATION FILE report1
<=SET WHERE OUTCOME=warning
<=START
To disable warning mode when you are finished testing the Safeguard security
settings:
ALTER SAFEGUARD, SYSTEM-WARNING-MODE OFF
AUTHENTICATE-MAXIMUM-ATTEMPTS = 3
AUTHENTICATE-FAIL-TIMEOUT = 60 SECONDS
AUTHENTICATE-FAIL-FREEZE = OFF
PASSWORD-REQUIRED = OFF PASSWORD-HISTORY = 0
PASSWORD-ENCRYPT = ON PASSWORD-MINIMUM-LENGTH = 0
PASSWORD-MAY-CHANGE = 3 DAYS BEFORE-EXPIRATION
PASSWORD-EXPIRY-GRACE = 0 DAYS-AFTER-EXPIRATION
SYSTEM-WARNING-MODE = ON WARNING-FALLBACK-SECURITY = GRANT
OBJECT-WARNING-MODE = OFF
DIRECTION-DEVICE = DEVICE-FIRST CHECK-DEVICE = ON
COMBINATION-DEVICE = FIRST-ACL CHECK-SUBDEVICE = OFF
ACL-REQUIRED-DEVICE = OFF
DIRECTION-PROCESS = PROCESS-FIRST CHECK-PROCESS = ON
COMBINATION-PROCESS = FIRST-ACL CHECK-SUBPROCESS = OFF
ACL-REQUIRED-PROCESS = OFF
DIRECTION-DISKFILE = FILENAME-FIRST CHECK-VOLUME = OFF
COMBINATION-DISKFILE = FIRST-ACL CHECK-SUBVOLUME = ON
ACL-REQUIRED-DISKFILE = OFF CHECK-FILENAME = ON
CLEARONPURGE-DISKFILE = OFF CHECK-DISKFILE-PATTERN = OFF
ALLOW-DISKFILE-PERSISTENT = NORMAL