Safeguard Administrator's Manual (G06.24+, H06.03+)
Table Of Contents
- What’s New in This Manual
- About This Manual
- 1 Introduction
- 2 Controlling User Access
- Introduction
- Using SAFECOM to Establish a Local User Community
- Using SAFECOM to Manage User Access to Your System
- Changing the Owner of a User Authentication Record
- Granting a User Temporary Access to Your System
- Requiring Users to Change Their Passwords
- Granting a Grace Period for Changing an Expired Password
- Forcing Immediate Expiration of a User’s Password
- Freezing a User's Ability to Access the System
- Specifying Auditing for a User ID
- Deleting Users
- Deleting Administrative Groups
- Using SAFECOM to Establish a Network of Users
- Using Safeguard With Nodes With Standard Security
- Identifying Network Users
- Granting a Network User Access to Objects on Your System
- Establishing a Community of Network Users
- Changes to the PAID During a User’s Session
- Additional Considerations for Aliases and Groups
- Additional Considerations for ACCESS with Network Specific Subject IDs
- Establishing Default Protection for a User's Disk Files
- Specifying a Default Command Interpreter for a User
- Establishing Guardian Defaults
- Assigning an Alias to a User
- 3 Managing User Groups
- 4 Securing Volumes and Devices
- 5 OBJECTTYPE Control
- 6 Managing Security Groups
- 7 Securing Terminals
- 8 Warning Mode
- 9 Configuration
- Safeguard Attributes
- Configuring User Authentication
- Configuring Password Control
- Configuring Device Control
- Configuring Process Control
- Configuring Disk-File Control
- Configuring Safeguard Auditing
- Configuring a Default Command Interpreter
- Configuring Communication With $CMON
- Configuring Logon Dialog
- Configuring Exclusive Access at Safeguard Terminals
- Configuring Warning Mode
- Configuring Persistence
- Configuring Attributes for Node Specific Subjects in ACLs
- 10 Installation and Management
- Safeguard Components
- Process Considerations for the SMP and SAFECOM
- Safeguard Subsystem Management Commands
- General Installation Procedure
- Installing the Safeguard Software
- Starting the SMP
- Converting to the Safeguard Subsystem
- Updating the Safeguard Software
- Guidelines for Securing the Safeguard Subsystem
- Monitoring the Safeguard Subsystem
- A SAFECOM Command Syntax
- Index

Configuration
Safeguard Administrator’s Manual—523317-013
9-18
Configuring Client Auditing
AUDIT-OBJECT-MANAGE-PASS
Successful attempts to create or manage authorization records for any system
object are audited. This setting supplements the audit settings for the individual
objects. The conditions can be ALL, NONE, LOCAL, or REMOTE. The default is
NONE.
AUDIT-OBJECT-MANAGE-FAIL
Unsuccessful attempts to create or manage authorization records for any system
object are audited. This setting supplements the audit settings for the individual
objects. The conditions can be ALL, NONE, LOCAL, or REMOTE. The default is
NONE.
To change any of these values, issue the ALTER SAFEGUARD command from
SAFECOM. For example, to audit all successful attempts to manage an authorization
record for any system object:
=ALTER SAFEGUARD, AUDIT-OBJECT-MANAGE-PASS ALL
Configuring Client Auditing
You can configure the Safeguard software so that it does not accept audit records from
privileged clients. If your site has no interest in client audit records, you can use this
feature to reduce the quantity of audit records written to the Safeguard audit files.
These Safeguard attributes control client auditing:
AUDIT-CLIENT-GUARDIAN
ON specifies that the Safeguard software will accept guardian related audit records
from privileged client subsystems and write those records in the Safeguard audit
files. OFF specifies that the Safeguard software will not accept client guardian
related audit records. The initial value is ON.
AUDIT-CLIENT-OSS
ON specifies that the Safeguard software will accept OSS related audit records
from privileged client subsystems and write those records in the Safeguard audit
files. OFF specifies that the Safeguard software will not accept client OSS related
audit records. The initial value is ON.
For more information about client subsystem auditing, see the Safeguard Audit Service
Manual.
Caution. Configuring the Safeguard software to audit all system objects might cause system
performance problems. Be sure you have adequate system resources to handle extensive
auditing.
Note. The AUDIT-CLIENT-GUARDIAN and AUDIT-CLIENT-OSS attributes are supported only
on systems running G06.29 and later G-series RVUs and H06.08 and later H-series RVUs.