Safeguard Administrator's Manual (G06.24+, H06.03+)
Table Of Contents
- What’s New in This Manual
- About This Manual
- 1 Introduction
- 2 Controlling User Access
- Introduction
- Using SAFECOM to Establish a Local User Community
- Using SAFECOM to Manage User Access to Your System
- Changing the Owner of a User Authentication Record
- Granting a User Temporary Access to Your System
- Requiring Users to Change Their Passwords
- Granting a Grace Period for Changing an Expired Password
- Forcing Immediate Expiration of a User’s Password
- Freezing a User's Ability to Access the System
- Specifying Auditing for a User ID
- Deleting Users
- Deleting Administrative Groups
- Using SAFECOM to Establish a Network of Users
- Using Safeguard With Nodes With Standard Security
- Identifying Network Users
- Granting a Network User Access to Objects on Your System
- Establishing a Community of Network Users
- Changes to the PAID During a User’s Session
- Additional Considerations for Aliases and Groups
- Additional Considerations for ACCESS with Network Specific Subject IDs
- Establishing Default Protection for a User's Disk Files
- Specifying a Default Command Interpreter for a User
- Establishing Guardian Defaults
- Assigning an Alias to a User
- 3 Managing User Groups
- 4 Securing Volumes and Devices
- 5 OBJECTTYPE Control
- 6 Managing Security Groups
- 7 Securing Terminals
- 8 Warning Mode
- 9 Configuration
- Safeguard Attributes
- Configuring User Authentication
- Configuring Password Control
- Configuring Device Control
- Configuring Process Control
- Configuring Disk-File Control
- Configuring Safeguard Auditing
- Configuring a Default Command Interpreter
- Configuring Communication With $CMON
- Configuring Logon Dialog
- Configuring Exclusive Access at Safeguard Terminals
- Configuring Warning Mode
- Configuring Persistence
- Configuring Attributes for Node Specific Subjects in ACLs
- 10 Installation and Management
- Safeguard Components
- Process Considerations for the SMP and SAFECOM
- Safeguard Subsystem Management Commands
- General Installation Procedure
- Installing the Safeguard Software
- Starting the SMP
- Converting to the Safeguard Subsystem
- Updating the Safeguard Software
- Guidelines for Securing the Safeguard Subsystem
- Monitoring the Safeguard Subsystem
- A SAFECOM Command Syntax
- Index

SAFECOM Command Syntax
Safeguard Administrator’s Manual—523317-013
A-13
SAFECOM Command Syntax
authority-list is one of:
{ authority }
{ ( authority [ , authority ] ... ) }
{ * }
authority is one of:
E[XECUTE]
O[WNER]
audit-spec is one of:
ALL
LOCAL
REMOTE
NONE
user-attribute is one of:
OWNER [owner-id]
OWNER-LIST [[-]user-list]
PASSWORD [password]
USER-EXPIRES [ date [ , time] ]
PASSWORD-MUST-CHANGE [EVERY num DAYS]
PASSWORD-EXPIRY-GRACE [num [DAYS]]
PASSWORD-EXPIRES [ date [ , time] ]
AUDIT-AUTHENTICATE-PASS [audit-spec]
AUDIT-AUTHENTICATE-FAIL [audit-spec]
AUDIT-MANAGE-PASS [audit-spec]
AUDIT-MANAGE-FAIL [audit-spec]
AUDIT-USER-ACTION-PASS [audit-spec]
AUDIT-USER-ACTION-FAIL [audit-spec]
TEXT-DESCRIPTION "[text]"
REMOTEPASSWORD \system-name remote-password
DEFAULT-PROTECTION [ obj-attr ]
[ ( obj-attr [ , obj-attr ] ...) ]
GUARDIAN [DEFAULT] SECURITY ["]string["]
GUARDIAN [DEFAULT] [SUB]VOLUME [\system.]$vol.subvol
INITIAL-DIRECTORY [dir-path]
INITIAL-PROGRAM [prog-path]
INITIAL-PROGTYPE [prog-type]
CI-PROG [prog-filename]
CI-LIB [lib-filename]
CI-CPU [cpu-number | ANY]
CI-NAME [process-name]
CI-SWAP [$vol.[subvol.filename]]
CI-PRI [priority]
CI-PARAM-TEXT [startup-param-text]
date is either dd mmm yyyy or mmm dd yyyy.
SET USER [ , ] { LIKE user-id | user-attribute }
[ , user-attribute ] ...