Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Safeguard Administrator’s Manual523317-013
2-1
2 Controlling User Access
This section describes how to use the SAFECOM user security commands to establish
a local user community and to manage user access to a system protected by the
Safeguard software. It also describes how to identify network users, how to set up
network access for users, and how to establish default protection for users’ disk files.
Introduction
User security controls are established with USER security commands when you add or
alter a user authentication record. They are supplemented by other user access
controls offered by the TERMINAL security commands and by the ALTER
SAFEGUARD command.
USER Commands
With USER security commands, you can specify the following user access and
authentication controls:
User expiration date, to terminate a user's ability to log on (USER-EXPIRES
attribute)
Future password expiration date for a user (PASSWORD-MUST-CHANGE
attribute)
Immediate or future password expiration for a user (PASSWORD-EXPIRES
attribute)
Grace period during which an expired password can be changed at a terminal
controlled by the Safeguard software (PASSWORD-EXPIRY-GRACE attribute)
Temporary suspension of a user's ability to log on (FREEZE and THAW)
Default protection for a user's disk files (DEFAULT-PROTECTION attribute)
Initial password for a user (PASSWORD attribute)
Remote password for a user (REMOTEPASSWORD attribute)
Guardian default security string (GUARDIAN DEFAULT SECURITY attribute)
Guardian default volume and subvolume (GUARDIAN DEFAULT VOLUME
attribute)
Auditing of a user's logon attempts (AUDIT-AUTHENTICATE attributes)
Auditing of attempts to change a user authentication record (AUDIT-MANAGE
attributes)
Auditing of a user's attempts to access objects and manage protection records
(AUDIT-USER-ACTION attributes)
Primary group for a user (PRIMARY-GROUP attribute)