Safeguard Administrator's Manual (G06.24+, H06.03+)
Table Of Contents
- What’s New in This Manual
- About This Manual
- 1 Introduction
- 2 Controlling User Access
- Introduction
- Using SAFECOM to Establish a Local User Community
- Using SAFECOM to Manage User Access to Your System
- Changing the Owner of a User Authentication Record
- Granting a User Temporary Access to Your System
- Requiring Users to Change Their Passwords
- Granting a Grace Period for Changing an Expired Password
- Forcing Immediate Expiration of a User’s Password
- Freezing a User's Ability to Access the System
- Specifying Auditing for a User ID
- Deleting Users
- Deleting Administrative Groups
- Using SAFECOM to Establish a Network of Users
- Using Safeguard With Nodes With Standard Security
- Identifying Network Users
- Granting a Network User Access to Objects on Your System
- Establishing a Community of Network Users
- Changes to the PAID During a User’s Session
- Additional Considerations for Aliases and Groups
- Additional Considerations for ACCESS with Network Specific Subject IDs
- Establishing Default Protection for a User's Disk Files
- Specifying a Default Command Interpreter for a User
- Establishing Guardian Defaults
- Assigning an Alias to a User
- 3 Managing User Groups
- 4 Securing Volumes and Devices
- 5 OBJECTTYPE Control
- 6 Managing Security Groups
- 7 Securing Terminals
- 8 Warning Mode
- 9 Configuration
- Safeguard Attributes
- Configuring User Authentication
- Configuring Password Control
- Configuring Device Control
- Configuring Process Control
- Configuring Disk-File Control
- Configuring Safeguard Auditing
- Configuring a Default Command Interpreter
- Configuring Communication With $CMON
- Configuring Logon Dialog
- Configuring Exclusive Access at Safeguard Terminals
- Configuring Warning Mode
- Configuring Persistence
- Configuring Attributes for Node Specific Subjects in ACLs
- 10 Installation and Management
- Safeguard Components
- Process Considerations for the SMP and SAFECOM
- Safeguard Subsystem Management Commands
- General Installation Procedure
- Installing the Safeguard Software
- Starting the SMP
- Converting to the Safeguard Subsystem
- Updating the Safeguard Software
- Guidelines for Securing the Safeguard Subsystem
- Monitoring the Safeguard Subsystem
- A SAFECOM Command Syntax
- Index

Controlling User Access
Safeguard Administrator’s Manual—523317-013
2-23
Freezing a User's Ability to Access the System
For example, assume that the current time is 10:14 on July 29, 2005. To add the new
user ADMIN.ALICE with an expired password and a password expiry grace period of
five days, ADMIN.MANAGER enters this command:
=ADD USER admin.alice, 1,6, LIKE admin.bob, PASSWORD abc,&
=PASSWORD-EXPIRES 29 jul 2005, 10:00,&
=PASSWORD-EXPIRY-GRACE 5 DAYS
The PASSWORD-EXPIRES attribute specifies a time that has already passed.
Therefore the user’s password is expired.
ADMIN.MANAGER then displays the user record to verify the results of the command:
INFO USER admin.alice, GENERAL
The display shows that Alice has five days in which to log on and change her
password.
The PASSWORD-EXPIRES attribute can also be set to a future date. However, this
date is altered if you subsequently set the user’s PASSWORD-MUST-CHANGE
attribute or if the user changes the password before expiration.
Freezing a User's Ability to Access the System
Security administrators occasionally need to suspend a user's ability to log on to the
system. For example, when a user goes on vacation, a security administrator might
want to ensure that nobody else uses that user's identity to gain access to the system
while the user is away. A security administrator can use the FREEZE USER command
to freeze a user ID and its associated user name. While a user ID is frozen, nobody
can use the user ID or its associated user name to gain access to the system.
However, freezing a user authentication record has no effect on user aliases
associated with the user ID. The user can still log on using an alias.
GROUP.USER USER-ID OWNER LAST-MODIFIED LAST-LOGON STATUS WARNING-MODE
ADMIN.ALICE 1,6 200,1 29JUL05, 10:14 * NONE * PSWD-EXP OFF
UID = 262
USER-EXPIRES = * NONE *
PASSWORD-EXPIRES = 29JUL05, 10:00
PASSWORD-MAY-CHANGE = * NONE *
PASSWORD-MUST-CHANGE EVERY = 30 DAYS
PASSWORD-EXPIRY-GRACE = 5 DAYS
LAST-LOGON = * NONE *
LAST-UNSUCESSFUL-ATTEMPT = * NONE *
LAST-MODIFIED = 29JUL05, 10:14
FROZEN/THAWED = THAWED
STATIC FAILED LOGON COUNT = 0
GUARDIAN DEFAULT SECURITY = OOOO
GUARDIAN DEFAULT VOLUME = $SYSTEM.NOSUBVOL