Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Controlling User Access
Safeguard Administrator’s Manual523317-013
2-25
Deleting Users
Deleting Users
The primary and secondary owners of a user authentication record can delete that user
with the DELETE USER command. For example, SECURITY.SUSAN can delete
ADMIN.BOB with this command:
=DELETE USER admin.bob
To remove a deleted user from an access control list, you must designate that user by
user ID, not by user name. For example, the following commands remove ADMIN.BOB
(user ID 1,0) from the access control lists for all disk files on the system:
=ALTER DISKFILE $*.*.*, ACCESS 1,0 - *
=ALTER DISKFILE $*.*.*, ACCESS 1,0 - DENY *
Use the same set of commands specifying the other object types to be sure that
ADMIN.BOB is removed from all access control lists.
To remove a user from a diskfile-pattern protection record:
=ALTER DISKFILE-PATTERN $*.*.*, ALL, ACCESS 1,0 - *, ACCESS 1,0 – DENY *
Deleting Administrative Groups
An administrative group that was created with the ADD USER command is deleted
automatically when the last member of the group is deleted. Just as the user name and
user ID of a deleted user can be reassigned to a new user, the group name and
number of a deleted group can be reassigned to a new group. The local super ID (or
anyone authorized to add users) can reassign the deleted group name and number to
a new administrative group by adding the first member of the new group with that
group name or group number.
Automatic deletion does apply to an administrative group created with the ADD
GROUP command. For more information, see Section 3, Managing User Groups.
Note. After deleting a user, the security administrator should notify users to remove the
deleted user ID from access control lists for objects they own. Also, objects that the deleted
user ID owns should be transferred to other owners or deleted. Until all references to a deleted
user ID are removed, the user ID cannot be safely reused.
After these precautions are taken, the deleted user ID can be reassigned to a new user.