Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Controlling User Access
Safeguard Administrator’s Manual523317-013
2-33
Establishing Default Protection for a User's Disk
Files
However, the underlying user ID defined for the alias at the remote node is still used in
access decisions based on Safeguard access control lists at that node.
If the remote node is running a product version prior to D30 and does not support user
aliases, the user ID identified by the PAID requesting the access is verified, and
access decisions are based on that user ID.
If the local node is running a product version prior to D30 and does not support user
aliases, the request cannot originate from an alias.
Group Lists
Effective with D30 Safeguard, users and aliases can belong to multiple groups. Each
user and alias has a group list that specifies group membership. Any user or alias can
belong to any group, no matter what kind of a group it is. When a subject is validated at
a remote node, the group list used is the one associated with that user or alias
authentication record at the remote node.
D30 and later Safeguard systems can determine the user ID or alias under which a
user originally logged on at the start of a session even when the PAID is changed
during the session. This original name, known as the login name, is used to determine
the subject’s group list at the remote node. Although the user or alias was validated
under a different PAID at the remote node, the group list is taken from the remote
node’s authentication record associated with the requestor’s login name.
If no group list is specified at the remote node, the group list is empty, and process'
group membership is indicated by its effective group ID. (The effective group ID is the
same as the user's primary group ID unless it has been changed during the session.)
If either the local node or the remote node is running a product version prior to D30
and does not support group lists, the administrative group of the user ID associated
with the requesting PAID is the only group to which the user belongs.
Establishing Default Protection for a User's
Disk Files
The owner of a user authentication record can specify default protection for a user's
disk files. With default protection, when a user creates a disk file, it is automatically
added to the Safeguard database with the specified settings. If no default protection is
specified, new files created by the user are protected by Guardian security unless the
user explicitly adds them to the Safeguard database. You control default protection
with the DEFAULT-PROTECTION attribute of the user authentication record.
You can specify the following DEFAULT-PROTECTION attributes for disk files that a
user creates:
A default access control list
A default owner of the disk-file authorization record