Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Securing Volumes and Devices
Safeguard Administrator’s Manual523317-013
4-4
Considerations for Devices and Subdevices
Considerations for Devices and Subdevices
By default, only super-group users (255,*) can add devices and subdevices to the
Safeguard database. If necessary, ownership can be transferred to another user
responsible for protection of that device or subdevice.
Until a device or subdevice is added to the Safeguard database, any process can open
that device or subdevice for input or output. After a device or subdevice is under
Safeguard control, only processes executing on behalf of users on the access control
list can access the device or subdevice.
Valid access authorities for devices and subdevices are:
This command adds an authorization record for the device $LASER and gives READ
and WRITE authority to all users who are members of groups 24 and 25:
=ADD DEVICE $laser, ACCESS 24,* (R,W); 25,* (R,W)
The Safeguard software does not check access control lists for subdevices unless it is
configured to check them. (For more information, see Configuring Device Control on
page 9-9.)
READ The authority to open a device or subdevice for input
WRITE The authority to open a device or subdevice for output
OWNER The authority to change the authorization record