Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
OBJECTTYPE Control
Safeguard Administrator’s Manual523317-013
5-5
Controlling Who Can Add an Object Type
Suppose you want only group 10 to add users, aliases, and groups. Consider this
command:
=ADD OBJECTTYPE USER, ACCESS 10,* C, OWNER 10,1
This command gives CREATE authority to all users who have group 10 as their
administrative group. They can add users by creating user authentication records.
Group managers no longer have authority to add users, but the super ID retains this
authority. This command also gives user ID 10,1 ownership of the authorization record
for OBJECTTYPE USER.
These same users also have the authority to add groups. For security, adding an alias
requires additional authority, as described in Assigning an Alias to a User on
page 2-39.
To verify the settings of the authorization record for OBJECTTYPE USER, issue the
INFO command:
=INFO OBJECTTYPE USER
The display shows:
Controlling Who Can Add an Object Type
Normally, only super-group users can issue the ADD OBJECTTYPE command. To
allow you to grant this authority to other users, the Safeguard software provides a
special object type called OBJECTTYPE. Once an OBJECTTYPE OBJECTTYPE
authorization record is created, only users with CREATE authority on the access
control list for OBJECTTYPE OBJECTTYPE can add OBJECTTYPE authorization
records.
This command adds an authorization record for OBJECTTYPE OBJECTTYPE and
gives CREATE authority to only two users:
=ADD OBJECTTYPE OBJECTTYPE, ACCESS 200,12 C; 200,8 C
These commands give ownership of the authorization record to a security administrator
(200,1) and deny the super ID all authorities for OBJECTTYPE OBJECTTYPE:
=ALTER OBJECTTYPE OBJECTTYPE, ACCESS 255,255 DENY *
=ALTER OBJECTTYPE OBJECTTYPE, OWNER 200,1
To verify the settings, use the INFO command:
=INFO OBJECTTYPE OBJECTTYPE
LAST-MODIFIED OWNER STATUS WARNING-MODE
OBJECTTYPE USER
27JAN88, 13:30 10,1 THAWED OFF
010,* C