Safeguard Administrator's Manual (G06.24+, H06.03+)

Table Of Contents
Managing Security Groups
Safeguard Administrator’s Manual523317-013
6-3
Adding Security Groups
Valid access authorities for groups are:
Adding Security Groups
Initially, any super-group member can add the group authorization records for the
SECURITY-ADMINISTRATOR, SYSTEM-OPERATOR, and SECURITY-OSS-
ADMINISTRATOR security groups. Once a group authorization record is created for a
security group, only users with EXECUTE (E) authority on the access control list can
execute the commands restricted to that security group. Only the record owner or
users with OWNER (O) authority on the access control list can manage the group
authorization record.
For example, assume that, as the local super ID, you initially want to define the
SECURITY-ADMINISTRATOR group so that it contains two members—ADMIN.SUE
(user ID 200,5) and ADMIN.KEVIN (user ID 200,6)—who will have EXECUTE
authority. Use this SAFECOM command:
=ADD SECURITY-GROUP SECURITY-ADMINISTRATOR, ACCESS 200,5 E; &
=200,6 E
Use the INFO SECURITY-GROUP command to verify the results of the command:
=INFO SECURITY-GROUP SECURITY-ADMINISTRATOR
The display shows:
Except for the super ID, ADMIN.KEVIN and ADMIN.SUE are now the only users who
can execute the restricted commands defined for the SECURITY-ADMINISTRATOR
security group.
SET SECURITY-GROUP Sets one or more group attribute values to specified
default values.
SHOW SECURITY-GROUP Displays the current default values of the group attributes.
THAW SECURITY-GROUP Reenables a frozen group. Then user IDs with EXECUTE
authority on the group access list can execute the
restricted commands once again.
EXECUTE Execute the set of commands restricted to the group.
OWNER Manage the group authorization record.
LAST-MODIFIED OWNER STATUS
GROUP SECURITY-ADMINISTRATOR
26JAN93, 11:12 255,255 THAWED
200,5 E
200,6 E
Table 6-2. SECURITY-GROUP Command Summary (page 2 of 2)
Command Description