Safeguard Administrator's Manual (G06.29+, H06.08+, J06.03+)
Configuration
Safeguard Administrator’s Manual—523317-029
9-37
Configuring Persistence
Configuring Persistence
Use the ADD command to configure persistence, which allows you to create protection
records for disk files. The NORMAL value of this attribute is designed to preserve
backward compatibility. The ALWAYS value provides access to the persistence feature.
This attribute relates to persistence:
ALLOW-DISKFILE-PERSISTENT
ALWAYS allows the creation of disk-file protection records for files that might not
exist. NORMAL restricts creation of disk-file protection records to files that exist.
The initial value is NORMAL.
To change any of these values, issue the ALTER SAFEGUARD command from
SAFECOM. For example, to enable disk file persistence:
=ALTER SAFE, ALLOW-DISKFILE-PERSISTENT ALWAYS
Configuring Attributes for Node Specific
Subjects in ACLs
Use the global configuration attribute ALLOW-NODE-ID-ACL to define ACL entries
containing explicit node identifiers for subjects to be consulted to determine access.
The initial ALLOW-NODE-ID-ACL value is off, ignoring ACL entries containing explicit
node identifiers.
This attribute relates to node identifiers:
ALLOW-NODE-ID-ACL
OFF ignores ACL entries containing explicit node identifiers. ON defines ACL
entries containing explicit node identifiers for subjects to be consulted to determine
access.
To change any of these values, issue the ALTER SAFEGUARD command from
SAFECOM.
Configuring Dynamic Process Updates
Use the global configuration attribute, DYNAMIC-PROC-UPDATE, to dynamically
update the process identity attributes (AUDIT-USER-ACTION-PASS, AUDIT-USER-
ACTION-FAIL, primary group, supplementary group list, and group count) when the
audit and group attributes of the corresponding user are modified.
Note. PROGID, LICENSE, TRUST, PRIV-LOGON, and CLEARONPURGE are reset for a disk
file with a persistent protection record when the file is created.