Safeguard Reference Manual (G06.24+, H06.03+ )
Security Group Commands
Safeguard Reference Manual—520618-013
13-14
FREEZE SECURITY-GROUP Command
FREEZE SECURITY-GROUP Command
FREEZE SECURITY-GROUP temporarily suspends the authorities granted to user IDs
listed on a security group ACL. While the security group is frozen, only the primary
owner, the primary owner’s group manager, an owner on the ACL, and the local super
ID can execute the commands restricted to that security group.
Use the THAW SECURITY-GROUP command to reenable all the ACL authorities
granted to user IDs before the security group was frozen.
sec-group-list
specifies the security group for which access is to be frozen. sec-group-list
can be either:
sec-group-spec
( sec-group-spec [ , sec-group-spec ] ... )
sec-group-spec
can be either:
SECURITY-ADMINISTRATOR
SYSTEM-OPERATOR
SECURITY-OSS-ADMINISTRATOR
Consideration
While a security group is frozen, the primary owner, the primary owner’s group
manager, and an owner on the ACL are implicitly granted all access authorities. The
local super ID also retains ownership.
Example
To disable access authorities granted to members of the SECURITY-
ADMINISTRATOR security group, the owner enters these command:
=FREEZE SECURITY-GROUP sec-admin
The SECURITY-OSS-ADMINISTRATOR security group can be frozen by the primary
owner or by any user with OWNER authority on the access control list for the group.
For example,
=FREEZE SECURITY-GROUP SECURITY-OSS-ADMINISTRATOR
FREEZE SECURITY-GROUP sec-group-list