Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Introduction
Safeguard Reference Manual 520618-030
1 - 3
Object-Access Authorization
The primary and secondary owners of a record can freeze and thaw the ability of a
user or alias to log on (FREEZE USER or ALIAS and THAW USER or ALIAS).
The primary and secondary owners of a record can delete the record (DELETE
USER or DELETE ALIAS).
The primary and secondary owners of a record can display record information
using the INFO USER command.
Object-Access Authorization
With the Safeguard software, you can secure these types of system objects:
Disk files
Disk volumes and subvolumes
Devices and subdevices (including terminals, tape drives, communication lines,
and printers)
Processes and subprocesses (both named and unnamed)
You protect objects by defining an access control list (ACL) with the ACCESS attribute.
ACLs specify who can access an object and what authorities they have. Except for the
super ID and the group manager of the protection record owner, users are implicitly
denied all access authorities if they do not appear on an object’s access control list.
The Safeguard software provides the object-access control features listed in the
following summaries. (The SAFECOM command appears in parentheses.)
Control Features for Disk Files
The owner of a disk file can create a Safeguard disk file authorization record (ADD
DISKFILE) unless a list of users has been designated with an access control list for
OBJECTTYPE DISKFILE.
Each file authorization record cont
ains these attributes:
°
OWNER—ownership can be transferred to another user
°
ACCESS—an access-control list to authorize access: Read, Write, Execute,
Purge, Create, Owner (RWEPCO)
°
Auditing specifications
°
LICENSE
°
PROGID
°
CLEARONPURGE
°
PERSISTENT
The owner of an authorization record for that file can modify the record (ALTER
DISKFILE).