Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
OBJECTTYPE Security Commands
Safeguard Reference Manual 520618-030
12 - 3
OBJECTTYPE Security Command Summary
Table 12-2 on page 12-3 lists the OBJECTTYPE security commands and gives a brief
description of each.
Note. Starting with H06.24/J06.13 RVUs, the OBJECTTYPE USER is granted additional
access permissions, WRITE (W) and PURGE (P), along with the existing CREATE (C) and
OWNER (O) permissions. Members having the WRITE (W) permission on OBJECTTYPE
USER can modify any subject records. Members having the PURGE (P) permission on
OBJECTTYPE USER can purge any subject records.
Note.
Starting with H06.26/J06.15 RVUs, the OBJECTTYPE
DISKFILE/VOLUME/SUBVOLUME is granted additional access permissions, WRITE (W) and
PURGE (P), along with the existing CREATE (C) and OWNER (O) permissions. Members
having the WRITE (W) permission on OBJECTTYPE DISKFILE/VOLUME/SUBVOLUME can
modify the respective DISKFILE/VOLUME/SUBVOLUME protection records. Members having
the PURGE (P) permission on OBJECTTYPE DISKFILE/VOLUME/SUBVOLUME can purge
the respective DISKFILE/VOLUME/SUBVOLUME protection records.
Table 12-2. OBJECTTYPE Security Command Summary (page 1 of 2)
Command Description
ADD
OBJECTTYPE
Adds an OBJECTTYPE authorization record with the specified
OBJECTTYPE
attribute values. If you do not specify attribute values, the
current default is used. By default, only a member of the local super group
can add an authorization record for an object type.
ALTER
OBJECTTYPE
Changes one or more attribute values in a
n OBJECTTYPE authorization
record. For all attributes except ACCESS, ALTER OBJECTTYPE
replaces the current value with the specified value. For the ACCESS
attribute, ALTER OBJECTTYPE changes the existing ACL to incorporate
access-spec.
DELETE
OBJECTTYPE
Deletes an OBJECTTYPE authorization record. Afterward, requests to
create a
n authorization record for any object of the specified object type
are subject to the rules described in Table 12-1.
FREEZE
OBJECTTYPE
Temporarily disables authorities granted to users who have
OBJECTTYPE
access. When an OBJECTTYPE is frozen, only the
primary owner, the primary owner’s group manager, owners on the ACL,
and the local super ID can create authorization records for that type of
object.
INFO
OBJECTTYPE
Displays the existing attribute values in a
n OBJECTTYPE authorization
record.
RESET
OBJECTTYPE
Sets default OBJECTTYPE attribute values to the predefined values of
the
SET command.