Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Safeguard Reference Manual 520618-030
13 - 1
13 Security Group Commands
Safeguard security group commands allow a security administrator to define security
groups of users who can execute certain restricted commands. The security group
commands are similar to OBJECTTYPE commands.
The security groups, SECURITY-ADMINISTRATOR, SYSTEM-OPERATOR,
SECURITY-OSS-ADMINISTRATOR, SECURITY-PRV-ADMINISTRATOR, SECURITY-
AUDITOR, SECURITY-MEDIA-ADMIN, and SECURITY-PERSISTENCE-ADMIN can
be added to the Safeguard database. These security groups do not exist until they are
added using the ADD SECURITY-GROUP command.
Until the security groups are added, all super-group members can execute audit
service commands, TERMINAL commands, EVENT-EXIT-PROCESS commands, and
the ALTER SAFEGUARD and STOP SAFEGUARD commands. Creating the security
groups allows you to restrict use of these commands by designating the specific users
who are allowed to execute the commands. After a security group is created, only
users with EXECUTE authority on the access control list (ACL) can use the commands
restricted to that security group.
Note. In prior product versions, the Safeguard security groups were managed by GROUP
commands. GROUP commands are now used to manage file-sharing groups, as described in
Section
7, Group Commands. Security groups are now managed with the SECURITY-GROUP
commands, as described in this section.
Note.
The SECURITY-OSS-ADMINISTRATOR security group is supported only on systems
running G06.29 and later G-series RVUs, and H06.08 and later H-series RVUs.
The SECURITY-PRV-ADMINISTRATOR security group is supported only on systems
running J06.11 and later J-series RVUs, and H06.22 and later H-series RVUs.
The SECURITY-AUDITOR security group is supported only on systems running J06.13
and later J-series RVUs, and H06.24 and later H-series RVUs.
The SECURITY-MEDIA-ADMIN security group is supported only on systems running
J06.15 and later J-series RVUs, and H06.26 and later H-series RVUs.
The SECURITY-PERSISTENCE-ADMIN security group is supported only on systems
running J06.16 and later J-series RVUs, and H06.27 and later H-series RVUs.
Note.
It is recommended that SUPER.SUPER must not be added to the SECURITY-OSS-
ADMINISTRATOR or SECURITY-PRV-ADMINISTRATOR security groups.
SECURITY-OSS-ADMINISTRATOR or SECURITY-PRV-ADMINISTRATOR security
groups must not be added by a SUPER.SUPER, but can be added by any SUPER.*. This
prevents SUPER.SUPER from gaining ownership of the security groups.
SUPER.SUPER must be denied access to SECURITY-OSS-ADMINISTRATOR or
SECURITY-PRV-ADMINISTRATOR Security groups using Safeguard ACLs. For example,
alter sec-group sec-prv-admin, access super.super deny *.