Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Security Group Commands
Safeguard Reference Manual 520618-030
13 - 3
Security Group Access Authorities
The SECURITY-AUDITOR security group designates a list of users, who are not
SUPER.SUPER, record owner or record owner's group manager to view the subject
and group records. Users who are part of this group will have read only privileges for
the subject and group records.
The SECURITY-MEDIA-ADMIN security group designates a list of users, who are
responsible for management of the tape subsystem and have the permission to
execute the tape management commands.
The SECURITY-PERSISTENCE-ADMIN security group designates a list of users who
have the same privileges as that of super-group users for managing persistence
processes.
Like the ADD OBJECTTYPE command, the ADD SECURITY-GROUP command can
be used only by super-group members. Once an authorization record for a security
group has been added to the Safeguard database, the record’s primary owner, the
owner’s group manager, and any user with OWNER authority on the ACL can use
other security group commands to manage the security group authorization record.
Security Group Access Authorities
The ACL defined for a security group can grant either of these access authorities to
users and user groups:
Security Group Command Summary
Table 13-1 lists the SECURITY-GROUP commands and gives a brief description of
each.
EXECUTE Execute the set of commands restricted to the security group
OWNER Manage the security group authorization record
Table 13-1. Security-Group Command Summary (page 1 of 2)
Command Description
ADD SECURITY-
GRO
UP
Adds a security group authorization record with the specified group
attribute values. If you do not specify attribute values, the current
defaults are used. Only a member of the local super group can
add an authorization record for a security group.
ALTER SECURITY-
GRO
UP
Changes one or more attribute values in a security group
authorization record. For all attributes except ACCESS, the ALTER
SECURITY-GROUP command replaces the current value with the
specified value. For the ACCESS attribute, ALTER SECURITY-
GROUP changes the existing ACL to incorporate access-spec.
DELETE SECURITY-
GRO
UP
Deletes a security group authorization record. Afterward, only
local super-group members can execute the restricted commands.