Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Security Group Commands
Safeguard Reference Manual 520618-030
13 - 17
FREEZE SECURITY-GROUP Command
To delete the SECURITY-PERSISTENCE-ADMIN security group protection record, use
the following command:
=DELETE SECURITY-GROUP SECURITY-PERSISTENCE-ADMIN
FREEZE SECURITY-GROUP Command
FREEZE SECURITY-GROUP temporarily suspends the authorities granted to user IDs
listed on a security group ACL. While the security group is frozen, only the primary
owner, the primary owner’s group manager, an owner on the ACL, and the local super
ID can execute the commands restricted to that security group.
Use the THAW SECURITY-GROUP command to reenable all the ACL authorities
granted to user IDs before the security group was frozen.
sec-group-list
specifies the security group for which access is to be frozen. sec-group-list
can be either:
sec-group-spec
( sec-group-spec [ , sec-group-spec ] ... )
sec-group-spec
can be either:
SECURITY-ADMINISTRATOR
SYSTEM-OPERATOR
SECURITY-OSS-ADMINISTRATOR
SECURITY-PRV-ADMINISTRATOR
SECURITY-AUDITOR
SECURITY-MEDIA-ADMIN
SECURITY-PERSISTENCE-ADMIN
Consideration
While a security group is frozen, the primary owner, the primary owner’s group
manager, and an owner on the ACL are implicitly granted all access authorities. The
local super ID also retains ownership.
Example
To disable access authorities granted to members of the SECURITY-
ADMINISTRATOR security group, enter this command:
=FREEZE SECURITY-GROUP sec-admin
FREEZE SECURITY-GROUP sec-group-list