Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Event-Exit-Process Commands
Safeguard Reference Manual 520618-030
15 - 27
Processing of Authorization Requests
PROTECTION_CHECK_ result is NORECORD. When NORECORD is the
PROTECTION_CHECK result, the final result appears in the Guardian column.
Timeout Policy for Authorization
If the event-exit process does not respond to a request within the configured time
interval, the SMON assumes that a problem has occurred and continues processing as
follows.
If the authorization request is from an undeniable user when a timeout occurs, a
response of YES is assumed, and the access attempt is allowed to proceed, subject to
a Safeguard access check as described in Processing of Authorization Requests on
page 15-26. Locally authenticated super-group members are considered undeniable
users. An EMS message is sent to indicate that an undeniable user has timed out,
thereby prompting the undeniable user to disable the malfunctioning event-exit
process.
If the authorization request is from a deniable user when the time out occurs, and if the
attribute TIMEOUT-ALL-AUTHZREQ is enabled, then the SEEP response is treated as
NO, and the control returns to the requestor without any further processing by the
Safeguard with the status as “security violation”. An EMS message is sent to indicate
that a deniable user has timed out. If the attribute TIMEOUT-ALL-AUTHZREQ is
Table 15-11. Decision Table for Event Exit, Safeguard, and Guardian Results
Event Exit Ruling Safeguard
Ruling
Protection_Check
_Result
Guardian Security
Ruling
YES YES YES Not consulted
YES NO NO Not consulted
YES NORECORD YES Not consulted
NO Not consulted NO Not consulted
NO Not consulted NO Not consulted
NO Not consulted NO Not consulted
NORECORD YES YES Not consulted
NORECORD NO NO Not consulted
NORECORD NORECORD NORECORD YES or NO
Event exit disabled YES YES Not consulted
Event exit disabled NO NO Not consulted
Event exit disabled NORECORD NORECORD YES or NO
Event exit disabled Safeguard
disabled
NORECORD YES or NO
Event exit disabled Safeguard
disabled
NORECORD YES or NO
*
* If an object has a Safeguard protection record and the Safeguard subsystem is disabled, access rulings
for that object are as described for the STOP SAFEGUARD command in Section 16, Safeguard
Subsystem Commands.