Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Safeguard Subsystem Commands
Safeguard Reference Manual 520618-030
16 - 10
ALTER SAFEGUARD Command
effect, users can change their own password at any time. A value of 0 also
allows the password to be changed at any time. The default value is 0 (no
restrictions on password change date). A null entry for this attribute resets the
value to the default value.
If the PASSWORD-MAY-CHANGE period is greater than the PASSWORD-
MUST-CHANGE period in a user authentication record, that user’s password
can be changed at any time.
PASSWORD-REQUIRED { ON | OFF }
defines whether a password is required for a super ID or group manager ID to
log on as another user. The initial value is OFF. (No password is required.)
PASSWORD-EXPIRY-GRACE [ n [ DAYS ] ]
n defines the number of days after password expiration during which users can
change their expired passwords during logon. The default value is 0 (no
extension period). A null entry for this attribute resets the value to the default
value.
PASSWORD-EXPIRY-GRACE can also be specified in individual user
authentication records. If the value of this attribute is not specified in a user
authentication record, the Safeguard software uses the value specified in the
Safeguard configuration record.
PASSWORD-ENCRYPT { ON | OFF }
defines whether new passwords are stored in an encrypted form. Changing
this setting does not affect current passwords. The initial value is ON.
CHECK-DEVICE { ON | OFF }
defines whether the device ACL is consulted to determine access to devices
and subdevices. The initial value is ON. (Device ACLs are consulted.)
CHECK-SUBDEVICE { ON | OFF }
defines whether the subdevice ACL is consulted to determine access to
subdevices. The initial value is OFF. (Subdevice ACLs are not consulted.)
Note. The owner of a user authentication record can always change the password. After the
owner changes the password, the users can change their own password once before the
PASSWORD-MAY-CHANGE setting is effective.
Note. Passwords are stored unencrypted. Any process with access to the
$SYSTEM.SYSTEM.USERID file can identify the current p
asswords. The initial value
for PASSWORD-ENCRYPT is ON only on systems running G06.29 and later G-series
RVUs and H06.06 and later H-series RVUs.