Safeguard Reference Manual (G06.29+, H06.08+, J06.03+)

Table Of Contents
Safeguard Subsystem Commands
Safeguard Reference Manual 520618-030
16 - 11
ALTER SAFEGUARD Command
DIRECTION-DEVICE { DEVICE-FIRST | SUBDEVICE-FIRST }
defines the direction in which device and subdevice ACLs are consulted to
determine access to devices and subdevices when both CHECK-DEVICE and
CHECK-SUBDEVICE are ON. The initial value is DEVICE-FIRST.
DEVICE-FIRST
specifies that device ACLs are to be consulted before subdevice ACLs.
SUBDEVICE-FIRST
specifies that subdevice ACLs are to be consulted before device ACLs.
COMBINATION-DEVICE { FIRST-RULE | FIRST-ACL | ALL }
defines the method by which overlapping ACLs are resolved for access to
devices and subdevices. COMBINATION-DEVICE is used in conjunction with
DIRECTION-DEVICE to resolve access conflicts. The initial value is FIRST-
ACL
FIRST-RULE
specifies that the Safeguard software is to determine access by searching
the ACLs until it finds the user ID mentioned.
FIRST-ACL
specifies that the Safeguard software is to determine access based on the
first ACL it finds.
ALL
specifies that all consulted ACLs must grant the requested access for the
success of the operation.
ACL-REQUIRED-DEVICE { ON | OFF }
defines whether the absence of an ACL for a device or subdevice causes the
denial of access to that device or subdevice. The initial value is OFF
. (The
absence of ACLs causes operation to revert to Guardian rules.)
CHECK-PROCESS { ON | OFF }
defines whether the process ACL is consulted to determine access to
processes and subprocesses. The initial value is ON. (Process ACLs are
consulted.)
CHECK-SUBPROCESS { ON | OFF }
defines whether the subprocess ACL is consulted to determine access to
subprocesses. The initial value is OFF
. (Subprocess ACLs are not consulted.)