Security Management Guide (G06.29+, H06.08+, J06.03+)

Guardian System Security
Security Management Guide 522283-021
2 - 2
Guardian User Security
Guardian User Security
Users on a NonStop system fall into one of these four classes. Each class is
determined by the user ID:
Table 2-1. Security-Relevant Commands and Programs
Command or Program Function
ADDUSER Adds new users to the system (User ID must be n,25
5.)
DEFAULT Sets system, volume, subvolume, and disk-file default security
attr
ibutes (RWEP)
DELUSER Deletes users from the system (User ID must be n,255
.)
FILEINFO Displays the characteristics of a file
FUP GIVE Changes the owner of a file
FUP INFO Displays the characteristics of a file
FUP LICENSE Allows nonprivileged users to execute a privileged program (User
ID must b
e 255,255.)
FUP REVOKE Revokes the license for a privileged program (User ID must be
255
,255.)
FUP SECURE Changes the Guardian security attributes for a file
LOGOFF Terminates communication
with a TACL process
LOGON Establishes communication with a TACL process
PASSWORD Selects, changes, or deletes a local password
REMOTEPASSWORD Establishes or deletes a password for a remote system
USERS Lists attributes for one or more users on the system
VOLUME Temporarily changes the default volume, subvolume, and file
security
, or resets these settings to their original default values
WHO Displays default information, includin
g the file-security attributes,
for the current TACL process
General users Log on to a system to run one or more specific applications such
as a text editor or manufacturing application. (General users
are sometimes called application users.)
Group managers Are responsible for members of a specific administrative group
on the system. The user ID is n,255, where n is the number of
the group.
The super group Performs various system functions such as managing system
files, disks, and other devices. The user ID is 255,n, where n is
an integer from 1 through 254.
The super ID Can access files, processes, and devices for the entire system
with no restrictions. The user ID is 255,255.