Spooler Utilities Reference Manual

Introduction to the Spooler Subsystem
Spooler Utilities Reference Manual522295-003
2-22
Spooler Security
Dummy locations represent the same null device key attribute value. In other words,
jobs whose output is directed to dummy locations, regardless of their value and
preciseness of their locations, will be grouped together in the same batch job if all other
key attributes match.
Group locations are also represented by the same null device attribute even though
there are devices specified for the group, which allows batch jobs to be formed without
direct knowledge of the device that will be used by the group. When printing of the
batch job is established for the first member job, all members of the batch are printed
to this same device. The total print effort for all of the jobs in a batch job is considered
when a device is selected from a group for printing a batch job.
Spooler Security
Each user can have his or her own spooler subsystem to provide for individual secure
printing needs. There can be multiple spooler subsystems running at one time on the
same system. All command requests to a certain spooler supervisor are validated. If
the validation fails, the request is rejected and a SECURITY VIOLATION message is
returned to the requester.
When you open a spooler supervisor (using either Peruse or Spoolcom), you will see
listed only the jobs that you are authorized to see. You are always authorized to see
the jobs that you created. If manager access is enabled for the spooler and you are a
group manager (user ID n,255), you can see and access all jobs created by members
of your group. You must be a system operator (user ID 255,n) to access all jobs.
Status Requests
All status information requests are granted by the spooler subsystem. All users can
obtain the status of any job by using Spoolcom or obtain the status of only their own
jobs by using Peruse. If manager access is enabled for the spooler, a group manager
can obtain the status of all jobs owned by his or her group.
All Other Requests
All requests other than status requests are validated for access authorization using the
following criteria:
The job creator always has access to his or her own jobs.
With manager access enabled for the spooler, a group manager (user ID n,255) is
allowed access to all jobs owned by the group.
Any system operator (user ID 255,n) is allowed access at all times.
The person who created the spooler (by warmstart or coldstart) is also authorized
access at all times.