Previous Topic: Protecting Files and Programs

Next Topic: How File Protection Works

Restricting Access to Files and Directories

CA Access Control leaves the UNIX system of permissions intact but adds a layer of enhanced access control to it.

CA Access Control intercepts each of the following file access operations and verifies that the user has authorization for the specific operation before returning control to UNIX. The access type is in parentheses.

CA Access Control access checking differs from the native UNIX authorization in the following ways:

The following are the limits of the File Protection System:

CA Access Control supports the following access types for files.

The File Protection System is useful for protecting selected sets of files that contain sensitive data. For example, you can use CA Access Control to protect the following files:

You should use CA Access Control to protect databases (access should be granted only to the server daemon) and all other sensitive files at your site.

Some files that always need access control are governed by rules even without you specifying them.