You can deny a user or group specific access types using a Negative Access Control List (NACL).
With the CA Access Control language (selang), use the following command to deny access:
auth className resourceName [gid(group‑name...)] \
[uid({user‑name...|*})] [deniedaccess(accessvalue)]
| Copyright © 2012 CA. All rights reserved. |
|