Each record in the UACC class defines the default access allowed to a resource class. The UACC record also determines the access level allowed to a resource of that class that is not protected by CA ControlMinder.
UACC is applicable to most, but not all, classes. The following table shows how each class uses the UACC class.
UACC Usage |
Class |
---|---|
Standard |
ADMIN, APPL, AUTHHOST, CALENDAR, CONNECT, CONTAINER, DOMAIN, GAPPL, GAUTHHOST, GHOST, GSUDO, GTERMINAL, HOLIDAY, HOST, HOSTNET, HOSTNP, MFTERMINAL, POLICY, PROCESS, PROGRAM, REGKEY, REGVAL, RULESET, SUDO, SURROGATE, TCP, TERMINAL, USER_DIR, User Defined Classes |
Nonstandard |
FILE, GFILE |
None |
AGENT, AGENT_TYPE, CATEGORY, GROUP, PWPOLICY, RESOURCE_DESC, RESPONSE_TAB, SECFILE, SECLABEL, SEOS, SPECIALPGM, USER, USER_ATTR |
For users outside the special _restricted group, the record for FILE in the UACC class protects only files that are part of CA ControlMinder-such as the seos.ini, seosd.trace, seos.audit, and seos.error files. These files are not explicitly defined to CA ControlMinder, but are automatically protected by CA ControlMinder.
The key of the UACC class record is the name of the class whose UACC properties are being defined.
The following definitions describe the properties contained in this class record. Most properties are modifiable and can be manipulated using selang or the administration interfaces. Non-modifiable properties are marked informational.
Defines a list of accessors (users and groups) permitted to access the resource, and the accessors' access types.
Each element in the access control list (ACL) contains the following information:
Defines an accessor.
Defines the access authority that the accessor has to the resource.
Use the access parameter with the authorize or authorize- command to modify the ACL.
A list of all allowed accesses for this class.
Defines the types of access events that CA ControlMinder records in the audit log. RAUDIT derives its name from Resource AUDIT. Valid values are:
All access requests.
Granted access requests.
Denied access requests (default).
No access requests.
CA ControlMinder records events on each attempted access to a resource, and does not record whether the access rules were applied directly to the resource, or were applied to a group or class that had the resource as a member.
Use the audit parameter of the chres and chfile commands to modify the audit mode.
Defines a list of the accessors (users and groups) that are permitted to access the resource, and their access types according to the Unicenter NSM calendar status.
Each element in the calendar access control list (CALACL) contains the following information:
Defines an accessor.
Defines a reference to a calendar in Unicenter TNG.
Defines the access authority that the accessor has to the resource.
Access is permitted only when the calendar is ON. Access is denied in all other cases.
Use the calendar parameter with the authorize command to permit user or group access to the resource according to the access defined in the calendar ACL.
Defines additional information that you want to include in the record. CA ControlMinder does not use this information for authorization.
Limit: 255 characters.
(Informational) Displays the date and time when the record was created.
The NACL property of a resource is an access control list that defines the accessors that are denied authorization to a resource, together with the type of access that they are denied (for example, write). See also ACL, CALACL, PACL. Each entry in the NACL contains the following information:
Defines an accessor.
Defines the type of access that is denied to the accessor.
Use the authorize deniedaccess command, or the authorize- deniedaccess- command, to modify this property.
Defines the user or group that owns the record.
Defines the default access authority for the resource, which indicates the access granted to accessors who are not defined to CA ControlMinder or who do not appear in the ACL of the resource.
Use the defaccess parameter with the chres, editres, or newres command to modify this property.
(Informational) Displays the date and time when the record was last modified.
(Informational) Displays the administrator who performed the update.
Copyright © 2013 CA Technologies.
All rights reserved.
|
|