HP 3000 Manuals

Listing Capabilities [ Manager's Guide to MPE/iX Security ] MPE/iX 5.0 Documentation


Manager's Guide to MPE/iX Security

Listing Capabilities 

Three commands allow the system manager to list capabilities of accounts,
groups, and users:  LISTACCT, LISTGROUP, and LISTUSER.

Listing Capabilities Assigned to an Account 

Use the LISTACCT command to check the capabilities of an account.  To
check the capabilities for the SMITH account, including the password,
enter

     LISTACCT SMITH;PASS 

The following account information appears on the screen:
______________________________________________________________________
|                                                                    |
|                                                                    |
|      ***************                                               |
|      ACCOUNT: SMITH                                                |
|                                                                    |
|      DISC SPACE:   754115 (SECTORS)   PASSWORD: ACCTPASS           |
|      CPU TIME:     33330 (SECONDS)    LOC ATTR: $00000000          |
|      CONNECT TIME:    102 (MINUTES)   SECURITY-- READ    :ANY      |
|      DISC LIMIT:   UNLIMITED                     WRITE  : AC       |
|      CPU LIMIT:   UNLIMITED                      APPEND   :AC      |
|      CONNECT TIME:    UNLIMITED                  LOCK     :ANY     |
|      MAX PRI: 150                                EXECUTE  :ANY     |
|      GROUP UFID: $0000001 $800001050 $00138A20 $00000008 $000001FA |
|      USER UFID : $0004001 $800001050 $00138C20 $00000008 $000001FB |
|      CAP: AM,AL,GL,DI,CV,UV,LG,CS,ND,SF,IA,BA,PH,DS,MR,PM          |
|                                                                    |
______________________________________________________________________

            

Refer to appendix A for definitions of the capabilities.

Users with system manager (SM) capability can list any account on the
system; all other users can list only their own accounts .

Refer to the MPE/iX Commands Reference Manual Volumes 1 and 2 
(32650-90003 and 32650-90364) for more information on the LISTACCT
command.

Listing Capabilities Assigned to a Group 

Use the LISTGROUP command to display capabilities for one or more groups.
For account managers (AM) and system managers (SM), the default is all
(@) groups within the user's logon account; for general users, the
default is the logon group.  Use wildcard characters to specify more than
one group.

To check group capabilities and the password of the group ENGR in the
account to which you are logged on, enter:

     LISTGROUP ENGR;PASS 

The screen displays:
______________________________________________________________________
|                                                                    |
|                                                                    |
|      THE "PASS" OPTION REQUIRES AM OR SM CAPABILITIES (CIWARN 720) |
|                                                                    |
|      ******************                                            |
|      GROUP: ENGR.SMITH                                             |
|                                                                    |
|      DISC SPACE:   5752 (SECTORS)       PASSWORD:   * *            |
|      CPU TIME:   102(SECONDS)           SECURITY-- READ     : GU   |
|      CONNECT TIME: 0(MINUTES)                      WRITE    : GU   |
|      DISC LIMIT:   UNLIMITED                       APPEND   : GU   |
|      CPU LIMIT:   UNLIMITED                        LOCK     : GU   |
|      CONNECT TIME:    UNLIMITED                    EXECUTE  : GU   |
|      PRIV VOL : n/a                                SAVE     : GU   |
|      FILE UFID: $OOOD401 $80001050 $OOOFF620 $00000008 $OOOOOOOA   |
|      MOUNT REF CNT: n/a                                            |
|      HOME VOL SET : MPE_SYS_VOL_SET                                |
|      CAP: IA,BA                                                    |
|                                                                    |
______________________________________________________________________

            

Refer to appendix A for definitions of the capabilities.


NOTE If the password is encrypted, the commands LISTUSER, LISTGROUP, and LISTACCT will only display the password as "*ENCRIPTED*", making a password truley private to its owner.
In this example, the user does not have AM or SM capability, so the password does not appear on the screen. Refer to the MPE/iX Commands Reference Manual Volumes 1 and 2 (32650-90003 and 32650-90364) for more information on the LISTGROUP command. Listing Capabilities Assigned to Users Use the LISTUSER command to check the capabilities of a user. The default is all (@) users and accounts within the user's capabilities (AM or SM). For example, to review the capabilities of the user BORIS in the JONES account, enter: LISTUSER BORIS;PASS The screen displays: _________________________________________________________________ | | | | | ******************** | | USER: BORIS.JONES | | HOME GROUP: DEVELOP PASSWORD: MYPASS | | MAX PRI : 150 LOC ATTR: $00000000 | | CONNECT TIME: 0(MINUTES) WRITE : GU | | LOGON CNT : 1 | | CAP: AM,AL,GL,DI,DV,UV,LG,CS,ND,SF,IA,BA,PH,DS,MR,PM | | | _________________________________________________________________ Refer to appendix A for definitions of the capabilities. Users with system manager (SM) capability can list any user in the system. Users with account manager (AM) capability can list any user in their account. Other users can list only their logon user. For more information on the LISTUSER command, refer to the MPE/iX Commands Reference Manual Volumes 1 and 2 (32650-90003 and 32650-90364). Table 6-1. Capabilities ---------------------------------------------------------------------------------------------------- | | | | | | | Capability | Abbreviation | Account | Group | User | | | | | | | ---------------------------------------------------------------------------------------------------- | | | | | | | System manager | SM | X | | X | | | | | | | | System supervisor | OP | X | | X | | | | | | | | Account manager | AM | X | | X | | | | | | | | Account librarian | AL | X | | X | | | | | | | | Batch access | BA | X | X | X | | | | | | | | Use communications software | CS | X | | X | | | | | | | | Diagnostician attribute | DI | X | | X | | | | | | | | Extra data segments | DS | X | X | X | | | | | | | | Group librarian | GL | X | | X | | | | | | | | Interactive access | IA | X | X | X | | | | | | | | Multiple RIN | MR | X | X | X | | | | | | | | Network administrator | NA | X | | X | | | | | | | | Node manager | NM | X | | X | | | | | | | | Use nonshareable devices | ND | X | | X | | | | | | | | Use private disk volumes | UV | X | | X | | | | | | | | Privileged mode | PM | X | X | X | | | | | | | | Process handling | PH | X | X | X | | | | | | | | Programmatic sessions | PS | X | | X | | | | | | | | Save user files permanently | SF | X | | X | | | | | | | | Use user logging facility | LG | X | | X | | | | | | | | Create volume sets | CV | X | | X | | | | | | | ---------------------------------------------------------------------------------------------------- When the system manager assigns and creates accounts, groups, and users, they each receive certain default capabilities. These capabilties are listed in the following table. Table 6-2. Default Capabilities -------------------------------------------------------------------------------------------- | | | | Entity | Default Capabilities | | | | -------------------------------------------------------------------------------------------- | | | | Account | AL, AM, BA, GL, IA, ND, SF | | | | -------------------------------------------------------------------------------------------- | | | | Group | BA, IA | | | | -------------------------------------------------------------------------------------------- | | | | User | BA, IA, ND, SF | | | | -------------------------------------------------------------------------------------------- | | | | Program | BA, IA | | | | -------------------------------------------------------------------------------------------- Accounts and users may have all 21 of the capabilities, but groups and programs may only have BA, DS, IA, MR, PH, and PM.


MPE/iX 5.0 Documentation