Listing Capabilities [ Manager's Guide to MPE/iX Security ] MPE/iX 5.0 Documentation
Manager's Guide to MPE/iX Security
Listing Capabilities
Three commands allow the system manager to list capabilities of accounts,
groups, and users: LISTACCT, LISTGROUP, and LISTUSER.
Listing Capabilities Assigned to an Account
Use the LISTACCT command to check the capabilities of an account. To
check the capabilities for the SMITH account, including the password,
enter
LISTACCT SMITH;PASS
The following account information appears on the screen:
______________________________________________________________________
| |
| |
| *************** |
| ACCOUNT: SMITH |
| |
| DISC SPACE: 754115 (SECTORS) PASSWORD: ACCTPASS |
| CPU TIME: 33330 (SECONDS) LOC ATTR: $00000000 |
| CONNECT TIME: 102 (MINUTES) SECURITY-- READ :ANY |
| DISC LIMIT: UNLIMITED WRITE : AC |
| CPU LIMIT: UNLIMITED APPEND :AC |
| CONNECT TIME: UNLIMITED LOCK :ANY |
| MAX PRI: 150 EXECUTE :ANY |
| GROUP UFID: $0000001 $800001050 $00138A20 $00000008 $000001FA |
| USER UFID : $0004001 $800001050 $00138C20 $00000008 $000001FB |
| CAP: AM,AL,GL,DI,CV,UV,LG,CS,ND,SF,IA,BA,PH,DS,MR,PM |
| |
______________________________________________________________________
Refer to appendix A for definitions of the capabilities.
Users with system manager (SM) capability can list any account on the
system; all other users can list only their own accounts .
Refer to the MPE/iX Commands Reference Manual Volumes 1 and 2
(32650-90003 and 32650-90364) for more information on the LISTACCT
command.
Listing Capabilities Assigned to a Group
Use the LISTGROUP command to display capabilities for one or more groups.
For account managers (AM) and system managers (SM), the default is all
(@) groups within the user's logon account; for general users, the
default is the logon group. Use wildcard characters to specify more than
one group.
To check group capabilities and the password of the group ENGR in the
account to which you are logged on, enter:
LISTGROUP ENGR;PASS
The screen displays:
______________________________________________________________________
| |
| |
| THE "PASS" OPTION REQUIRES AM OR SM CAPABILITIES (CIWARN 720) |
| |
| ****************** |
| GROUP: ENGR.SMITH |
| |
| DISC SPACE: 5752 (SECTORS) PASSWORD: * * |
| CPU TIME: 102(SECONDS) SECURITY-- READ : GU |
| CONNECT TIME: 0(MINUTES) WRITE : GU |
| DISC LIMIT: UNLIMITED APPEND : GU |
| CPU LIMIT: UNLIMITED LOCK : GU |
| CONNECT TIME: UNLIMITED EXECUTE : GU |
| PRIV VOL : n/a SAVE : GU |
| FILE UFID: $OOOD401 $80001050 $OOOFF620 $00000008 $OOOOOOOA |
| MOUNT REF CNT: n/a |
| HOME VOL SET : MPE_SYS_VOL_SET |
| CAP: IA,BA |
| |
______________________________________________________________________
Refer to appendix A for definitions of the capabilities.
NOTE If the password is encrypted, the commands LISTUSER, LISTGROUP, and
LISTACCT will only display the password as "*ENCRIPTED*", making a
password truley private to its owner.
In this example, the user does not have AM or SM capability, so the
password does not appear on the screen.
Refer to the MPE/iX Commands Reference Manual Volumes 1 and 2
(32650-90003 and 32650-90364) for more information on the LISTGROUP
command.
Listing Capabilities Assigned to Users
Use the LISTUSER command to check the capabilities of a user. The
default is all (@) users and accounts within the user's capabilities (AM
or SM). For example, to review the capabilities of the user BORIS in the
JONES account, enter:
LISTUSER BORIS;PASS
The screen displays:
_________________________________________________________________
| |
| |
| ******************** |
| USER: BORIS.JONES |
| HOME GROUP: DEVELOP PASSWORD: MYPASS |
| MAX PRI : 150 LOC ATTR: $00000000 |
| CONNECT TIME: 0(MINUTES) WRITE : GU |
| LOGON CNT : 1 |
| CAP: AM,AL,GL,DI,DV,UV,LG,CS,ND,SF,IA,BA,PH,DS,MR,PM |
| |
_________________________________________________________________
Refer to appendix A for definitions of the capabilities.
Users with system manager (SM) capability can list any user in the
system. Users with account manager (AM) capability can list any user in
their account. Other users can list only their logon user.
For more information on the LISTUSER command, refer to the MPE/iX
Commands Reference Manual Volumes 1 and 2 (32650-90003 and 32650-90364).
Table 6-1. Capabilities
----------------------------------------------------------------------------------------------------
| | | | | |
| Capability | Abbreviation | Account | Group | User |
| | | | | |
----------------------------------------------------------------------------------------------------
| | | | | |
| System manager | SM | X | | X |
| | | | | |
| System supervisor | OP | X | | X |
| | | | | |
| Account manager | AM | X | | X |
| | | | | |
| Account librarian | AL | X | | X |
| | | | | |
| Batch access | BA | X | X | X |
| | | | | |
| Use communications software | CS | X | | X |
| | | | | |
| Diagnostician attribute | DI | X | | X |
| | | | | |
| Extra data segments | DS | X | X | X |
| | | | | |
| Group librarian | GL | X | | X |
| | | | | |
| Interactive access | IA | X | X | X |
| | | | | |
| Multiple RIN | MR | X | X | X |
| | | | | |
| Network administrator | NA | X | | X |
| | | | | |
| Node manager | NM | X | | X |
| | | | | |
| Use nonshareable devices | ND | X | | X |
| | | | | |
| Use private disk volumes | UV | X | | X |
| | | | | |
| Privileged mode | PM | X | X | X |
| | | | | |
| Process handling | PH | X | X | X |
| | | | | |
| Programmatic sessions | PS | X | | X |
| | | | | |
| Save user files permanently | SF | X | | X |
| | | | | |
| Use user logging facility | LG | X | | X |
| | | | | |
| Create volume sets | CV | X | | X |
| | | | | |
----------------------------------------------------------------------------------------------------
When the system manager assigns and creates accounts, groups, and users,
they each receive certain default capabilities. These capabilties are
listed in the following table.
Table 6-2. Default Capabilities
--------------------------------------------------------------------------------------------
| | |
| Entity | Default Capabilities |
| | |
--------------------------------------------------------------------------------------------
| | |
| Account | AL, AM, BA, GL, IA, ND, SF |
| | |
--------------------------------------------------------------------------------------------
| | |
| Group | BA, IA |
| | |
--------------------------------------------------------------------------------------------
| | |
| User | BA, IA, ND, SF |
| | |
--------------------------------------------------------------------------------------------
| | |
| Program | BA, IA |
| | |
--------------------------------------------------------------------------------------------
Accounts and users may have all 21 of the capabilities, but groups and
programs may only have BA, DS, IA, MR, PH, and PM.
MPE/iX 5.0 Documentation