Commands; Adding A Command; Section 5.8, "Commands - Novell PRIVILEGED USER MANAGER 2.2.1 - ADMINISTRATION GUIDE 03-31-2010 Administration Manual

Hide thumbs Also See for PRIVILEGED USER MANAGER 2.2.1 - ADMINISTRATION GUIDE 03-31-2010:
Table of Contents

Advertisement

Option
write
unlink
mknod
exec
unsafe
link
log[=<0-9>]
all
You can use wildcards, regular expressions, and strings in the path policy. For example, using the
word
default
path default all:log
path /opt/oracle/private/** !all:log=9

5.8 Commands

Command definitions contain the commands you want to control. A command definition can
contain a single command, or several commands that you want to control in the same way. You can
also specify a command that you want to run in place of a submitted command.
Section 5.8.1, "Adding a Command," on page 94
Section 5.8.2, "Modifying a Command," on page 95
Section 5.8.3, "Setting the Command Risk," on page 97
Section 5.8.4, "Removing a Command Risk," on page 97
Section 5.8.5, "Copying a Command," on page 97
Section 5.8.6, "Moving a Command," on page 98
Section 5.8.7, "Deleting a Command," on page 98
Section 5.8.8, "Importing Sample Commands," on page 98

5.8.1 Adding a Command

You can add command definitions to your rule conditions to control whether the rule is processed,
depending on the command that is submitted by the user. You can also use commands as script
entities.
To add a new command:
1 Click Command Control on the home page of the console.
2 Click Commands in the navigation pane.
94
Novell Privileged User Manager 2.2.1 Administration guide
Description
Enables the application with the
specified directory or file.
Enables the application with the
or file.
Enables the application to create system files in the specified directory.
Enables the application to execute the shared files and files for which the
application does not have
Enables the application to execute any file that does not inherit the policy.
Enables the application to create a symbolic link or hard link to another file.
Enables the application to audit system calls, with an optional risk value of
0
-
9
.
Enables the application to have all the permissions.
specifies the default policy.
and
create
write
deletion
rights for the specified directory
read
and
write
permission.
permissions for the

Advertisement

Table of Contents
loading

This manual is also suitable for:

Privileged user manager 2.2.1

Table of Contents