Controlled Access With Program File Id Adoption; Effect Of Adopting The Owner Id Of A Program File; Figure 16-2. Effect Of Adopting The Owner Id Of A Program File; Figure 16-3. Employee Record Format - HP Guardian User Manual

Hide thumbs Also See for Guardian:
Table of Contents

Advertisement

Managing Users and Security

Figure 16-2. Effect of Adopting the Owner ID of a Program File

Program File
for Process p1;
Owner ID = 1,112
The program file's security
has been set to "use owner
ID as process access ID."

Controlled Access With Program File ID Adoption

In any application, some data files might require a controlled type of access—such as
letting many users access certain records, while denying access to other records that are
considered sensitive. For example, an employee file might contain such data as
employees' identification numbers, names and addresses, and sensitive information such
as salaries. This data might be in a record format as shown in

Figure 16-3. Employee Record Format

emp #
emp name
This example shows how a user can control the access to such a data file and also
control any future file accesses or program functions.
An employee data file is owned by user 1,112 and is secured for local owner access only
(OOOO). This means that only the file owner (or the local super ID) has direct access to
the file. However, a controlled form of file access is allowed using a query program that
has been written to return only nonsensitive information. The program file is owned by
user 1,112 and is secured so that any local user can execute the process (OOAO).
Additionally, program file ID adoption has been specified (use owner ID as process
access ID).
As shown in
Figure
program, which returns "limited data views" only. The query process adopts the owner
ID of the program file (1,112), which becomes its process access ID. (If the query
program were to create another process, that process would inherit 1,112 as both its
creator access ID and its process access ID.)
(CI)
(p1)
(p2)
benefits
address
16-4, user 8,10 (process access ID of 8,10) executes the query
Guardian User's Guide —425266-001
16 -17
Controlled Access With Program File ID Adoption
Process Access ID = 8,10
Creator Access ID = 8,10
Process Access ID = 1,112
Creator Access ID = 1,112
Process Access ID = 1,112
CDT
013
.CDD
salary
.....etc.
CDT
014
.CDD
Figure
16-3.

Advertisement

Table of Contents
loading

Table of Contents