
XYGATE
®
Data Protection
™
Reference Manual
XYPRO Technology Corporation
83
Proprietary and Confidential
Example:
DPGROUP OSS
MASK $OSS.XDPTEST.*
REQUESTOR $system.app.*
OPERATION DECRYPT
ACL $EVERYONE *
PROCESS_AS_ACL
AUDIT_ACCESS_PASS ON
AUDIT_ACCESS_FAIL ON
The Example above shows that every ENCRYPT operation attempt will be failed. XDP
will not continue searching for other matches.
PROCESS_AS_RULE
Use PROCESS_AS_RULE when the access rules can be superseded by subsequent
DPGroups whose selection criteria also match the access request.
Example:
DPGROUP OSS
MASK $OSS.XDPTEST.*
REQUESTOR $system.app.*
OPERATION DECRYPT
ACL $EVERYONE *
PROCESS_AS_RULE
AUDIT_ACCESS_PASS ON
AUDIT_ACCESS_FAIL ON
The Example above shows that every ENCRYPT operation attempt will be failed. XDP
will search for the next DPGroup to find a match.
B5:
ACLGROUP
ACLGroups (Access Control List Groups) are entries that allow profiling of users by job
function, thus providing an efficient mechanism for organizing complex access
groupings. For example, suppose you want to allow certain operators to perform some
of the tasks of SUPER Group members. For this situation you would create an
ACLGROUP named $PRIVILEGED following the syntax below. This would include
both the SUPER Group and the privileged operators.
Syntax:
ACLGROUP $<Group-name> <User-list> [NOT <user-list>]
Example:
aclgroup $everyone \*.*.* alias:"\*.*"
Summary of Contents for Trinitron WEGA KV-DZ29M91
Page 2: ......