Table 3-1 RDF Process and Program Security Attributes
(continued)
LICENSE Required for Object File?
Run Under a Specific Logon ?
Program Name
YES
YES ++
RDFEXTO
YES
YES ++
RDFMONO
NO
YES ++
RDFNETO
YES
YES ++
RDFPRGO
YES
YES ++
RDFRCVO
NO
NO++++
RDFSCAN
YES
YES +++
RDFSNOOP
YES
YES ++
RDFUPDO
NO
NO
READLIST
YES
YES ++
RDIMAGE
+ RDFCOM operational commands require super-user group access; however, INFO and STATUS commands can
be issued by all users.
++ The RDF processes run under the userid of the user who set the PROGID attribute, or the RDF OWNER.
+++ RDFSNOOP requires super-user group access to read image files.
++++ Depends upon security of entry-sequenced file being accessed.
The following summarizes the reasons for the various security requirements of each RDF program:
•
RDFAFXO. The RDFAFXO process uses privileged TMF procedures to fix the audit trail
files and reset the CRASHOPEN flag in the audit trail file label and must be licensed with
FUP or by running the RDFINST macro. RDFAFXO can be owned by any user ID.
•
RDFCOM. The RDFCOM program communicates with the TMP in privileged mode and
must be licensed with FUP or by running the RDFINST macro. RDFCOM can be owned by
any user ID; however, it must be run by a member of the super-user group (user ID 255,
nnn
)
to change the running state of RDF.
Alternatively, RDFCOM supports the use of the SAFEGUARD PROGID attribute to enable
any user to start, stop, and manage RDF. Once the PROGID attribute is set, you must limit
EXECUTE access to the RDFCOM object so that only those persons authorized to manage
RDF can run RDFCOM.
•
RDFEXTO. The RDF extractor program communicates with the TMP in privileged mode
and must be licensed with FUP or by running the RDFINST macro. RDFEXTO can be owned
by any user ID.
•
RDFMONO. The RDF monitor program communicates with the TMP in privileged mode
and must be licensed with FUP or by running the RDFINST macro. RDFMONO can be
owned by any user ID.
•
RDFNETO. The RDFNETO program opens and writes to the network synchronization file
on each of the primary systems participating in the RDF network. RDFNETO can be owned
by any user ID.
•
RDFPRGO. The RDF purger program purges image files in privileged mode and must be
licensed with FUP or by running the RDFINST macro. RDFPRGO can be owned by any user
ID.
•
RDFRCVO. The RDF receiver program opens the image files in privileged mode and must
be licensed with FUP or by running the RDFINST macro. RDFRCVO can be owned by any
user ID.
•
RDFSCAN. The RDFSCAN program contains no privileged calls or privileged code and
need not be licensed. RDFSCAN can be owned and run by any user ID.
Installing RDF
77
Содержание NonStop RDF
Страница 68: ...68 ...
Страница 186: ...186 ...
Страница 260: ...260 ...
Страница 278: ...278 ...
Страница 284: ...284 ...
Страница 290: ...290 ...
Страница 308: ...308 ...
Страница 322: ...322 ...
Страница 336: ...336 ...
Страница 348: ...348 ...
Страница 464: ...464 ...
Страница 478: ......