136
•
SSHCOM Command Reference
HP NonStop SSH Reference Manual
If a user is denied executing Safeguard SAFECOM ADD/ALTER USER commands, then this user must be denied
ADD/ALTER USER in SSHCOM in order to ensure a consistent security policy.
Starting with release 89 there is tighter coupling of SSHCOM security with Safeguard security. This does not only
include checking if a Safeguard user is frozen (see section "
ALLOWFROZENSYSTEMUSER
") but also includes
support of OBJECTTYPE USER (please refer to HP NonStop manuals "Safeguard Reference Manual" and "Safeguard
Administrator's Manual").
The current implementation ignores OBJECTTYPE USER ACL entries containing a network id (\node-spec). The SSH2
process issues a warning message if it finds such an entry. Another restriction is that only the primary group of a user is
checked against group based OBJECTTYPE USER ACL entries.
In order to reduce overhead the OBJECTTYPE USER, USER and ALIAS information retrieved from SafeGuard is
cached. It can take up to 5 minutes before an SSH2 process takes SafeGuard modifications into account. By restarting an
SSH2 process any SafeGuard changes will be active in the SSH2 process immediately.
SSHCOM Security without Safeguard OBJECTTYPE USER Record
If a Safeguard OBJECTTYPE USER record does not exist or exists but is frozen, the behavior is as follows:
DAEMON MODE commands
The user super.super can execute any daemon mode commands. The parameter sets FULLSSHCOMACCESSUSER<i>
and FULLSSHCOMACCESSGROUP<j> are evaluated and users and groups configured in these parameter sets are
granted full access to all daemon mode commands.
CLIENT MODE commands
The user super.super can execute any client mode command for any user. The parameter sets
FULLSSHCOMACCESSUSER<i> and FULLSSHCOMACCESSGROUP<j> are evaluated and configured users and
groups are granted full access to all client mode commands for any user.
If a person that is not logged on as super.super and not configured in parameter sets FULLSSHCOMACCESSUSER<i>
and FULLSSHCOMACCESSGROUP<j> wants to execute an SSHCOM CLIENT MODE command affecting records
for a specific Guardian user or alias <user-or-alias> must either be logged on as <user-or-alias> or meet these two
qualifications:
•
Be the group manager of the underlying Safeguard user ID
•
Be the owner of the underlying Safeguard user ID of <user-or-alias> or be the group manager of the owner of
the underlying Safeguard user ID of <user-or-alias>
SSHCOM Security with existing Safeguard OBJECTTYPE USER Record
If a Safeguard OBJECTTYPE USER record exists and is not frozen, the behavior is as follows:
DAEMON MODE commands
The user super.super can execute any daemon mode commands unless explicitly configured in the OBJECTTYPE USER
with DENY Create authority. The parameter sets FULLSSHCOMACCESSUSER<i> and
FULLSSHCOMACCESSGROUP<j> are ignored. Non-super.super users configured with Create authority in the
OBJECTTYPE USER record are granted full access to all daemon mode commands.
CLIENT MODE commands
The user super.super can execute any client mode commands for all users unless explicitly configured in the
OBJECTTYPE USER with DENY Create authority. The parameter sets FULLSSHCOMACCESSUSER<i> and
FULLSSHCOMACCESSGROUP<j> are ignored.
If a person wants to execute an SSHCOM CLIENT MODE command affecting records for a specific Guardian user or
alias <user-or-alias> must either be logged on as <user-or-alias> or meet these two qualifications:
•
Have CREATE (C) authority on the OBJECTTYPE USER access control list
Содержание NonStop SSH 544701-014
Страница 12: ...xii Contents HP NonStop SSH Reference Manual ...
Страница 24: ...24 Preface HP NonStop SSH Reference Manual ...
Страница 30: ...30 Introduction HP NonStop SSH Reference Manual ...
Страница 46: ...46 Installation Quick Start HP NonStop SSH Reference Manual ...
Страница 132: ...132 The SSH User Database HP NonStop SSH Reference Manual ...
Страница 214: ...214 SSH and SFTP Client Reference HP NonStop SSH Reference Manual ...
Страница 278: ...278 STN Reference HP NonStop SSH Reference Manual ...
Страница 298: ...298 Monitoring and Auditing HP NonStop SSH Reference Manual ...
Страница 302: ...302 Performance Considerations HP NonStop SSH Reference Manual ...