Download PDF Part II
Transcript
31 System Security Services This chapter describes the security system services that provide various mechanisms to enhance the security of operating systems. It contains the following sections: Section 31.1 provides an overview of the protection scheme. Section 31.2 describes identifiers and how they are used in security. Section 31.3 describes the rights database. Section 31.4 describes the persona and per-thread security features. Section 31.5 describes how to create, translate, and maintain access control entries (ACEs). Section 31.6 describes protected subsystems. Section 31.7 describes security auditing. Section 31.8 describes how to determine a user’s access to an object. Section 31.9 describes SYS$CHECK_PRIVILEGE system service. Section 31.10 describes how to implement site-specific security policies. 31.1 Overview of the Operating System’s Protection Scheme The basis of the security scheme is an identifier, which is a 32-bit binary value that represents a set of users to the system. An identifier can represent an individual user, a group of users, or some aspect of the environment in which a user is operating. A process is a holder of an identifier when that identifier can represent that process to the system. The protection scheme also includes the user identification code (UIC), the authorization database, and access control lists. Authorization Database The authorization database consists of the system authorization file (SYSUAF.DAT), the network proxy database, and the rights list database (RIGHTSLISTS.DAT). Note that the network proxy database is called NETPROXY.DAT on Alpha systems and NET$PROXY.DAT on VAX systems. (The file NETPROXY.DAT on VAX systems is maintained for platform compatibility, translation of DECnet Phase IV node names, and layered product support.) The system rights database is an indexed file consisting of identifier and holder records. These records define the identifiers and the holders of those identifiers on a system. When a user logs in to the system, a process is created and LOGINOUT creates a rights list for the process from the applicable entries in the rights database. The process rights list contains all the identifiers that the process holds. A process can be the holder of a number of identifiers. These identifiers determine the access rights of the list holder. The process rights list becomes part of the process and is propagated to any created subprocesses. System Security Services 31–1
Related documents
PDF Vol. II - Software Products Library
OpenVMS System Services Reference Manual: GETUTC–Z
HP Fortran for OpenVMS User Manual
Guide to OpenVMS File Applications
Model 4200-SCS Semiconductor Characterization System
POLYCENTER Software Installation Utility User`s Guide
OpenVMS System Manager`s Manual, Volume 2
DECdfs for OpenVMS Management Guide - OpenVMS Systems
C-ISAM Programmer`s Manual
Ada in Action
K1 SYSTEM K1 K1-SB
PDF Vol. II