HP -UX B6941-90001 Administrator's Reference Manual page 451

Management server on hp-ux
Table of Contents

Advertisement

Tuning, Troubleshooting, Security, and Maintenance
ITO Security
File Access and Permissions
When a user starts an ITO operator GUI session, the working directory
is defined by environment variable $OPC_HOME (if set) or $HOME. If
neither $OPC_HOME nor $HOME is set, then /tmp is the default working
directory. For more information on common ITO variables, see
"Variables" on page 291.
If the unix user that started the ITO operator GUI has no write
permission in the default working directory, an error message is
displayed but the ITO GUI starts nonetheless. However, any subsequent
attempt by the operator to write files to the default directory will fail
unless the directory permissions are changed. This includes the
automatic save of the broadcast-command history file. In addition,
whenever an operator saves application, instruction, or report output to
a file without specifying an absolute path, the file is stored in the user's
working directory and owned by the operator's unix user ID, not by
opc_op (unless the operator logged in as unix user opc_op). The
permissions of the file will reflect the value of umask as set before the
ITO operator GUI was started. Operators who want to share files with
other operators need to set (or ask the system administrator to set) the
appropriate file and group and permissions for the desired degree of
sharing. ITO will no longer change any of these settings automatically.
However, ITO operators are not able to make unauthorized changes, and
all ITO configuration files remain secure. Any files that are created when
the administrator saves report and application output are owned by the
administrator's unix user and saved in the $OPC_HOME directory if no
absolute path is specified.
NOTE
"Write" permission for the group can be overridden by "no write"
permission for the owner. In addition, ITO operator ARFs (and related
symbolic links and directories) that are changed by the administrator
remain readable and traversable by all and not just opc_op.
The Administrator GUI
In the Motif administrator GUI (the GUI that is started when the ITO
user opc_adm logs on), the unix process that is used for making
configuration changes, opcuiadm, runs with root permissions. However,
opcuiopadm, the unix process that is used for the administrator's
browser, runs under the unix user ID of the user who started the Motif
administrator GUI rather than unix user opc_op.
Chapter 10
451

Advertisement

Table of Contents
loading

This manual is also suitable for:

Openview it

Table of Contents