1.5  Security and Required Permissions

In order to enhance security, only privileged users can access the WEBES directory tree and run SEA commands. The requirements for each operating system are given here.

Tru64 UNIX

The following actions are restricted to privileged users:

Only the "root" user can perform these actions. The /usr/opt/hp/svctools directory is owned by root, and has rwx (read, write, and execute) permissions for root (owner), and no permissions for any other user (group or world).

HP-UX

The following actions are restricted to privileged users:

Only the "root" user can perform these actions. The /opt/hp/svctools directory is owned by root, and has rwx (read, write, and execute) permissions for root (owner), and no permissions for any other user (group or world).

Linux

The following actions are restricted to privileged users:

Only the "root" user can perform these actions. The /usr/opt/hp/svctools directory is owned by root, and has rwx (read, write, and execute) permissions for root (owner), and no permissions for any other user (group or world).

OpenVMS

Commands—To execute any SEA commands (DESTA or WSEA commands), the user needs all of the following OpenVMS privileges. Note that these are a subset of the privileges required to install, upgrade, or uninstall WEBES as described in the WEBES Installation Guide:

ALTPRI
BUGCHK
CMKRNL

DIAGNOSE
IMPERSONATE
NETMBX

SYSPRV
TMPMBX

Files—File access is restricted in the WEBES installed directory tree pointed to by the SVCTOOLS_HOME logical (SYS$COMMON:[HP] by default). To view these files, you must be a member of the System group, your user ID must have all privileges, or you must issue the SET PROCESS /PRIV=ALL command.

All directories and files in the SVCTOOLS_HOME tree are owned by the System user, and have System, Owner, and Group permissions of RWED (Read, Write, Execute, and Delete). There are no permissions for World.

Windows

The following actions are restricted to privileged users:

To perform restricted actions, your user ID must be either: