<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ? in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459152#M17008</link>
    <description>hi,&lt;BR /&gt;&lt;BR /&gt; if you don't want direct system access maybe consider the openvms management station :-&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/openvms/products/argus/" target="_blank"&gt;http://h71000.www7.hp.com/openvms/products/argus/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 14 Jul 2009 14:20:28 GMT</pubDate>
    <dc:creator>marsh_1</dc:creator>
    <dc:date>2009-07-14T14:20:28Z</dc:date>
    <item>
      <title>Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459145#M17001</link>
      <description>Hello folks,&lt;BR /&gt;&lt;BR /&gt;Plain question:&lt;BR /&gt;&lt;BR /&gt;Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?&lt;BR /&gt;&lt;BR /&gt;We tested and it seems that SYSPRV and OPER are already enough. But when I do this:&lt;BR /&gt;&lt;BR /&gt;MAIL&amp;gt; help set forward /user&lt;BR /&gt;&lt;BR /&gt;SET-SHOW&lt;BR /&gt;&lt;BR /&gt;  FORWARD&lt;BR /&gt;&lt;BR /&gt;    /USER&lt;BR /&gt;&lt;BR /&gt;          /USER=user-name&lt;BR /&gt;&lt;BR /&gt;       Indicates the name of another user for whom you are setting or&lt;BR /&gt;       showing a forwarding address. You can use the /USER qualifier&lt;BR /&gt;       only if you have SYSNAM privilege. With the SHOW FORWARD command,&lt;BR /&gt;       there are two ways to show a user's forwarding address: you can&lt;BR /&gt;       specify the user name or you can use the wildcard characters (*&lt;BR /&gt;       or %) to search for names with a particular string in common.&lt;BR /&gt;&lt;BR /&gt;.... this suggests that SYSNAM *IS* needed.&lt;BR /&gt;&lt;BR /&gt;What do you think?&lt;BR /&gt;Thks in advance.</description>
      <pubDate>Tue, 14 Jul 2009 08:29:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459145#M17001</guid>
      <dc:creator>Jan van den Boogaard_1</dc:creator>
      <dc:date>2009-07-14T08:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459146#M17002</link>
      <description>According to the Manual you do&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/82final/aa-pv5mj-tk/aa-pv5mj-tk.html" target="_blank"&gt;http://h71000.www7.hp.com/doc/82final/aa-pv5mj-tk/aa-pv5mj-tk.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;so I guess the intention is that SYSNAM is required.</description>
      <pubDate>Tue, 14 Jul 2009 08:47:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459146#M17002</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2009-07-14T08:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459147#M17003</link>
      <description>Jan,&lt;BR /&gt;&lt;BR /&gt;SYSPRV is sufficient (I ran a test case on one of my OpenVMS VAX 6.2 systems).&lt;BR /&gt;&lt;BR /&gt;I note that the HELP text for ASSIGN/SYSTEM is more forthcoming, in that it states that it "requires SYSNAM (system logical name) OR [emphasis mine] SYSPRV (system privilege) privilege".&lt;BR /&gt;&lt;BR /&gt;I would therefore conclude that you have a reportable documentation erratum.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Tue, 14 Jul 2009 10:44:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459147#M17003</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2009-07-14T10:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459148#M17004</link>
      <description>This particular MAIL forwarding interface mimics the old logical name forwarding mechanism (which still works just fine, BTW), and that required SYSNAM privilege.  &lt;BR /&gt;&lt;BR /&gt;SYSPRV provides SYSNAM access based on the typical protection model in place on the logical name table.&lt;BR /&gt;&lt;BR /&gt;What's your real question, rather than your "plain question"?  No offense intended here, but you're not telling _why_ you're asking this, and that detail can be as important as question and the literal answer to the question; it allows us to target the answer.&lt;BR /&gt;&lt;BR /&gt;As for the "plain question", the privilege model on OpenVMS is a little complex, and there is very often more than one combination of privileges that can authorize the desired operation.&lt;BR /&gt;&lt;BR /&gt;And depending on what you're up to (which is why I ask why), it's entirely feasible to toss forwarding entries into a database (without requiring the caller have privileges) with an installed executable image as MAIL has a documented API.  That interface is trivial to use, and I've posted examples of calling the API (though not specifically the forwarding entry points) at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://labs.hoffmanlabs.com/node/744" target="_blank"&gt;http://labs.hoffmanlabs.com/node/744&lt;/A&gt;</description>
      <pubDate>Tue, 14 Jul 2009 11:14:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459148#M17004</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-14T11:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459149#M17005</link>
      <description>Hoff,&lt;BR /&gt;&lt;BR /&gt;The underlying problem is that we want to grant the task of adding and modifying UAF accounts (including MAIL SET FORWARD setting) to a non-SYSTEM user, and so we want to give this user the minimal set of privileges to do this. Obvious SYSPRV is necessary toadd/modify UAF accounts, but we were not sure abount SYSNAM.&lt;BR /&gt;&lt;BR /&gt;Now, the Guide to system security says also (appendix A):&lt;BR /&gt;&lt;BR /&gt;The SYSPRV privilege also lets a process perform the following tasks: Task  Interface  &lt;BR /&gt;Modify a file's expiration date  SET FILE/EXPIRATION  &lt;BR /&gt;Modify the number of interlocked queue retries  $QIO request to an Ethernet 802 driver (DEBNA/NI)  &lt;BR /&gt;Set the spin-wait time on the port command register  $QIO request to an Ethernet 802 driver (DEBNA)  &lt;BR /&gt;Set the FROM field in a mail message  MAIL routines  &lt;BR /&gt;Access a MAIL maintenance record  MAIL  &lt;BR /&gt;Modify or delete a MAIL database record  MAIL  &lt;BR /&gt;Modify the group number and password of a local area cluster  CLUSTER_AUTHORIZE component of SYSMAN  &lt;BR /&gt;Perform transaction recovery, join a transaction as coordinator, transition a transaction  DECdtm software  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;But nevertheless, I believe that you are tight: SYSPRV implies SYSNAM in the case of default protection mask of the system logical name table.&lt;BR /&gt;&lt;BR /&gt;So, the sentence "You can use the /USER qualifier only if you have SYSNAM privilege." should be interpreted: "You can use the /USER qualifier only if you have SYSNAM privilege or the SYSPRV privilege."&lt;BR /&gt;&lt;BR /&gt;Thanks for your reply.  It is clear now. Jan.</description>
      <pubDate>Tue, 14 Jul 2009 11:33:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459149#M17005</guid>
      <dc:creator>Jan van den Boogaard_1</dc:creator>
      <dc:date>2009-07-14T11:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459150#M17006</link>
      <description>Why dispense any privileges here?&lt;BR /&gt;&lt;BR /&gt;Use a CAPTIVE login procedure, and manage your OpenVMS environment from that environment.  Or use a DECnet task-to-task approach (DCL or otherwise), and have the server end of the connection running with the necessary privileges.  Either avoids issuing privileges (directly) to end-users.&lt;BR /&gt;&lt;BR /&gt;Here are some high-level discussions on this general topic:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://labs.hoffmanlabs.com/node/491" target="_blank"&gt;http://labs.hoffmanlabs.com/node/491&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://labs.hoffmanlabs.com/node/955" target="_blank"&gt;http://labs.hoffmanlabs.com/node/955&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I included a chapter on this topic in the 2nd edition of the Writing Real Programs book, if you can locate a copy of that book.&lt;BR /&gt;&lt;BR /&gt;SYSNAM is among the ALL-class privileges, and it's trivial to gain any (other) OpenVMS privilege should you be granted SYSNAM privilege.  Differentiating users with SYSPRV or with SYSNAM isn't worth any particular effort.&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Jul 2009 12:18:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459150#M17006</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-14T12:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459151#M17007</link>
      <description>&amp;gt;&amp;gt; The underlying problem is that we want to grant the task of adding and modifying UAF accounts (including MAIL SET FORWARD setting)&lt;BR /&gt;&lt;BR /&gt;fyi, MAIL SET FORWARD has NOTHING to do with UAF accounts. It only concerns itself with SYS$SYSTEM:VMSMAIL_PROFILE.DATA.&lt;BR /&gt;Entries may or might not correspond with SYSUAF  entries. Often they do of course.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;  to a non-SYSTEM user, and so we want to give this user the minimal set of privileges to do this. Obvious SYSPRV is necessary toadd/modify UAF accounts,&lt;BR /&gt;&lt;BR /&gt;That's NOT obvious to me.&lt;BR /&gt;&lt;BR /&gt;Obviously write access to SYSUAF.DAT / VMSMAIL_PROFILE.DATA is needed. One way to accomplish that is to have SYSPRV. &lt;BR /&gt;But ACL's can provide a fine alternative.&lt;BR /&gt;&lt;BR /&gt;Now if you give someone uncontrolled write access to SYSUAF, then you have effectively given that person SETPRV / SYSPRV and it woudl be clearer to just give that, callign a spade a spade.&lt;BR /&gt;&lt;BR /&gt;But for OpenVMS Email forwarding maintenance just allowing access through an ACE probably works fine and is not too risky. (IMHO of course)&lt;BR /&gt;&lt;BR /&gt;fwiw,&lt;BR /&gt;Hein.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Jul 2009 14:13:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459151#M17007</guid>
      <dc:creator>Hein van den Heuvel</dc:creator>
      <dc:date>2009-07-14T14:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459152#M17008</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt; if you don't want direct system access maybe consider the openvms management station :-&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/openvms/products/argus/" target="_blank"&gt;http://h71000.www7.hp.com/openvms/products/argus/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Jul 2009 14:20:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459152#M17008</guid>
      <dc:creator>marsh_1</dc:creator>
      <dc:date>2009-07-14T14:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459153#M17009</link>
      <description>FWIW, OpenVMS Management Station (OMS) requires a Microsoft Windows box (not everybody has those) and (last I looked) also requires a mid-or upper-end license for OpenVMS I64; EOE or MCOE.</description>
      <pubDate>Tue, 14 Jul 2009 14:41:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459153#M17009</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2009-07-14T14:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is SYSNAM privilege really needed for MAIL SET FORWARD /USER ?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459154#M17010</link>
      <description>You're right (of course) Hoff, though it was one of the things that I raised i a meeting in the UK when one of the guys from the UK support centre outlined the licensing on IA64.  OMS became a product that needed a license again rather than being the complementary product that it was on Alpha and VAX.&lt;BR /&gt;Steve</description>
      <pubDate>Wed, 15 Jul 2009 02:10:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/is-sysnam-privilege-really-needed-for-mail-set-forward-user/m-p/4459154#M17010</guid>
      <dc:creator>Steve Reece_3</dc:creator>
      <dc:date>2009-07-15T02:10:58Z</dc:date>
    </item>
  </channel>
</rss>

