<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMS: UIC [1,1] - Need explanation in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195903#M89769</link>
    <description>Varsha,&lt;BR /&gt;&lt;BR /&gt;Like Steven wrote, "What problem are you trying to solve" and "Why go looking for trouble"&lt;BR /&gt;&lt;BR /&gt;but if you really want to&lt;BR /&gt;&lt;BR /&gt;$ SET FILE /OWN=SYSTEM SYS$SYSTEM:SYSUAF.DAT&lt;BR /&gt;&lt;BR /&gt;wil do the trick, and AFAIK is in itself pretty harmless.&lt;BR /&gt;However, DO NOT MAKE TYPO'S in such commands!!!&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
    <pubDate>Mon, 12 May 2008 13:59:07 GMT</pubDate>
    <dc:creator>Jan van den Ende</dc:creator>
    <dc:date>2008-05-12T13:59:07Z</dc:date>
    <item>
      <title>VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195899#M89765</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I am Varsha B from IBM. I just wanted to know if the UIC [1,1] is same as SYSTEM UIC. Below you can find the owner field of SYSUAF.DAT file as [1,1]. But [1,1] UIC does not exist on the system. Could you please elaborate what the UIC [1,1] exactly mean? Also Is it fine if we change the owner field for the below file to SYSTEM. Please help.&lt;BR /&gt;&lt;BR /&gt;$ dir sys$system:sysuaf.dat/sec/prot&lt;BR /&gt;&lt;BR /&gt;Directory SYS$COMMON:[SYSEXE]&lt;BR /&gt;&lt;BR /&gt;SYSUAF.DAT;1         [1,1]                            (RWE,RWE,RWE,)&lt;BR /&gt;&lt;BR /&gt;Total of 1 file.&lt;BR /&gt;$ mc authorize&lt;BR /&gt;UAF&amp;gt; sh [1,1]&lt;BR /&gt;%UAF-W-BADSPC, no user matches specification&lt;BR /&gt;UAF&amp;gt; exit&lt;BR /&gt;%UAF-I-NOMODS, no modifications made to system authorization file&lt;BR /&gt;%UAF-I-NAFNOMODS, no modifications made to network proxy database&lt;BR /&gt;%UAF-I-RDBNOMODS, no modifications made to rights database</description>
      <pubDate>Mon, 12 May 2008 10:47:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195899#M89765</guid>
      <dc:creator>Varsha</dc:creator>
      <dc:date>2008-05-12T10:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195900#M89766</link>
      <description>Varsha,&lt;BR /&gt;&lt;BR /&gt;to begin with: WELCOME to the VMS forum!&lt;BR /&gt;&lt;BR /&gt;The UIC [1,1] is quite often not named.&lt;BR /&gt;It is in the [1, ] group, meaning it automatically has SYSTEM rights.&lt;BR /&gt;&lt;BR /&gt;Very often disks are initialised as belonging to [1,1], and under certain circumstances directories on it, and also files therein, inherit that ownership.&lt;BR /&gt;&lt;BR /&gt;Many _PEOPLE+ prefer named ownerships, and that is why often an account (or only a UIC format identifier) for that value is created, and then I have always encountered the name SYSTEMBUILD for it.&lt;BR /&gt;&lt;BR /&gt;(Maybe somebody here knows if that is or was, perhaps under certain circumstances, coming from Engeneering?)&lt;BR /&gt;&lt;BR /&gt;Anyway, for the OS, only the numeric values are used anyway, so the presence or absence of a name for it has NO operational significance. (but humans ARE more at ease with named entities)&lt;BR /&gt;&lt;BR /&gt;If you would like to make this system more human-friendly, you may execute (from a priv'd account):&lt;BR /&gt;&lt;BR /&gt;$ MCR AUTHORISE ADD/IDENTIFIER SYSTEMBUILD /VALUE=UIC:[1,1] /ATTRIB=RESOURCE&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Mon, 12 May 2008 11:49:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195900#M89766</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2008-05-12T11:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195901#M89767</link>
      <description>Thanks so much for your reply.&lt;BR /&gt;Also I would like to know if we can change the ownership of the files (who is currently having [1,1]) to [1,4] which is the system account. Please advise.</description>
      <pubDate>Mon, 12 May 2008 11:59:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195901#M89767</guid>
      <dc:creator>Varsha</dc:creator>
      <dc:date>2008-05-12T11:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195902#M89768</link>
      <description>&amp;gt; so I would like to know if we can change&lt;BR /&gt;&amp;gt; the ownership of the files (who is&lt;BR /&gt;&amp;gt; currently having [1,1]) to [1,4] which is&lt;BR /&gt;&amp;gt; the system account.&lt;BR /&gt;&lt;BR /&gt;What problem will this solve?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;  Please advise.&lt;BR /&gt;&lt;BR /&gt;Why go looking for trouble?</description>
      <pubDate>Mon, 12 May 2008 13:19:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195902#M89768</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2008-05-12T13:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195903#M89769</link>
      <description>Varsha,&lt;BR /&gt;&lt;BR /&gt;Like Steven wrote, "What problem are you trying to solve" and "Why go looking for trouble"&lt;BR /&gt;&lt;BR /&gt;but if you really want to&lt;BR /&gt;&lt;BR /&gt;$ SET FILE /OWN=SYSTEM SYS$SYSTEM:SYSUAF.DAT&lt;BR /&gt;&lt;BR /&gt;wil do the trick, and AFAIK is in itself pretty harmless.&lt;BR /&gt;However, DO NOT MAKE TYPO'S in such commands!!!&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Mon, 12 May 2008 13:59:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195903#M89769</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2008-05-12T13:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195904#M89770</link>
      <description>Vatsala,&lt;BR /&gt;&lt;BR /&gt;Let me add my welcome to the OpenVMS forum!&lt;BR /&gt;&lt;BR /&gt;I would, however, not necessarily agree with changing the ownership of the files. I could easily agree with creating an accounting file entry for [1,1] in the SYSUAF.DAT (or at least creating an entry in RIGHTSLIST).&lt;BR /&gt;&lt;BR /&gt;A quick check of my systems at various versions of OpenVMS show that some files are owned by SYSTEM ([1,4]) and some files are owned by [1,1]. This is normal. While file access by a privileged process should not be a problem, there is no guarantee that there is not some process on your system that would  then experience a problem. &lt;BR /&gt;&lt;BR /&gt;It is true that a quick check of the active processes shows no obvious processes running under [1,1], but that is far different from a guarantee. &lt;BR /&gt;&lt;BR /&gt;So, with all due respect to my colleague, I would recommend leaving the protection set as it is. The definition of a rights identifier for [1,1] would make the listings "prettier", and have a far higher probability of being completely harmless.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Mon, 12 May 2008 14:20:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195904#M89770</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2008-05-12T14:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195905#M89771</link>
      <description>&amp;gt; So, with all due respect to my colleague, I&lt;BR /&gt;&amp;gt; would recommend leaving the protection set&lt;BR /&gt;&amp;gt; as it is.&lt;BR /&gt;&lt;BR /&gt;Which of your colleagues _recommended_&lt;BR /&gt;changing the ownership (not "the&lt;BR /&gt;protection")?  "but if you really want to"&lt;BR /&gt;does not sound to me like a recommendation.&lt;BR /&gt;&lt;BR /&gt;If I were looking to buy myself some trouble&lt;BR /&gt;this way, I'd probably make sure that I had&lt;BR /&gt;a good backup of the disk before I started&lt;BR /&gt;fiddling around with it, too.</description>
      <pubDate>Mon, 12 May 2008 15:37:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195905#M89771</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2008-05-12T15:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195906#M89772</link>
      <description>Somebody somewhere is apparently somewhat confused here, though there does exist a very subtle distinction of phrasing here.&lt;BR /&gt;&lt;BR /&gt;[1,1] is a system UIC.&lt;BR /&gt;&lt;BR /&gt;[1,1] is not the UIC of the SYSTEM user.&lt;BR /&gt;&lt;BR /&gt;A "system uic" is any user with a UIC group with a UIC group of the maxsysgroup system parameter or less.  SYSPRV privilege grants the same access; SYSPRV allows the possessor to have the same access as a user with a system UIC.&lt;BR /&gt;&lt;BR /&gt;Central recommendation: Don't mess with this.  Not without a whole lot better reason than what I've seen here so far.  This system disk is configured appropriately.&lt;BR /&gt;&lt;BR /&gt;This setting is likely a result of a system disk volume that was initialized with /SYSTEM, as most disks correctly are, and the creation operation having been run while SYSPRV or better privileges or with a system UIC, and thus the ownership is inherited.&lt;BR /&gt;&lt;BR /&gt;Stephen Hoffman&lt;BR /&gt;HoffmanLabs LLC&lt;BR /&gt;&lt;BR /&gt;-- -- --&lt;BR /&gt;&lt;BR /&gt;INITIALIZE&lt;BR /&gt;&lt;BR /&gt;  /SYSTEM&lt;BR /&gt;&lt;BR /&gt;     Requires a system UIC or SYSPRV (system privilege) privilege.&lt;BR /&gt;&lt;BR /&gt;     Defines a system volume. The owner UIC defaults to [1,1].&lt;BR /&gt;     Protection defaults to complete access by all ownership&lt;BR /&gt;     categories, except that only system processes can create top-&lt;BR /&gt;     level directories.&lt;BR /&gt;</description>
      <pubDate>Mon, 12 May 2008 20:42:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195906#M89772</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-05-12T20:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195907#M89773</link>
      <description>I'll try an explanation in different terms...&lt;BR /&gt;&lt;BR /&gt;UICs in octal format [g,m] are a throwback from earlier operating systems, like RSX and RSTS. Being very small and limited, they had some dependencies on specific, hard coded UICs used for specific purposes. Although VMS has more flexibility, it inherited some dependencies as "standard conventions". In theory, they are arbitrary and could be changed, but in practice most folk just accept the out-of-the-box defaults.&lt;BR /&gt;&lt;BR /&gt;The user "SYSTEM" has UIC [1,4] &lt;BR /&gt;There is no magic reason for the choice, consider it historic fact.&lt;BR /&gt;&lt;BR /&gt;The default UIC for ownership of a system volume is [1,1]. This is in the same UIC GROUP as the user "SYSTEM", but is NOT the same UIC. &lt;BR /&gt;&lt;BR /&gt;Again you should consider this historic fact with no particular reason. &lt;BR /&gt;&lt;BR /&gt;All UICs with group numbers less or equal to SYSGEN parameter MAXSYSGROUP (default octal 10) have implicit SYSTEM privilege, so, in some senses are equivalent as they (mostly) imply the same privileged access to object.&lt;BR /&gt;&lt;BR /&gt;There is no good reason to change any of these conventions. Although such changes could be expected to be benign, you can't be certain you don't run code which assumes the "normal" defaults and conventions and may break if confronted with unexpected changes.&lt;BR /&gt;&lt;BR /&gt;I would strongly recommend AGAINST changes unless you have a compelling problem you're trying to solve and understand the potential impact of your changes.</description>
      <pubDate>Tue, 13 May 2008 01:18:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195907#M89773</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2008-05-13T01:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195908#M89774</link>
      <description>If you change the files from [1,1] to 1,4] a process that runs as user SYSTEM (=[1,4]) would access the file as OWNER too. This will not cause an access denial because the other protection fields will still be used if the owner isn't granting access.&lt;BR /&gt;&lt;BR /&gt;But it could add additional access that is not wanted. E.g. owner has RWED and group, world and system only R. &lt;BR /&gt;&lt;BR /&gt;Fwiw&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 13 May 2008 08:35:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195908#M89774</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2008-05-13T08:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: VMS: UIC [1,1] - Need explanation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195909#M89775</link>
      <description>Hi Varsha,&lt;BR /&gt;&lt;BR /&gt;SYtem UIC and system user UIC are differnt ,&lt;BR /&gt;&lt;BR /&gt;According to the convention some UIC are assigned to systems.&lt;BR /&gt;&lt;BR /&gt;Right now system ,owner and group can RWE sysuaf.dat,&lt;BR /&gt;&lt;BR /&gt;if you wanna protection u can change the protection of that file.. &lt;BR /&gt;</description>
      <pubDate>Wed, 14 May 2008 12:16:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-uic-1-1-need-explanation/m-p/4195909#M89775</guid>
      <dc:creator>Neelmani Pandey</dc:creator>
      <dc:date>2008-05-14T12:16:33Z</dc:date>
    </item>
  </channel>
</rss>

