Managing Users

Current groups (user-specified groups) are stored only in the operational database. Therefore, users must use the SET PORT command to configure these groups; users cannot use the DEFINE PORT or CHANGE PORT command.

Current groups are always equal to or a subset of the AUTHORIZED GROUPS. If a user enters SET PORT GROUPS ALL, the current groups consist of all the enabled authorized groups.

The access server uses the current groups for these functions:

Checking authorization when the user enters a CONNECT command on the access server

Displaying information with the SHOW NODES and SHOW SERVICES commands

Example: Assigning User Groups

The following example shows the command for nonprivileged users to assign groups from among their authorized groups:

Local> SET PORT GROUPS 5

If the authorized groups for the port were groups 4 to 7, the user can only access group 5 after executing the command. In addition, the SHOW SERVICES command shows only the information for services and nodes in group 5, and the SHOW PORT CHARACTERISTICS command shows the groups assigned to the port in the (Current) Groups field.

11-42 Configuring and Managing Interactive Devices