The ALL Record and MODE

book

Article ID: 14970

calendar_today

Updated On:

Products

CA Top Secret CA Top Secret - LDAP

Issue/Introduction



What happens if you give a MODE to the ALL Record?  Will all users then be given the mode of the ALL Record?

Environment

Release: TOPSEC00200-15-Top Secret-Security
Component:

Resolution

The All Record is not considered the same as other profiles.  It is not explicitly given to users via an ADD command which must be done with other profiles.  If you list a user you will not see the ALL Record listed in the user's list of profiles.  Therefore, when you issue a command to put a MODE on the ALL Record it is not inherited by users because it is not attached to their acid record.  If the user does not have a MODE on their acid record then they will inherit the mode of the facility that they are using.