The 'F' option transfers the screen without adding to the stack by using the FTH-FUNCT. If the Stack Option is left blank, a pop-up window will be displayed to the operator whenever the fourth screen (the (cont.) limit is three) is added to the stack. When the window is displayed, the operator must choose one of the (cont.) above-mentioned option codes. To view or change your Session Options: **Do this:** Key in the command OPTION. Press ENTER. You can change your session options either temporarily (for this session only) or permanently (until you again change (cont.) it to something else), by pressing either PF4 or ENTER, respectively. If you press ENTER the new option is stored in (cont.) your security profile and applied each subsequent time you log on to MAGEC. At this time you may wish to experiment with different session options, setting different values and then pressing (cont.) CLEAR and PA1 to see what happens. Most MAGEC users find that option B or C is the best suited to their usage patterns (cont.) since MAGEC is structured to steer operators away from menus and toward entering direct mnemonic commands. Application (cont.) developers sometimes prefer the D option. ``` ** OPTION 000000018 Date 05/11/92 M A G E C User View TS01 Time 11:48:09 SESSION OPTIONS Operator Name BOBBIE  LLOYD Special Keys Option: C Option A == PA1 = $$MENU, CLEAR = CLEARS Option B == PA1 = **MENU, CLEAR = CLEARS Option C == PA1 = VERZUN, CLEAR = CLEARS Option D == PA1 = MSKDEF, CLEAR = TSKLST Option E == PA1 = $$MENU, CLEAR = **MENU Stack Option: P Option P == PUSH oldest entry from stack and add this entry before doing attach Option C == CLEAR all entries from stack Option F == FETCH instead of attach--stack remains Blank == Present pop-up window for stack options Enter desired Option Codes; press PF4 for temporary setting ENTER for permanent setting ** ``` **Note:** There is no need to enter a key value with the OPTION function code since the onlu Operator ID uou are (cont.) allowed to set options for is your own and MAGEC wil automatically insert your ID into the SKEY screen field, (cont.) regardless waht you may, or may not, have typed there. Figure 10 — Session Options Screen # Operator Profile ## SIFxxx Functions **Do this:** Enter the command : SIFSEE 18 The Security Information File screen will be displayed showing the profile for employee 18, Bobbie Lloyd. Let's review the parameters from this screen: Employee # is the 9-digit number (usually Social Security or Social Insurance number) which identifies this operator (cont.) uniquely. This is a protected field since you have already entered the employee number on the top line of the screen as (cont.) the key. **Password** is a 4-character password which may be alpha-numeric. **Location**** **is a 3-character code defining which location(s) this operator may log on to MAGEC from. the dot (.) is a "wildcard"; hence, a location of ". . ." means "any location." **Days **defines (with Y or N flags) which days of the week this operator may log on, the eighth position (H) means Holidays. **U-Views** (user-views) specifies which of the sixteen MAGEC user-views this operator may access MAGEC through. The user-views are TS01 thru TS08 (test), and PR01 thru PR08 (production). **Last Name** & **First** are the name of the operator. **On Hold** is a Y or N indicator, Y means this operator is *suspended* - "on hold." **Term Date**** **is the date (MM/DD/CCYY) that this operator is terminated. MAGEC will automatically suspend him/her on that date. **Max # Unauth Funct** is the number (000 through 999) of times the operator may attempt to do a function he/she is not authorized to do before MAGEC automaticallly suspends him/her. **Logon Attempts** is the number of attempts this operator may make to get his/her password correct (when logging on) before MAGEC automatically suspends him/her. Zeros (or '999') means infinite. **Time Out** is the number of minutes (000 thru 999) this operator may leave the terminal idle (fail to press any transmit keys), before he/she is automatically logged off. Zeros means never. **Multi-Term Logon** is a Y or N indicator specifying whether this operator may be logged on to more than one terminal at a time. **Group Identifier**** **is any 10-character "code" which you may wish to use to identify operators belonging to any (cont.) grouping, i.e. "TEMP" for temporary help, or "MIS" for MIS employees. You can alter the profiles for an entire group in (cont.) one transaction if necessary, i.e.. the project that the TEMP's were working on is cancelled. **Last Logon **indicates the date and terminal this operator last logged on. ``` ** SIFSEE 18  ++ CENTRAL SECURITY OFFICER ++   M A G E C OPERATOR SECURITY INFORMATION   EMPLOYEE # 000000018  B L  TEST  PROD   PASSWORD: ALEE  SMTWTFSH  87654321  87654321   LOCATION: ...  DAYS: YYYYYYYY  U-VIEWS: YYYYYYYY  YYYYYYYY  LAST NAME: LLOYD  FIRST:  BOBBIE  ON HOLD: N  TERM DATE: 12/31/2029  MAX # UNAUTH FUNCT: 999  LOGON ATTEMPTS: 999   TIME OUT: 999 MIN.  GROUP IDENTIFIER: ALA Inc.  MULTI-TRM LOGON: Y LAST LOGON: PC01 ON 04/16/2021 SUSPEND AFTER: 999 INACTIVE DAYS PSWD CHNGD: 11/03/2020 ,GOOD FOR 999 DAYS  AUTHORIZED HOURS: 00 00 TO 24 00 ....................AUTHORIZATION LEVELS BY APPLICATION........................   Empl(01): 9   SPLR(48): 9  SEC.(49): 9  PROG(50): 9 Press PF4 for browse (LOC) screen   Press PF13 for Hardcopy Press PF16 to Copy field to buffer  Press PF17 to Paste data from buffer Press PF2 for field-level HELP** ``` Figure 11 — Operator Security Information Screen **Suspend After** indicates the number of days of inactivity (failure to log on to MAGEC) which may pass before MAGEC (cont.) will automatically suspend the operator, assuming him/her to be terminated, deceased, or just (cont.) dis-interested. **Pswd Changed** indicates the last date this operator changed his/her password (at logon time). **Good For ____ Days** is the number of days (000 through 999) which the operator may go without changing his/her (cont.) password. After that number of days MAGEC will not allow the operator to log on without changing the password. It (cont.) automatically prevents the use of "trivial" passwords (too easy to guess) and the re-use of the same passwords by the (cont.) same operator. A value of zeros (or '999') means infinity. **Authorized Hours** is the range of hours-of-the-day (24-hour clock) during which this operator may log on. A range of 00 00 thru 24 00 means "any time of day." **Authorization Levels by Application** specifies the levels (0 through 9) of authorization that this operator posesses (cont.) in each of the defined logical applications (LAP's). The short name for each LAP is shown along with the LAP number. (cont.) The LAP's 48, 49, and 50 are pre-defined by MAGEC and must always retain their original meanings (Spooler functions, (cont.) Security functions, and Developer function, respectively). Other LAP's are defined by you as you need them. The new LAP (cont.) (01) is shown on the screen. If you add other new LAP's they will also appear. A level of zero means a minimum (or no) (cont.) authorization, a level of nine indicates the highest possible authorization, for each LAP. **Note:** There are some special meanings associated with certain authorization levels in the three MAGEC-defined (cont.) LAP's. For example: a level 9 in Security (49) designates the operator as a "central security officer", a level 8 (cont.) designates him/her as a "local security officer" -- a level 9 in Programming (50) designates the operator as a (cont.) supervisor-level developer who can access other developer's library members without having to know the passwords, (cont.) etc. **Note:** Your developers can associate certain levels of authorization in certain LAP's with special meanings. MAGEC (cont.) always presents (in the TWA area) all of the security data (read-only access) for the current session; your programmers (cont.) can interrogate that data and allow or disallow certain operations based upon operator, terminal, location, date, time, (cont.) group-id, or any other criteria. This is in addition to the standard automatic security verifications done by (cont.) MAGEC. **Do this:** Define yourself to the MAGEC security system. Enter the command: SIFADD nnnnnnnnn (where nnnnnnnnn is your (cont.) employee ID or social security number). Fill in the fields on the screen and press ENTER. If you have successfully added the new record defining yourself to the security system you will receive the message at (cont.) the top left corner of the screen saying: Data ADDED to Database. You could immediately use your new ID and password to (cont.) log on to MAGEC, there are no other steps necessary (i.e. no assemblies, no re-cycling of the online system, no "new (cont.) copy" command). ``` ** SIFADD 123456789   M A G E C OPERATOR SECURITY INFORMATION   EMPLOYEE # TEST  PROD   PASSWORD: ____  SMTWTFSH  87654321  87654321   LOCATION: ___  DAYS: ________ U-VIEWS: ________  ________  LAST NAME: ___________________  FIRST:  ______________  ON HOLD: _  TERM DATE: __________  MAX # UNAUTH FUNCT: ___  LOGON ATTEMPTS: ___   TIME OUT: ___ MIN.  GROUP IDENTIFIER: __________MULTI-TRM LOGON: _ LAST LOGON:  ON  SUSPEND AFTER: ___ INACTIVE DAYS PSWD CHNGD:  ,GOOD FOR ___ DAYS  AUTHORIZED HOURS: __ __ TO __ __ ....................AUTHORIZATION LEVELS BY APPLICATION........................   Empl(01): _   SPLR(48): _  SEC.(49): _  PROG(50): _ ** ``` Figure 12 — Operator Security Information Screen # Terminal Profile ## DVCxxx Functions Now let us look at the definition for a terminal in the MAGEC security system. **Do this:** Enter the command: DVCSEE * -- press ENTER. The definition for your terminal will be displayed. The asterisk is interpreted as meaning "this terminal", as a (cont.) convenience for you. MAGEC will substitute your terminal ID for the asterisk. You could have entered the (cont.) command: DVCSEE xxxx where xxxx is any valid terminal ID, your own or anyone else's. The specified terminal's profile would be shown. The profile for a terminal is similar to the profile for an operator. When an operator logs on to a terminal MAGEC (cont.) compares the authorization levels for the terminal and the operator (in each individual category) and applies the more (cont.) restrictive of the two. This means that an operator's authorization at one terminal may be lower than at another. If (cont.) any of his/her authorizations have been reduced, a message will warn him/her at log on time. The reduction applies only (cont.) to this session, it does not alter the operator's profile. An exception to this automatic authorization reduction is when a *central security officer* logs on. MAGEC automaticaly (cont.) gives central security officers full access to all functions from all terminals. This is necessary in order to rescue (cont.) *local security officers* who have somehow locked themselves out of the system or otherwise woven a tangled web from (cont.) which they cannot escape. Needless to say, there should be only a few select individuals with central security officer (cont.) authorization. **Location** is the 3-character (no wildcards here) designation for the location of this terminal. Location codes are (cont.) defined by you in MAGEC Table number 252. You can refer to the "Database Administration" chapter for explanations on (cont.) how to update MAGEC Tables. **Buf Size** is the size of the terminal's buffer (normally 1,920). It is used by the Spooler, not by the Security system. **Type** is the terminal device type, i.e. 3278, 3279, etc. **L/R** is the line connection type: Local Remote, Dialup, (cont.) or logial Unit (the uppercase letter is the one-character abbreviation you can enter). **7-Color** is a Y or N (cont.) indicator to specify whether this terminal has 7-color support. **Form** is the 4-character designation for the type of (cont.) paper mounted in this device if it is a printer, not a CRT. **Active Report** also applies only to printers. These fields are not used for Security, but for other MAGEC subsystems. **Desc **is a 30-character free-form text field, a brief description for this terminal. **Status** indicates whether this terminal is in service or not, valid values are Available or Disabled (the uppercase letter may be used as an abbreviation when entering). ``` ** DVCSEE PC01   M A G E C DEVICE DEFINITION (CRT/PRINTER)  ID= PC01  Home Gateway: ................  Location: SYS ( COMPUTER ROOM (SYSTEM PRINTERS)  ) Buf Size: 1,920  Type: 3279  L/R: LOCAL  7-Color (Y/N) : N  --TEST--  --PROD--  Desc: MAGEC Software - AT Portable  87654321  87654321  Status AVAILABLE  Form:  User Views: YYYYYYYY  YYYYYYYY  Active Report  Time Out: 999 min. Print Classes: A  SMTWTFSH   Authorized Hours : 00 00 to 24 00 Days: YYYYYYYY ...............MAXIMUM AUTHORIZATION LEVELS BY APPLICATION......................   Empl(01) : 0   SPLR(48): 9  SEC.(49): 9  PROG(50): 9 Press PF4 for browse (LOC) screen   Press PF13 for Hardcopy Press PF16 to Copy field to buffer  Press PF17 to Paste data from buffer Press PF2 for field-level HELP** ``` Figure 13 — Device Definition Screen **Print Classes** specifies the class (one character) to be assigned to reports generated from this terminal via the MAGEC Spooler. **Authorized Hours** and **Authorization Levels by Application** are similar to those specifications for the operator. If you wished to define another terminal to the MAGEC dictionary you would use the DVCADD command as: DVCADD tttt where tttt is a valid terminal ID. **Note:** Since terminal-level security is optional in MAGEC it is not necessary to define your terminals to the (cont.) dictionary. If a terminal is not defined, MAGEC assumes that it has unlimited access (subject, of course, to the (cont.) operator's authorizations). It is necessary to define terminals in order to take advantage of some Spooler functions or (cont.) 7-Color extended attribute support; however. **Home Gateway** is the Gateway name of this computer as defined on MAGEC Lookup Table #248. This entry must be a valid (cont.) name, as defined on the table, or it must be left blank. An entry in this field is needed only if this computer is used (cont.) as a Host and also as a Client machine using MAGEC's intrinsic TCP/IP networking facility. The purpose for this entry (cont.) is to tell MAGEC's I/O module that any Data Classes which are defined as being at this Gateway name are actually local (cont.) to this machine. This machine, it is assumed, also serves a Host so that other machines (Clients) can access Data (cont.) Classes which are local to this machine. If this machine never serves as a Host, then it is not necessary for it to be defined to Table #248 and it is correct to leave this Home Gateway specification blank. ``` ** DVCADD tttt  Enter data to be ADDED   M A G E C DEVICE DEFINITION (CRT/PRINTER)  ID= TTTT  Home Gateway: ................  Location: ___ (  ) Buf Size: ______  Type: ____  L/R: ______ 7-Color (Y/N) : _  --TEST--  --PROD--  Desc: ____________________________  87654321  87654321  Status _________  Form: ____  User Views: ________  ________ Next: https://magec.com/DOC/markdown/sectut04.md.txt