This token replaces the groups token. Notice that the praudit command does not distinguish between the two tokens, as both token IDs are labelled groups when ASCII output is displayed.
The newgroups token records the groups entries from the process's credential. The newgroups token has two fixed fields:
a token ID field that identifies this token as a newgroups token
a count that represents the number of groups that are contained in this audit record
The remainder of this token is composed of zero or more group entries. The praudit command displays the ip port token as follows:
group, staff, admin |
The following figure shows the format of a newgroups token.
The newgroups token is output only when the group audit policy is active.