Most web consoles bolt their own permissions onto the system they manage.
Steward does the opposite: OpenVMS stays the single authority, and Steward
stays out of its way.
AS YOU
Every request runs as you
Each request takes on your own OpenVMS identity, a persona. Your privileges and
rights identifiers decide what you may see and change, exactly as at a terminal.
There is no second set of permissions to manage, and nothing to drift out of step.
SYSPRV
Least privilege, provably
The service account runs with IMPERSONATE, TMPMBX and NETMBX. SYSPRV is switched on
only for the instant a persona is created, and the server checks after every
request that it is off again. If it is not, the process stops rather than carry on.
DCL
It speaks VMS
Screens laid out as AUTHORIZE lays them out. DCL wildcards in every filter.
Messages in %FACILITY-S-IDENT form, with the system's own text when
OpenVMS says no. Privileges you switch on and off like
SET PROCESS/PRIVILEGE.
C99
Native, with no runtime to install
A small C program on OpenVMS, run as a pool of FastCGI processes behind lighttpd.
No Java, no Node.js, no Python on the server. One PCSI kit and one configuration
procedure, with startup and shutdown hooks like any layered product.
AUDIT
Security-audited code
Static analysis, sanitizers, fuzzing and secret scanning run on every change,
and every phase closes only after a security review. What each review found, and
the test that now guards it, is published with the source.
LOG
A record of every change
Each sign-in, privilege switch and change is logged with who made it, from where,
and what OpenVMS answered. Passwords are never recorded. Break-in evasion applies
to each browser separately, even behind a reverse proxy.