<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: AS/400 access control for commands</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/as400-access-control/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/as400-access-control/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Jun 2013 19:19:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/as400-access-control/#comment-80908</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Fri, 27 Aug 2010 19:47:31 +0000</pubDate>
		<guid isPermaLink="false">#comment-80908</guid>
		<description><![CDATA[The problem might be that right now you shouldn&#039;t have any normal users who have access to those commands.

If your users already have sufficient authority to run CHGSYSLIBL for example, then someone has already changed authorities to make the command available &lt;b&gt;or&lt;/b&gt; your users have excessive authority, perhaps because they have *ALLOBJ special authority or have access to it through a group profile or other means.

The default *PUBLIC authority for CHGSYSLIBL is *EXCLUDE. There shouldn&#039;t be anything for you to do. It should already be okay.

If command authorities have previously been changed, you should simply set each command back to the default authority. Appendix C of the &lt;a href=&quot;http://publib.boulder.ibm.com/infocenter/iseries/v5r4/index.jsp?topic=/rzamv/rzamvrelated.htm&quot;&gt;Security Reference&lt;/a&gt; manual lists all commands that ship with *PUBLIC *EXCLUDE default authority. If any of your commands are different, use EDTOBJAUT or GRTOBJAUT to reset the authority.

If your users have excessive authority such as *ALLOBJ, then you can&#039;t restrict the commands. You need to remove the special authority from the users. Be aware that that will probably cause other things not to work for those users, so you&#039;ll need to fix anything that fails by some other method.

Unless we know why your users can run troublesome commands, we can&#039;t tell you how to fix it.

Why do you think there is a problem now? What happens that you think should be fixed? Does it happen for all users or only for certain ones?

Tom]]></description>
		<content:encoded><![CDATA[<p>The problem might be that right now you shouldn&#8217;t have any normal users who have access to those commands.</p>
<p>If your users already have sufficient authority to run CHGSYSLIBL for example, then someone has already changed authorities to make the command available <b>or</b> your users have excessive authority, perhaps because they have *ALLOBJ special authority or have access to it through a group profile or other means.</p>
<p>The default *PUBLIC authority for CHGSYSLIBL is *EXCLUDE. There shouldn&#8217;t be anything for you to do. It should already be okay.</p>
<p>If command authorities have previously been changed, you should simply set each command back to the default authority. Appendix C of the <a href="http://publib.boulder.ibm.com/infocenter/iseries/v5r4/index.jsp?topic=/rzamv/rzamvrelated.htm">Security Reference</a> manual lists all commands that ship with *PUBLIC *EXCLUDE default authority. If any of your commands are different, use EDTOBJAUT or GRTOBJAUT to reset the authority.</p>
<p>If your users have excessive authority such as *ALLOBJ, then you can&#8217;t restrict the commands. You need to remove the special authority from the users. Be aware that that will probably cause other things not to work for those users, so you&#8217;ll need to fix anything that fails by some other method.</p>
<p>Unless we know why your users can run troublesome commands, we can&#8217;t tell you how to fix it.</p>
<p>Why do you think there is a problem now? What happens that you think should be fixed? Does it happen for all users or only for certain ones?</p>
<p>Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/9 queries in 0.011 seconds using memcached
Object Caching 268/271 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-06-19 22:39:16 -->