<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DLTOBJ command restricted</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Jun 2013 16:59:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: The Most-Watched IT Questions: October 4, 2011 - ITKE Community Blog</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/#comment-97349</link>
		<dc:creator>The Most-Watched IT Questions: October 4, 2011 - ITKE Community Blog</dc:creator>
		<pubDate>Tue, 04 Oct 2011 06:55:32 +0000</pubDate>
		<guid isPermaLink="false">#comment-97349</guid>
		<description><![CDATA[[...] 7. Abiha6325, Deepu9321, CharlieBrowne, TomLiotta, and Splat discuss a member&#8217;s policy of restricting the DLTOBJ command. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] 7. Abiha6325, Deepu9321, CharlieBrowne, TomLiotta, and Splat discuss a member&#8217;s policy of restricting the DLTOBJ command. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: splat</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/#comment-96877</link>
		<dc:creator>splat</dc:creator>
		<pubDate>Wed, 21 Sep 2011 14:38:58 +0000</pubDate>
		<guid isPermaLink="false">#comment-96877</guid>
		<description><![CDATA[Tom, I seem to remember that command on the &lt;b&gt;S/38&lt;/b&gt;, and a right nuisance it was too.  It was replaced with the various object-specific delete commands as it was a bit too indiscriminate for most developers.]]></description>
		<content:encoded><![CDATA[<p>Tom, I seem to remember that command on the <b>S/38</b>, and a right nuisance it was too.  It was replaced with the various object-specific delete commands as it was a bit too indiscriminate for most developers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/#comment-96791</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 20 Sep 2011 00:54:05 +0000</pubDate>
		<guid isPermaLink="false">#comment-96791</guid>
		<description><![CDATA[DLTOBJ is a i 7.1 command from IBM. It was provided as a generic command to handle many kinds of objects. However, each object has a specific command that works on that kind of object. Further, many objects can be deleted using the IFS form with the DEL command or using Qshell and the rm utility (or using other shells). Objects may even be deleted using Windows Explorer without actually entering any commands at all.

The only real way to stop users from deleting files is to remove their authority to delete the files. Use resource security to set your rules. Then your users can run DLTOBJ as often as they want, but those files won&#039;t be deleted.

If users have the authority to delete an object, then securing a command won&#039;t protect that object. It just adds more work for administrators.

Tom]]></description>
		<content:encoded><![CDATA[<p>DLTOBJ is a i 7.1 command from IBM. It was provided as a generic command to handle many kinds of objects. However, each object has a specific command that works on that kind of object. Further, many objects can be deleted using the IFS form with the DEL command or using Qshell and the rm utility (or using other shells). Objects may even be deleted using Windows Explorer without actually entering any commands at all.</p>
<p>The only real way to stop users from deleting files is to remove their authority to delete the files. Use resource security to set your rules. Then your users can run DLTOBJ as often as they want, but those files won&#8217;t be deleted.</p>
<p>If users have the authority to delete an object, then securing a command won&#8217;t protect that object. It just adds more work for administrators.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: charliebrowne</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/#comment-96765</link>
		<dc:creator>charliebrowne</dc:creator>
		<pubDate>Mon, 19 Sep 2011 16:14:04 +0000</pubDate>
		<guid isPermaLink="false">#comment-96765</guid>
		<description><![CDATA[With jounaling you would be able to find out who did it, but you would not be able to easily restore the data since the the journal would only contain a single entry that the file was deleted. You would have to RSTOBJ from a backup and then use the Journal to apply all the changes that were done since that backup.

Now, regarding restricting a user from deleting an object.
You can use standard AS400 Authority to do this.
My questions are:
What users are working from a cmd line? and what are they doing?
What types of files/objects are they deleting?
There are many different ways to control this, but without having more knowledge of the problem and the business logic to give users use of a command line, it would be useless to give more suggestions.
Point of clarification: When you say users, I am assuming you do not mean develoeprs.]]></description>
		<content:encoded><![CDATA[<p>With jounaling you would be able to find out who did it, but you would not be able to easily restore the data since the the journal would only contain a single entry that the file was deleted. You would have to RSTOBJ from a backup and then use the Journal to apply all the changes that were done since that backup.</p>
<p>Now, regarding restricting a user from deleting an object.<br />
You can use standard AS400 Authority to do this.<br />
My questions are:<br />
What users are working from a cmd line? and what are they doing?<br />
What types of files/objects are they deleting?<br />
There are many different ways to control this, but without having more knowledge of the problem and the business logic to give users use of a command line, it would be useless to give more suggestions.<br />
Point of clarification: When you say users, I am assuming you do not mean develoeprs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: deepu9321</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/dltobj-2/#comment-96757</link>
		<dc:creator>deepu9321</dc:creator>
		<pubDate>Mon, 19 Sep 2011 13:15:06 +0000</pubDate>
		<guid isPermaLink="false">#comment-96757</guid>
		<description><![CDATA[How are you restricting user? Is it at command level?
DLTOBJ command looks like TAATOOL command.
When you are restricting the user from DLTOBJ, When user takes option &#039;4&#039; the corresponding Command will be DLTF(for file), DLTPGM(for Program), You will need to restrict the user from using all these commands.
Are you restricting the user without using these commands also?

Pradeep.]]></description>
		<content:encoded><![CDATA[<p>How are you restricting user? Is it at command level?<br />
DLTOBJ command looks like TAATOOL command.<br />
When you are restricting the user from DLTOBJ, When user takes option &#8217;4&#8242; the corresponding Command will be DLTF(for file), DLTPGM(for Program), You will need to restrict the user from using all these commands.<br />
Are you restricting the user without using these commands also?</p>
<p>Pradeep.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.177 seconds using memcached
Object Caching 323/329 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-06-19 17:00:00 -->