 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is a special authority needed for active socket connections?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 13:53:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99630</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Wed, 30 Nov 2011 22:39:18 +0000</pubDate>
		<guid isPermaLink="false">#comment-99630</guid>
		<description><![CDATA[&lt;i&gt;Will see if our audit team accepts this change or not.&lt;/i&gt;

With the IBM document to justify the change, it could be acceptable. Still, I would make a call to IBM Support and ask for some specific justification for the requirement or for IBM-recommended alternatives.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>Will see if our audit team accepts this change or not.</i></p>
<p>With the IBM document to justify the change, it could be acceptable. Still, I would make a call to IBM Support and ask for some specific justification for the requirement or for IBM-recommended alternatives.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gfroehlich</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99598</link>
		<dc:creator>gfroehlich</dc:creator>
		<pubDate>Wed, 30 Nov 2011 10:10:26 +0000</pubDate>
		<guid isPermaLink="false">#comment-99598</guid>
		<description><![CDATA[To give the user QTMHHTTP *JOBCTL let the problem disappear. 

Will see if our audit team accepts this change or not. 

If somebody has an idea for an alternative, please let me know. 

Thanks 
Gabriel]]></description>
		<content:encoded><![CDATA[<p>To give the user QTMHHTTP *JOBCTL let the problem disappear. </p>
<p>Will see if our audit team accepts this change or not. </p>
<p>If somebody has an idea for an alternative, please let me know. </p>
<p>Thanks<br />
Gabriel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99569</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 29 Nov 2011 21:41:14 +0000</pubDate>
		<guid isPermaLink="false">#comment-99569</guid>
		<description><![CDATA[&lt;i&gt;I’m using DSPJRN or DSPAUDJRNE and create a file with it.&lt;/i&gt;

Use DSPJRN or CPYAUDJRNE -- DSPAUDJRNE is only okay for basic overviews. It should not be used for precise details. See &lt;a href=&quot;http://www-912.ibm.com/s_dir/SLKBase.nsf/1ac66549a21402188625680b0002037e/a3292c17ce8bf0aa8625776c0062b8a3?OpenDocument&amp;ExpandSection=-1&quot;&gt;MustGather: Security Issues&lt;/a&gt; and &lt;a href=&quot;http://www-912.ibm.com/s_dir/SLKBase.nsf/1ac66549a21402188625680b0002037e/6a55b3977b17cc2b862565c2007d4658?OpenDocument&quot;&gt;Using Auditing to Track Spooling Activity&lt;/a&gt; for a couple of the various documents that discourage the use of DSPAUDJRNE for specific analysis.

As for the actual problem, I see a V5R3 document, &lt;a href=&quot;http://www-01.ibm.com/support/docview.wss?uid=nas1f74c243361f6f3bc8625703e005c6fd6&quot;&gt;DSPAUDJRNE Shows Numerous AF K Entries after Upgrading to R530&lt;/a&gt;, that could apply equally well to V5R4. It looks as if adding *JOBCTL to the QTMHHTTP is worth a try in order to verify that it is the problem. If the problem disappears, then it becomes one of seeing if any alternative exists.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>I’m using DSPJRN or DSPAUDJRNE and create a file with it.</i></p>
<p>Use DSPJRN or CPYAUDJRNE &#8212; DSPAUDJRNE is only okay for basic overviews. It should not be used for precise details. See <a href="http://www-912.ibm.com/s_dir/SLKBase.nsf/1ac66549a21402188625680b0002037e/a3292c17ce8bf0aa8625776c0062b8a3?OpenDocument&amp;ExpandSection=-1">MustGather: Security Issues</a> and <a href="http://www-912.ibm.com/s_dir/SLKBase.nsf/1ac66549a21402188625680b0002037e/6a55b3977b17cc2b862565c2007d4658?OpenDocument">Using Auditing to Track Spooling Activity</a> for a couple of the various documents that discourage the use of DSPAUDJRNE for specific analysis.</p>
<p>As for the actual problem, I see a V5R3 document, <a href="http://www-01.ibm.com/support/docview.wss?uid=nas1f74c243361f6f3bc8625703e005c6fd6">DSPAUDJRNE Shows Numerous AF K Entries after Upgrading to R530</a>, that could apply equally well to V5R4. It looks as if adding *JOBCTL to the QTMHHTTP is worth a try in order to verify that it is the problem. If the problem disappears, then it becomes one of seeing if any alternative exists.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gfroehlich</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99554</link>
		<dc:creator>gfroehlich</dc:creator>
		<pubDate>Tue, 29 Nov 2011 16:27:19 +0000</pubDate>
		<guid isPermaLink="false">#comment-99554</guid>
		<description><![CDATA[To use CPYAUDJRNE makes no difference in the result: there is no object or path information ore any other information that gives me a hint on what authority is missing. 

Gabriel]]></description>
		<content:encoded><![CDATA[<p>To use CPYAUDJRNE makes no difference in the result: there is no object or path information ore any other information that gives me a hint on what authority is missing. </p>
<p>Gabriel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rayj1031</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99549</link>
		<dc:creator>rayj1031</dc:creator>
		<pubDate>Tue, 29 Nov 2011 16:05:28 +0000</pubDate>
		<guid isPermaLink="false">#comment-99549</guid>
		<description><![CDATA[Try the CPYAUDJRNE command. 

http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/index.jsp?topic=/cl/cpyaudjrne.htm

This command was added in v5r4m0.  I have not experimented with this command but since it was just released I would expect it to provide the most information.]]></description>
		<content:encoded><![CDATA[<p>Try the CPYAUDJRNE command. </p>
<p><a href="http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/index.jsp?topic=/cl/cpyaudjrne.htm" rel="nofollow">http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/index.jsp?topic=/cl/cpyaudjrne.htm</a></p>
<p>This command was added in v5r4m0.  I have not experimented with this command but since it was just released I would expect it to provide the most information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gfroehlich</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99535</link>
		<dc:creator>gfroehlich</dc:creator>
		<pubDate>Tue, 29 Nov 2011 08:45:52 +0000</pubDate>
		<guid isPermaLink="false">#comment-99535</guid>
		<description><![CDATA[I&#039;m using DSPJRN or DSPAUDJRNE and create a file with it. 

There is only one record with a path information with type A not K, this was possibly a wrong file permission on the socket. The rest has no additional information except the port. 

Is there something that I can do to get more information?

Gabriel]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m using DSPJRN or DSPAUDJRNE and create a file with it. </p>
<p>There is only one record with a path information with type A not K, this was possibly a wrong file permission on the socket. The rest has no additional information except the port. </p>
<p>Is there something that I can do to get more information?</p>
<p>Gabriel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99515</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Mon, 28 Nov 2011 23:42:57 +0000</pubDate>
		<guid isPermaLink="false">#comment-99515</guid>
		<description><![CDATA[The &quot;*INSTR&quot; part should be saying that a machine instruction signaled the violation. The &quot;*N/*N&quot; part is for the Object Library and Object Name subfields; but I wouldn&#039;t expect those to have anything but &quot;*N&quot; in them for this.

What would be more useful would be anything in the path or folder fields farther out in the AF format. What are you using to view the entries?

I&#039;ve never needed any authorities for general sockets work. Zend/PHP runs on a couple of our systems with no problems, though we&#039;re not accessing LDAP through it.

Tom]]></description>
		<content:encoded><![CDATA[<p>The &#8220;*INSTR&#8221; part should be saying that a machine instruction signaled the violation. The &#8220;*N/*N&#8221; part is for the Object Library and Object Name subfields; but I wouldn&#8217;t expect those to have anything but &#8220;*N&#8221; in them for this.</p>
<p>What would be more useful would be anything in the path or folder fields farther out in the AF format. What are you using to view the entries?</p>
<p>I&#8217;ve never needed any authorities for general sockets work. Zend/PHP runs on a couple of our systems with no problems, though we&#8217;re not accessing LDAP through it.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gfroehlich</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99479</link>
		<dc:creator>gfroehlich</dc:creator>
		<pubDate>Mon, 28 Nov 2011 08:26:25 +0000</pubDate>
		<guid isPermaLink="false">#comment-99479</guid>
		<description><![CDATA[In the audit entries are no object information: *INSTR/*N/*N
There is one entry of thousands that shows a path information. This points to the socket used for communication between native apache and PASE PHP jobs. 

The reason why I&#039;m thinking that the entries happen at opening remote socket connections, are the remote ports  in the audit log entries: 389=LDAP, 80=HTTP (SOAP requests) and 10137=ZendServer remote debug. 

Is it possible that a bind to a remote socket needs *IOSYSCFG? 

Gabriel]]></description>
		<content:encoded><![CDATA[<p>In the audit entries are no object information: *INSTR/*N/*N<br />
There is one entry of thousands that shows a path information. This points to the socket used for communication between native apache and PASE PHP jobs. </p>
<p>The reason why I&#8217;m thinking that the entries happen at opening remote socket connections, are the remote ports  in the audit log entries: 389=LDAP, 80=HTTP (SOAP requests) and 10137=ZendServer remote debug. </p>
<p>Is it possible that a bind to a remote socket needs *IOSYSCFG? </p>
<p>Gabriel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-a-special-authority-needed-for-active-socket-connections/#comment-99446</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Sat, 26 Nov 2011 07:20:06 +0000</pubDate>
		<guid isPermaLink="false">#comment-99446</guid>
		<description><![CDATA[For AF entries, detail type K means &quot;An attempt was made to perform an operation for which the user did not have the required special authority.&quot;

I don&#039;t have a Zend/PHP configuration to experiment with for now, but I wouldn&#039;t be comfortable adding any special authority to any server profile in any case.

What objects show up in audit entries?

Tom]]></description>
		<content:encoded><![CDATA[<p>For AF entries, detail type K means &#8220;An attempt was made to perform an operation for which the user did not have the required special authority.&#8221;</p>
<p>I don&#8217;t have a Zend/PHP configuration to experiment with for now, but I wouldn&#8217;t be comfortable adding any special authority to any server profile in any case.</p>
<p>What objects show up in audit entries?</p>
<p>Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/8 queries in 0.013 seconds using memcached
Object Caching 381/382 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-20 14:24:44 -->