<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Need to prevent user from creating more than one client access Workstation icon on a PC.</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Jun 2013 16:59:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78280</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Thu, 17 Jun 2010 20:36:56 +0000</pubDate>
		<guid isPermaLink="false">#comment-78280</guid>
		<description><![CDATA[&lt;i&gt;Assign the user a specific wrkstation name like WS101 .&lt;/i&gt;

This is an example of where I was going with the suggestion that new sessions (*DEVDs) might be restricted from use on the AS/400. It might not matter if new .WS files are created if the they result in *DEVDs that can&#039;t be used.

Note, however, that restricting a user to a particular *DEVD has no effect on whether the associated .WS might allow VB macros, which was the point of the question. You can have any number of .WS files that all attach to the same *DEVD.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>Assign the user a specific wrkstation name like WS101 .</i></p>
<p>This is an example of where I was going with the suggestion that new sessions (*DEVDs) might be restricted from use on the AS/400. It might not matter if new .WS files are created if the they result in *DEVDs that can&#8217;t be used.</p>
<p>Note, however, that restricting a user to a particular *DEVD has no effect on whether the associated .WS might allow VB macros, which was the point of the question. You can have any number of .WS files that all attach to the same *DEVD.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bigmac46</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78264</link>
		<dc:creator>bigmac46</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:24:14 +0000</pubDate>
		<guid isPermaLink="false">#comment-78264</guid>
		<description><![CDATA[Assign the user a specific wrkstation name like WS101 .  
create a CLLE and have the user profile changed to have this as initial program for user. In it check workstation and IP address . iF NOT AS EXPECTED DO NOT ALLOW TO SIGNON. 
IF OK continue to what would have been the initial signon program before.
IF user has more than 1 signon do same for all..]]></description>
		<content:encoded><![CDATA[<p>Assign the user a specific wrkstation name like WS101 .<br />
create a CLLE and have the user profile changed to have this as initial program for user. In it check workstation and IP address . iF NOT AS EXPECTED DO NOT ALLOW TO SIGNON.<br />
IF OK continue to what would have been the initial signon program before.<br />
IF user has more than 1 signon do same for all..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: djac</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78224</link>
		<dc:creator>djac</dc:creator>
		<pubDate>Wed, 16 Jun 2010 13:50:47 +0000</pubDate>
		<guid isPermaLink="false">#comment-78224</guid>
		<description><![CDATA[Given the various loopholes that have pointed out, I am wondering if the only way to try an resolve this is to make it a disciplinary issue?

Get it formally agreed that it is policy that ALL access to the system is ONLY via the provided desktop icon. Any staff not complying can be subjected to your company&#039;s normal disciplinary procedure - informal warning - written formal warning - sanctions including dismissal, however it goes.

Sounds a bit harsh? maybe, but it would focus the users&#039; minds!]]></description>
		<content:encoded><![CDATA[<p>Given the various loopholes that have pointed out, I am wondering if the only way to try an resolve this is to make it a disciplinary issue?</p>
<p>Get it formally agreed that it is policy that ALL access to the system is ONLY via the provided desktop icon. Any staff not complying can be subjected to your company&#8217;s normal disciplinary procedure &#8211; informal warning &#8211; written formal warning &#8211; sanctions including dismissal, however it goes.</p>
<p>Sounds a bit harsh? maybe, but it would focus the users&#8217; minds!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: johnsonmumbai</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78213</link>
		<dc:creator>johnsonmumbai</dc:creator>
		<pubDate>Wed, 16 Jun 2010 07:24:45 +0000</pubDate>
		<guid isPermaLink="false">#comment-78213</guid>
		<description><![CDATA[The workstations are being created using pcsws.exe file which is called the windows Start and Run commands.

Johnson]]></description>
		<content:encoded><![CDATA[<p>The workstations are being created using pcsws.exe file which is called the windows Start and Run commands.</p>
<p>Johnson</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78185</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 15 Jun 2010 17:50:51 +0000</pubDate>
		<guid isPermaLink="false">#comment-78185</guid>
		<description><![CDATA[&lt;i&gt;...remove that menu option and rename the programs that run behind the ‘Emulator -&gt; Multiple sessions’ and ‘Emulator -&gt; Start or Configure Sessions’ options.&lt;/i&gt;

That prevents them from running menu options. It doesn&#039;t prevent them from simply using copy/paste for a .WS file and making any changes they want to the copy. Notepad is all that&#039;s needed.

However -- &quot;Defense in depth.&quot; It might be worthwhile just to increase the obstacles by an extra layer.

In a sense, the problem becomes one of having the clever user digging deeper to learn more. It&#039;s not unheard of to have users be more knowledgeable than AS/400 administrators about Windows.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>&#8230;remove that menu option and rename the programs that run behind the ‘Emulator -&gt; Multiple sessions’ and ‘Emulator -&gt; Start or Configure Sessions’ options.</i></p>
<p>That prevents them from running menu options. It doesn&#8217;t prevent them from simply using copy/paste for a .WS file and making any changes they want to the copy. Notepad is all that&#8217;s needed.</p>
<p>However &#8212; &#8220;Defense in depth.&#8221; It might be worthwhile just to increase the obstacles by an extra layer.</p>
<p>In a sense, the problem becomes one of having the clever user digging deeper to learn more. It&#8217;s not unheard of to have users be more knowledgeable than AS/400 administrators about Windows.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: djac</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78173</link>
		<dc:creator>djac</dc:creator>
		<pubDate>Tue, 15 Jun 2010 14:29:31 +0000</pubDate>
		<guid isPermaLink="false">#comment-78173</guid>
		<description><![CDATA[How are these additional session file being created? If it is through the &#039;Start -&gt; Programs -&gt; IBM iSeries Access for Windows&#039; method, then remove that menu option and rename the programs that run behind the &#039;Emulator -&gt; Multiple sessions&#039; and &#039;Emulator -&gt; Start or Configure Sessions&#039; options.

The users should still have access to data transfer etc. through the buttons on theClient Access menu bar....]]></description>
		<content:encoded><![CDATA[<p>How are these additional session file being created? If it is through the &#8216;Start -&gt; Programs -&gt; IBM iSeries Access for Windows&#8217; method, then remove that menu option and rename the programs that run behind the &#8216;Emulator -&gt; Multiple sessions&#8217; and &#8216;Emulator -&gt; Start or Configure Sessions&#8217; options.</p>
<p>The users should still have access to data transfer etc. through the buttons on theClient Access menu bar&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: johnsonmumbai</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78168</link>
		<dc:creator>johnsonmumbai</dc:creator>
		<pubDate>Tue, 15 Jun 2010 11:21:44 +0000</pubDate>
		<guid isPermaLink="false">#comment-78168</guid>
		<description><![CDATA[&lt;aPI]
DDE/HLL=N
PcCodePage=1252

We would want to control the above parameters within the workstation file.

By default the above 3 lines do not exist which means ie DDE/HLL = Y when ever a new workstation is created.

Johnson]]></description>
		<content:encoded><![CDATA[<p><aPI]<br />
DDE/HLL=N<br />
PcCodePage=1252</p>
<p>We would want to control the above parameters within the workstation file.</p>
<p>By default the above 3 lines do not exist which means ie DDE/HLL = Y when ever a new workstation is created.</p>
<p>Johnson</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78152</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Tue, 15 Jun 2010 00:35:12 +0000</pubDate>
		<guid isPermaLink="false">#comment-78152</guid>
		<description><![CDATA[&lt;i&gt;...fresh set of workstation with default parameters...&lt;/i&gt;

Can you describe the parameters that you need to control?

There are two general possible directions.

First, you can try to prevent the creation of new workstation sessions on the PC. I don&#039;t have a good idea how that might be done.

But second, you might be able to control whether or not a new workstation session can be used on your AS/400. The example from Slateken about QAUTOCFG is one potential idea along that line, but there might be other thoughts that are more useful and more precise. It&#039;s possible that the parameters you want to protect will give a clue.

Even if new sessions are created, maybe they can&#039;t be used. That might be a sufficient resolution to your problem. Different parameters might cause a different workstation type -- you might be able to reject those when they try to connect.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>&#8230;fresh set of workstation with default parameters&#8230;</i></p>
<p>Can you describe the parameters that you need to control?</p>
<p>There are two general possible directions.</p>
<p>First, you can try to prevent the creation of new workstation sessions on the PC. I don&#8217;t have a good idea how that might be done.</p>
<p>But second, you might be able to control whether or not a new workstation session can be used on your AS/400. The example from Slateken about QAUTOCFG is one potential idea along that line, but there might be other thoughts that are more useful and more precise. It&#8217;s possible that the parameters you want to protect will give a clue.</p>
<p>Even if new sessions are created, maybe they can&#8217;t be used. That might be a sufficient resolution to your problem. Different parameters might cause a different workstation type &#8212; you might be able to reject those when they try to connect.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: johnsonmumbai</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-78126</link>
		<dc:creator>johnsonmumbai</dc:creator>
		<pubDate>Mon, 14 Jun 2010 09:42:30 +0000</pubDate>
		<guid isPermaLink="false">#comment-78126</guid>
		<description><![CDATA[Hi Tom,

The objective is to prevent users from creating another workstation on his pc as earlier workstation parameters are saved and we do not want user to have fresh set of workstation with default parameters as parameters such as within API section to be would get modified.

Hope you have understood.

Johnson]]></description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>The objective is to prevent users from creating another workstation on his pc as earlier workstation parameters are saved and we do not want user to have fresh set of workstation with default parameters as parameters such as within API section to be would get modified.</p>
<p>Hope you have understood.</p>
<p>Johnson</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tomliotta</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/need-to-prevent-user-from-creating-more-than-one-client-access-workstation-icon-on-a-pc/#comment-77413</link>
		<dc:creator>tomliotta</dc:creator>
		<pubDate>Fri, 21 May 2010 21:32:38 +0000</pubDate>
		<guid isPermaLink="false">#comment-77413</guid>
		<description><![CDATA[&lt;i&gt;Mr. Pesky Conniving User can now TRY to create a new client access session, but alas, will not be able to connect …&lt;/i&gt;

Unless, of course, they connect to WS130 or WS129 or any of the other devices that already exist.

Not only do system values such as QAUTOCFG need to be disabled, but a security structure needs to be implemented and managed to assign and control authorities for all of the various *DEVDs (and device *MSGQs) that probably already exist so that each user can use only appropriate devices.

Tom]]></description>
		<content:encoded><![CDATA[<p><i>Mr. Pesky Conniving User can now TRY to create a new client access session, but alas, will not be able to connect …</i></p>
<p>Unless, of course, they connect to WS130 or WS129 or any of the other devices that already exist.</p>
<p>Not only do system values such as QAUTOCFG need to be disabled, but a security structure needs to be implemented and managed to assign and control authorities for all of the various *DEVDs (and device *MSGQs) that probably already exist so that each user can use only appropriate devices.</p>
<p>Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.035 seconds using memcached
Object Caching 393/399 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-06-19 17:37:29 -->