We are currently cleaning up the security related objects on our iSeries and noticed that user profiles are owned by a variety of users. The question came up then - who should own the non-IBM user profiles? Has anyone else addressed this question and how did you decide who owns which profile?
Software/Hardware used:
ASKED:
November 16, 2005 1:16 PM
UPDATED:
November 20, 2009 6:28 AM
All of our iSeries admins belong to one group profile, and everything they create under their admin profile (including day-to-day profiles they create) is owned by that group. That gives visibility of all such created profiles to all members of the admin group, such that they are all able to change profiles, remove them, etc. without having to have *ALLOBJ and *SECOFR authority. Auditors are quite OK with this setup as it prevents the need to give all the admin types all the god-like special authorities.
For what it’s worth, all of ours are owned by QSYS.
For what it’s worth, all of ours are owned by QSYS.