Home > Ask the AS/400 Experts > Questions & Answers > Securing a library
Ask The iSeries 400 Expert: Questions & Answers
EMAIL THIS

Securing a library

Carol Woodbury EXPERT RESPONSE FROM: Carol Woodbury

Pose a Question
Other iSeries 400 Categories
Meet all iSeries 400 Experts
Become an Expert for this site
>
QUESTION POSED ON: 03 October 2003
My company uses a four-tier validation environment to control software change (dev., test, validation and controlled). Some programmers need *ALLOBJ, yet corporate policy refuses it in order to protect the validation and controlled environments -- fair enough. How can you secure a library in such a way that an *ALLOBJ programmer cannot access it?

>

You can't. Some people would attempt to control the programmer by removing the *ALLOBJ from the programmer, placing the programmer in a group profile and giving the *ALLOBJ to the group. Then you can grant the programmer *EXCLUDE authority to the library, prohibiting him or her from accessing it. The problem with that approach is that you have to secure many, many interfaces to ensure they can't get around this roadblock. For example, you'd have to exclude the programmer from all the profiles that are allowed to work with the library or else they could submit a job to run under one of those profiles. You'd have to secure the programmer from being able to create a program that adopts a profile that has authority to work with the library. Practically speaking, it is impossible to control access to a library when a user has *ALLOBJ -- even through a group profile.

A different approach to take might be to create tools for the change management process that adopt a powerful profile and enable the functions for which the programmers need *ALLOBJ. That way, the programmers can do their job but not be given *ALLOBJ. This should satisfy your corporate policy as well.

==================================
MORE INFORMATION ON THIS TOPIC
==================================

The Best Web Links: tips, tutorials and more.

Search400's targeted search engine: Get relevant information on security.

Ask your systems management questions--or help out your peers by answering them--in our live discussion forums.

Check out this Search400.com Featured Topic: Top ten security tips


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



iSeries Networking - Printing, Remote Access, TCP/IP
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts