Home > Ask the AS/400 Experts > iSeries i5/OS and OS/400 Questions & Answers > Limit command line access
Ask The iSeries 400 Expert: Questions & Answers
EMAIL THIS

Limit command line access

Ken Graap EXPERT RESPONSE FROM: Ken Graap

Pose a Question
Other iSeries 400 Categories
Meet all iSeries 400 Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 November 2004
Due to a recent Sarbanes-Oxley (SOX) audit we need to limit command line access from our users. Many of the legacy a/r, o/e menus contain a call to QCMDEXC for basic commands such as WRKSPLF, WRKSBMJOB. Do you have a suggestion to accomplish this without changing each menu?

>
EXPERT RESPONSE
There is an attribute associated with a user profile called:

LMTCPB - Limit capabilities

Its use is explained quite well in OS400 Command HELP...

Limit capabilities (LMTCPB) - Help

Specifies the limit to which the user can control the program, menu, current library, and the ATTN key handling program values. It also determines whether the user can run commands from a command line. This parameter is ignored when the security level is 10.

Note: When creating or changing other users' user profiles, you cannot specify values on this parameter that grant greater capabilities to other users than your own user profile grants to you. For example, if *PARTIAL is specified for the Limit capabilities (LMTCPB) parameter in your user profile, you can specify *PARTIAL or *YES for another user. You cannot specify *NO for another user.

*NO

The program, menu, and current library values can be changed when the user signs on the system. Users may change the program, menu, current library, or ATTN key handling program values in their own user profiles with the Change Profile (CHGPRF) command. Commands can be run from a command line.

*PARTIAL

The program and current library cannot be changed on the sign-on display. The menu can be changed and commands can be run from a command line. A user can change the menu value with the Change Profile (CHGPRF) command. The program, current library, and the ATTN key handling program cannot be changed using the CHGPRF command.

*YES

The program, menu, and current library values cannot be changed on the sign-on display. Commands cannot be run when issued from a command line or by selecting an option from a command grouping menu such as CMDADD, but can still be run from a command entry screen.

The user cannot change the program, menu, current library, or the ATTN key program handling values by using the CHGPRF command.

Once you have set a user profile to LMTCPB(*YES) the only way a command can be executed from a command line is if the command's attribute ALWLMTUSR (Allow limited users) is set to *YES.

Allow limited users (ALWLMTUSR) - Help

Specifies whether the command can be entered from the command line on a menu by a user whose profile is set for limited capabilities (the LMTCPB keyword on the Create User Profile (CRTUSRPRF) and Change User Profile (CHGUSRPRF) commands).

*SAME

The limited user authority does not change.

*NO

This command cannot be entered from the command line on a menu by a user whose profile is set for limited capabilities.

*YES

This command can be entered from the command line on a menu by a user whose profile is set for limited capabilities.

Some IBM command have this value set by default, for example DSPJOB, but most don't. Do a DSPCMD DSPJOB to see "Allow limited user . . . . . . . . . . : *YES".

Using these two attributes you should be able to easily satisfy your Sarbanes/Oxley audit requirements.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Past Releases
iSeries i5/OS: Top 10 Q&As
iSeries i5/OS: Top 10 Q&As
Error message within the printer file
How often are message queues cleared?
Connect the dots: Get your iSeries servers talking to one another
Embedding SQL into RPG LE programs
In search of a table that shows system & O/S release compatibility
V5R3 view disk IOA cache battery expiration
New option within the WRKSYSACT command
See the users with *change or *all authority

Upgrading
System i blades not selling yet, it seems
ISV lures art company away from HP to iSeries
iSeries i5/OS: Top 10 Q&As
iSeries i5/OS: Top 10 Q&As
IBM cuts prices for System i Enterprise, HA servers
Readers respond to pending V5R4 release
SAP-friendly iSeries lowers ERP barriers
In search of a table that shows system & O/S release compatibility
New option within the WRKSYSACT command
See the users with *change or *all authority

Installation
iSeries i5/OS: Top 10 Q&As
iSeries i5/OS: Top 10 Q&As
New option within the WRKSYSACT command
See the users with *change or *all authority
Copy a spoolfile (report) into the IFS as a .txt file
Improve Windows Disaster Recovery & High Availability w/ iSeries & i5
Upgrade from V5R1 to V5R3 and license validation
Set up journals
Moving Beyond Tape Backup & Recovery: Journaling-Free iSeries DR
Creating new user profiles on the iSeries
Installation Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AS/400  (Search400.com)
i5/OS  (Search400.com)
iSeries  (Search400.com)
OS/400  (Search400.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 1999 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts