Home > Ask the AS/400 Experts > iSeries Security Questions & Answers > Understanding the user class of a profile
Ask The iSeries 400 Expert: Questions & Answers
EMAIL THIS

Understanding the user class of a profile

Carol Woodbury EXPERT RESPONSE FROM: Carol Woodbury

Pose a Question
Other iSeries 400 Categories
Meet all iSeries 400 Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 26 July 2005
If a user has the QSECOFR class assigned to them but has the special authority *SECADM removed, does the user still have *SECADM abilities because they are assigned to the QSECOFR class?

>
A lot of confusion surrounds the User class of a profile. I don't know how this idea started, but many people are under the impression that the User class carries more meaning than it does. OS/400 only uses User class for three things on the system 1- to default the special authorities given to the profile when the profile is created, 2- to determine what OS/400 menu options the user sees and 3- to determine how to adjust the special authorities for users when moving from security level 20 to levels 30, 40 or 50 (at security level 20, all profiles, by default, are given *ALLOBJ and *SAVSYS, so OS/400 removes these based on the User class when the system level changes.)

A user can be in the *SECOFR user class and have no special authorities or the user can be in the *USER user class and have all of the special authorities. It really doesn't matter. OS/400 never checks the User class when it is looking to see if a user has sufficient authority to access an object or is looking to see if a user has a specific special authority.

That said, let's look at your question. You ask if a user is assigned to the "QSECOFR class" whether they still have *SECADM capabilities because they are in this class. First a bit of clarification -- there is no "QSECOFR class" so I'm guessing that you mean the *SECOFR User class. Next, as I explained above, OS/400 is going to look to see if the user has *SECADM special authority -- it is not going to look at the user profile's User class. So despite the fact that the user is in the *SECOFR User class, the user does not have *SECADM capabilities.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
iSeries Security
Changing password security levels and upgrading operating systems on the IBM i
Determine the value of parameter UPPWEI in the DSPUSRPRF field
Define journal code value "K"
Modify content within a journal receiver file
Change password parameters on the AS/400 without deactivating user's passwords
Prevent insiders with *READ or *USE access from circumventing object authority on IBM i
Prevent insiders from obtaining user ids and passwords on the IBM i
Change the IBM i system to allow only certain types of SSL protocol versions
Authorize a specific user to select files in a separate library
Allow a user to view a library prod without granting full access to all data

Security
Monitoring QSECOFR
Use caution when providing access to file shares
Top advice on securing your iSeries
Top 10 security tips
20 ways to improve your system's security
iSeries immune to Mydoom? Sort of
Tightening iSeries security
Understand all your trace options, including the latest one -- STRTRC
DDM and limit capabilities? I don't think so
A security no-brainer: Analyze default passwords

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



iSeries Networking - Printing, Remote Access, TCP/IP
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts