Home > Ask the AS/400 Experts > iSeries Security Questions & Answers > Establishing user accountability in AS400
Ask The iSeries 400 Expert: Questions & Answers
EMAIL THIS

Establishing user accountability in AS400

Carol Woodbury EXPERT RESPONSE FROM: Carol Woodbury

Pose a Question
Other iSeries 400 Categories
Meet all iSeries 400 Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 August 2007
If three administrators need to use QSECOFR, what is the best way to audit their activities? In other words, what can be done in AS400 to establish user accountability so that we know which one of the three admins logged on and used this powerful user profile?


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
iSeries Security
Changing password security levels and upgrading operating systems on the IBM i
Determine the value of parameter UPPWEI in the DSPUSRPRF field
Define journal code value "K"
Modify content within a journal receiver file
Change password parameters on the AS/400 without deactivating user's passwords
Prevent insiders with *READ or *USE access from circumventing object authority on IBM i
Prevent insiders from obtaining user ids and passwords on the IBM i
Change the IBM i system to allow only certain types of SSL protocol versions
Authorize a specific user to select files in a separate library
Allow a user to view a library prod without granting full access to all data

Profile and ID control on System i
Is your AS/400 secure?: How a hacker could get valuable information from your system
A guide to System i security, part 2: Landing and establishing access
New password-control security features for i5/OS V6R1
Script kiddie FTP attacks on System i
iSeries user accountability help from Search400.com reader
Establish strong OS security to ward off FTP hackers
Gaining control over use of SST profiles
Preventing password hacking
How to make secure iSeries connections
Maintaining user profiles boosts iSeries security

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


If users require *ALLOBJ, they should be given *ALLOBJ in their own profiles or made a member of QSECOFR. This way, the i5/OS audit journal entries will log the actual user performing each function. (These users, along with the QSECOFR profile, should be audited. In other words, turn on *CMD auditing by running the CHGUSRAUD command.)

The only time they should be signing on with QSECOFR is when the actual profile "QSECOFR" is required, such as when upgrading the system or when an non-security-conscious vendor inappropriately requires you to be signed on with "QSECOFR" to install their product. For most i5/OS functions, it is sufficient to be signed on with a profile that has the required special authorities (such as *ALLOBJ and *SECADM).

In the rare case that the actual QSECOFR profile is required, there is virtually no way to guarantee that you can determine who is using the profile when more than one user knows the QSECOFR password; therefore, you will want to very tightly control who has the password and when it is used, and change it immediately.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



iSeries Networking - Printing, Remote Access, TCP/IP
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts