 |
| ADVICE: |
| >> |
The danger of indiscriminately assigning special authorities
TIP :This article explains the special authorities and points out the main exposures if they are not assigned judiciously. |
| >> |
Auditing user profile storage
TIP :Find out whose profiles are taking up a lot of storage space and why. |
| >> |
Reviewing *PUBLIC authority
TIP :Be sure to check the *PUBLIC default security setup so that the configuration doesn't override all your other security ... |
| >> |
Controlling access to spool files
TIP :Viewing spool files can be a helpful and convenient, but it is best to limit access to spool files for security reasons. This ... |
| >> |
Controlling access to spool files -- Part 2
TIP :This tip covers three parameters that are associated with OS/400 output queues that can extend the level of control you have ... |
| >> |
Granting OS/400 users special authorities
ASK THE EXPERTS :
I remember the old VAX/VMS operating system that allowed us to give an individual certain "types" of security -- for ... |
| >> |
Limiting user authority in Client Access
ASK THE EXPERTS :User profiles are assigned a group on our iSeries, and the group has object authority to the data files. What data they can ... |
| >> |
Prevent access for a user with *ALLOBJ special authority
ASK THE EXPERTS :Is there a way to prevent a user with *ALLOBJ special authority from accessing specific files/programs until I can get the ... |
| >> |
Understanding the user class of a profile
ASK THE EXPERTS :If a user has the QSECOFR class assigned to them but has the special authority *SECADM removed, does the user still have ... |
| >> |
See the users with *change or *all authority
ASK THE EXPERTS :
Is there a way to see the users with "change" or "all authority" on objects in a library? The library has 200 objects ... |
| >> |
Things about *ALLOBJ special authority to be aware of
ASK THE EXPERTS :We have been discovering many quirks for profiles with *ALLOBJ special authority. Specifically, we are finding that operators ... |
| >> |
Possible to restrict *SAVSYS special authority?
ASK THE EXPERTS :Some users have *SAVSYS special authority. Is it possible to restrict them from saving or restoring over some highly ... |
| >> |
How much authority should programmers have?
ASK THE EXPERTS :What has been your opinion and experience in giving programmers access to production libraries to fix critical production ... |
| >> |
What's adopted authority all about?
ASK THE EXPERTS :I'm in search of adopted authority information. Do you know where I can find detailed information? |
| >> |
Restrict authority in the root directory
ASK THE EXPERTS :How can security be setup so that folders/files cannot be
added to the root of the IFS unless you have specific
... |
| >> |
Revoking *ALLOBJ authority
ASK THE EXPERTS :
On our iSeries, several users have *ALLOBJ authority. I want to revoke that without annoying these people with ... |
| >> |
Sufficient authority, but not *ALLOBJ authority
ASK THE EXPERTS :
I have a user that adds queries to other user's libraries on a regular basis.
I've given her a menu item with the ... |
| >> |
Prevent a user from deleting the DFU Audit Log?
ASK THE EXPERTS :How can I prevent the user, who has an UPDDTA authority, from deleting the DFU Audit Log?
|
| >> |
Limiting user profiles
ASK THE EXPERTS :
I would like to give my help desk staff access to change user profiles, but I don't want the operator to change the ... |
| >> |
Authorities you need to manage user profiles
ASK THE EXPERTS :I am replacing a programmer and was recently granted *SECADM access.
When working with user profiles, however, I only see a ... |