Home > AS/400 Tips > iSeries administrator tips > Security Tools can help manage your system security
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ISERIES ADMINISTRATOR TIPS

Security Tools can help manage your system security


Ron Turull
01.05.2005
Rating: -4.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



Ron Turull

Security Tools provides you with a generous set of utilities that can help you manage most areas of security on your iSeries. The tools are divided into two groups. The interactive tools contain tools for managing security attributes related to user profiles and system security auditing. The reporting tools contain a number of reports that can help you profile all sorts of things that can lead to security problems. For instance, there is a report that lists all programs that adopt the owner's authority.

Accessing and using the interactive tools
The easiest way to access the security tools is via the SECTOOLS menu. Type "GO SECTOOLS" on any command line, and if you are authorized to access them, you will be able to use any of the security tools listed.

More Information

To activate a tool, simply type its menu option number and press Enter. You will be prompted for any additional information. For example, to see a list of user profiles due to expire in the future, type a "7" (Display expiration schedule) and press Enter. The system will prompt you for an output option (display or print). Press Enter again after making the appropriate selection.

How to access the reporting tools
You have a choice of three methods when it comes to creating security reports:

  1. Interactively. You can run any of the numerous reports from the SECTOOLS menu. The reports are listed on this menu after the interactive tools. Many of the reports are fairly long-running, so use this method with caution.
  2. Batch mode. To produce a report in batch mode, use the SECBATCH menu. The reports are listed in the same order on this menu as they are on the SECTOOLS menu.
  3. Scheduled batch mode. This option is like the previous option except you can schedule the report to run during off hours. Again, use the SECBATCH menu to schedule a report. The scheduled reports are listed after the regular batch reports on this menu.

Tip: You can access the SECBATCH menu from the SECTOOLS menu by using menu option 20 (Submit or schedule security reports to batch).

"Change only" reports save you time
Most of the reports have a Change report only option that can save you a lot of time. Each time you run a report, the system saves related information in a system file. When you choose the Change report only option, the system uses the information in the file to produce a report that reflects only the things that have changed since the last time the report was produced. The system also updates the system file with the current information.

For example, the Adopting objects report produces information on programs and service programs that use adopted authority (i.e., run using the authority of program's owner). When you choose the Change report only option for this report, the produced report will show only the programs and service programs that have been created or changed since the last time the report was run.

Note: When you run a complete report, the associated system file is completely replaced with the new information. If you choose the Change report only option but have never run the report before, the report will run as though you choose a complete report. That is, since there is no baseline information in the system file, the system will produce a complete report.

Security tools lack sophistication
As mentioned above, many of the reports save information in a system file to support the Change report only option. Unfortunately, that means only one "copy" of any given tool can run at any given moment. In and of itself, that is not a major drawback. The problem is that you have to manually ensure it.

You can run different tools at the same time. However, because the documentation is not clear about interaction among different tools, it is probably best to run only one tool at a time.

Also, the security tools lack the "work with" user interface of other operating system features. For example, the security tools lack a single screen that lists the user profiles scheduled for activation and expiration and that provides you with options that allow you to make modifications right there. Instead, you have to request the list of profiles scheduled for either activation or expiration. If you need to make changes, you must first exit the list and then run individual commands to effect the changes.

Finally, IBM implemented the options on the SECBATCH menu by simply combining the associated command and a SBMJOB command. But they did not specify any other parameters on the SBMJOB command, such as the Job name, to help identify the job. So, for example, if you don't want a bunch of jobs all named QDFTJOBD (or some other name), make sure you change the Job name parameter when the SBMJOB command is prompted. Note: This drawback does not exist for reports submitted for Scheduled batch mode because the Job name parameter is a required parameter on the ADDJOBSCDE command.

TCP/IP security not a part of Security Tools
The one major feature missing from the Security Tools is a way to configure TCP/IP security. This is unfortunate because most of the iSeries world uses TCP/IP in one way or another. You can use the CFGTCP (Configure TCP/IP) command to help you with TCP/IP security.

Documentation
The security tools are documented in the manual Tips and Tools for Securing Your AS/400-iSeries (SC41-5300). This manual is a good source for examples on how to use the tools.

-----------------------------------
About the author: Ron Turull is editor of Inside Version 5. He has more than 20 years experience programming for and managing AS/400-iSeries systems.


Rate this Tip
To rate tips, you must be a member of Search400.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
iSeries system and application security
Developing a security incident response system for System i
Setting up security for programmers on IBM i
Blocking AS/400 DB2 users
Trouble accessing IFS path from Win2k3 server
Checking in on your IBM i authorization lists
Strategies for securing IBM i production files
Changing password security levels and upgrading operating systems on the IBM i
Determine the value of parameter UPPWEI in the DSPUSRPRF field
Define journal code value "K"
Modify content within a journal receiver file

Systems Management Tools
Strategies for securing IBM i production files
Legacy AS/400 and new IBM i products both featured at COMMON
Translating Linux for IBM i admins: User profile commands
AS/400 lessons from the past, present, and future: A holiday tale
How to: Monitoring job activity on the AS/400
Checking if a local port is used by another job on AS/400
How to: Reduce the percentage of ASP used on the AS/400
Changing BRMS configurations for new naming conventions for i5
AS/400 system values quiz
DAYSPAST CLLE program for AS/400: Compares object creation date with today's date

iSeries administrator tips
Researching high availability for your System i shop
Translating Linux for IBM i admins: Using GUI to make it easy
Translating Linux for IBM i admins: Working with jobs and networking
OpenOffice: What to know before making the transition from Microsoft Office
OpenOffice: An enterprise open source solution
Database performance comparisons on IBM i
Translating Linux for IBM i admins: User profile commands
Modern System i reports using Client Access
Tips for installing Lotus Domino server on a System i partition
The iSeries Blog has a new home on IT Knowledge Exchange

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
midrange  (Search400.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



iSeries Security - Security Tools, Physical Security and System Security
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts