Home > AS/400 Tips > iSeries security tips > System i security configuration: Restoring
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ISERIES SECURITY TIPS

System i security configuration: Restoring


Rich Loeber
02.06.2007
Rating: -4.71- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Rich Loeber
Once you've got your system backed up, including all of the security information, what's the best way to make sure that all of that security information is restored correctly when you have to do a full system restore? Missing something or getting things in the wrong sequence could result in your objects being restored without the security configuration that you want.

More Information

First, you will need to plan the sequence of events in your restore operation. For security to come out right, you should always restore your saved user profiles first. The second task is then to restore the objects to your system. Lastly, once the profiles and objects have all been restored, you should restore the private authorities to objects.

Let's take a look at how to accomplish each of these steps in a way the makes certain that your security settings are all preserved. As a safeguard, make sure you have access to the password for the QSECOFR profile on the system being restored. You should have access to the current password and the password being restored. If you have any serious security issues during the restore, you may have to logon as QSECOFR as a recovery option, so having access to these passwords may become critical.

First, to restore your saved user profiles, use the Restore User Profiles (RSTUSRPRF) command. If you are restoring all user profiles, you should be aware that all settings for each profile will be based on the saved version of that profile. If any changes have been made to a profile and you are restoring to the same system, those changes will be lost. Also, make sure that the user profile being used to do the restore has both all object (*ALLOBJ) and security administrator (*SECADM) special authorities. Otherwise, any profiles being restored with *ALLOBJ special authority could have that authority stripped during the profile restore operation. This will not affect critical IBM Q profiles, in case you're worried.

Once your user profiles are successfully restored, the next step is to get your objects restored. You can use any of the following commands to restore objects on your system:

  • Restore Library (RSTLIB)
  • Restore Object (RSTOBJ)
  • Restore Configuration (RSTCFG)
  • Restore Object (RST) - for objects in the IFS
  • Restore Document Lib Object (RSTDLO) - for objects in shared folders (QDLS)

    When restoring objects, be careful how you use the "Allow object differences" (ALWOBJDIF) parameter. If you attempt to restore an object that already exists on the system and the object being restored is owned by a different profile than that being restored, the allow object differences command setting of *NONE will result in the object not being restored. If you use a value of *ALL, then the object will be restored and the system owner will be preserved.

    Also, you need to be aware that there are special considerations for public authority and authorization list values during object restores. Generally, if an object is being restored that already exists on the system; the current object settings are preserved rather than applying those from the saved object. For objects secured by authorization lists, the ALWOBJDIF parameter can result in objects not being restored when there is a difference between the current value and that being restored. There is a thorough discussion of what is restored and not restored in the Security Reference Manual, Chapter 8. Check on the issues of private authorities, object auditing, authority holders and more for these considerations.

    To restore authorities, it is recommended that you run the Restore Authority (RSTAUT) command after all objects have been restored. This will rebuild the object authorities in the user profiles. Your restore will not be complete until this step is done.

    ---------------------------
    About the author: Rich Loeber is president of Kisco Information Systems Inc. in Saranac Lake, N.Y. The company is a provider of various security products for the iSeries market.


    Rate this Tip
    To rate tips, you must be a member of Search400.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    iSeries security tips
    Security considerations for IBM i backups
    Developing a security incident response system for System i
    Tracking remote access users on System i
    Setting up security for programmers on IBM i
    Controlling remote access on your IBM i
    Checking in on your IBM i authorization lists
    PCI data security standards and the System i
    Securing the integrated file system on IBM System i
    Contextual security on IBM i: Limit user profile access
    Time for a security checkup for your i

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • iSeries Security - Security Tools, Physical Security and System Security
    HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts