I have a user that just needs to start printer/stop printer and change passwords on iSeries. What user call should I give them *user or *secadm? Our security level is set at 40.
I assume that when you say "*USER" or "*SECADM" that you are referring to the user class to specify in their user profile. That's not the place to focus. While the system uses the user class to default the special authorities a profile is assigned, it does not look at the user class when checking authority to an object or to see if the user has sufficient special authorities to perform a task. I recommend that you look through the
System i Security Reference manual
to understand what authorities are required for the tasks the user needs to perform. In particular, Appendix D should prove very useful as it lists the authorities required to run all of the CL commands on the system.
Dig Deeper on iSeries system and application security
Before changing password levels and upgrading operating systems on the AS/400, ensure the clients connecting to the NetServer do not need the old ...
Look in the audit journal (QAUDJRN) on the AS/400 for an authority failure message with the name of the library as the object name. Use the ...
When error messages arise concerning attempts to use a permanent system object without authority, find the source of the issue by looking for an AF ...