Q
Problem solve Get help with specific problems with your technologies, process and projects.

Implications of giving a user *SAVSYS special authority

What are the implications of giving a user *SAVSYS special authority so they can backup other user's files?


As with most special user authorities, the *SAVSYS special authority grants a significant level of additional capability to a user and you should think twice about granting it to anyone.

Any user of the AS/400 has the necessary rights to use the OS/400 SAV* commands. Therefore, they can save any objects they have sufficient authority to. Sufficient authority in this case would be having *OBJEXIST rights to the object. Object existence rights provide authority to control the object's existence and ownership.

By default users have *OBJEXIST rights to all the objects they own. Therefore, they can save any of their own data. They don't have the authority to restore anything, though, because access to the RST* commands are *PUBLIC *EXCLUDE by default.

The *SAVSYS special authority gives a user the additional ability to save objects they don't have *OBJEXIST rights to. One very important implication of this is the fact that when an object is saved, you can also specify that its storage be freed.

IBM's definition of this feature is this: "Freeing storage during a save means that the storage occupied by the data portion of the specified objects being saved is freed as part of the save operation."

In effect, you can remove from the system everything but the header of an object saved in this manner.

Therefore, someone with *SAVSYS authority could do the following:
1. Save any object on the system to a save file specifying that its storage be freed.
2. Delete the save file.

Anyone with *SAVSYS authority has the ability to delete any object from the system. Because this provides so much authority, you may not want anyone but an operator or system administrator to have it.


This was last published in February 2001

Dig Deeper on Performance

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

SearchDataCenter

  • How do I size a UPS unit?

    Your data center UPS sizing needs are dependent on a variety of factors. Develop configurations and determine the estimated UPS ...

  • How to enhance FTP server security

    If you still use FTP servers in your organization, use IP address whitelists, login restrictions and data encryption -- and just ...

  • 3 ways to approach cloud bursting

    With different cloud bursting techniques and tools from Amazon, Zerto, VMware and Oracle, admins can bolster cloud connections ...

Close