Re: User Profile handling in ancient release(s)

Richard Schoen <richard-DiTrGpQEJGItADg8e/3/[email protected]> Tue, 21 Sep 2021 17:06:15 +0000
Newsgroups gmane.comp.lang.as400.c
Message-ID <CH0PR12MB52500F65BE1CAA19583EBB96B7A19@CH0PR12MB5250.namprd12.prod.outlook.com>
What's the reason for switching profiles ?

No other platform does this that I'm aware of. 

In general a daemon job or web server/service generally runs under a specific server/daemon user profile and then all work is done under that user. 

However on IBMi you can certainly authenticate via the user profile check API, I would not be switching user profiles. 

Unless you have a specific reason to do so. 

I did this with a product several years back for recreating spool files with the right user and it forced us to store user/password combos in a table. Ugh.

Regards,
Richard Schoen
Web: http://www.richardschoen.net
Email: richard-DiTrGpQEJGItADg8e/3/[email protected]

----------------------------------------------------------------------

message: 1
date: Mon, 20 Sep 2021 19:32:00 +0200
from: Patrik Schindler <[email protected]>
subject: [C400-L] User Profile handling in ancient release(s)

Hello,

lately I was following the blog of Cris Hird to learn about "daemon programming". He provides a great example with a main task (testsvr) spawning a worker task (worker) on request.

https://www.shieldadvanced.com/Blog/ibm-i/lets-c-integration-with-security/

For switching the user profile on the fly, he uses functions from qsyphandle.h. These functions aren't available on OS/400 V4R5.

POSIX setuid() doesn't work, because the function isn't referenced in sys/types.h, nor in unistd.h (as it's in Linux).

Does anybody remember how user switching was done two decades ago in OS/400?

:wq! PoC



-- 
This is the Bare Metal Programming IBM i (AS/400 and iSeries) (C400-L) mailing list
To post a message email: [email protected]
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/c400-l
or email: [email protected]
Before posting, please take a moment to review the archives
at https://archive.midrange.com/c400-l.

Help support midrange.com by shopping at amazon.com with our affiliate
link: https://amazon.midrange.com