RE: Prevent User Profile from using public authority

Steve Martinson <[email protected]>
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
Charles,

Rather than risk hosing something else on your box by trying to create a
"replacement *PUBLIC profile" or even just trying to hit every object on
your box, it seems to me it would be a lot easier to use an exit program for
the ODBC/JDBC remote transactions.  

There are several exit program security products out there, but only one
that I know of can afford 'pinpoint' accuracy with regard to controlling
access via the exit point without having to modify any existing OS/400
object authorities or user profile groupings.

Contact me offline if you would like more details.

Steven W. Martinson, CISSP, CISM
iSeries Security Consultant  |  NetIQ Corporation

Cell 281.546.9836  |  www.netiq.com 
1233 West Loop South  |  Suite 1800  |  Houston, TX 77027
 

> message: 1
> date: Fri, 22 Apr 2005 14:01:25 -0400
> from: "Wilt, Charles" <CWilt-GqJsjaCkv4dWk0Htik3J/[email protected]>
> subject: [Security400] Prevent User Profile from using public authority

> Is there any way to prevent a user profile from using *PUBLIC authority?

> Here's the scenario, I've got a user profile set up for JDBC use from a
external web server.  All I want this profile do > be able to do is call
stored procedures it is specifically authorized to.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.