Seeing all authorities on DSPOBJAUT???

Dan <[email protected]>
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
Interesting thing happened today that we're trying to figure out how. I
won't bore everyone with the details, but knowing the definitive answers to
the following questions could significantly narrow down the possibilities.

Background:
V5R2
User profile QSECOFR is owned by QSYS and the only authority "entry" is
*PUBLIC *EXCLUDE.
(FWIW, user profile QSYS is owned by QSYS and the only authority "entry" is
*PUBLIC *EXCLUDE.)

That *is* the ultimate lockdown, right? No one can adopt authority, or do
*anything* with the QSECOFR profile, correct?

The thing I wonder about is if DSPOBJAUT isn't showing us the whole picture.
Could there be other profiles that have authority to the QSECOFR profile
that won't show up on DSPOBJAUT? Would we have to sign on as QSECOFR and do
the DSPOBJAUT from there to know for sure? The gentleman who has the
password is out today, so if there's a way to know without signing on as
QSECOFR, that would be helpful.

TIA, Dan
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.