Re: Seeing all authorities on DSPOBJAUT???

Dan <[email protected]>
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
On 11/11/05, Gary Monnier <gary.monnier-Ua2wos9bJ7y1Z/[email protected]> wrote:
>
> Dan,
>
> Any profile with *ALLOBJ authority can use them. Any clones of QSECOFR
> can use and change it.


*ALLOBJ trumps *PUBLIC *EXCLUDE?

Seems to be a catch-22 here. Assuming someone here can sign on as a *secofr
w/ *ALLOBJ authority, is there an easy way to quickly determine all of the
profiles that have *ALLOBJ authority?

When you talk about "clones of QSECOFR", I presume you are thinking of
copying the QSECOFR profile to another profile. But isn't the real clincher
to this is the new profile assumes the same *ALLOBJ authority that QSECOFR
has? Or is there some other property precludes the need for *ALLOBJ
authority?

- Dan
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.