Re: Securing WAS, WPS, etc. for developers
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <OF0B2E50A5.D1521D95-ON05257139.0059F2AD-05257139.005A07B0@dekko.com> |
I think I'd cross post this on the web list. Maybe even submit some DCR's on increasing the granularity of the web administration. Rob Berendt -- Group Dekko Services, LLC Dept 01.073 PO Box 2000 Dock 108 6928N 400E Kendallville, IN 46755 http://www.dekko.com "Crump, Mike" <[email protected]> Sent by: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected] 03/22/2006 09:49 AM Please respond to Security Administration on the AS400 / iSeries <security400-Zwy7GipZuJhWk0Htik3J/[email protected]> To <security400-Zwy7GipZuJhWk0Htik3J/[email protected]> cc Subject [Security400] Securing WAS, WPS, etc. for developers I may ramble on this one but I am struggling with some ways to properly secure things within WAS and WPS. Right now I am working with WAS 6 (ND) and WPS (5.1.0.1). My first beef tends to be that within WAS it takes a high degree of authority to allow someone to run the HTTP Admin Client - I am not aware of any way to allow someone access to it but limit what they can do. For example I want operators and sometimes even developers the ability to take servers up or down and even make some changes. My problem is that I feel that certain things should not be open - there should be some control on configurations. And then if they have to have *IOSYSCFG or other access I struggle with that. It is such a hassle to allow that and while I hate my auditors (if they would ever evaluate things from a business cost/benefit vs. security standpoint and if they would ever help solve a problem then I might like them) I have to agree with their assessments about the impact of such a special authority. And then I have an issue between production, development, and test servers/instances. So it makes sense for someone to have more control in a test server instance than in a production instance. I can't figure out how to meter out this authority. My second beef is how to secure the IFS structure for these products. I am constantly getting requests for write or existence access to a number of objects and with the directory structure of these products they can exist all over the place. I don't want to give the carte blanch type of access but I can't have them restricted all the time either. Has anyone spent any time trying to create a granular security environment for WAS and had any success? Michael Crump Manager, Computing Services Saint-Gobain Containers 1509 S. Macedonia Ave. Muncie, IN 47302 (765)741-7696 (765)741-7012 f (800)428-8642 "The probability that we may fail in the struggle ought not to deter us from the support of a cause we believe to be just" Abraham Lincoln _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.