Re: STRSRVJOB and database journal entries
Ed Fishel <edfishel-r/[email protected]>
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <OFF869E69E.35C3DE3C-ON8625719C.007377B9-8625719C.0075666C@us.ibm.com> |
Tom Liotta wrote on 06/29/2006 02:45:13 PM: > Nevertheless, this is fairly a novel idea and is well worth being > made known to everyone. It clearly demonstrates that proper > precautions must be taken. It provides a textbook example of why, > for example, debug access to production tasks is a serious issue. > The discussion illustrates for everyone who is learning from this > list why the related precautionary guidelines exist. I agree. I will add that one of those precautions might be to turn on *SERVICE auditing in the QAUDLVL or QAUDLVL2 system value. This will cause an ST audit record to be written to the security audit journal when some service or debugging tools are used. The Char(2) Service Tool field in this audit record indicates which service or debugging tool was used. The value "SJ" stands for STRSRVJOB. The complete list of the values for the Service Tool field can be found in the description of the ST audit record in Appendix F of the Security Reference manual. Ed Fishel, edfishel-r/[email protected] _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.