Re: STRSRVJOB and database journal entries

Ed Fishel <edfishel-r/[email protected]>
Newsgroups gmane.comp.systems.as400.security
Message-ID <OFF869E69E.35C3DE3C-ON8625719C.007377B9-8625719C.0075666C@us.ibm.com>
Tom Liotta wrote on 06/29/2006 02:45:13 PM:

> Nevertheless, this is fairly a novel idea and is well worth being
> made known to everyone. It clearly demonstrates that proper
> precautions must be taken. It provides a textbook example of why,
> for example, debug access to production tasks is a serious issue.
> The discussion illustrates for everyone who is learning from this
> list why the related precautionary guidelines exist.

I agree.  I will add that one of those precautions might be to turn on
*SERVICE auditing in the QAUDLVL or QAUDLVL2 system value. This will cause
an ST audit record to be written to the security audit journal when some
service or debugging tools are used. The Char(2) Service Tool field in this
audit record indicates which service or debugging tool was used. The value
"SJ" stands for STRSRVJOB. The complete list of the values for the Service
Tool field can be found in the description of the ST audit record in
Appendix F of the Security Reference manual.

Ed Fishel,
edfishel-r/[email protected]




_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.