Re: STRSRVJOB and database journal entries,
"Shalom Carmel" <shalom-a/[email protected]>
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
I looked at the level of detail provided by the audit journal. It says that a strsrvjob command was executed on job X by user Y. As Ed pointed out, you must have *SERVICE in the auditing definitions or even this information is omitted. On the other side of the issue, let's see what does *USE authority to user profiles mean. a. A user with *ALLOBJ has *USE authority to all user profiles. b. A user who is the owner of the user profile can grant herself *USE authority if she does not have it already. c. A user has automatic *USE to the group profile that she belongs to. d. QSYSOPR does not need *USE authority. Considering the common practices in most as400 shops, I would feel much better if CHGPGMVAR, CHGPTR and their kin were also logged to the audit journal under some code, or if the database journal had an indication of being created in a debug session. Shalom _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.