Re: Commands for Limited Users

[email protected]
Newsgroups gmane.comp.systems.as400.security
Message-ID <OFE64A86A9.D58E88FF-ON852571E2.00609EEF-852571E2.006136ED@dekko.com>
I much prefer authorization lists over groups.  Supplemental groups make 
me shudder.  The overhead on them is tremendous.  A simple SAVSYS went 
from 4 minutes to 44 minutes when we tinkered around with them.  IBM 
dialed in and via PRTPVTAUT determined supplemental groups to be the 
culprit.  Besides, we had more supplemental groups than you could put in 
CHGUSRPRF SUPGRPPRF(...).  Lots of divisions, and then each division had a 
different software vendor between accounting and ERP.  When you have two 
different divisions feeding two different fierce competitors we had to 
demonstrate a pretty solid line between the two.

Rob Berendt
-- 
Group Dekko Services, LLC
Dept 01.073
PO Box 2000
Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com





"David Morris" <[email protected]> 
Sent by: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
09/07/2006 01:30 PM
Please respond to
Security Administration on the AS400 / iSeries  <security400-Zwy7GipZuJhWk0Htik3J/[email protected]>


To
"Security Administration on the AS400 / iSeries" 
<security400-Zwy7GipZuJhWk0Htik3J/[email protected]>
cc

Subject
Re: [Security400] Commands for Limited Users






Phil,

Adopted authority is nearly as outdated as limited capability. It
doesn't work well with triggers or IFS files and is incompletely
implemented. Adoption is ineffective in exits but based on your message
you may have overcome some of the limitations I have run up against. The
biggest reason to avoid adoption is that it is often implemented
incorrectly and is frequently the source of serious security problems. 

A few years back, I started using a technique that gives similar
function by swapping in or setting effective groups and supplemental
groups. 

--David Morris 

-----Original Message-----
From: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
[mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] On Behalf Of Phil Ashe
Sent: Thursday, September 07, 2006 10:09 AM
To: Security Administration on the AS400 / iSeries
Subject: Re: [Security400] Commands for Limited Users

John:

...I have three basic problems with LMTCPB and commands. 
1) It's obsolete in that it hasn't been updated to check commands in
newer interfaces. [limited scope]
2) It's checked after the user has already been determined to have
object authority to the command.
3) It's difficult to find the LMTCPB "violations". They aren't placed in
the system audit journal. [more obsolescence]

...I would use adopted authority for access through the expected
application interfaces and use proxy commands to limit the use of EDTF
or DFU to well-defined views of the data, then take away the data rights
to the file. The object authority is still checked on the remote server
interfaces. If you need access to the file from one or more remote
servers, you can use exit programs to give you this authority...

Phil Ashe

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) 
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.