Re: Commands for Limited Users

[email protected] Thu, 07 Sep 2006 15:05:37 -0700
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
David.Morris wrote:

> In your original message you said:
> 
> "I would use adopted authority for access through the expected
> application interfaces and use proxy commands to limit the use of EDTF
> or DFU to well-defined views of the data, then take away the data rights
> to the file. The object authority is still checked on the remote server
> interfaces. If you need access to the file from one or more remote
> servers, you can use exit programs to give you this authority."
> 
> I took that to mean that you used adopted authority in your exit program
> but it sounds like you are actually swapping or setting the effective
> user, which is the approach I use in all cases where I used to use
> adoption. There are some other steps you need to take like register
> exits to back out the authority to mimic adoption.

Now there's an interesting point to discuss...

One item that is needed is a clear agreement on terms. "Adopted 
authority" is used in ways that seem to mean different things to 
different people at different times. I have had a personal understanding 
that limits its meaning, and maybe others could comment so that a 
consensus is reached and available.

To me, "adopted authority" refers specifically to the authority gained 
by a program that has the USRPRF(*OWNER) attribute set. It does _not_ 
refer to any authority resulting from the use of any profile-switching 
APIs. "Adopted authority" becomes active when, within the program, an 
object access is attempted and the job current user does not have 
sufficient authority but (1) the program USRPRF(*OWNER) attribute is set 
and (2) the program owner does have sufficient authority.

One result is that the USEADPAUT(*YES/*NO) program attribute _only_ 
affects the authority gained within a higher program in the call stack 
by the above mechanism. It has no effect on authority gained by a 
profile switch from any API because that isn't "adopted authority".

Anybody have modifications (or direct corrections) to add?

Tom Liotta

-- 
Tom Liotta
The PowerTech Group, Inc.
19426 68th Avenue South
Kent, WA 98032
Phone  253-872-7788 x313
Fax    253-872-7904
http://www.powertech.com
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.