Re: Commands for Limited Users
"Dave Odom" <[email protected]> Fri, 08 Sep 2006 14:30:19 -0700
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
Rob, Having been a DBA on DB2 on VM and MVS, couldn't agree with you more!!! Now working on a i5 that is treated like a big PC I'm trying to get them to see the need for a DBA and bring them into the latter half of the 20th Century. Dave >>> [email protected] 9/7/2006 10:22 >>> Also, regarding respecting the integrity of data files. This is where a lot of people who do not think that the i5 requires a dba fall flat on their face. There is much more that should be done at the database level to ensure that people can't muck it up through back doors. Frankly it's the very limited few who have *ALLOBJ that are more likely to think they know what they are doing and screw up the data. Like the systems person who's just going to run that quick sql to fix some data. And, oops, 10,000+ rows are fubared. What is needed is more usage of constraints and triggers. Rob Berendt -- Group Dekko Services, LLC Dept 01.073 PO Box 2000 Dock 108 6928N 400E Kendallville, IN 46755 http://www.dekko.com "Phil Ashe" <[email protected]> Sent by: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected] 09/07/2006 12:09 PM Please respond to Security Administration on the AS400 / iSeries <security400-Zwy7GipZuJhWk0Htik3J/[email protected]> To "Security Administration on the AS400 / iSeries" <security400-Zwy7GipZuJhWk0Htik3J/[email protected]> cc Subject Re: [Security400] Commands for Limited Users John: Your opinion is valid. There are many shops that haven't crafted a complete plan to access the resources on their servers. LMTCPB is designed only to stop commands from a classic command line interface. We are in agreement that it is useless for anything else. As you have pointed out it is possible to execute remote commands on the local server (including executing commands against 127.0.0.1) to get around the limitations imposed by LMTCPB. I have three basic problems with LMTCPB and commands. 1) It's obsolete in that it hasn't been updated to check commands in newer interfaces. [limited scope] 2) It's checked after the user has already been determined to have object authority to the command. 3) It's difficult to find the LMTCPB "violations". They aren't placed in the system audit journal. [more obsolescence] When used in the environment for which it was designed, LMTCPB can be a tool of last resort to stop some undesired activity. You need to look hard to find out that LMTCPB is doing anything of value on your system. The information is in the joblog. But it also can interfere with desired activity, requiring a bunch of work-arounds. Anyway, let's talk about the Inventory Master. By giving a user *CHANGE rights to the master file, you give them rights to the file in all interfaces. The user can get at the file through EDTF/DFU or Excel, as well as the expected application interfaces. I would use adopted authority for access through the expected application interfaces and use proxy commands to limit the use of EDTF or DFU to well-defined views of the data, then take away the data rights to the file. The object authority is still checked on the remote server interfaces. If you need access to the file from one or more remote servers, you can use exit programs to give you this authority. Database administration is bunch of landmines. How you implement your security plan can have a significant impact on performance. I prefer to start out with a simple plan (then resist all efforts to make it more complex). Phil Ashe NetIQ (A division of Attachmate) 1233 West Loop South, Suite 1800 | Houston, TX 77027 USA 713.418.5279 phone [email protected] www.netiq.com Phil, Would you care for a little open and spirited debate? <snip> sure! _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.