Re: Library Authority
Mike <[email protected]> Thu, 14 Aug 2008 09:55:06 -0500
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Aug 14, 2008 at 9:16 AM, Jim Franz <franz400-goaWJWIt5zpWk0Htik3J/[email protected]> wrote: > > But what if we want to give them *ALL on an object within that library, > > would they be able to delete that work file? > yes - *USE on lib will allow delete of object in lib if user has delete > auth > to object. Thanks, I wasn't sure on this one. > > Also, if we have *EXCLUDE on a library. Then we have a logical in another > > library pointing to a file within the secured library. Would that work? > > The > > file in the locked library would have READ access only. > yes - (i've not tested this), note: data authorities on LF cannot be more > than on PF. > (this one i was not positive till checking Woodbury/Botz's Experts Guide > book p164) I did just try this one and it works. I give the READ data authority only on the PF in one library with *EXCLUDE on the library, then give them *USE access on the logical on a seperate library. Now we can control what live data they can access and what data within the file they can access. I'll have to look into that book more. _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.