Object Authority

mgarton-z3OK0Yh6KsD9d7wJ/[email protected] Wed, 27 Aug 2008 09:23:48 -0500
Newsgroups gmane.comp.systems.as400.security
Message-ID <OF044AF8A9.6A61CD7B-ON862574B2.004DA1D6-862574B2.004F1668@oreillyauto.com>
I need some help with securing our prod iSeries systems from the experts.
Currently on our prod systems the program and data object are owned by a
system profile and the programmers have that profile as group profile.
Also many of our libs and object have public *change or *use authority.  I
am wanting to get our prod systems setup such that everything is Public
*exclude, data and program objects are owned by a non-system profile (that
can't be used to sign on), and be able to restrict programmers to *use or
in some cases *change authority to data objects.   I originally was going
to use group profiles with *use or *change access and just put the
programmer in the appropriate group but when objects are promoted to
production the private authorities have to be given for the group profiles
manually.  I don't want folks that do the installs to have to mess with
authorities.  So I am looking at authority lists since that info is saved
with the object.  Would there be an issue with using an authority list and
then putting the group profiles in the list?  If anyone has any advice on
gotcha's or how best to migrate, it would be greatly appreciated.

Thanks.

Mark Garton

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.