Re: Object Authority

"Jones, John (US)" <John.Jones-4kQQZ61tH+/[email protected]> Wed, 27 Aug 2008 10:06:25 -0500
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
You shouldn't need to do that; objects in use should be auto-moved to
QRPLOBJ.

-- 
John A. Jones, CISSP
Sr. Analyst, Global Information Security
Jones Lang LaSalle, Inc.
Voice: +1.630-455.2787
FAX: +1.312.601.1782
Email: john.jones-4kQQZ61tH+/[email protected]


-----Original Message-----
From: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
[mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] On Behalf Of Edwin Davidson
Sent: Wednesday, August 27, 2008 9:44 AM
To: Security Administration on the AS400 / iSeries
Subject: Re: [Security400] Object Authority

One gotcha we have -- when we replace an object, we move it to a library

which is lower in the library list to prevent people who are using that 
object from dumping out of the program.  MOVOBJ.   The we compile the 
new object into production. 

While if we compiled the object directly ontop the existing object, the 
authority would stay, since we movobj the authority is replaced with the

defaults.

We have a number of AS/400's.   On one of them I'm more in control of 
than the others.  Things don't change much.  There is a CL which runs 
nightly and assigns a ton of authorities to objects in case someone's 
attempted to change something or forgot the caveat above.  We also have 
special subsystems for programmer sessions versus normal users.  The 
same job makes sure the QPADEV* devices have the right authorities...

Anyway, my .02$ worth.




**********************************************************************
This email and any files transmitted with it are confidential
and intended solely for the use of the individual or entity to
whom they are addressed.  If you have received this email
in error please reply to the sender of the message.

The views expressed in this correspondence may not
reflect the views of Prime, Inc.

This footnote also confirms that this email message has
been scanned for the presence of computer viruses.
http://www.primeinc.com
**********************************************************************

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.



This email is for the use of the intended recipient(s) only.  If you have 
received this email in error, please notify the sender immediately and then 
delete it.  If you are not the intended recipient, you must not keep, use, 
disclose, copy or distribute this email without the author's prior 
permission.  We have taken precautions to minimize the risk of transmitting 
software viruses, but we advise you to carry out your own virus checks on 
any attachment to this message.  We cannot accept liability for any loss 
or damage caused by software viruses.  The information contained in this 
communication may be confidential and may be subject to the attorney-client 
privilege. If you are the intended recipient and you do not wish to receive 
similar electronic messages from us in the future then please respond to the 
sender to this effect.

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.