Re: Authority levels

[email protected] Mon, 4 May 2009 16:59:13 -0400
Newsgroups gmane.comp.systems.as400.security
Message-ID <OF879A39DB.59BF8F42-ON852575AC.0071CF34-852575AC.00734980@dekko.com>
I do not have any QOTH* user profiles.   However, I do not use Lansa, etc.

Granted, if often grinds us to have products requiring a user profile with 
*ALLOBJ to do certain things.  It's not right that packages have to do 
that sometimes, it should only be us that sometimes have to do that.  :-)

Perhaps they feel that it's important that their products just "work". 
Now, if you want to remove *ALLOBJ from them and then ensure that you add 
their owning user profile to all of the correct authorization list, 
groups, command security, etc, necessary then you could probably do so. By 
the time you're done it may boil down to you might as well have given them 
*ALLOBJ.

*SECADM is a different animal.  I would probably search through their 
document as to their statement of why they need *SECADM.  It should be a 
FAQ on their website.  In that same vein, perhaps a statement of need for 
*ALLOBJ isn't out of the question.  Hey, if it's a documented need then 
that satisfies SOX, right?

It would be nice to have some level of trust with these packages, but 
after having one package that had a program with QSECOFR adopted authority 
to find out it was a one line CL program that just had CALL QCMD (gets a 
command line) so that raw users could do stuff when on the phone with 
their support without having to deal with the users pesky security 
officers, you get leery of trust.

Rob Berendt
-- 
Group Dekko Services, LLC
Dept 01.073
Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com





From:
César Rafael <[email protected]>
To:
"Security Administration on the AS400 / iSeries" 
<security400-Zwy7GipZuJhWk0Htik3J/[email protected]>
Date:
05/04/2009 11:46 AM
Subject:
Re: [Security400] Authority levels
Sent by:
security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]



Hi,
I don't know about other profiles, but QOTHPRDOWN is used as the LANSA
Product Owner (don't know if any other product uses the same profile,
thougt).

----- Original Message ----- 
From: "Duran, Beatriz" <[email protected]>
To: <security400-Zwy7GipZuJhWk0Htik3J/[email protected]>
Sent: Monday, May 04, 2009 4:24 PM
Subject: [Security400] Authority levels


Hi, besides QSECOFR is it normal to find accounts like QEJBSVR,
QOTHPRDOWN, RBTADMIN and QTIVROOT with authorities like *ALLOBJ and
*SECADM?








<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0"
style="width: 681px">
<tr>
<td width="43" valign="top" style="width:32.25pt;padding:0in 0in 0in 0in">
<p class="MsoNormal" 
style="margin-top:7.5pt;margin-right:0in;margin-bottom:
  22.5pt;margin-left:0in;line-height:16.8pt">
<span style="font-size: 7.0pt; font-family: Arial,sans-serif; color:
#89C326">
<img border="0" src="http://www.kpmg.com.mx/images/livinggreen.gif"
width="37" height="54"></span></td>
<td valign="bottom" style="width:607px;padding-left:0in;
padding-right:24.0pt; padding-top:.1in; padding-bottom:0in">
<p class="MsoNormal" 
style="margin-top:7.5pt;margin-right:0in;margin-bottom:
  22.5pt;margin-left:0in;line-height:16.8pt">
<span style="font-size: 7.0pt; font-family: Arial,sans-serif; color:
#89C326">
KPMG está comprometido con la responsabilidad ambiental.</span><span
style="font-size:7.0pt;
  font-family:"Arial","sans-serif";color:#89C326"><br>
</span>
<span style="font-size: 7.0pt; font-family: Arial,sans-serif; color:
#89C326">
Por favor, considere el medio ambiente antes de imprimir este
e-mail.</span></td>
</tr>
<tr>
<td valign="top" style="width:681px;padding:0in; " colspan="2">
<span style="font-size: 7.0pt; font-family: Arial,sans-serif; color:
#000080">
The information in this e-mail is confidential and may be legally
privileged. It is intended solely for the addressee. If you are not the
intended recipient, any disclosure, copying, distribution or any action
taken or omitted to be taken in reliance on it, is prohibited and may be
unlawful. Any opinions or advice contained in this e-mail are subject to
the terms and conditions expressed in the governing KPMG client
engagement letter. <br>
<br>
KPMG cannot guarantee that e-mail communications are secure or
error-free, as information could be intercepted, corrupted, amended,
lost, destroyed, arrive late or incomplete, or contain viruses.<br>
<br>
KPMG Cardenas Dosal, S .C. is a Mexican partnership and the Mexican
member firm of KPMG International. KPMG International is a Swiss
cooperative of which all KPMG firms are members. KPMG International
provides no professional services to clients. Each member firm is a
separate and independent legal entity and each describes itself as
such.</span></td>
</tr>
</table>



----------------------------------------------------------------------------
----


> _______________________________________________
> This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
> To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
> To subscribe, unsubscribe, or change list options,
> visit: http://lists.midrange.com/mailman/listinfo/security400
> or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
> Before posting, please take a moment to review the archives
> at http://archive.midrange.com/security400.
>
>

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) 
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.



_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.