Re: Adopted authority and owner primary group

Walter Nasich <[email protected]> Mon, 10 Aug 2009 12:48:35 -0300
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
>
> Hi, Walter:
>
> Can you describe what is "not working" as you expect?  Try to be 
> specific.  This should help us to try to answer your question.
>
> Mark S. Waterbury

Hi Mark,

  I have this case:

Users:
# GROUP1
# OWNER1: GRPPRF(GROUP1)
# OWNER2: GRPPRF(GROUP1)
# USER1

Objects:
# USER1MENU2 (type *PGM CLP): USRPRF(*OWNER) - Owner: OWNER1 - 
Authorities: PUBLIC *CHANGE

# MENU2 (type *MENU, *FILE and *MSGF): Authorities (PUBLIC *EXCLUDE - 
OWNER2 *ALL - GROUP1 *ALL)


The program USER1MENU2 has only a GO MENU(MENU2).
The USER1 has authority and executes USER1MENU2. USER1 does'nt have 
authority on MENU2, but the program owner's primary group has it 
(GROUP1). However USER1 gets the message CPF9802 Not authorized to 
object MENU2 in BIBL1.

So, It look like as authorities of owner's primary group is not adopted.

Regards,

Walter
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.