Re: Removing *ALLOBJ from user profile
"Ron Boris" <[email protected]> Fri, 11 Dec 2009 13:37:19 -0600
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <A356BF36EFEF4BED8767D2BE30604206@D9150> |
Steve, You can use auditing to analyze the profile. See "Auditing the security officer's actions" http://publib.boulder.ibm.com/infocenter/iseries/v5r4/topic/rzamv/rzamvaudit secofraction.htm or http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/topic/rzarl/rzarlaud action.htm. If the profile is only used for running a limited number of scheduled batch jobs and you have a test environment, it might be simpler to create a test profile without *ALLOBJ authority and run the scheduled jobs in the test environment using this profile to see what problems pop up. If it's used for ad-hoc submitted jobs, you can find jobs run by the user in QHST using DSPLOG or a utility (e.g., TAATOOLS). How is the profile used? Do many users have access to it for submitting jobs? I assume from your message that it is disabled for interactive signon. How many different jobs need to be analyzed? Are these scheduled or on-demand? Do you have a test environment? Do you have a utility for analyzing the history log? Thank you for your support, Ron _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.