Re: Removing *ALLOBJ from user profile

"Ron Boris" <[email protected]> Fri, 11 Dec 2009 13:37:19 -0600
Newsgroups gmane.comp.systems.as400.security
Message-ID <A356BF36EFEF4BED8767D2BE30604206@D9150>
Steve,

You can use auditing to analyze the profile.  See "Auditing the security
officer's actions"
http://publib.boulder.ibm.com/infocenter/iseries/v5r4/topic/rzamv/rzamvaudit
secofraction.htm or
http://publib.boulder.ibm.com/infocenter/iseries/v6r1m0/topic/rzarl/rzarlaud
action.htm.

If the profile is only used for running a limited number of scheduled batch
jobs and you have a test environment, it might be simpler to create a test
profile without *ALLOBJ authority and run the scheduled jobs in the test
environment using this profile to see what problems pop up.

If it's used for ad-hoc submitted jobs, you can find jobs run by the user in
QHST using DSPLOG or a utility (e.g., TAATOOLS).

How is the profile used?  Do many users have access to it for submitting
jobs?  I assume from your message that it is disabled for interactive
signon.  How many different jobs need to be analyzed?  Are these scheduled
or on-demand?

Do you have a test environment?  Do you have a utility for analyzing the
history log?

Thank you for your support,
 
Ron


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.