× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Thanks Charles. That was what I needed to know.

Is there a way to create the folder so that it is owned by the group profile from the start? In other words specify who the owner is as part of the create command. We can't login with the group profile. However, Alan's response is reminding me that we could create the directory using a SBMJOB and specifying the group profile as the user for the job. I guess I answered my own question.
Dean

On 2014-09-11 4:08 PM, Charles Wilt wrote:>>From the manual
http://www-01.ibm.com/support/knowledgecenter/ssw_ibm_i_71/rzarl/rzarlifscommands.htm?lang=en

Authority needed for object1
Ownership15

15 - If you have *ALLOBJ special authority, you do not need the listed
authority.

Welcome to the world of Unix! ;)

You should probably make sure objects are created with a group profile
owning them.

Charles


On Thu, Sep 11, 2014 at 3:58 PM, Dean Eshleman <Dean.Eshleman@xxxxxxxxxxxx>
wrote:

Hi,

I'm trying to change the authority on an IFS folder via the WRKLNK command
and option 9 to work with authority. The group my user profile is a member
of has *RWX data authority and all object authorities on this directory. I
am not the owner of the folder. The primary group on the folder is *NONE
and no authorization list is specified. When I try to add a new user to
this directory I receive the following error

Message ID . . . . . . : CPFA0B1 Severity . . . . . . . : 40
Message type . . . . . : Diagnostic
Date sent . . . . . . : 09/11/14 Time sent . . . . . . :
15:39:09

Message . . . . : Requested operation not allowed. Access problem.
Cause . . . . . : An operation was requested on an object, but the
operation
is not allowed in the context of the request. Appropriate privileges
may be
required or the file system may not allow an operation to the selected
object.
Recovery . . . : Check the name of the object to make sure it is
correct.
Correct the name and retry the operation. If trying to remove a
directory,
use the RMVDIR command. If trying to link directories, specify *SYMBOLIC
for
the LNKTYPE parameter of the ADDLNK command.

I tried granting authority to a user profile that I don't have authority
to look at. I also tried granting authority to a user profile that I do
have authority to look at. Both failed with the same error. Using the
CHGAUT command also produces the same error. What am I missing? It seems
like we have always had this problem with IFS security. It seems like only
the owner of the folder can change the authority. We are on V7.1.

Dean Eshleman
Software Development Architect

Everence Financial
1110 North Main Street
PO Box 483
Goshen, IN 46527
Phone: (574) 533-9515 x3528
www.everence.com<http://www.everence.com/>

______________________________________________________________________
Confidentiality Notice: This information is intended only for the
individual or entity named. If you are not the intended recipient, do not
use or disclose this information. If you received this e-mail in error,
please delete or otherwise destroy it and contact us at (800) 348-7468 so
we can take steps to avoid such transmission errors in the future. Thank
you.
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/midrange-l.




Dean Eshleman
Software Development Architect

Everence Financial
1110 North Main Street
PO Box 483
Goshen, IN 46527
Phone: (574) 533-9515 x3528
www.everence.com<http://www.everence.com/>

______________________________________________________________________
Confidentiality Notice: This information is intended only for the individual or entity named. If you are not the intended recipient, do not use or disclose this information. If you received this e-mail in error, please delete or otherwise destroy it and contact us at (800) 348-7468 so we can take steps to avoid such transmission errors in the future. Thank you.

As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.