×
The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.
<snip>
Why not just fix it "once and for all" using OS/400 or IBM i security and
object authorization?
</snip>
Answer is
<snip>
Due to a mess with security let's forego the thought of changing each of
the several hundred schemas to GRTOBJAUT ODBCUSER *EXCLUDE one at a time.
</snip>
<snip>
Is this ODBCUSER a group profile?
</snip>
It's a single user. Even if it was a group it still would require that I
do the GRTOBJAUT ODBCUSER *EXCLUDE for a few hundred schemas. Not only
that, but everytime someone creates a new schema I would have to discover
that it occurred and change it's authority. Even if I changed the command
defaults or some such thing on creating a schema dollars to doughnuts the
person who created it would make it *PUBLIC *ALL.
<snip>
What does the authority for a typical "schema" (library) look like? Please
show the results of issuing:
DSPOBJAUT schemaname *LIB
</snip>
There is no typical schema. I have to secure them from accessing any,
except for one, with odbc. Some use authorization lists, of which we have
quite a list of authorization lists. Many don't bother with authorization
lists.
<snip>
What does *PUBLIC authority look like for these libraries?
</snip>
Depends on the schema. Could vary to *ALL, *AUTL and depending on the
*AUTL could be any number of things including *EXCLUDE, *USE, *ALL.
Rob Berendt
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact
[javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.