|
-----Original Message----- From: Jim Langston <jlangston@conexfreight.com> To: 'MIDRANGE-L@midrange.com' <MIDRANGE-L@midrange.com> Date: Sunday, October 24, 1999 2:53 AM Subject: User can't delete file >We have 2 users that use this procedure, anna and rod, rod's user group >is anna. This is the start of your problem. The users are not on equal footing. > >When Rod runs the procedure, everything is fine and dandy. >When Anna runs the procedure after Rod does, an error occurs saying she >is not allowed to delete the file. > >Rod can delete the file if anna creates it, but anna can not delete the >file if rod >creates it. > Since Rod belongs to the Anna group, he has authority to the objects of that group. Anna however, does NOT have authority to objects created by members of the group. Why? If you look at Rod's user profile, I am sure you will find that the OWNER parameter is set to *USRPRF (this is the default.) Normally, you would set up a group profile and make BOTH Rod and Anna members of that group. Then you can change the owner parameter on each of Rod's and Anna's profiles to be *GRPPRF. This makes objects created by either Rod or Anna, owned by the group and not either Rod or Anna and thus, both Rod and Anna, being part of the same group, each has the appropriate authority to delete the files created by the other. >I do notice that Anna is *SYSOPR and Rod is *SECADM (noticing that, >since >i didn't create this account, I think I'm going to lower him down to >*SYSOPR). > This is NOT the problem. *SECADM is NOT *SECOFR and does not convey *ALLOBJ authority. =========================================================== R. Bruce Hoffman, Jr. -- IBM Certified AS/400 Professional System Administrator -- IBM Certified AS/400 Professional Network Administrator "The sum of all human knowledge is a fixed constant. It's the population that keeps growing!" +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.