× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.


  • Subject: Re: Profile security
  • From: "Ed Fishel" <edfishel@xxxxxxxxxx>
  • Date: Mon, 5 Mar 2001 13:42:07 -0600
  • Importance: Normal


Ray,

>>I understand that, but can you explain to me how having the mentioned
profiles with Limited Capability equal to *NO and Password (*NONE) can
cause a problem?  By the way, I did not mean to include QSECOFR in the list
of profiles.<<

>>His exact words were, "You have too many profiles with Limited Capability
equal to *NO and Password equal to *NONE."  Does that mean that I should
change all the IBM profiles that are not being use to Limited Capability
equal to *YES???<<

I can think of no security exposure that is simply caused by having LMTCPB
(*NO) for a user profile that also has PASSWORD(*NONE). If the security
level of the system was set to 10 that by itself is a security exposure. If
a LMTCPB(*YES) or LMTCPG(*PARTIAL) user profile has *USE authority to a
LMTCPB(*NO) user profile that could be a security exposure, if you are
using menu security. (Menu security is rarely secure.) Perhaps this is what
the security auditor is referring to. Why don't you ask them.

If you change any IBM supplied user profile, other than QUSER, to LMTCPB
(*YES) you may find that you have to change it back if and when a real
person needs to sign on using that user profile.

Ed Fishel,
edfishel@US.IBM.COM


+---
| This is the Midrange System Mailing List!
| To submit a new message, send your mail to MIDRANGE-L@midrange.com.
| To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com.
| To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com.
| Questions should be directed to the list owner/operator: david@midrange.com
+---

As an Amazon Associate we earn from qualifying purchases.

This thread ...


Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.