|
Steve: The only realistic response is the same as it's *ALWAYS* been... *EVERY* program run by *EVERY* *ALLOBJ user must be controlled if you want any chance of controlling security. There are ways of getting the same "If so, it..." result you mention that are much easier to achieve than replacing exit programs. But I expect you already know that. Tom Liotta On Tue, 31 July 2001, "srichter " wrote: > > Another scenario: > > A user without *AllObj authority codes and creates a chgc0100 exit pgm. > > A profile that does have *AllObj authority runs AddExitPgm to register the >chgc0100 exit pgm. > > The exit pgm is then replaced by a user with existance rights to the exit >pgm ( but no *AllObj special authority ). > > The new exit pgm, which runs every time the registered cmd is used, and >runs with the authority of the job that calls it, contains code that checks to >see if the running user has *AllObj/*SecAdm authority. If so, it .... > > You must have *AllObj and *SecAdm to register an exit pgm. Should not the >exit pgm itself have to be owned by a profile with *AllObj/*SecAdm ? -- Tom Liotta The PowerTech Group, Inc. 19426 68th Avenue South Kent, WA 98032 Phone 253-872-7788 Fax 253-872-7904 http://www.400Security.com ___________________________________________________ The ALL NEW CS2000 from CompuServe Better! Faster! More Powerful! 250 FREE hours! Sign-on Now! http://www.compuserve.com/trycsrv/cs2000/webmail/ +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.