|
Ummm, if the group has *ALLOBJ the user has enough authority to give it
back to themselves!
Regards,
Scott Ingvaldson
System i Administrator
GuideOne Mutual Insurance Company
-----Original Message-----
date: Wed, 3 Jan 2007 13:20:47 -0500
from: "Wilt, Charles" <CWilt@xxxxxxxxxxxx>
subject: RE: Is DFU capability a part of the *ALLOBJ privlidge or can
DFUbe separately denied?
*ALLOBJ means *ALLOBJ
Security check goes something like,
1) Does the user have *ALLOBJ, then allow.
2) ....
Now, if instead of the user having *ALLOBJ, you've given *ALLOBJ to the
group profile the user belongs to, then you could explicitly deny the
user access to the object; since the users individual permissions are
check before his group profile permissions.
HTH,
Charles Wilt
--
iSeries Systems Administrator / Developer
Mitsubishi Electric Automotive America
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2025 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.