|
Forgive me if I'm wrong here, wouldn't be the first time, but
I thought the following applied, at least at security level 40...
You need at least *SECADM authority to change a user profile,
*ALLOBJ is not enough.
You can't submit a job as QSECOFR even if you do haveHmm - I'm not sure if that is true - and I'm on an airplane now so I
*ALLOBJ.
-----Original Message-----
From: midrange-l-bounces@xxxxxxxxxxxx
[mailto:midrange-l-bounces@xxxxxxxxxxxx] On Behalf Of Crispin Bates
Sent: Wednesday, April 02, 2008 7:54 AM
To: Midrange Systems Technical Discussion
Subject: Re: Anti-virus for i5OS
Forgive me if I'm wrong here, wouldn't be the first time, but
I thought the following applied, at least at security level 40...
You need at least *SECADM authority to change a user profile,
*ALLOBJ is not enough.
Message ID . . . . . . : CPF2292
Date sent . . . . . . : 04/02/08 Time sent . . . . .
. : 10:44:32
Message . . . . : *SECADM required to create or change user
profiles.
Special authority (SPCAUT) - Help
o The user profile creating or changing another user
profile must have all of the special authorities being
given. All special authorities are needed to give all
special authorities to another user profile.
o A user must have *ALLOBJ and *SECADM special
authorities to give a user *SECADM special authority
when using the CHGUSRPRF command.
o The user must have *ALLOBJ, *SECADM, and *AUDIT
special authorities to give a user *AUDIT special
authority when using the CHGUSRPRF command.
You can't submit a job as QSECOFR even if you do have
*ALLOBJ. What you can do is submit a job as another user who
has *SECADM, or *SECOFR, but that's an entirely different discussion.
Sorry, but a user with *ALLOBJ can give themselves *AUDIT,*IOSYSCFG,
*JOBCTL, *SAVSYS, *SECADM and *SPLCTL. From "Expert'sGuide to OS/400
and i5/OS Security", page 67:unlimited access
"For example, *ALLOBJ special authority gives a user
to and control over ALL objects-a user with *ALLOBJ specialauthority
can perform any function on any object on your system."them up to
There is only a one step difference between a user with *ALLOBJ and
QSECOFR, that of the user with *ALLOBJ going into their own profile
and granting themselves the missing options. You can lock both
*ALLOBJ users and QSECOFR out of certain sysvals by pushing
SST level maintenance, but if you've given a user *ALLOBJyou might as
well have made them QSECOFR.auditing level,
Do you want your new software package to adjust your
calls homecreate a PPP connection and add a job schedule entry that
your veryand reports **anything it wants** from your system? ABC Corp may
have just used "social engineering" to get you to install
point is thatown iSeries virus!
A totally false question. Who is going to say yes? The
merely changing the user id used for installation fromQSECOFR to one
with *ALLOBJ hasn't fixed anything. I can do anything with *ALLOBJrights to
that I can do with QSECOFR. The user with *ALLOBJ has full
the QSECOFR profile. If he doesn't, he can just granthimself those rights.
level, so that
As hinted at above, you can push auditing values to SST
even QSECOFR can't change them. The point remains, *ALLOBJ is(MIDRANGE-L) mailing
essentially no different from QSECOFR..........
--
This is the Midrange Systems Technical Discussion
list To post a message email: MIDRANGE-L@xxxxxxxxxxxx To subscribe,please take
unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting,
a moment to review the archives at
http://archive.midrange.com/midrange-l.
--
This is the Midrange Systems Technical Discussion
(MIDRANGE-L) mailing list To post a message email:
MIDRANGE-L@xxxxxxxxxxxx To subscribe, unsubscribe, or change
list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx Before posting,
please take a moment to review the archives at
http://archive.midrange.com/midrange-l.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.