Dan, Any profile with *ALLOBJ authority can use them. Any clones of QSECOFR can use and change it. -----Original Message----- From: security400-bounces@xxxxxxxxxxxx [mailto:security400-bounces@xxxxxxxxxxxx] On Behalf Of Dan Sent: Friday, November 11, 2005 8:37 AM To: Security400@xxxxxxxxxxxx Subject: [Security400] Seeing all authorities on DSPOBJAUT??? Interesting thing happened today that we're trying to figure out how. I won't bore everyone with the details, but knowing the definitive answers to the following questions could significantly narrow down the possibilities. Background: V5R2 User profile QSECOFR is owned by QSYS and the only authority "entry" is *PUBLIC *EXCLUDE. (FWIW, user profile QSYS is owned by QSYS and the only authority "entry" is *PUBLIC *EXCLUDE.) That *is* the ultimate lockdown, right? No one can adopt authority, or do *anything* with the QSECOFR profile, correct? The thing I wonder about is if DSPOBJAUT isn't showing us the whole picture. Could there be other profiles that have authority to the QSECOFR profile that won't show up on DSPOBJAUT? Would we have to sign on as QSECOFR and do the DSPOBJAUT from there to know for sure? The gentleman who has the password is out today, so if there's a way to know without signing on as QSECOFR, that would be helpful. TIA, Dan _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400@xxxxxxxxxxxx To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request@xxxxxxxxxxxx Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.
As an Amazon Associate we earn from qualifying purchases.
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.