Dan,

Any profile with *ALLOBJ authority can use them.  Any clones of QSECOFR
can use and change it.


-----Original Message-----
From: security400-bounces@xxxxxxxxxxxx
[mailto:security400-bounces@xxxxxxxxxxxx] On Behalf Of Dan
Sent: Friday, November 11, 2005 8:37 AM
To: Security400@xxxxxxxxxxxx
Subject: [Security400] Seeing all authorities on DSPOBJAUT???


Interesting thing happened today that we're trying to figure out how. I
won't bore everyone with the details, but knowing the definitive answers
to
the following questions could significantly narrow down the
possibilities.

Background:
V5R2
User profile QSECOFR is owned by QSYS and the only authority "entry" is
*PUBLIC *EXCLUDE.
(FWIW, user profile QSYS is owned by QSYS and the only authority "entry"
is
*PUBLIC *EXCLUDE.)

That *is* the ultimate lockdown, right? No one can adopt authority, or
do
*anything* with the QSECOFR profile, correct?

The thing I wonder about is if DSPOBJAUT isn't showing us the whole
picture.
Could there be other profiles that have authority to the QSECOFR profile
that won't show up on DSPOBJAUT? Would we have to sign on as QSECOFR and
do
the DSPOBJAUT from there to know for sure? The gentleman who has the
password is out today, so if there's a way to know without signing on as
QSECOFR, that would be helpful.

TIA, Dan
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
To post a message email: Security400@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.




As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2021 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.