ibmi-brunch-learn

Announcement

Collapse
No announcement yet.

Authority to Command?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Authority to Command?

    If one were to create a user profile (let's say 'PROFADMIN' with *SECADM authority only used to reset AS400 profile passwords, my understanding is this:
    -The 'PROFADMIN' profile needs authority TO the actual profile being reset
    -The 'PROFADMIN' profile ALSO needs authority to the actual command being ran

    My assumption initially was that all the profadmin acct needed was *SECADM and they would be on their merry way. However, I was surprised that I had to actually give authorities to the profile & command itself. Authorities such as *OBJOPR, *OBJMGT & what made things more confusing was that the command needed *READ, *UPD & *EXECUTE data authorities too.

    Unless I'm missing something, IBM topic on 'chgusrprf' doesn't mention needing special authority to the actual 'chgusrprf' cmd itself:
    http://www.ibm.com/support/knowledge...rf.htm?lang=en

    Thanks

  • #2
    While I agree it isn't clearly indicated, those requirements are actually stated in the link you provided to the CHGUSRPRF documentation under Special Authority/*SECADM: *SECADM Security administrator authority is given to the user. The user can create, change, or delete user profiles if authorized to the Create User Profile (CRTUSRPRF), Change User Profile (CHGUSRPRF), or Delete User Profile (DLTUSRPRF) commands and is authorized to the user profile. "

    Comment


    • #3
      To avoid accidently giving extra authority, we made a certain admin profile (admin for a country) the owner of all of that country's user profiles. That way you don't have to worry about all the other stuff.

      ... oh, almost forgot... in addition to giving it *SECADM.

      Kit
      www.ecofitonline.com
      DeskfIT - ChangefIT - XrefIT
      Last edited by kitvb1; May 23, 2016, 02:05 AM. Reason: almost forgot
      Regards

      Kit
      http://www.ecofitonline.com
      DeskfIT - ChangefIT - XrefIT
      ___________________________________
      There are only 3 kinds of people -
      Those that can count and those that can't.

      Comment

      Working...
      X