A Word About EHLLAPI Security

Security - Other
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

EHLLAPI programs externally interact with emulator sessions. That is to say, the EHLLAPI program actually types data into the presentation space, just as the keyboard does. You can literally watch the data being entered in the emulator session if the window is visible while the program executes.

Because automation involves potentially sensitive data (for example, a password), two security concerns generally arise in EHLLAPI programming discussions. The concerns involve the specification and storage of this sensitive data.

Many users hard-code passwords in their EHLLAPI sign-on programs. Conventional wisdom suggests this is bad practice, but if only one user is executing the automation program and the PC is adequately protected (for example, power-on password, activated lock screen) the exposure is minimal, and perhaps the concerns are overstated.

However, if the integrity of a program or workstation cannot be assured, or the program needs to be shared by multiple users, there are some techniques to explore.

One technique is to parameterize the automation program, passing data in as arguments, perhaps even prompting a user for data. This way, sensitive data does not need to be maintained in the program itself. Parameterizing has the added benefit that multiple users can use the same programs with no modifications.

To keep observable screen activity to a minimum and prying eyes at bay, an EHLLAPI program can routinely minimize the emulator session while performing data entry or screen parsing activity. After the sensitive screen data has been cleared, the program maximizes the screen before exiting the program.

Security precautions are as appropriate in REXX EHLLAPI as they are in AS/400 applications. Where conflicts between convenience and security emerge, common sense should dictate a course of action.


Martin Norman

Martin Norman has worked for more than 25 years in the IT industry, specializing in Systems and Security Management of the IBM System i platforms. Martin has performed consultancy and implementations in the UK and Central Europe, and for the last 10 years in the U.S., Canada, and the Caribbean, with particular focus on Fortune 100 and 500 organizations.

 

Martin is Technical Support Manager at Halcyon Software Inc., based in Philadelphia, where he focuses on helping IBM Power Systems users get the optimum performance from their IT business environment and the maximum efficiency and ROI for their operations.

 

A regular speaker at IBM events, such as COMMON and within the LUG network, he is also a contributor to a number of U.S. IT publications.

BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: