TechTalk: AS/400 Security Idea

Security - Other
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

From: Chris Ringer To: All

I need some feedback regarding AS/400 security and how to best implement it. My feeling is that the AS/400 security is too proprietary; if we ever migrate to another system, our object security will be lost during the migration.

Therefore, I've been toying with the idea of building security into my software. I would still set up security as usual in the AS/400, but I would have my program use the Check Object (CHKOBJ) command in a CL program to see if the user has authority to an object. My CL program would be called right away whenever a user attempted to run a program. With this approach, if we ever migrate to another system, I have to change only one program to reinstate my security scheme.

I believe that the AS/400 security checks would still be performed only once since security is not checked until a user accesses an object. Since my program would check the authority, the program would never get to the point of accessing the object if the user did not have authority to it.

I would appreciate all comments.

From: Carol Smith To: Chris Ringer

We are using a security program like the one you are talking about. We have a file set up with the name of the user and the programs he is allowed to run. If we have a user who needs access to everything, we set him up with one record with a special code in the program field. The program bypasses security checking for that person.

We pass the name of the program back to the user in a message that says the program is not available. When the user can't get into the program, he can tell us which program name to set up.

It did get a little tiresome with so many requests for access to programs.

Now we are using a program that stores each user's menu in a database file. The security program worked fine though. You might think about setting up something with group profiles instead of individual user profiles. You can retrieve the group profile with the Retrieve User Profile (RTVUSRPRF) command.

BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: