Newsletters   Subscriptions  Forums  Store   Career  Media Kit  About Us  Contact  Search   Home 
fhg
Volume 5, Number 6 -- February 9, 2005

Running Query Without Adopted Authority

Hey, Ted:


Because of the Sarbanes/Oxley Act, we are tightening our security. One problem we have is using AS/400 Query. Several of our menus include options that run the Work with Queries command. The problem is that a user who takes one of these options is running WRKQRY under adopted authority, and therefore has access to files that should from now on be secured. How can we change the WRKQRY command so that the user does not have adopted authority?

--Lin


You can't change the command. You may be able to change the command-processing program, QSYS/QQUDA, but I don't like to monkey with IBM-created objects. I'm so conservative, I wear a belt and suspenders, and I have no idea what might happen.

Here's what I suggest you do. First, create a new CL source member from your CL program template. (You do have a template, don't you? If not, use this one.) You will need only one CL command in the regular routine: WRKQRY.

Compile the new CL program. It should run as either an OPM program or an ILE program.

If necessary, transfer ownership of the new program to the user who owns your applications.

CHGOBJOWN OBJ(mylib/mypgm)  OBJTYPE(*PGM) NEWOWN(newowner)

Then change the program not to use adopted authority.

CHGPGM PGM(mylib/mypgm) USRPRF(*USER) USEADPAUT(*NO)

The parameter USRPRF(*USER) says that the program uses the current user's authority only when it runs. USEADPAUT(*NO) does not allow the program to adopt authority from programs higher in the call stack.

--Ted


Click here to contact Ted Holt by e-mail.

Sponsored By
COMMON

COMMON Spring 2005
IT Education Conference & Expo
Chicago, Illinois
March 13-17, 2005

Register Now!

COMMON in Chicago will feature hundreds of sessions in business strategy, networking, and development, with a featured educational focus section on Systems Management.

Conference Highlights
· Explore the latest technologies in the industry's largest Expo
· Network at COMMON socials
· Talk to IBM executives at the iSeries Nation Town Hall Meeting
· PLUS, be part of the first USERblue, a conference-within-a-conference for IT professionals who run UNIX systems on IBM technologies. COMMON conference attendees can attend USERblue sessions at no extra charge.

COMMON conferences are one of the most cost-effective ways to gain the tools and knowledge you need to meet the changing demands of information technology. You'll pay a reasonable amount for intensive education, unlike any offered within the industry, and you'll garner a tangible and immediate return on your investment.

In addition to the direct savings on education, conference attendees make professional contacts whom they can consult long after the conference ends. Attendees will also have direct access to IBM developers and managers. The Expo offers an opportunity to talk one-on-one with industry vendors who provide the latest products and services. This means attendees return to the office with real-time solutions that can be implemented immediately--without wasting countless hours in independent research.

A typical COMMON conference attendee participates in nearly 40 hours of sessions presented by leading professionals in the IT industry - individuals who would charge up to $500 per hour, if you could secure them! At COMMON conferences, they're a standard part of our educational package.

COMMON is the largest users group of IBM and IBM-compatible IT professionals, and it holds two education conferences per year.

For more information, visit:
www.common.org


Technical Editors: Howard Arner, Joe Hertvik, Ted Holt,
Shannon O'Donnell, Kevin Vandever
Managing Editor: Shannon Pastore
Contributing Technical Editors: Joel Cochran, Wayne O. Evans, Raymond Everhart,
Bruce Guetzkow, Marc Logemann, David Morris
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.


THIS ISSUE
SPONSORED BY:

T.L. Ashford
WorksRight Software
COMMON


BACK ISSUES

TABLE OF
CONTENTS
The Integrated File System for Intelligent People

Limiting All-Object Authority

Running Query Without Adopted Authority


The Four Hundred
DB2 Is the Next Logical eServer Convergence

Is .NET a Litmus Test for iSeries Loyalty?

Why Do Rack Servers Persist When Blade Servers Are Better?

Four Hundred Stuff
JDE Shops Have Plenty of Options for Third-Party Maintenance

Products Based on New AS3 Protocol Are Ready to Go

inFORM Widens Forms Design Options with iDocs 4.0

Four Hundred Monitor


Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc. (formerly Midrange Server), 50 Park Terrace East, Suite 8F, New York, NY 10034
Privacy Statement