Stuff
OS/400 Edition
Volume 1, Number 15 -- August 29, 2002

Security Made Easy with Operations Navigator


by Shannon O'Donnell

You may not realize it, but AS/400 security management became a whole lot easier with the release of OS/400 V5R1. The V5R1 Operations Navigator client contains several "shortcuts" for defining and configuring OS/400 security. Keep reading to find out how easy it is for you to become an AS/400 security wizard!

display

A Word of Caution

The information you are about to read, while easy to follow and understand, can also be disastrous if allowed to be used by unauthorized individuals. The security choices you can make with Operations Navigator will directly and immediately change your AS/400 System Security Values. Be warned that not everyone in your organization should be given access to these tools.

Requirements

The first requirement for becoming an AS/400 security wizard is to ensure that you have OS/400 V5R1 installed on your AS/400 and the V5R1 version of Client Access Express (and, by default, the V5R1 version of Operations Navigator) on your PC.

Getting There

To get to the security tools in Operations Navigator, connect to your V5R1 AS/400 and then drill down to the Security tree item. Expand it. You should see two entries: Authorization Lists and Policies.

If you click on the Policies tree item, you'll get a set of four new options appearing in the right-hand pane of the Operations Navigator GUI: Password Policy, Security Policy, Audit Policy, and Sign-on Policy.

Let's start by double-clicking the Password Policy item. You should see a panel like that shown in Figure 1.

Figure 1: The Password Policy panel lets you easily define password rules

From here, you can very quickly define such rules as whether or not to support the new 128-character password, the minimum and maximum password lengths, and when passwords will expire.

If you double-click the Security Policy item, you'll see the Security Policy Properties panel. From this panel, you can set the system's security level, control the settings for restoring objects, and control which objects are auditable, among other things.

The Audit Policy panel (Figure 2) allows you to set the allowed options for all system and object level auditing as well as journaling options.

Figure 2: Use the Audit Policy panel to control system journaling and auditing parameters

And, finally, the Sign-on Policy panel (Figure 3) allows you to control how many attempts at signing on your users get before the system automatically takes some pre-defined action (also defined here). You can also control various log-on properties for remote users from this panel.

Figure 3: The Sign-on Policy panel controls what actions to take for invalid sign-on attempts

Authorization Lists

The other security tree item in Operations Navigator is the Authorizations List option. You can click this tree item to work with previously defined authorization lists. You can also right-click this tree item to create new authorization lists.

Maintain Positive Control

As always, any time you are working with security values on any system, it is absolutely critical that you maintain control of who has access to what. The security tree item in the Operations Navigator GUI is no exception. In the hands of the wrong person, your AS/400 could very quickly be brought to its knees by one inadvertent or intentional click of a mouse button. Therefore, it's very important that you limit access to this function of Operations Navigator to those individuals who absolutely require it.

If you are not sure how to control who gets access to what items in Operations Navigator, see the article "Exporing iSeries Navigator Application Administration," where you'll find tips on how to control access to various features of the Operations Navigator GUI.


Sponsored By
PROFOUND LOGIC SOFTWARE

Don't be left behind!

Thousands of programmers have adopted RPG-Alive, and are now able to read and understand RPG code 2 to 3 times faster.

To try RPG-Alive on your system, visit http://www.RPGAlive.com/now

"I am very happy with RPG-Alive! It's a terrific productivity booster!" says Brian Johnson of Help/Systems.

See other user testimonials at http://www.rpgalive.com/testimonials.html


THIS ISSUE
SPONSORED BY:

T.L. Ashford
Aldon Computer Group
LANSA
ASNA
Profound Logic Software
WorksRight Software


BACK ISSUES

TABLE OF CONTENTS
Back To Basics: Message Subfiles

The 5250 Word Wrap Utility

Cool Things in CODE/400: A Bag Full of Tips

The Opportunity of a Lifetime

Security Made Easy with Operations Navigator

More on XLE and XML File Creation


Editors
Shannon O'Donnell
Kevin Vandever

Managing Editor
Shannon Pastore

Contributing Editors
Howard Arner
Joe Hertvik
Ted Holt
David Morris
Richard Shaler

Publisher and
Advertising Director

Jenny Thomas

Contact the Editors
Do you have a gripe, inside dope or an opinion?
Email the editors:
editors@itjungle.com



Last Updated: 8/29/02
Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.