• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • New PowerTech Product Cracks Down on Special Authorities

    January 18, 2005 Alex Woodie

    In an ideal world, there would be no need to grant All Object (ALLOBJ) privileges on your OS/400 server. Everybody would be granted just enough access to do their jobs, and no more. Of course, we live in an imperfect world, and IT administrators, programmers, and even outside auditors often need special authorities, like ALLOBJ, to do their jobs. Thanks to a new program called AuthorityBroker, launched by PowerTech Group last week, the use of special authorities can be minimized and monitored.

    Users with special authorities can do quite a bit of damage to an OS/400 server. The big one is ALLOBJ authority, which gives users unfettered access to the system, including all libraries, data, and programs. “A user with All Object authority cannot be controlled,” PowerTech warns on its Web site. “An employee with access to this profile who has malicious intent has very little difficulty in exploiting it to steal critical data or to wreak havoc on a system.”

    Even access to lesser authorities can be the equivalent of a blank check to evil doers. A user with Spool Control (SPLCTL) authority can read and modify payroll data after it has been sent to a printer, according to PowerTech. Similarly, a nefarious user with Job Control (JOBCTL) authority can power-down the system or terminate subsystems and individual jobs at will, bringing your business to a painful, grinding halt.

    But this doesn’t have to happen to you.

    PowerTech’s new product, PowerLock AuthorityBroker, is designed to reduce the number of profiles with special authorities on users’ systems, without needlessly disrupting everyday business. When users do need a special authority to accomplish a task, such as loading a new program, kicking off a system save, configuring network access, or changing other user profiles, they can go into AuthorityBroker and swap into a “switch” profile, which temporarily gives them the special authority. In this way, users don’t need the special authorities in their everyday profile.

    AuthorityBroker allows administrators to restrict the types of special authorities that users have access to. It also tracks all switches through an audit trail, and will generate regular reports on switch activity. Administrators can even configure AuthorityBroker to send e-mail notifications when users swap into their powerful “switch” profile.

    PowerTech CEO Bruce Leader says AuthorityBroker is a good complement to regulatory compliance initiatives at OS/400 shops. “Auditors are finding an unacceptable amount of users with powerful profiles,” he says. “Under pressure from regulations like Sarbanes-Oxley, executives are no longer willing to allow this kind of unchecked access and are demanding tighter monitoring and control.”

    AuthorityBroker puts controls in place for the eight special authorities in OS/400, including All Object (ALLOBJ), Security Admin (SECADM), Network Services (IOSYSCFG), Audit Rights (AUDIT), Spool File Authority (SPLCTL), Hardware Administrator (SERVICE), System Operator (JOBCTL), and Backup Operator (SAVESYS).


    So are you a candidate for AuthorityBroker? According to Dan Riehl, an iSeries security expert and the founder of PowerTech, if your shop has more than 10 profiles with ALLOBJ authority, you are opening yourself to potential security problems, and could even be out of compliance with new industry regulations. Riehl lays out the special authority problem in his article “The Exposures of Indiscriminate Assignment of iSeries Special Authorities” (in PDF format).

    AuthorityBroker supports OS/400 V4R4 and later versions. Licenses are tier-based and range from $1,400 to $7,600, which allows a customer to install the software in a single partition; an additional fee of $1,000 or more is required for additional partitions.

    More information and trial downloads for AuthorityBroker are available from PowerTech’s Web site, at www.powertech.com.

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    The Dangers of Temporarily Changing User Profiles Date-Handling in CL Procedures

    Leave a Reply Cancel reply

Volume 5, Number 3 -- January 18, 2005
THIS ISSUE
SPONSORED BY:

PowerTech
ProData Computer Svcs
Patrick Townsend & Associates
iMessaging Systems
Affirmative Computer

Table of Contents

  • Testing At iSeries Shops Not Up to Snuff, Original Finds
  • New PowerTech Product Cracks Down on Special Authorities
  • iSeries Is Center of Lean IT Operation At adidas-Salomon Canada
  • NGS Provides a Quick ‘Dashboard’ View into Business Performance

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle