Re: Restrict ftp access to a certain HFS directory



On 1/20/2006 9:51 AM, R.S. wrote:
Simple answer is PErmit, not profile:
PE * CLA(PROGRAM) ID(SSCSWS) ACC(READ)

Usually CL(PROGRAM) * is UACC(READ), so there is no big issue to give restricted user such permit.
However * profile should be checked: While it is good idea to put whole LNKLST to the profile *, there are programs on linklist which shouldn't be open for everyone. The exceptions I know are ICHDSM00 and IRRDPTAB.



True, but PROGRAM * basically needs to have UACC(READ), and PERMITting the RESTRICTED users explicitly with READ will not hurt.


If they do not have PROGRAM IRRDPI00 and PROGRAM ICHDSM00 specifically defined that is a different exposure, not related to the introduction of RESTRICTED users into the access list of PROGRAM *.

	Walt Farrell, CISSP
	z/OS Security Design, IBM

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html
.



Relevant Pages

  • RE: ISPF PROFILE Question.
    ... Sorry I forgot how to change the profile in ISPF ... ... on the ISPF command line. ... For IBM-MAIN subscribe / signoff / archive access instructions, send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html. ...
    (bit.listserv.ibm-main)
  • Re: IBM Announcements
    ... Pommier, Rex R. wrote: ... looked at my profile and I wasn't using it best. ... For IBM-MAIN subscribe / signoff / archive access instructions, send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html. ...
    (bit.listserv.ibm-main)
  • Re: IDC3009I RC=110
    ... Yes, EGN is on, and I understand all that, but I still wonder why it worked before when there was no PAGE.** profile. ... For IBM-MAIN subscribe / signoff / archive access instructions, ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
    (bit.listserv.ibm-main)
  • Re: tcpip, vary obey command failed
    ... I copy my profile info into and use this in the obey command. ... WHEN ISSUING VARY OBEY COMMAND, ... For IBM-MAIN subscribe / signoff / archive access instructions, ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
    (bit.listserv.ibm-main)
  • Re: Another Generalized Resource question(problem solved)
    ... I would like to be able to add profiles to the Facility class within racf such that the profile will be made up of three qualifiers. ... For IBM-MAIN subscribe / signoff / archive access instructions, ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
    (bit.listserv.ibm-main)