TechTalk: Don't Let Users Rewrite History

Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

The AS/400 keeps a history log in QSYS/QHST, a message queue (*MSGQ) object. When it becomes full, OS/400 creates a *FILE object in QSYS whose name begins with QHST, copies the contents of the history log and clears the log.

On our system, these files were created with public authority of *EXCLUDE during Version 1 of OS/400. When we upgraded to V2R1M0, we found that the system history files were created with public authority of *LIBCRTAUT, which generally became *CHANGE for our clients.

This was unacceptable because it permitted anyone with a command line and authority to the right commands to write HLL programs to alter the system history files. Changing QSYS's CRTAUT parameter to *EXCLUDE wouldn't help because it would affect message queues, communications objects and other libraries by giving the public *EXCLUDE authority.

I ran into resistance from Level 2 and the developers. It seemed that they didn't want to change this. After discussing the problem with our local branch, several PTFs magically became available. Here are the numbers for the security conscious:

 V2R1M0: SF11409 V2R1M1: SF11347 V2R2M0: SF11348 

As of this writing, I don't believe these PTFs are on a cumulative PTF package. I recommend that the PTF be applied and authority removed from system history files already created with *CHANGE. Make sure the PTF is applied before correcting the current files. The command is:

 RVKOBJAUT OBJ(QSYS/QHST*) + OBJTYPE(*FILE) + USER(*PUBLIC) + AUT(*ALL) 
BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: