Previous Table of Contents Next


The authority component controls the use of objects, resources, certain instructions, and machine attributes in the system via the user profile. The user profile defines the following capabilities for a particular user:

•  User Class — Each user class has special authorities based on the system security.
•  Objects Owned and Authorized — A list of the objects owned and authorized to the user is contained in the user profile.
•  Authorization of Objects — The authority to the above list of objects is in the user profile.
•  Privileged Instructions and Special Authorities — Any privileged instructions and special authorities for the user are contained in the user profile.
•  Password — This password is required for all security levels except level 10 to sign on to the system.
•  Current Library — When the user creates a new object, the object is put into the user’s current library.
•  Initial Program and Menu — After the user signs on to the system, this field identifies the first program and the first menu the user will see.
•  Limited-Capability User — When this option is enabled, the commands are restricted and the user is limited to menu selections.
•  Limit Device Session — The user is limited to one session per device.
•  Maximum Storage Allowed — This field gives the total disk space allowed for objects this user owns.
•  Priority Limit — This field gives the highest scheduling priority a user can have. We discuss priorities in more detail in Chapter 9.
•  Special Environment — This field specifies the environment in which the user will execute (e.g., System/36 Environment).

Most of these fields are self-explanatory, but the first four need some further discussion.

User Class

The AS/400 has five user classes that determine the level of system access a user is permitted. The class defines the functions a user can perform, the menu options available to the user, and the privileged instructions, if any, the user can execute. The five user classes, starting with the highest level of access, are

•  Security Officer — This is the highest level of user in the system. The security officer performs all security functions, including the creation of other user classes.
•  Security Administrator — The security administrator has the responsibility to enroll users and to secure the system resources.
•  System Programmer — This user develops applications for the system.
•  System Operator — This user performs the system-operation functions, such as backing up the system.
•  Workstation User — This is the user of the application programs. The workstation user has the lowest level of access in the system.

When the AS/400 is initially shipped, one user profile exists for each user class. It is then up to the customer to decide who in each installation fills each of the roles. Obviously, for a given installation, a single person can fill more than one role.

Objects Owned and Authorized

The user profile contains two lists. The first is a list of all the objects owned by the user, and the second is a list of all the objects authorized to the user. A user who creates an object is the owner of that object. If a user profile is a member of a group file, which we discuss later in this chapter, you can specify in the user profile that all objects created by the user belong to the group. Object ownership can be transferred. The owner of an object or anyone with object-management authority (see the next section) has the authority to grant other users private authority to the object. These individuals also can grant public authority to the object. Thus, every user in the system has access to his or her owned objects, the objects to which (s)he has been granted private authority, and any objects that have public authority. Only the objects with owner and private authority are listed in the user profile.

Authorization of Objects

For each object on the AS/400, eight authorities can be granted. These are

•  Object operational authority — Allows the user to look at the description of the object and use the object as determined by the data authorities the user has to the object.
•  Object management authority — Allows the user to specify the security for the object, move or rename the object, and add members to the database files. Object existence rights are needed to remove members from database files.
•  Object existence authority — Allows the user to delete the object, free the storage of the object, perform save/restore operations, and transfer ownership of the object.
•  Authorization list management authority — Allows a user to add, remove, and change users and their authorities on an authorization list.
•  Read authority — Allows the user to access the object.
•  Add authority — Allows the user to add records to the object.
•  Delete authority — Allows the user to delete records from the object.
•  Update authority — Allows the user to change records in the object.
OS/400 groups these eight authorities into four combinations to make it easier for the end user to understand the capabilities allowed. End users are not prevented from creating other combinations, but most use these combinations of authorities. The four groupings are
•  ALL — Combines all eight authorities.
•  CHANGE — Combines object operation, read, add, delete, and update authorities.
•  USE — Combines object operation and read authorities.
•  EXCLUDE — Has no authority to the object. EXCLUDE overrides any authority granted to the public or group profile because of the order in which authorities are searched. We will see this search order later in this chapter.

Privileged Instructions and Special Authorities

Each user profile contains information indicating privileged instruction and special authority for the user. Several MI privileged instructions can be executed only by users who are authorized to do so in their user profiles. For example, the profile for the security officer is created with the capability to execute the instruction that terminates the machine processing. The instruction that does this is accessed through the PWRDWNSYS (Power Down System) command. This privileged instruction is, for obvious reasons, not available to all users. Likewise, a series of special authorities exist that can be granted to selected users. These special authorities deal with such functions as suspending objects, controlling processes, performing load/dump operations, and using low-level service tools.


Previous Table of Contents Next

Copyright © NEWS/400 Books