Re: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?)

2016-05-19 Thread Joel C. Ewing
On 05/18/2016 05:16 AM, Elardus Engelbrecht wrote: > Robert S. Hansel (RSH) wrote: > >> OPERATIONS users actually can grant privileges because they can create >> dataset profiles for any group. And if they own a profile they create, they >> can permit access to it. > RACF by default will allow th

Re: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?)

2016-05-18 Thread Jesse 1 Robinson
: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?) Hi Skip, OPERATIONS users actually can grant privileges because they can create dataset profiles for any group. And if they own a profile they create, they can permit access to it. In z/OS 2.2, you will be able to

Re: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?)

2016-05-18 Thread Elardus Engelbrecht
Robert S. Hansel (RSH) wrote: >OPERATIONS users actually can grant privileges because they can create dataset >profiles for any group. And if they own a profile they create, they can permit >access to it. RACF by default will allow that OPERATIONS stunt. IRREVX01 can be used to block those acr

Re: Privileged Users (was: EXTERNAL: Re: [EXTERNAL] Re: smp/e sha-2 support?)

2016-05-18 Thread Robert S. Hansel (RSH)
Hi Skip, OPERATIONS users actually can grant privileges because they can create dataset profiles for any group. And if they own a profile they create, they can permit access to it. In z/OS 2.2, you will be able to replace the assignment of AUDITOR authority with ROAUDIT, which truly is benign