IBM i Security Authorization Chart



Soure: Robin Tatam, Helpsystems.com and please note that this flowchart is actually an interpretation of the flowchart published by IBM in the security reference manual.

Double click on the image to enlarge.

Authority Considerations in IBM i

The following flowchart explains the process of how authorities are checked to access objects / libraries in IBM i
Note: Double click on the image to enlarge

FTP Subcommand: NAMEFMT

The NAMEFMT (name format) sub-command controls whether our FTP client session can access file systems on an IBM i Integrated File System (IBM i IFS) besides our DB2/400 data. NAMEFMT can be set on either an IBM i FTP client or server and — in addition to providing or denying access to IBM i IFS file systems; it affects how you code IBM i path names to IBM i IFS files you want to transfer.

NAMEFMT can be executed with a parameter of 0 or 1

NAMEFMT - This command displays the Name Format setting for each machine if both machines are IBM i. If our FTP host machine is an IBM i and our FTP client machine is running on another operating system (such as Windows or UNIX), we can check the status of the IBM i NAMEFMT value by issuing the NAMEFMT command as follows:
QUOTE SITE NAMEFMT

NAMEFMT 0 - 

1. This command tells an IBM i to use a naming format that assumes we are transferring files to and from the DB2/400 file system (the QSYS.LIB file system in the IBM i IFS). 
2. With NAMEFMT 0, we cannot perform file transfers from any other IBM i IFS file system except QSYS.LIB. That means we cannot access the Root (/), QOpenSys, QDLS, and the other IBM i IFS file systems. 
3. It also affects the way we specify our IBM i working directories or libraries in our other FTP commands. 
4. When NAMEFMT 0 is specified, we must use the following pathname naming convention in our FTP command when we are referencing AS/400 QSYS.LIB libraries, files, and members: LibraryName/FileName.MemberName

NAMEFMT 1 - This command tell IBM i that our client can access files in any IBM i IFS file system (such as Root, QOpenSys, and QDLS). It allows us to access any file residing on my IBM i, provided we have the access to that file. However, when NAMEFMT = 1, we must change the pathname naming convention for referencing a folder or file on the IBM i IFS to the following:

• /QSYS.LIB/libraryname.lib/filename.file/membername.mbr — when dealing with objects in the QSYS.LIB file system
• /filesystem/directoryname/filename.extension — when dealing with non- QSYS.LIB file systems. 


File naming convention in FTP

The following figure explains the file naming convention when using FTP

  • If you want to target or replace a particular member with FTP, you can do so by adding the member in the command.
  • Note: In the IBM i system LIBRARY, FILE and MEMBER names can only be a maximum of 10 characters or fewer.
  • Unix, Windows-based systems do not have these restrictions. File naming conventions may be a consideration when you build FTP automated applications.

Common FTP commands

Some FTP commands are the same on different OS, but others are not. You can usually get a list of commands if you enter help or ? (question mark) at the ftp> prompt.

Some useful FTP commands available on most systems include:
ascii - Switch to ASCII mode. ASCII mode is the default mode; use it for transferring text files.
binary - Switch to binary mode. Use to transfer binary files, including files ending in .zip, .tar, .Z, and .gz, executable programs, and graphics files.
bye (or quit) - Close the connection to the remote computer and exit FTP.
cd - Change the directory on the remote computer.
close - Close the connection to the remote computer.
del - Delete files from the remote computer.
dir (or ls) - List the files in the current directory on the remote computer.
get - Copy a file from the remote computer to the local computer.
hash - Displays a # on the screen for every block of bytes transferred. A block is 1024 bytes in some cases, 2048 in others, but is between 1024 and 4096 in most cases. Check FTP's online help for the number represented in the FTP program you are using.
help (or ?) - Lists or provides help on the use of FTP commands.
lcd - Change the directory on the local computer.
lpwd - Show the current directory (present working directory) on the local computer. This command is not available in all FTP versions. On Unix systems, try !pwd if lpwd doesn't work.
mdel - Delete multiple files on the remote computer.
mget - Copy multiple files from the remote computer to the local computer.
mkdir - Create a directory on the remote host.
mput - Copy multiple files from the local computer to the remote computer.
open - Open a connection to a remote computer.
prompt - Turn on (or turn off) file transfer prompting. Often used to turn off prompting when using mdel, mput, or mget so that you are not required to confirm the transfer of each file before it is transferred.
put - Copy a file from the local computer to the remote computer.
pwd - Show the current directory (present working directory) on the remote computer.
rmdir - Remove a directory on the remote host (the directory usually has to be empty).
user - Log into the remote computer to which you are currently connected. FTP will ask for a login name and possibly a password.

FTP Client/Server Considerations

FTP consists of two parts: the Client and the Server.

The distinction between FTP client and FTP server is from the viewpoint of where the FTP commands are initiated, not from the viewpoint of where the data resides.

Transfer Modes in FTP

ASCII is used by the rest of the world (stands for American Standard Code for Information Interchange)
  • Use if you want to purposely translate your data to ASCII - for example when the target system is a PC or a UNIX machine
EBCDIC is used nearly exclusively in IBM machines (stands for Extended Binary Coded Decimal Interchange Code)
  • Use if you want to purposely maintain EBCDIC Coding - for example when the target system is an IBM 390 or IBM i
BINARY
  • Use if you want to preserve the original content of the file and ensure NO translation takes place in the transfer of data. For example when transferring a *SAVF or a graphic image.

File Transfer Protocol (FTP)

FTP is an acronym for File Transfer Protocol. As the name suggests, FTP is used to transfer files between computers (client and server) on a network.

FTP uses a client-server architecture. Users provide authentication using a sign-in protocol, usually a username and password, however some FTP servers may be configured to accept anonymous FTP logins where you don't need to identify yourself before accessing files. Most often, FTP is secured with SSL/TLS.

How to FTP 
Files can be transferred between two computers using FTP software. The user's computer is called the local host machine and is connected to the Internet. The second machine, called the remote host, is also running FTP software and connected to the Internet.
  •     The local host machine connects to the remote host's IP address.
  •     The user would enter a username/password (or use anonymous).
  •     FTP software may have a GUI, allowing users to drag and drop files between the remote and local host. If not, a series of FTP commands are used to log in to the remote host and transfer files between the machines.

Timeline of IBM i

Here is a visual timeline of IBM i


Click on the image for the large version.
Right click for download options.


Source: Angus the IT Chap

Timeline of System i

Here is a visual timeline of System i
Click on the image for the large version.
Right click for download options.


Source: Angus the IT Chap

Display Authorized Users

The Display Authorized Users (DSPAUTUSR) command displays or prints the names of the authorized system users, in alphabetic order. The following information is provided for each user: the group profile of which the user is a member, the most recent password change date, whether the user profile has a password, and the text of the user profile.

Note:    While this command is searching for user profile information to display, another job cannot change user profiles (for example, with the Change User Profile (CHGUSRPRF) command). 


Restriction: The list of system users contains only the names of the user profiles to which the user of this command has at least read (*READ) authority. 

DSPAUTUSR SEQ(*GRPPRF) --> The group profiles are listed alphabetically in the group profile column. Members of that group are displayed alphabetically in the user profile column.

DSPAUTUSR SEQ(*USRPRF) --> This command displays the names of the system users in alphabetic order. For each user the following columns are displayed:
Group profile – the group profile of which the user is a member
Password Last Changed – the last password change date
No password – contains an ‘X’ is the user has no password.  Note that this means that the user cannot sign on
Level 0 or 1 Password - *YES, the user has a password for password levels 0 or 1 as required by the QPWDPVL system value
Level 2 or 3 Password - *YES, the user has a password for password levels 2 or 3 as required by the QPWDPVL system value
Netserver Password – *YES, the user has a Netserver password (enables Windows clients to access shared directory paths and shared output queues)
Local Pwd Mgt – *YES, the user profile password is managed locally (on the AS/400). When the password is not management locally, users cannot access the system by direct sign-on, but through other platforms.

IBM Supplied User Profiles

The following are the few user profiles shipped with the operating system

QSECOFR   - Security Officer
QPGMR      - Programmer
QBRMS      - BRMS profile
QSPL         - Spool profile
QSRV        - Service profile
QSYS        - System profile
QSYSOPR  - System Operator profile
QTCP        - Transmission Control Protocol (TCP) profile
QDFTOWN - For ownership purposes


Printers in AS400

Printer: Hardware device that prints the spool file

Writer: A writer is an IBM program that reads a spool file from an output queue and sends it to a printer

Each printer must have a printer device description. The printer device description contains a configuration description of the printer. Printers can be attached by a variety of attachment methods.

AS/400 supports 2 types of printer objects
1. Print Devices
2. Remote outqs

Print Devices are used to define local printers that are directly attached to or are controlled from AS/400. A print device contains an associated outq for printing spool files

Remote Outqs are spooling writers that send OS/400 spooled file output to a printer that is located on and controlled by remote system (AIX, Linux, Windows box). A remote outq is not associated with any AS400 device. A remote outq is an outq object that contains configuration parameters for sending spooled files to another system for processing. 

Printer files describe how the system operates on the data as it passes between your application program and a printer.

Printing Process Overview
  1. The printing process starts when an application program runs. The application program creates output data. The output data is based on the application program and information contained in the printer file. 
  2. If print spooling is selected, the output data is placed in a spooled file and the spooled file is placed in an output queue. If direct printing is selected, the output data is sent directly to the printer.
WRKWTR *ALL – Display all writers 
  • Printer writers (PRT)
  • Remote printer writer (RMT)
  • 2=Change   3=Hold   4=End   5=Work with   6=Release   7=Display messages   8=Work with output queue 
WRKWTR – Display printer writers only
STRPRTWTR – Start printer writer
STRRMTPRT – Start remote writer

Difference between SST and DST

SST is available when the OS is started. The OS is required for accessing SST. SST is used to manage firmware & hardware. It is not used to manage OS.

DST is available even when the system has limited capabilities. DST is available even if OS is not installed. LIC is required for accessing DST.  

Accessing SST

To access service tools using SST, complete the following steps:
  1. Enter STRSST (Start SST) on an IBM i command line. The Start SST Sign On display is shown.
  2. Enter the following information:
    • Service Tools User ID: The service tools user ID you sign on with.
    • Password: The password associated with this user ID.
  3. Press Enter.
Note: To login to SST, the user ID must have Service (*SERVICE) special authority 

Accessing DST

We can access DST in 2 different ways
1. From Control Panel
2. Through manual IPL

Accessing DST from the control panel:
To access service tools using DST from the control panel, complete the following steps:
  • Put the control panel in manual mode.
  • Use the control panel to select function 21 and press Enter. The DST Sign On display appears on the console.
  • Sign on to DST using your service tools user ID and password. The Use dedicated service tools (DST) display appears.
  • Select the appropriate option from the list and press Enter.
    • Select option 5 (Work with DST environment) to get to additional options for working with service tools user IDs.
    • Select option 7 (Start a service tool) to start any of the service tools available from DST.
    • Select any of the other options, as appropriate.

Accessing service tools using DST from a manual IPL:
To access service tools using DST from a manual initial program load (IPL), complete the following steps:
  • Put the control panel in manual mode.
  • Take either of the following actions:
    • If the system is powered off, turn the system on.
    • If the system is powered on, enter the Power Down System (PWRDWNSYS) command, PWRDWNSYS *IMMED RESTART(*YES), on a command line to turn off the system and restart it.
  • Sign on to DST using your service tools user ID and password. The Use dedicated service tools (DST) display is shown.
  • Select the appropriate option from the list and press Enter.
    • Select option 5 (Work with DST environment) to get additional options for working with service tools user IDs.
    • Select option 7 (Start a service tool) to start any of the service tools available from DST.
    • Select any of the other options, as appropriate.



Service Tools

Service tools are used to perform various system functions including diagnosing system problems, managing disk units, and managing system security. 

Dedicated Service Tools (DST) or System Service Tools (SST) are used to access service tools functions.  The following are the few functions we can perform with DST or SST.
  • Add hardware resources to the system.
  • Diagnose system problems.
  • Manage disk units.
  • Manage logical partition (LPAR) activities, including memory.
  • Manage or view main storage dumps.
  • Manage other service tools user IDs.
  • Manage system security.
  • Review the Licensed Internal Code and product activity logs.
Service tools user IDs are user IDs that are required for accessing service functions through DST, SST, i series navigator (for disk unit management), and Operations Console. 

Service tools user IDs are created through DST or SST and are separate from IBM i (OS/400) user profiles. It is possible to have a service tools user ID and operating system user profile with the same name.

You can create a maximum of 100 service tools user IDs (including the four IBM-supplied user IDs).

Authorization Lists

Authorization lists are a powerful tool for the management of security. Authorization list is a list of 2 or more user IDs & their authorities for system resources.  Authorization list grant users (or groups) the same authority to multiple objects.  

Authorization list reduces the number of private authorities stored in *usrprf object. The system identifies it as an object type *autl.

Note: The only drawback in authorization list is that they are only restored when restoring all profiles. 


Authorization List Commands

CRTAUTL command creates the authorization list 
Eg: CRTAUTL AUTL(List1)  

GRTOBJAUT command allows to associate the authorization list with the files (i.e, to determine which objects should be secured with authorization list)
Eg: GRTOBJAUT OBJ(Lib1/*ALL) OBJTYPE(*FILE) AUTL(List1)
By running above example, you are adding all files in library Lib1 to authorization list List1

ADDAUTLE command allows you to grant users the authority to the lists.
Eg: ADDAUTLE AUTL(List1) USER(Rahsin) AUT(*USE) 
By running above example, you are giving USE authority to the user Rahsin for the authorization list List1

EDTAUTL command allows you to add and remove users from the list, and specify their authority to the list. 

DLTAUTL command allows you to delete an authorization list.

DSPAUTL command allows you to display an authorization list.

WRKAUTL (Work with Authorization Lists) Command allows you to work with authorization lists. With this command, you can display, edit, delete, display the list's objects, or change the text for an authorization list.
Eg: WRKAUTL  AUTL(*all) -  It lists of all the authorization lists that you either own or have authority to see is shown.

Difference between HMC Upgrade & Update

It’s important to distinguish between updating and upgrading a system. The terms are not synonymous. 

Upgrade
To upgrade is to bring the system to a higher version or release of HMC code. When the HMC’s version number is incremented, such as going from Version 6 to Version 7, the upgrade method must be used in order to apply the new version of HMC code.

Update (Corrective Service)
In between HMC releases, or between upgrades, there will be times when interim fixes or cumulative service packs need to be applied. Interim fixes consist of security fixes or fixes that are considered critical to be released immediately to customers. Service packs are generally larger in contents. Both can be installed on the HMC by using the Install Corrective Service task under HMC Code Update, or by using the updhmc command on the HMC.

HMC Roles for User IDs

HMC comes with two predefined users: hscroot and root and cannot be deleted. They come with default passwords, but it is strongly recommended that they be changed during HMC setup and configuration. The default passwords are:

Username: hscroot
Password: abc123

Username: root
Password: passw0rd

Note: Make sure you change them!

hscroot & root have all the access to HMC and can manage & modify almost everything in HMC. Logging in as root is disabled. Note that while you will not be using the root password for daily administration, you may need it from time to time when performing problem determination, usually with the assistance of IBM support or product engineering.

Apart from these accounts, additional user IDs should be created on the HMC so that not every user is accessing the system with the same user ID and password, and not necessarily with the same level of authority.

Each HMC user IDs can be a member of a different role. A task role in HMC defines the access level for a user to do tasks on the managed object or group of objects, such as a managed system or logical partition. HMC roles are either predefined or customized. 

When you create an HMC user, you must assign that user a task role. There are 5 system defined task roles:
    •hmcsuperadmin - The super administrator acts as the root user, or manager, of the HMC system. The super administrator has unrestricted authority to access and modify most of the HMC system. This should not be confused with user root.

      •hmcservicerep - A service representative is generally someone (from IBM) physically at the managed system location to install, configure or repair managed systems.

        •hmcoperator - An operator is responsible for daily system operations, but do not have authority to add new users or modify the roles.

          •hmcpe - A product engineer assists in support situations (for both the managed system and the HMC), but cannot access HMC user management functions. To provide support with access for your system, you must create and administer user IDs with the product engineer role. PE can additionally shutdown HMC & close virtual terminal windows which service rep can't do.

            •hmcviewer - A viewer can view HMC information, but cannot change any configuration information.