IBM i : Limit Security Officer (QLMTSECOFR) - '1'

Information

The Limit Security Officer (QLMTSECOFR) system value controls whether a user with all-object (*ALLOBJ) or service (*SERVICE) special authority can sign on to any workstation. Limiting powerful user profiles to certain well-controlled workstations provides security protection.

Solution

Set QLMTSECOFR to 1, so that a user with *ALLOBJ or *SERVICE special authority can sign on at a workstation only if that user is specifically authorized (that is, given *CHANGE authority) to the workstation or if user profile QSECOFR is authorized (given *CHANGE authority) to the workstation. This authority cannot come from public authority.

See Also

https://www.ibm.com/support/knowledgecenter/ssw_ibm_i_73/rzarl/sc415302.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1)

Plugin: AS/400

Control ID: f5a5e65839b6c127d775fa0719f2463e6068778d7e3e079cbfb8a6a735b6b1d0