HP3000-L Archives

August 2004, Week 1

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"Baker, Mike L." <[log in to unmask]>
Reply To:
Baker, Mike L.
Date:
Fri, 6 Aug 2004 19:20:32 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (9 lines)
Has anybody had any experience with having a system udc check to see if you are a session or a job, and if you are a session, running (xeq) a cobol program that checks an encrypted ksam file for a user-id and password, thus bypassing mpe security?  Has anyone done that (at a financial institution) and had their auditors say that was ok?  (i.e. run a cobol program to check a file that you can't list the contents of that checks parameters when you are logging on as a session, not a job).  I know this opens an entire can of worms in regards to when the user and password are setup, and how you change it, and the frequency of changing it, reusing the password, etc...

Just curious if anybody has done something like that and the auditors were ok with bypassing mpe user/group/account security that way.

Mike Baker

* To join/leave the list, search archives, change list settings, *
* etc., please visit http://raven.utc.edu/archives/hp3000-l.html *

ATOM RSS1 RSS2